Onfound

Privacy Policy

Last updated: 26 May 2026

This Privacy Policy explains how Onfound (“Onfound”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use our website, mobile application, and related services. It also explains your rights regarding your personal data and how to exercise them.

Please read this policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy. This policy should be read together with our Terms and Conditions.

1 Who We Are (Data Controller)

Onfound Inc. is the data controller responsible for your personal data.

Entity: Onfound Inc.
Registered address: 1111B S Governors Ave STE 29782, Dover, DE 19904, United States
Email: support@onfound.com
Website: https://onfound.com

Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), we are the “data controller.” Under South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA), we are the “responsible party.” Under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA), we are the “data controller.”

2 What This Policy Covers

This Privacy Policy applies to personal data collected through:

  • Our website at onfound.com
  • The Onfound mobile application (iOS and Android)
  • The member dashboard
  • Any Onfound-organised meetups, events, or activities
  • Email, WhatsApp, and other communications with us

It does not apply to third-party websites, apps, or services linked from Onfound (such as Stripe, WhatsApp, or partner venues). Those services have their own privacy policies, which we encourage you to review.

3 Personal Data We Collect

3.1 Data You Provide Directly

When you register, complete onboarding, use the platform, or contact us, we may collect:

CategoryExamplesWhen Collected
Identity dataFirst name, last name, date of birth, gender (optional)Registration and onboarding
Contact dataEmail address, WhatsApp/phone number in international format, selected cityRegistration and onboarding
Profile dataProfile photo, what you’re working on, your biggest challenge, your biggest win, business name, business website, social links (LinkedIn, Instagram, X, personal website), and any other profile text you choose to shareOnboarding and profile editing
Member-to-member contentDirect messages, group chat messages, message edits and reactions, profile views, saved (“hearted”) profilesWhen you use the directory and messaging features
Event contentEvent description, meeting point, arrival instructions, what to expect, event banner image, your RSVPs to city eventsWhen you create or RSVP to a city event
Financial dataSubscription plan, billing events, currency, cancellation reason and feedback (card brand and last 4 digits only; full card details are handled by Stripe)Subscription and checkout
Communication dataMessages to support, feedback, survey responses, meetup suggestionsWhen you contact us or respond to in-app prompts
Important: Full payment card details (card number, CVV, expiry) are collected and stored directly by our payment processor, Stripe, and are never stored on Onfound’s servers.

3.2 Data We Collect Automatically

When you use the website or app, we automatically collect:

CategoryExamplesPurpose
Device and technical dataIP address, browser type, operating system, device type, screen resolution, per-device identifiers used for push notifications (Capacitor device ID, APNs/FCM push tokens), and User-Agent stringPlatform security, push notification routing, debugging
Usage dataPages and screens visited, features used, profile views, profiles you save, direct message initiations, message read events, event RSVPs, click patternsService improvement and product personalisation
Location dataCity-level location derived from the city you select during onboarding (or from your IP address). We do not collect precise GPS location.Surfacing members and events in your city
Log dataAccess times, error logs, referring URLs (held in our hosting provider’s console)Security monitoring, troubleshooting
Advertising dataData collected via the Meta Pixel and Meta Conversions API, including page views, button clicks, sign-up and subscription conversion events, browser and device data, IP address, User-Agent, and hashed identifiers (SHA-256 hashed email address and phone number) used to attribute conversions to your Meta account. On iOS, the device advertising identifier (IDFA) is only accessed if you grant permission via the App Tracking Transparency prompt.Measuring ad effectiveness, remarketing, and audience building

3.3 Data from Third Parties

We may receive limited data from third parties, including:

  • Stripe: payment confirmation status, subscription status, and billing events (not full card details).
  • Meta (Facebook/Instagram): conversion data and ad interaction data used to measure campaign performance and serve relevant ads.
  • App stores (Apple App Store, Google Play): download and installation data, crash reports.

We do not purchase personal data from data brokers or third-party marketing databases.

4 How We Use Your Personal Data

We use your personal data for the following purposes:

PurposeWhat We DoLegal Basis (GDPR)Legal Basis (POPIA)
Provide the ServicesCreate and manage your account, run the city directory, surface relevant members through the “Why Connects” suggestion engine, deliver direct messages and group chats, manage subscriptions and billingContractual necessityProcessing necessary for a contract
Communicate with youSend transactional email (billing receipts, account notifications, digests), push notifications, service updates, and respond to support requestsContractual necessityProcessing necessary for a contract
Improve the ServicesAnalyse usage patterns, test new features, refine the suggestion engine, fix bugsLegitimate interestLegitimate interest of the responsible party
Moderate member contentBefore publication, automatically scan profile text, event text, and uploaded images for safety risks (e.g. abuse, sexual content, violence) using a third-party moderation service. Maintain a moderation queue and audit trail of flagged content.Legitimate interestLegitimate interest of the responsible party
Ensure safety and securityDetect and prevent fraud, enforce our Terms, investigate misconduct, protect membersLegitimate interestLegitimate interest of the responsible party
MarketingSend newsletters, feature announcements, promotions, and community content (only with your consent)ConsentConsent
Push notificationsSend message alerts, event reminders, and community updates via the mobile app (only with your consent)ConsentConsent
Legal complianceComply with tax, accounting, regulatory, and legal obligationsLegal obligationProcessing necessary for legal compliance
EventsOrganise city events, manage RSVPs, facilitate community activitiesContractual necessity / Legitimate interestContract / Legitimate interest
Advertising and remarketingMeasure the effectiveness of our advertising campaigns, serve relevant ads on Meta (Facebook/Instagram), and retarget visitors who have interacted with our website or appConsentConsent

5 Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website and app to improve your experience and analyse how the Services are used.

5.1 Types of Cookies We Use

TypePurposeExamplesDuration
Strictly necessaryRequired for the website and app to function (authentication, security, session management)Session cookies, CSRF tokens, authentication tokensSession or up to 12 months
FunctionalRemember your preferences and settingsLanguage preference, city selectionUp to 12 months
MarketingUsed to deliver targeted advertising, measure ad performance, and serve remarketing ads on third-party platforms (only with consent)Meta Pixel, email campaign tracking pixelsUp to 12 months

5.2 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling strictly necessary cookies may affect the functionality of the Services.

For advertising cookies, you can manage your preferences through Meta Ad Preferences. You can also opt out of interest-based advertising from participating companies at aboutads.info.

5.3 Mobile App Tracking (iOS App Tracking Transparency and Android)

Our mobile app uses tracking technologies, including the Meta Pixel and Meta Conversions API, to measure conversions and serve relevant ads on third-party platforms.

iOS (App Tracking Transparency): When you first open the Onfound app on an iPhone or iPad, Apple will show you an App Tracking Transparency (ATT) prompt asking whether you allow Onfound to track your activity across other companies’ apps and websites.

  • If you allow tracking, we and our advertising partner (Meta) may access your device’s Identifier for Advertisers (IDFA) and use it to measure the performance of ads you have seen and to serve you more relevant ads.
  • If you ask the app not to track, we will not access the IDFA and will not share device-level identifiers with our advertising partner. We will still measure conversions using aggregated, privacy-preserving methods (such as Apple’s SKAdNetwork and aggregated event measurement), which do not identify you individually.
  • You can change your choice at any time in iOS Settings › Privacy & Security › Tracking, or in Settings › Onfound.

Android: On Android devices, conversion and ad measurement is performed using the Google Advertising ID (GAID) by our advertising partner (Meta). You can reset your GAID or opt out of personalised ads at any time in Settings › Google › Ads.

Declining tracking does not affect your ability to use the Onfound app or any of its core features.

6 Who We Share Your Data With

We do not sell your personal data to anyone. We share your data only in the following circumstances:

6.1 Service Providers

We use trusted third-party service providers to operate and improve the Services. These providers process data on our behalf and are contractually required to protect your data:

ProviderPurposeData SharedLocation
StripePayment processing and subscription management. Full card details are entered on Stripe’s own hosted checkout and never reach Onfound’s servers.Card details (held by Stripe only), email, name, internal user ID, attribution parameters (fbclid, UTMs), subscription plan and statusUnited States
RailwayCloud hosting and infrastructureAll platform data (encrypted at rest and in transit). Application logs may contain internal user and device IDs.United States
PostmarkTransactional email delivery (account, billing, digests, password reset)Recipient name and email, profile photo URL, city name, sender name and channel-list phrases used in digests, short-lived URL tokens for password reset and onboardingUnited States
Mailchimp (Intuit)Contact-list sync, segmentation, and taggingName, email address (plain and MD5-hashed for lookup), phone number, date of birth, city, subscription-status tagsUnited States
AblyReal-time messaging (direct messages and group chats) and push notification routingInternal user ID, device ID and platform, APNs/FCM push tokens, message channel payloads (the content of messages you send and receive)Global / United States
OpenAIAutomated content moderation before publishing, and language understanding for AI member search (interpreting search requests and indexing profile text by meaning)Profile text, event text, uploaded images, and the text of member search requests. Content is sent in isolation with no account identifiers attached, and is not used to train OpenAI’s models.United States
Anthropic (Claude)AI member search (Frontier Intelligence): reading shortlisted member profiles to suggest relevant founders and explain why they may be worth meetingMember name and profile information you share with the community (bio, what you are building, help offered and needed, interests, challenges and wins), plus the search request. Revenue information is never included. Not used to train Anthropic’s models; retained briefly by Anthropic for abuse monitoring only.United States
Meta (Facebook/Instagram)Advertising, conversion tracking, and remarketing via the Meta Pixel and Meta Conversions APIPixel events (page views, sign-ups, subscription starts, button clicks), SHA-256 hashed email and phone number, IP address, browser and device User-Agent, fbclid and UTM attribution parameters, event identifiers, subscription value and currency. On iOS, the device advertising identifier (IDFA) only if you have granted App Tracking Transparency permission.United States
MinIO (object storage)Storage for profile photos and event banner imagesImage binary and MIME type; the storage key contains your internal user IDSelf-hosted
Apple Push (APNs) / Google FCMMobile push notification delivery (routed via Ably)Device push token, notification payloadUnited States

6.2 Other Members

Onfound is a member directory. When your profile is approved, the profile content you have chosen to publish (your first name, last name, profile photo, city, what you’re working on, your biggest challenge, your biggest win, business name and website, and any social links you have added) is visible to other approved Onfound members.

If you send a direct message or post in a group chat, the contents of those messages are visible to the other people in the conversation. If you RSVP to a city event, your first name, last name, and profile photo are visible on the event’s attendee list to other approved members.

Your email address, phone number, date of birth, and gender are not displayed in the directory or to other members. Other members can message you within the Onfound app, but cannot see your email or phone number unless you choose to share them in a message.

You can request that your profile be hidden from the directory by contacting us, though this may limit your ability to participate in the community.

6.3 Legal and Safety Disclosures

We may disclose your personal data if we are required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to:

  • Comply with a legal obligation, court order, or regulatory request.
  • Protect the rights, safety, or property of Onfound, our members, or the public.
  • Investigate or prevent fraud, security incidents, or violations of our Terms.
  • Respond to an emergency involving potential harm to any person.

6.4 Business Transfers

If Onfound is involved in a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and ensure the receiving party is bound by obligations consistent with this Privacy Policy.

7 International Data Transfers

Onfound is based in the United States. If you are located in the United Kingdom, European Economic Area, South Africa, or any other jurisdiction with data protection laws that restrict international data transfers, your personal data will be transferred to and processed in the United States and potentially other countries where our service providers operate.

We ensure that international transfers of personal data are protected by appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the UK Information Commissioner’s Office (ICO), incorporated into our agreements with service providers.
  • Adequacy decisions, where the European Commission or UK government has determined that a country provides an adequate level of data protection.
  • Other lawful transfer mechanisms as recognised under applicable law.
South Africa, POPIA

Under Section 72 of POPIA, cross-border transfers are permitted where the recipient is subject to laws or binding agreements that provide an adequate level of protection, or where you have consented to the transfer. Our agreements with service providers include data protection obligations substantially similar to those required by POPIA.

Thailand, PDPA

Under Sections 28 and 29 of the Personal Data Protection Act B.E. 2562 (2019), cross-border transfers of personal data are permitted where the recipient country has adequate protection, or where the transfer is necessary for the performance of a contract with you, your consent has been obtained, or appropriate safeguards (such as contractual data protection clauses substantially similar to Standard Contractual Clauses) are in place. Our agreements with service providers include such safeguards.

8 Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.

Data TypeRetention PeriodReason
Account and profile dataDuration of membership plus 12 months after account deletionAccount reactivation inquiries and post-cancellation disputes
Financial and billing data7 years after the transactionTax, accounting, and legal compliance obligations
Communication data3 years after last interactionService quality improvement and recurring issue resolution
Analytics and usage data26 months (aggregated and pseudonymised)Service improvement and trend analysis
Member-to-member content (direct messages, group chat messages, profile views and saves, event RSVPs)Duration of membership plus 6 monthsSuggestion engine improvement and dispute resolution
Moderation records (excerpts of flagged content, classifier scores)Duration of membership plus 12 monthsAudit trail and appeals review
Marketing consent recordsDuration of membership plus 3 yearsDemonstrate compliance with consent requirements

After the applicable retention period, we will securely delete or anonymise your personal data so that it can no longer be associated with you.

9 Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it, including:

  • Encryption of data in transit using TLS/SSL and encryption at rest for stored data.
  • Secure authentication mechanisms, including hashed and salted passwords.
  • Access controls limiting who within Onfound can access personal data, on a need-to-know basis.
  • Regular security reviews and monitoring of our infrastructure.
  • PCI-DSS compliant payment processing through Stripe (Onfound never stores full card details).
  • Incident response procedures to detect, investigate, and respond to data breaches.

While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.

10 Your Rights

Depending on where you are located, you have certain rights regarding your personal data. We are committed to helping you exercise these rights.

UK & EEA, GDPR / UK GDPR

If you are located in the United Kingdom or European Economic Area, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request that we correct inaccurate or incomplete data.
  • Right to erasure: Request that we delete your personal data (“right to be forgotten”), subject to certain legal exceptions.
  • Right to restrict processing: Request that we limit how we use your data in certain circumstances.
  • Right to data portability: Request a copy of your data in a structured, machine-readable format and have it transferred to another controller.
  • Right to object: Object to processing based on legitimate interest, including direct marketing.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: Complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or your local supervisory authority.
South Africa, POPIA

If you are located in South Africa, you have the following rights under the Protection of Personal Information Act 4 of 2013:

  • Right to be notified: Be informed when your personal information is being collected and the purpose of the collection.
  • Right of access: Request confirmation of whether we hold personal information about you, and request access to that information.
  • Right to correction: Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • Right to deletion: Request destruction or deletion of personal information that we are no longer authorised to retain.
  • Right to object: Object to the processing of your personal information on reasonable grounds, and object to receiving direct marketing.
  • Right to submit a complaint: Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
Thailand, PDPA

If you are located in Thailand, you have the following rights under the Personal Data Protection Act B.E. 2562 (2019):

  • Right of access: Request access to, and a copy of, the personal data we hold about you, and to be informed of how that data was obtained without your consent.
  • Right to data portability: Request that your personal data be sent to another data controller in a readable format, where technically feasible.
  • Right to object: Object to the processing of your personal data in certain circumstances, including for direct marketing.
  • Right to erasure or anonymisation: Request that we delete, destroy, or anonymise your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful.
  • Right to restrict processing: Request that we restrict use of your personal data in certain circumstances.
  • Right to rectification: Request that we correct personal data that is inaccurate, out of date, incomplete, or misleading.
  • Right to withdraw consent: Withdraw any consent you have previously given, at any time, without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: Submit a complaint to the Office of the Personal Data Protection Committee (PDPC) at pdpc.or.th.

How to Exercise Your Rights

To exercise any of these rights, please contact us at support@onfound.com with the subject line “Data Rights Request.” We may ask you to verify your identity before processing your request.

Deleting your account: You can delete your Onfound account at any time directly from within the mobile app (Settings › Account › Delete Account) or your member dashboard on the web. Account deletion is permanent and removes your profile, photos, group history, and messages from active use. Some data may be retained for the periods set out in Section 8 (Data Retention) where required for legal, financial, or safety reasons. You can also email us at support@onfound.com to request deletion if you cannot access your account.

We will respond to your request within:

  • 30 days for requests under UK GDPR / EU GDPR (extendable by a further 60 days for complex requests, with notice).
  • A reasonable period for requests under POPIA (generally within 30 days).

We will not charge a fee for most requests. However, we may charge a reasonable administrative fee if your request is manifestly unfounded, excessive, or repetitive, or we may refuse to act on the request in such cases.

11 Children’s Privacy

Onfound is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@onfound.com and we will take steps to delete that information promptly.

12 Marketing and Communications

12.1 Marketing Consent

We will only send you marketing communications (such as newsletters, promotional offers, and community content) where you have given us your explicit consent or where we are permitted to do so under applicable law.

UK / EEA

We rely on your opt-in consent for electronic marketing communications, in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and ePrivacy rules.

South Africa

We rely on your opt-in consent for direct marketing, in accordance with Section 69 of POPIA and the Consumer Protection Act.

Thailand

We rely on your opt-in consent for direct marketing communications, in accordance with the Personal Data Protection Act B.E. 2562 (2019). You may withdraw consent at any time.

12.2 Opting Out

You can opt out of marketing communications at any time by:

  • Clicking the “Unsubscribe” link in any marketing email.
  • Updating your communication preferences in your account dashboard.
  • Contacting us at support@onfound.com.

Opting out of marketing does not affect transactional communications necessary for the operation of your account (such as billing receipts, message and event notifications, and service updates).

13 Automated Decision-Making and Profiling

Onfound uses an automated suggestion engine (“Why Connects”) to surface members from the directory who may be relevant to you, based on factors such as city, what you’re working on, interests, and goals.

Onfound also offers an optional AI-powered member search (“Frontier Intelligence”). When you use it, your search request and the community profile information of potentially relevant members are processed by the AI providers listed in Section 6.1 to identify and briefly explain relevant suggestions. Suggestions are informational only, you can always browse the full directory without using this feature, and the data involved is never used to train the providers’ models. Search requests are also stored on Onfound’s own systems, linked to your account, so we can improve the feature and understand what members are looking for; they are visible only to Onfound administrators.

This suggestion process constitutes profiling under GDPR but does not produce legal effects or similarly significant effects on you. It is used to help you discover potentially relevant members in the directory, not to make decisions about you, and you can browse the directory freely without relying on these suggestions.

You have the right to request information about the logic involved in the suggestion process and to object to automated decision-making. To do so, please contact us at support@onfound.com.

We do not use automated decision-making for any purpose that produces legal effects or significantly affects you (such as credit decisions, employment, or access to essential services).

14 Do Not Track Signals

Some browsers transmit “Do Not Track” (DNT) signals. There is currently no industry standard for how to respond to DNT signals. Our website does not currently respond to DNT signals, but you can manage tracking preferences through your browser settings and cookie choices as described in Section 5.

15 Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.

If we make material changes, we will notify you by:

  • Sending an email to the address associated with your account.
  • Displaying a prominent notice within the platform or app.
  • Updating the “Last Updated” date at the top of this policy.

We will provide at least 14 days’ notice before material changes take effect, except where changes are required by law. Your continued use of the Services after the updated policy takes effect constitutes your acceptance of the changes. If you do not agree, you should stop using the Services and delete your account from within the app or member dashboard.

16 Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your personal data, please contact us:

Data Rights RequestsSubject line: “Data Rights Request”
PostOnfound Inc., 1111B S Governors Ave STE 29782, Dover, DE 19904, United States

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

United KingdomInformation Commissioner’s Office (ICO)
ico.org.uk
South AfricaInformation Regulator
inforegulator.org.za
ThailandPersonal Data Protection Committee (PDPC)
pdpc.or.th
European UnionYour local data protection supervisory authority
Back to top
© 2026 Onfound Inc. All rights reserved.