Privacy at a Glance

The short version of what we collect, what we never do, and the controls you have. Our rule: collect only what a community app genuinely needs — and never to track or advertise to you.

These are exactly the categories in our App Store & Google Play privacy labels — explained in plain language.

What we collect — and why

Contact Info

Linked to your account

Name, email, optional social handles (Instagram, LinkedIn, WhatsApp), and a billing address only when you buy something.

Your name and email create and secure your account. Social handles are optional, so the community can reach you. A billing address is collected only at checkout because tax law requires it on the invoice — never at sign-up. No phone number is collected.

Location

Linked to your account

Approximate (city-level) location.

To place you on the community map and show nearby members and events. Your pin is always placed at your city, never at your exact position. You choose who can see it, and you can stop sharing at any time.

User Content

Linked to your account

Photos & videos, audio (voice messages), and your posts, comments and messages.

It's a community app — your posts, chats and voice messages need an author so your history, replies, and moderation all work.

Purchases

Linked to your account

Purchase history (bookings, membership, add-ons).

To manage what you booked and send you receipts. Your card details go straight to Stripe and never reach our servers.

Identifiers

Linked to your account

Your account ID and a push-notification token.

To keep you logged in and to deliver push notifications. Never used for ads or cross-app tracking.

Usage Data

Linked to your account

Basic interaction logs, plus device model, OS, app version, language, time zone and IP address.

To run the app, remember your preferences, keep it secure, and see which features need work. Measured internally only — never with third-party trackers and never for advertising.

Diagnostics

Linked to your account

Crash logs and performance data.

To find and fix bugs and crashes so the app stays stable. Used only to keep things working — never to profile you or for advertising.

Sensitive Info — Face data

Opt-in · off by default

Face recognition for photo tagging — entirely optional.

Off by default — you can use the whole app without it. If you opt in, the matching runs on our servers (via our processor Trigger.dev), not on your device: from your profile and event photos we create a numeric face signature — not the photos themselves — stored in our EU database and linked to your account so it can suggest tagging you. Opting out or deleting your account deletes it.

What we never do

  • No ads, and no ad networks in the app.
  • No advertising or analytics SDKs, and no cross-app tracking.
  • No advertising identifier (IDFA) collected.
  • We never sell your data, and never share it for tracking.
  • We never read your phone's address book or contacts.

The controls you have

  • Delete your account anytime in the app — your data is removed, with a 30-day recovery window in case it was a mistake.
  • Choose how location works: who can see your city, or stop sharing entirely.
  • Turn face recognition on or off whenever you want.

How long we keep it

  • Account and community content — until you delete it or your account.
  • Booking and invoice records — up to 10 years (EU tax law), kept anonymized after deletion.
  • Crash and security logs — up to 90 days.

How we protect it

Everything you send is encrypted in transit (TLS), so on shared or public wifi nobody on the network can read your location, messages, or payment details. Data is encrypted at rest (AES-256), and access to it is locked down with strict per-user permissions and staff two-factor authentication. Payments go through Stripe, so your card details never reach our servers.

Messages and content are not end-to-end encrypted, so they're protected in transit, at rest, and by access controls rather than being technically unreadable to us. To be clear about what that means: no one on the team reads or monitors your private messages — we have no tool to browse them, and our reporting and moderation system doesn't cover private messages at all. Public content (posts, comments, stories) can be reported and reviewed by moderators, which the app stores require us to be able to do; those admin actions are logged. We don't offer end-to-end encryption today.

This is a summary, not the full legal text. Questions? Write to hello@nomadbase.com.

Read the full Privacy Policy