Skip to main content

Privacy Policy

This Privacy Policy (v3.10) replaces our previous Privacy Policy v3.9. Previous versions are available upon request at support@nomadtable.app.

1. Introduction

Welcome to Nomadtable ("we," "our," or "us"), where you can find friends while traveling solo. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and services that connect solo travelers for shared activities worldwide. Undefined terms in this Privacy Policy will have the same definition as in our Terms of Service.

2. Information We Collect

Some of the information we collect is necessary for you to create and maintain a Nomadtable account, and some voluntary. However, if you don't provide necessary information when requested, then we may not be able to provide you with access to the App or fulfill our obligations to you (such as providing services you request).

Information You Provide

  • Contact information (e.g., name, email).
  • Profile details (e.g., age, gender, home country, languages spoken, interests).
  • Content you submit (e.g., messages, activities created, future trips).
  • Profile pictures, images, and locations you send as chat messages.
  • Verification images.
  • Referral information (e.g., how you heard about Nomadtable).
  • Ratings and meetup feedback you submit about other users (e.g., a thumbs up or thumbs down after a confirmed meetup).

Ratings and Meetup Feedback: After a meetup confirmed by its organizer and attendees, you may rate other participants (thumbs up or thumbs down), and they may rate you. Ratings are anonymous to the person being rated: we do not disclose who submitted a rating, and users are not notified when they receive one. Only a user's aggregate thumbs-up count is displayed on their profile. Thumbs-down ratings are never shown on profiles or to other users; they are used internally only for trust, safety, and moderation purposes (for example, a sustained pattern of negative feedback may flag an account for human review by our safety team).

Verification images you choose to submit are retained only temporarily to allow comparison between your profile image and your submitted verification image. After verification, they are deleted within 7 days unless we must retain them longer to comply with law or to investigate fraud/security incidents.

Photo Verification

Nomadtable offers optional photo verification to help confirm that your profile photos appear to represent you. When you choose to verify, you submit a selfie through the app. A trained member of our safety team visually compares your selfie to your own uploaded profile photos to confirm they appear to represent the same person.

What we do:

  • A human reviewer performs a one-to-one visual comparison of your verification selfie against your own profile photos. We do not search your face across other users, build a searchable face database, or perform real-world identity lookups.
  • Reviewers access verification selfies solely for this purpose, under confidentiality obligations.

What we do not do:

  • We do not use automated facial recognition or face-comparison technology for verification, and we do not create biometric identifiers, biometric templates, face geometry scans, or similar biometric data from your photos.
  • We do not sell, lease, trade, or otherwise profit from verification selfies.
  • We do not use verification selfies for advertising, tracking, profiling, or AI model training.
  • We do not disclose verification selfies to third parties except our cloud storage provider (which hosts them on our behalf), or as required by law.

Retention and deletion: Verification selfies are deleted within 7 days after submission, unless retention is required to comply with a legal obligation or to investigate fraud or security incidents. Any face-comparison results generated under our previous verification process are deleted on the same schedule.

Consent: Photo verification is optional. Before you submit a verification selfie, the app presents a consent screen explaining how your selfie will be used. You must affirmatively consent before verification begins. You may withdraw your consent or request deletion of your verification selfie at any time by contacting us at support@nomadtable.app.

Your rights: Depending on your location, you may have additional rights regarding your photos and personal data under applicable laws (such as the EU General Data Protection Regulation or similar laws). Please see Section 7 ("Your Privacy Rights and Choices") or contact us for more information.

All photos and images you upload—including profile pictures, additional profile images, and images shared in activities or chats—are automatically analyzed using AI-powered tools (AWS Rekognition) to detect explicit, violent, or otherwise prohibited content, and to perform basic quality checks (for example, confirming that a profile photo contains a face). This moderation scanning is separate from optional photo verification: it does not use facial recognition to identify you, does not compare your images against other people's images, and does not create biometric identifiers or biometric templates. This helps maintain a safe community and uphold our Community Guidelines. In some cases, flagged images may be reviewed by trained human moderators under confidentiality obligations. We do not use these images to train external or internal AI models, and analysis is limited to safety and policy-enforcement purposes.

Message and Text Moderation. Messages, activity descriptions, profile text, and other text content you submit through Nomadtable may be automatically analyzed using automated moderation tools, including AI-assisted classifiers provided by our chat infrastructure provider (Stream Chat) and keyword-based systems, to detect potential violations of our Terms of Service, Community Guidelines, or safety policies. Activity names may also be screened using the OpenAI API during the activity creation process. This may include attempts to detect harassment, spam, scams, sexual misuse of the platform, threats, illegal activity, or other prohibited conduct.

Where text content is flagged by these systems or reported by another user, authorized moderators may review limited relevant content and account information for safety, abuse-prevention, and policy-enforcement purposes. We do not routinely read private messages, and human review is generally limited to content that has been flagged, reported, or is otherwise necessary to investigate safety, security, legal, or policy concerns.

We do not currently use private messages to train Nomadtable AI models. If we materially change this practice, we will update this Privacy Policy and, where required, provide notice or obtain consent.

Information We Collect Automatically

  • Location Information: We collect location information through your device. You can limit this collection via your device controls.
  • App Usage: We collect information about when and how you use our Products, including what profiles and events you view.
  • Log Data and Device Information: We automatically collect certain technical information when you use Nomadtable to ensure proper functionality and improve performance. This may include your device model, operating system version, app version, language, time zone, IP address, and diagnostic data related to log-ins, crashes, or errors.
  • Device Identifiers and Advertising Attribution Data: With your permission on iOS (via the App Tracking Transparency prompt), we may collect your device's advertising identifier (IDFA) and campaign attribution data (such as which advertisement or campaign led you to install Nomadtable). We use this only to measure the performance of our own advertising. You can withdraw this permission at any time in your device settings (Settings > Privacy & Security > Tracking).

3. How We Use Your Information

We use the personal information we collect mainly to provide our Products to you and to improve them. Specifically, we may use the data we collect to:

  • Provide the Products you requested.
  • Register your account, verify your account, and verify the accuracy of your information.
  • Develop, operate, improve, maintain, and protect our Products.
  • Manage and administer your subscription.
  • Personalize our Products, including to show nearby activities, nearby AI activity suggestions, nearby travelers, and to show your distance from other users on the platform (which you can disable at any time by toggling the "Hide my distance away from others" option in your app settings).
  • Provide engagement insights, such as profile-view notifications and analytics (e.g., showing premium users nearby travelers who have viewed their profile).
  • Verify and enhance the safety and security of our Products.
  • Verify and analyze user engagement, trends, and usage.
  • Handle and record user rights requests, including opt-ins and opt-outs.
  • Prevent fraud or other unauthorized or illegal activity.
  • Enforce, investigate, and report conduct violating our Terms of Service, Community Guidelines, or other policies.
  • Analyze submitted content, including messages, activity descriptions, and profile text, using automated and human-assisted moderation tools to detect, prevent, investigate, and enforce against violations of our Terms of Service, Community Guidelines, and safety policies.
  • Respond to requests from law enforcement agencies or other government agencies, and comply with legal or regulatory requirements.
  • Provide aggregated engagement analytics to partners offering Sponsored Activities (e.g., total views or clicks), without sharing personal or identifiable user information.
  • Measure the performance of our own advertising campaigns and attribute app installs and subscriptions to those campaigns (only where you have granted tracking permission on iOS).

Location Data: We collect your location to show nearby travelers, display relevant activities in your area, and generate personalized AI-based activity recommendations. We also use approximate location data to show your distance from other users, and to power profile-view insights for nearby users (premium users can see how far away you were when you viewed their profile, if you have allowed the app to show your distance away). You can disable distance visibility at any time by toggling "Hide my distance away from others" in your app settings.

Verification Data: Nomadtable offers optional photo verification to help confirm that your profile photos represent you. If you choose to verify, you submit a selfie that a trained member of our safety team visually compares one-to-one against your own uploaded profile photos. We do not use automated facial recognition for verification and do not create biometric identifiers or templates. Verification selfies are used solely for photo verification and platform safety, are not used for advertising, tracking, profiling, or AI model training, and are deleted within 7 days. See the "Photo Verification" section in Section 2 for full details.

Legal Bases: The table below sets out a description of all the ways we use your personal data, and which of the justifications we rely on to do so. We have also identified what our legitimate interests are where we rely on that justification for processing.

PurposeLegal BasesData Categories Used
Create and maintain your account and enable account login/authenticationContractual NecessityContact info; profile details; profile photos; verification images; device/log data
Confirm that your profile photos represent you and protect the platform from fraudConsent (for optional photo verification); contractual necessity; legal obligation; legitimate interests (fraud prevention and platform safety)Verification selfies; profile details; log data
Enable chat, groups, and activity participationContractual NecessityProfile info; messages; group membership; device/log data
Display nearby users and activitiesConsent (for location); legitimate interests (to provide core functionality)Location grid data; profile info; activity participation
Personalize suggestions and AI-generated recommendationsLegitimate interests (service improvement); consent (for AI features where required)Location; interests; AI suggestion data
Process subscriptions and payments (Nomadtable Plus)Contractual necessity; legal obligation (tax/audit)Transaction identifiers; subscription status; email
Improve, troubleshoot, and secure the appLegitimate interestsAnalytics data; log data; crash reports
Detecting, preventing, investigating, and enforcing against violations of our Terms, Community Guidelines, and safety policies, including through automated and human-assisted moderation of submitted contentLegitimate interests, including platform safety, abuse prevention, fraud prevention, enforcement of our Terms and Community Guidelines, and protection of users; and, where applicable, compliance with legal obligationsAccount information, profile information, messages and other submitted text content, photos/images, reports, moderation flags, device and log data, and other relevant safety or account activity data
Operate the anonymous peer rating system (display aggregate thumbs-up counts on profiles; use negative ratings internally for safety review)Legitimate interests (community trust, platform safety, abuse prevention)Ratings you submit and receive; meetup participation and confirmation data
Provide engagement insights (e.g., profile-view notifications and analytics)Legitimate Interests – to help users understand engagement with their profile and encourage meaningful interactionsProfile details (e.g., name, photo, home country), App Usage data (e.g., profiles viewed), Location Information (for nearby views)
Measure the performance of our own advertising campaigns (install and subscription attribution)Consent (App Tracking Transparency permission on iOS)Device advertising identifier (IDFA); user ID; install and conversion events (e.g., trial starts, subscriptions)

Automated Decision-Making: Nomadtable does not make decisions with significant legal or similar effects based solely on automated processing without appropriate safeguards. AI-based systems are used to assist with moderation, recommendations, and safety features, under human oversight. Automated moderation tools may flag content or accounts for potential violations and may apply temporary safety restrictions while an account is awaiting review. Permanent account bans initiated by automated systems are reviewed by human moderators — generally before they take effect and in all cases promptly afterward — and human moderators may reverse any such decision. You have the right to appeal any enforcement decision and to obtain human review by contacting us through in-app support or at support@nomadtable.app.

4. How We Share Information

We may share Personal Information we collect about you:

  • With other Nomadtable users, according to your account preferences and consistent with our Terms of Service and Community Guidelines.
  • With service providers who help us operate the platform (for example, for hosting, analytics, messaging, verification, or customer support). These providers only access the information necessary to perform their services and are bound by confidentiality and data protection obligations.
  • For legal, safety, and protection purposes, including to comply with law enforcement requests, subpoenas, or court orders, or to protect the rights, property, and safety of Nomadtable, our users, or the public.
  • To enforce our rights, including investigating or preventing potential violations of our Terms of Service, Community Guidelines, or applicable law.
  • In connection with a corporate transaction, such as a merger, acquisition, financing, or sale of assets. In such cases, any successor entity will be required to treat your information in a manner consistent with this Privacy Policy.

We do not sell your personal information and we do not share your personal information with third parties for cross-context behavioral advertising. Where you have granted tracking permission on iOS, we share device identifiers and conversion events with our mobile measurement partner (AppsFlyer), acting as our service provider, solely to measure the performance of our own advertising campaigns. We do not use this data to display third-party ads, and you can withdraw this permission at any time in your device settings (Settings > Privacy & Security > Tracking).

Other Users and Travelers Here List

When you are in a given area, your public profile (including name, profile photo, home country, and age) may appear in the "Travelers Here" list visible to other users in that area. Your exact location is never shown to other users. Instead, your location is associated with a map grid, with the most precise level being approximately 8 km × 8 km. Depending on zoom level, the grid may be larger (less precise). If users zoom in beyond a certain threshold (more precise than the 8 km x 8 km grid), the "Travelers Here" list will show users in the broader 8 km x 8 km grid around the center point of the map's screen, not the users whose location is in the more precise viewport.

Users can freely move the map to view other cities or countries, but doing so does not reveal your exact location; it only loads public traveler data for the selected area. In less populated or remote areas, even grid-based visibility may still allow others to infer your general region. By using the platform, you acknowledge and accept this potential.

Users can enable "Snooze Mode" at any time to hide themselves from the "Travelers Here" List.

Third-Party Service Providers

We use third-party providers to enable essential app functions, such as analytics and messaging. Service Providers will have access to your Personal Information needed to perform their business functions, but may not use or share that Personal Information for purposes outside the scope of their functions related to the App:

  • Firebase (Google LLC) – Usage analytics and crash reporting, authentication, database, backend functions, storage.
  • Stream Chat (GetStream.io, Inc.) – Chat functionality and AI-assisted moderation of messages transmitted through the chat system.
  • OpenAI API (OpenAI, Inc.) – AI-generated recommendations and AI-assisted moderation of activity names during activity creation.
  • AWS Rekognition (Amazon Web Services, Inc.) – AI-powered image moderation (detection of explicit or prohibited content and basic photo-quality checks). Not used for facial recognition or identity verification.
  • AppsFlyer (AppsFlyer Ltd.) – Mobile measurement and advertising attribution. Where you have granted tracking permission on iOS, AppsFlyer processes your device advertising identifier (IDFA) and install/subscription conversion events on our behalf so we can measure the effectiveness of our own advertising campaigns. AppsFlyer acts as our service provider for measurement purposes only.
  • RevenueCat (RevenueCat, Inc.) – Subscription management and purchase processing for Nomadtable Plus.
  • Stripe (Stripe, Inc.) – Payment processing for business customers of our advertising portal (Sponsored Activity placements). Stripe processes advertiser billing details and payment card information on our behalf; Nomadtable does not store payment card details. Not used for consumer app subscriptions, which are processed by Apple and Google.
  • Independent Moderators and Reviewers – In limited cases, we may engage independent contractors to assist with human review for photo verification and content moderation. These contractors are bound by confidentiality agreements and data protection obligations and are only permitted to access the minimum information necessary to perform their assigned tasks.

Verification. For optional photo verification, users submit a selfie in the app, which a trained member of our safety team visually compares one-to-one against the user's own uploaded profile photos. We do not use automated facial recognition for verification, do not create biometric identifiers or templates, and do not search across other users, build a face database, or perform real-world identity lookups. Verification selfies are deleted within 7 days after submission, unless retention is required by law or for fraud/security investigations. See the "Photo Verification" section above for full details.

AI Data Controls. According to OpenAI's API data controls, data sent through the OpenAI API is not used by OpenAI to train or improve OpenAI models unless the API customer explicitly opts in. Nomadtable has not opted in to such training. Stream Chat's built-in moderation features process messages within Stream's infrastructure; for details on Stream's data handling, refer to Stream's privacy documentation.

Legal Compliance

We may share your information when required by law, including in response to:

  • Law enforcement requests, subpoenas, or court orders.
  • Legal obligations related to fraud prevention, financial regulations, or national security.
  • Compliance with applicable data protection laws, including GDPR and CCPA/CPRA.

Security & Protection

We may also process or share your information when necessary to:

  • Detect, investigate, and prevent fraudulent activities, unauthorized access, or security threats.
  • Enforce our Terms of Service and protect the rights, safety, and property of Nomadtable, our users, or the public.
  • Respond to reports of inappropriate content or violations of our community guidelines.

Sponsored Activities & Partner Insights

Nomadtable may display sponsored or paid activity listings ("Sponsored Activities") created by third-party partners. When you view or interact with a Sponsored Activity, we may share aggregated or anonymized performance metrics with the partner who purchased the placement—for example, total views, clicks, or general engagement trends.

Advertiser accounts. If you create an account on our advertising portal as a business customer, we collect and process your advertiser account information (name, email address, business name, campaign content, and billing information processed by Stripe) for account management, campaign review, billing, analytics, and communications about your campaigns, as further described in our Advertiser Terms.

We do not share personal information, account details, location data, or identity information with partners unless required by law or with your explicit consent. Partners never receive information that identifies you or reveals your interactions on an individual level. All data shared with partners is aggregated or anonymized to protect your privacy.

5. Third-Party Services

Parts of Nomadtable may link to or integrate with third-party services. Nomadtable does not own or control these third parties, and this Privacy Policy does not apply to their data practices. When you interact with these services or choose to link your Nomadtable account (for example, with a social network), you are providing your information directly to that third party. Please review their privacy policies before sharing any information.

6. Data Security

While no organization can guarantee perfect security, we are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unlawful or unauthorized access, loss, destruction, or alteration. Access to personal data is restricted to authorized personnel and service providers under strict contractual and technical safeguards, and data is encrypted in transit and at rest where applicable.

7. Your Privacy Rights and Choices

You can control your experience on the App via the settings in the Nomadtable App, options on our other surfaces, or your device controls — for instance, by updating your contact information, unsubscribing from marketing emails, turning off push notifications, or restricting sharing of your location.

Depending on your location, you may have additional rights under local privacy laws:

  • Access and Portability. You may request certain copies of your personal information held by us. In certain instances, you also have the right to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
  • Rectification. You may ask us to correct inaccurate or incomplete personal information about you (and which you cannot update yourself within your Nomadtable account).
  • Erasure. We generally retain your personal information for as long as is necessary for the performance of the contract between you and us, to comply with our legal obligations, and as permitted by applicable law. You may ask us to delete your personal information, subject to certain limitations and restrictions. Please note that if you request the erasure of your personal information, we may retain certain information about you:
    • to the extent necessary to comply with our legal, tax, reporting, and auditing obligations.
    • as necessary for our legitimate business interests and safety, such as prevention of money laundering, fraud detection and prevention, enforcing account bans and preventing ban evasion, and enhancing safety.
  • Withdrawing Consent. If we are processing your personal information based on your consent you can withdraw your consent at any time by changing your account settings or, consistent with applicable law, by emailing support@nomadtable.app specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal.
  • Restriction of Processing. You may ask us to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information, (ii) the processing is unlawful and you oppose the erasure of your personal information, (iii) we no longer need your personal information for the purposes of the processing, but you require the personal information for the establishment, exercise, or defence of legal claims, or (iv) you have objected to the processing and pending the verification whether the legitimate grounds of Nomadtable override your own.
  • Objection to Processing. You may contact us to tell us that you object to the processing of your personal information based on grounds specific to your situation if such processing is for direct marketing or is for a purpose based on a legitimate interest or public interest. If you object to processing based on legitimate or public interests, we will no longer process your personal information for these purposes unless we have compelling legitimate grounds for such processing or where the processing is otherwise lawful or required for the establishment, exercise, or defence of legal claims. To submit an objection, including objections related to the processing of your personal information for direct marketing purposes, you may send us an email at support@nomadtable.app.

Opting Out of Personalized Advertising and Sale and Sharing of Data: We do not show personalized ads in the Nomadtable app and we do not sell or share personal information for cross-context behavioral advertising. On iOS, you can opt out of advertising attribution (our measurement of which ads led you to Nomadtable) at any time by disabling tracking permission for Nomadtable in Settings > Privacy & Security > Tracking.

Opt-out Signals: We strive to honor opt-out preference signals where required by applicable law. When we detect an opt-out preference signal, we will make reasonable efforts to honor such opt outs for jurisdictions that require them. Please note that your opt-out preference signal might only apply to the particular browser, device, or technology that you use to opt-out. The opt-out preference signals are offered by a third party that we do not control. Please see the opt-out preference signal settings and policies for more information.

Opt-Out of Processing or Limit Use and/or Disclosure of Sensitive Personal Information: Certain categories of personal information that we collect and use might be "sensitive" under data privacy laws. Consistent with applicable law, you may have the right to limit certain uses or disclosures of your sensitive personal information or opt-out of processing of your sensitive personal information.

Please note that you may need to verify your identity and request before further action is taken. As a part of this process, you may be required to provide personal information, such as your name, state of residence, phone number, email address associated with your account, and government identification. Consistent with applicable law, you may also designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, we may require that: (i) you or your authorized agent provide a valid power of attorney, (ii) the agent provide proof that you gave the agent signed, written permission to submit the request, (iii) you verify your identity with us, and (iv) you directly confirm with us that you provided the authorized agent permission to submit the request. To appeal a refusal to take action on your request, please see the instructions in our response to your request or submit your appeal in writing by contacting support@nomadtable.app with the subject "Appeal of Consumer Rights Request."

8. Data Retention

We retain personal information for as long as needed or as permitted in light of the purpose(s) for which it was obtained and further processed and consistent with applicable law. For a category-by-category summary of retention periods, see the table in Section 10 (California Privacy Rights), which applies to all users, not only California residents. The criteria used to determine our retention periods include:

  • the length of time we have an ongoing relationship with you and provide services to you, what activities you engage in on the platform (for instance, whether you host activities), and the length of time during which we may have a legitimate need to retain your personal information, such as to manage and protect our business, to address issues or defend claims that may arise;
  • whether there is a legal, tax, reporting, or auditing obligation to which we are subject, such as anti-money laundering requirements that requires us to keep records of your transactions for a certain period of time before we can delete them; and
  • whether retention is advisable in light of our legal position or to protect the safety of individuals, which includes retention that is required or prudent in accordance with applicable statutes of limitations, litigation, or regulatory investigations.

Residual Copies. Because we take measures to protect data from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.

Moderation and Safety Records. We may retain moderation flags, reports, enforcement history, device/log data, and limited related account information for as long as reasonably necessary to enforce our Terms, prevent abuse, protect users, resolve disputes, comply with legal obligations, and defend legal claims. Where possible, we minimize or delete underlying content when it is no longer needed for these purposes.

Banned Accounts. If your account is banned for violating our Terms of Service or Community Guidelines, we retain a minimal ban record — such as your account identifier, the date of the ban, and the reason — even if you request deletion of your personal information. We retain this record for as long as necessary to enforce the ban and prevent banned individuals from creating new accounts (ban evasion). This retention is limited to the minimum information needed for these safety and enforcement purposes and is based on our legitimate interest in keeping the platform safe.

9. International Data Transfers

As a global platform, we may transfer, store, and process your information with partners and service providers based in Europe, Asia Pacific, and North and South America, including the United States. Where necessary, measures have been taken pursuant to applicable data protection law, such as standard contractual clauses. When we transfer personal data from the EEA/UK to countries without an adequacy decision (e.g., the U.S.), we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA/Addendum, as applicable).

10. California Privacy Rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this Privacy Policy. It also serves as our Notice at Collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").

Categories of Personal Information We Collect

The table below lists the categories of personal information (as defined by the CCPA) we have collected in the preceding 12 months, examples of what that includes for Nomadtable, who we disclose it to for business purposes, and how long we keep it. Purposes of collection are described in Section 3 above; sources are you, your device, and our service providers.

CCPA CategoryWhat we collectDisclosed for business purposes toRetention period
IdentifiersName, email address, username/handle, unique user ID, IP address, device identifiers; device advertising identifier (IDFA) only with your iOS tracking permissionCloud hosting, analytics, chat, and measurement service providersUntil you delete your account. IDFA/attribution data: until you withdraw tracking permission or it is no longer needed to measure the campaign
Customer records (Cal. Civ. Code §1798.80(e))Name and contact information as aboveSame as identifiersUntil you delete your account
Protected classification characteristicsAge and gender (used for your profile and safety features)Cloud hosting service providers; shown to other users per your profile settingsUntil you delete your account
Commercial informationSubscription status and purchase/transaction identifiers for Nomadtable Plus (payments themselves are processed by Apple/Google)Subscription management service provider (RevenueCat)Until you delete your account, plus as required for tax, audit, and accounting obligations
Internet or other electronic network activityApp usage (e.g., profiles and events viewed), log and diagnostic data, crash reportsAnalytics and crash-reporting service providersProfile-view records are deleted within 7 days; user-level analytics data is retained for 14 months from your last activity; logs and crash reports are retained for shorter operational periods
Geolocation data (including precise geolocation)Device location, used to show nearby travelers and activities and power location features you requestCloud hosting service providers; shown to other users only as an approximate (~8 km) grid, never your exact locationYour current coordinates are overwritten as your location updates and deleted when you delete your account; we do not keep a running history of your movements
Audio, electronic, visual, or similar informationProfile photos, images shared in chats/activities, optional verification selfiesCloud hosting and image-moderation service providersPhotos: until you remove them or delete your account. Verification selfies: deleted within 7 days of submission

We do not collect Social Security numbers, driver's license numbers, financial account or payment card numbers (Apple and Google process payments), health information, biometric identifiers or biometric information, or information about race, ethnicity, religion, or union membership. We also do not create or retain profiles of inferred characteristics about you: AI activity recommendations are generated on demand from your stated interests and general location, are cached only on a per-city basis (not linked to your account), and are not stored to your profile.

Moderation and safety records (reports, enforcement history, and ban records) may be retained longer than the periods above where reasonably necessary to enforce our Terms, prevent ban evasion, comply with legal obligations, or defend legal claims, as described in Section 8.

Sensitive Personal Information

The only category of "sensitive personal information" we collect is precise geolocation. We collect it with your device-level permission and use it only to provide the services you request (showing nearby travelers, activities, and recommendations), to protect the safety and integrity of the platform, and for other purposes permitted by the CCPA regulations. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not sell it or share it for cross-context behavioral advertising. Because our use is limited to these permitted purposes, we are not required to offer a "Limit the Use of My Sensitive Personal Information" link. You can nonetheless control location collection at any time through your device settings, hide your distance from other users via "Hide my distance away from others" in app settings, or hide yourself from the map entirely with Snooze Mode.

No Sale or Sharing

We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising, and have not done so in the preceding 12 months. We also have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age (Nomadtable requires users to be 18 or older).

Your California Rights

California residents have the right to: (i) know/access the personal information we collect and how we use and disclose it; (ii) delete personal information we collected from you, subject to legal exceptions (see Section 7, including the ban-record exception in Section 8); (iii) correct inaccurate personal information; (iv) opt out of sale or sharing (not applicable — we do neither); (v) limit use of sensitive personal information (not applicable, as described above); and (vi) non-discrimination — we will never deny you services, charge different prices, or provide a different level of service because you exercised your privacy rights.

You can exercise these rights in the app (Settings > Account) or by emailing support@nomadtable.app. We will verify your request as described in Section 7 and respond within the timeframes required by law (generally 45 days). You may use an authorized agent as described in Section 7, and you may appeal a refusal by writing to support@nomadtable.app with the subject "Appeal of Consumer Rights Request."

California "Shine the Light" Law

California residents may request information about whether we disclose personal data to third parties for their direct marketing purposes. Nomadtable does not sell or share personal data with third parties for their direct marketing purposes. If you have questions about how we handle your data, contact us at support@nomadtable.app.

11. Brazil Privacy Rights (LGPD)

This section applies to users in Brazil and supplements the rest of this Privacy Policy. Nomadtable processes personal data as a "controller" under Brazil's Lei Geral de Proteção de Dados (Law No. 13,709/2018, "LGPD").

Legal bases. We process your personal data under the legal bases set out in Article 7 of the LGPD, which parallel those described elsewhere in this policy: performance of the contract with you (providing the services you signed up for), your consent (for example, optional photo verification and device location permission), compliance with legal or regulatory obligations, and our legitimate interests (for example, platform safety and fraud prevention), always balanced against your fundamental rights and freedoms.

Your rights. Under Article 18 of the LGPD, you have the right to obtain from us, at any time and free of charge: (i) confirmation that we process your personal data; (ii) access to your data; (iii) correction of incomplete, inaccurate, or outdated data; (iv) anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of the LGPD; (v) portability of your data to another service provider; (vi) deletion of personal data processed with your consent, subject to the legal exceptions described in Sections 7 and 8 (including safety and ban records); (vii) information about the public and private entities with which we have shared your data (described in Section 4); (viii) information about the possibility of refusing consent and the consequences of doing so; and (ix) revocation of consent at any time.

How to exercise your rights. You can exercise these rights in the app (Settings > Account) or by emailing support@nomadtable.app. This mailbox is also our communication channel for LGPD matters under Article 41 of the LGPD and ANPD Resolution CD/ANPD No. 2/2022 (as a small-scale processing agent, Nomadtable provides this channel in lieu of appointing a separate Data Protection Officer). You also have the right to petition the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD) regarding your data; see www.gov.br/anpd.

International transfers. Your personal data is processed in the United States and other countries as described in Section 9. Where required, transfers of personal data from Brazil are carried out with contractual safeguards consistent with Chapter V of the LGPD and ANPD Resolution CD/ANPD No. 19/2024, including standard contractual clauses.

12. Children's Privacy

Our service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware of such collection, we will delete the information promptly.

13. Changes to This Privacy Policy

We may modify this Privacy Policy at any time in accordance with applicable law. When we do, we will post the revised version within the app and on our website and update the "Last Updated" date at the top. For material changes, we may also notify you by email, in-app message, or other reasonable means. Your continued use of Nomadtable after the updated version is posted constitutes your acceptance of the revised Privacy Policy.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:

Email: support@nomadtable.app

Mailing Address:
Nomadtable Inc.
2108 N St Ste N,
Sacramento, CA 95816
United States of America

For users in the EU/EEA: Nomadtable Inc. is the data controller responsible for your personal data. EU/EEA users may contact us directly at support@nomadtable.app for privacy-related questions or to exercise their data rights. You also have the right to lodge a complaint with your local supervisory authority.

EU/EEA, UK and Swiss Representative: If you are based in the EU/EEA, the United Kingdom, or Switzerland, and wish to contact us via our data protection representative, DataRep, appointed under Article 27 of the GDPR, Article 27 of the UK GDPR, and Article 14 of the Swiss FADP, you may do so at:

nomadtable@datarep.com
www.datarep.com/nomadtable
DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland
DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom
DataRep, Leutschenbachstrasse 95, Zurich, 8050, Switzerland

When raising a matter with DataRep, please quote "Nomadtable" in any correspondence so it can be routed to us. A full list of DataRep contact locations is available at www.datarep.com/data-request.

Please note that DataRep handles data protection matters only. For general questions about your account, the app, or our services, contact us directly at jay@nomadtable.app.

This Privacy Policy is designed to be transparent about our data practices while ensuring compliance with global privacy regulations. We encourage you to read it carefully and contact us with any questions.