The short version of what we collect, what we never do, and the controls you have. Our rule: collect only what a community app genuinely needs — and never to track or advertise to you.
These are exactly the categories in our App Store & Google Play privacy labels — explained in plain language.
Name, email, optional social handles (Instagram, LinkedIn, WhatsApp), and a billing address only when you buy something.
Your name and email create and secure your account. Social handles are optional, so the community can reach you. A billing address is collected only at checkout because tax law requires it on the invoice — never at sign-up. No phone number is collected.
Approximate (city-level) location.
To place you on the community map and show nearby members and events. Your pin is always placed at your city, never at your exact position. You choose who can see it, and you can stop sharing at any time.
Photos & videos, audio (voice messages), and your posts, comments and messages.
It's a community app — your posts, chats and voice messages need an author so your history, replies, and moderation all work.
Purchase history (bookings, membership, add-ons).
To manage what you booked and send you receipts. Your card details go straight to Stripe and never reach our servers.
Your account ID and a push-notification token.
To keep you logged in and to deliver push notifications. Never used for ads or cross-app tracking.
Basic interaction logs, plus device model, OS, app version, language, time zone and IP address.
To run the app, remember your preferences, keep it secure, and see which features need work. Measured internally only — never with third-party trackers and never for advertising.
Crash logs and performance data.
To find and fix bugs and crashes so the app stays stable. Used only to keep things working — never to profile you or for advertising.
Face recognition for photo tagging — entirely optional.
Off by default — you can use the whole app without it. If you opt in, the matching runs on our servers (via our processor Trigger.dev), not on your device: from your profile and event photos we create a numeric face signature — not the photos themselves — stored in our EU database and linked to your account so it can suggest tagging you. Opting out or deleting your account deletes it.
Everything you send is encrypted in transit (TLS), so on shared or public wifi nobody on the network can read your location, messages, or payment details. Data is encrypted at rest (AES-256), and access to it is locked down with strict per-user permissions and staff two-factor authentication. Payments go through Stripe, so your card details never reach our servers.
Messages and content are not end-to-end encrypted, so they're protected in transit, at rest, and by access controls rather than being technically unreadable to us. To be clear about what that means: no one on the team reads or monitors your private messages — we have no tool to browse them, and our reporting and moderation system doesn't cover private messages at all. Public content (posts, comments, stories) can be reported and reviewed by moderators, which the app stores require us to be able to do; those admin actions are logged. We don't offer end-to-end encryption today.
This is a summary, not the full legal text. Questions? Write to hello@nomadbase.com.
Read the full Privacy Policy