Privacy Policy

Effective date: August 14, 2025

Controller / Business: NearNudge LLC, a Delaware LLC ("we," "us," "our")
Contact: contact@nearnudge.com
Security contact: security@nearnudge.com

This Privacy Policy explains how we collect, use, disclose, and protect your information when you use NearNudge (the "App") and related services. If you do not agree with this Policy, please do not use the App.

1) Scope & audience

Where the App is offered: We primarily offer the App to residents of the United States and its territories. You may use the App while traveling internationally.

What this covers: This Policy covers personal information we process through the App and our support channels. It does not cover third‑party websites/services that have their own privacy notices.

2) Notice at collection (what we collect & why)

We collect only what we need to operate location‑based Nudges and related features. The table below summarizes categories, examples, purposes, whether we "sell" or "share" (as defined under the California Privacy Rights Act, CPRA), and typical retention.

Category Examples Purpose(s) Sold/Shared Typical retention
Identifiers Name, username, email, password hash, avatar/profile photo Create/manage your account; authenticate; provide support No Until you delete your account
Contact info for SMS Mobile number (if you opt in) Send transactional SMS Nudge alerts; respond to STOP/HELP No Until you disable SMS or delete your account
Geolocation (precise) Device location, selected place IDs, chosen radius Trigger Nudges; show distance; detect arrival; mark visited No Nudge definitions kept until account deletion
Nudge content Nudge titles, lists, categories, completion status, share links Provide core features; list sharing; dashboard analytics No Until you delete your account
Device/usage App/version, OS, device identifiers, event logs, crash diagnostics Security, troubleshooting, service quality, abuse prevention No Short‑term operational logs

We do not "sell" or "share" personal information for cross‑context behavioral advertising. We do not use or disclose sensitive personal information (precise location) for purposes other than to provide the services you request, security, or as permitted by law.

3) Information we collect

3.1 Information you provide

• Account details (name, email, password hash), avatar/profile photo

• Nudge content (titles, categories, named lists, chosen distance, completion status)

• SMS mobile number (if you opt in to text alerts)

• Support messages and feedback

3.2 Information collected automatically

• Location data (precise) when you grant permission and enable Nudges: used to determine proximity to your selected locations and trigger notifications

• Device and usage data: device type, OS version, app version, language, time zone, diagnostics, performance events

3.3 Information from third parties

• Mapping/location services: We use Google Maps Platform for search/places/geolocation

• Hosting: We build/host on Replit, which runs on Google Cloud Platform (GCP)

• Authentication: User authentication handled by Replit Auth

4) How we use information

We use information to:

• Provide the App and core features (Create a Nudge, My Nudges, Dashboard, Account)

• Process location for geofencing triggers and distance calculations you configure

• Send notifications/SMS you request (you can disable push/SMS at any time)

• Operate list sharing and allow recipients to report abuse

• Maintain safety/security (detect, prevent, and respond to fraud, abuse, and security incidents)

• Troubleshoot & improve the App (diagnostics, analytics limited to service operation)

• Comply with laws and enforce our Terms

Legal bases (EEA/UK): performance of a contract (provide App); consent (precise location, push/SMS, where required); legitimate interests (security, fraud prevention, service improvement); and legal obligations.

5) Your choices & controls

• Location permissions: You can enable/disable precise or background location in your OS settings; the App may not function as intended without it

• Notifications/SMS: Control push in your OS settings; opt out of SMS anytime by replying STOP (reply HELP for help)

• Manage data: View/mark Nudges completed, edit lists, and use the in‑app Delete Account control

• Travel: You can use the App while abroad; local device/OS privacy controls still apply

6) SMS program (transactional only)

If you opt in to SMS, we send transactional Nudge alerts only (no marketing texts). Message frequency varies based on your settings and travel. Message & data rates may apply. Carriers are not liable for delayed or undelivered messages. You can opt out at any time by replying STOP and get help by replying HELP.

7) Google Maps Platform & Google API Services

We use Google Maps Platform (e.g., Places/Geocoding/Geolocation) to power location search and proximity features. We follow Google's attribution and data‑use requirements, including limits on caching and use with non‑Google maps. Our use of Google services adheres to the Google API Services User Data Policy.

8) How we share information

We do not sell your personal information. We share it only with:

• Service providers: Hosting/build (Replit on GCP), Mapping/location (Google Maps Platform), Authentication (Replit Auth)

• Recipients of shared lists: When you choose to share; recipients may reshare content you share with them

• Legal, safety, and compliance: To comply with law or valid legal requests; to protect you, us, or others

We may use and share aggregated or de‑identified data (that cannot reasonably be linked to you) for analytics and service improvement.

9) International data transfers & regions

Primary region: United States (GCP data centers).

Cross‑border safeguards: For EEA/UK personal data processed in the U.S., we rely on appropriate safeguards, such as the EU Standard Contractual Clauses (SCCs) and implement additional technical and organizational measures (including encryption in transit and at rest).

10) Retention

Your Nudge definitions, visit/completion logs, and any raw location events we process are deleted when you delete your account. We do not retain this information beyond account deletion, except:

• System backups: Residual copies in routine backups may persist for up to 30 days and are automatically overwritten on a rolling basis

• Legal holds: If required by law, dispute, or fraud prevention, we may retain limited records as necessary

Operational logs and diagnostics are kept only as long as needed for security and troubleshooting.

11) Security

We implement technical and organizational measures designed to protect your information, including encryption in transit (TLS 1.2+) and encryption at rest (AES‑256) within our hosting environment. We limit access to authorized personnel and vendors who need it to operate the service. No system is perfectly secure; please use strong, unique passwords and keep your device OS up to date.

12) Children's privacy

The App is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will delete the account. Where local law requires a higher age (e.g., up to 16 in parts of the EEA), we will honor that requirement and/or seek verifiable parental consent.

13) Your privacy rights

13.1 EEA/UK residents

You have the right to access, rectify, erase, restrict, port, and object to certain processing, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority.

13.2 U.S. state privacy laws

Depending on your state, you may have the right to know/access, correct, delete, and portability, and to appeal our decision on your request. We do not sell or share personal information for cross‑context behavioral advertising and do not use your precise location for targeted ads.

13.3 How to exercise your rights

• Use the in‑app Delete Account control for deletion

• For other requests (access, correction, portability, etc.), email contact@nearnudge.com

• We will verify your identity and aim to respond within 45 days

14) Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you (e.g., in‑app notice or email) and indicate the newest Effective date. Your continued use of the App after the effective date means you accept the updated Policy.

15) Contact us

Privacy requests: contact@nearnudge.com

Security reports: security@nearnudge.com

Postal address: NearNudge LLC, United States

16) Additional information

"Personal information / personal data" means information that identifies or can reasonably be linked to an individual.

"Precise geolocation" means location within a radius of 1,850 feet (≈ 564 meters) or less, or as defined by law.

"Service providers / processors" are vendors that process personal information for us under contract and are restricted from using it for their own purposes.

Last updated: August 14, 2025