Privacy Policy
This Privacy Policy explains how Onfound (“Onfound”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use our website, mobile application, and related services. It also explains your rights regarding your personal data and how to exercise them.
Please read this policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy. This policy should be read together with our Terms and Conditions.
1 Who We Are (Data Controller)
Onfound Inc. is the data controller responsible for your personal data.
Entity: Onfound Inc.
Registered address: 1111B S Governors Ave STE 29782, Dover, DE 19904, United States
Email:
Website: https://onfound.com
Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), we are the “data controller.” Under South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA), we are the “responsible party.” Under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA), we are the “data controller.”
2 What This Policy Covers
This Privacy Policy applies to personal data collected through:
- Our website at onfound.com
- The Onfound mobile application (iOS and Android)
- The member dashboard
- Any Onfound-organised meetups, events, or activities
- Email, WhatsApp, and other communications with us
It does not apply to third-party websites, apps, or services linked from Onfound (such as Stripe, WhatsApp, or partner venues). Those services have their own privacy policies, which we encourage you to review.
3 Personal Data We Collect
3.1 Data You Provide Directly
When you register, complete onboarding, use the platform, or contact us, we may collect:
| Category | Examples | When Collected |
|---|---|---|
| Identity data | First name, last name, date of birth, gender (optional) | Registration and onboarding |
| Contact data | Email address, WhatsApp/phone number in international format, selected city | Registration and onboarding |
| Profile data | Profile photo, what you’re working on, your biggest challenge, your biggest win, business name, business website, social links (LinkedIn, Instagram, X, personal website), and any other profile text you choose to share | Onboarding and profile editing |
| Member-to-member content | Direct messages, group chat messages, message edits and reactions, profile views, saved (“hearted”) profiles | When you use the directory and messaging features |
| Event content | Event description, meeting point, arrival instructions, what to expect, event banner image, your RSVPs to city events | When you create or RSVP to a city event |
| Financial data | Subscription plan, billing events, currency, cancellation reason and feedback (card brand and last 4 digits only; full card details are handled by Stripe) | Subscription and checkout |
| Communication data | Messages to support, feedback, survey responses, meetup suggestions | When you contact us or respond to in-app prompts |
3.2 Data We Collect Automatically
When you use the website or app, we automatically collect:
| Category | Examples | Purpose |
|---|---|---|
| Device and technical data | IP address, browser type, operating system, device type, screen resolution, per-device identifiers used for push notifications (Capacitor device ID, APNs/FCM push tokens), and User-Agent string | Platform security, push notification routing, debugging |
| Usage data | Pages and screens visited, features used, profile views, profiles you save, direct message initiations, message read events, event RSVPs, click patterns | Service improvement and product personalisation |
| Location data | City-level location derived from the city you select during onboarding (or from your IP address). We do not collect precise GPS location. | Surfacing members and events in your city |
| Log data | Access times, error logs, referring URLs (held in our hosting provider’s console) | Security monitoring, troubleshooting |
| Advertising data | Data collected via the Meta Pixel and Meta Conversions API, including page views, button clicks, sign-up and subscription conversion events, browser and device data, IP address, User-Agent, and hashed identifiers (SHA-256 hashed email address and phone number) used to attribute conversions to your Meta account. On iOS, the device advertising identifier (IDFA) is only accessed if you grant permission via the App Tracking Transparency prompt. | Measuring ad effectiveness, remarketing, and audience building |
3.3 Data from Third Parties
We may receive limited data from third parties, including:
- Stripe: payment confirmation status, subscription status, and billing events (not full card details).
- Meta (Facebook/Instagram): conversion data and ad interaction data used to measure campaign performance and serve relevant ads.
- App stores (Apple App Store, Google Play): download and installation data, crash reports.
We do not purchase personal data from data brokers or third-party marketing databases.
4 How We Use Your Personal Data
We use your personal data for the following purposes:
| Purpose | What We Do | Legal Basis (GDPR) | Legal Basis (POPIA) |
|---|---|---|---|
| Provide the Services | Create and manage your account, run the city directory, surface relevant members through the “Why Connects” suggestion engine, deliver direct messages and group chats, manage subscriptions and billing | Contractual necessity | Processing necessary for a contract |
| Communicate with you | Send transactional email (billing receipts, account notifications, digests), push notifications, service updates, and respond to support requests | Contractual necessity | Processing necessary for a contract |
| Improve the Services | Analyse usage patterns, test new features, refine the suggestion engine, fix bugs | Legitimate interest | Legitimate interest of the responsible party |
| Moderate member content | Before publication, automatically scan profile text, event text, and uploaded images for safety risks (e.g. abuse, sexual content, violence) using a third-party moderation service. Maintain a moderation queue and audit trail of flagged content. | Legitimate interest | Legitimate interest of the responsible party |
| Ensure safety and security | Detect and prevent fraud, enforce our Terms, investigate misconduct, protect members | Legitimate interest | Legitimate interest of the responsible party |
| Marketing | Send newsletters, feature announcements, promotions, and community content (only with your consent) | Consent | Consent |
| Push notifications | Send message alerts, event reminders, and community updates via the mobile app (only with your consent) | Consent | Consent |
| Legal compliance | Comply with tax, accounting, regulatory, and legal obligations | Legal obligation | Processing necessary for legal compliance |
| Events | Organise city events, manage RSVPs, facilitate community activities | Contractual necessity / Legitimate interest | Contract / Legitimate interest |
| Advertising and remarketing | Measure the effectiveness of our advertising campaigns, serve relevant ads on Meta (Facebook/Instagram), and retarget visitors who have interacted with our website or app | Consent | Consent |
5 Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and app to improve your experience and analyse how the Services are used.
5.1 Types of Cookies We Use
| Type | Purpose | Examples | Duration |
|---|---|---|---|
| Strictly necessary | Required for the website and app to function (authentication, security, session management) | Session cookies, CSRF tokens, authentication tokens | Session or up to 12 months |
| Functional | Remember your preferences and settings | Language preference, city selection | Up to 12 months |
| Marketing | Used to deliver targeted advertising, measure ad performance, and serve remarketing ads on third-party platforms (only with consent) | Meta Pixel, email campaign tracking pixels | Up to 12 months |
5.2 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling strictly necessary cookies may affect the functionality of the Services.
For advertising cookies, you can manage your preferences through Meta Ad Preferences. You can also opt out of interest-based advertising from participating companies at aboutads.info.
5.3 Mobile App Tracking (iOS App Tracking Transparency and Android)
Our mobile app uses tracking technologies, including the Meta Pixel and Meta Conversions API, to measure conversions and serve relevant ads on third-party platforms.
iOS (App Tracking Transparency): When you first open the Onfound app on an iPhone or iPad, Apple will show you an App Tracking Transparency (ATT) prompt asking whether you allow Onfound to track your activity across other companies’ apps and websites.
- If you allow tracking, we and our advertising partner (Meta) may access your device’s Identifier for Advertisers (IDFA) and use it to measure the performance of ads you have seen and to serve you more relevant ads.
- If you ask the app not to track, we will not access the IDFA and will not share device-level identifiers with our advertising partner. We will still measure conversions using aggregated, privacy-preserving methods (such as Apple’s SKAdNetwork and aggregated event measurement), which do not identify you individually.
- You can change your choice at any time in iOS Settings › Privacy & Security › Tracking, or in Settings › Onfound.
Android: On Android devices, conversion and ad measurement is performed using the Google Advertising ID (GAID) by our advertising partner (Meta). You can reset your GAID or opt out of personalised ads at any time in Settings › Google › Ads.
Declining tracking does not affect your ability to use the Onfound app or any of its core features.
6 Who We Share Your Data With
We do not sell your personal data to anyone. We share your data only in the following circumstances:
6.1 Service Providers
We use trusted third-party service providers to operate and improve the Services. These providers process data on our behalf and are contractually required to protect your data:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing and subscription management. Full card details are entered on Stripe’s own hosted checkout and never reach Onfound’s servers. | Card details (held by Stripe only), email, name, internal user ID, attribution parameters (fbclid, UTMs), subscription plan and status | United States |
| Railway | Cloud hosting and infrastructure | All platform data (encrypted at rest and in transit). Application logs may contain internal user and device IDs. | United States |
| Postmark | Transactional email delivery (account, billing, digests, password reset) | Recipient name and email, profile photo URL, city name, sender name and channel-list phrases used in digests, short-lived URL tokens for password reset and onboarding | United States |
| Mailchimp (Intuit) | Contact-list sync, segmentation, and tagging | Name, email address (plain and MD5-hashed for lookup), phone number, date of birth, city, subscription-status tags | United States |
| Ably | Real-time messaging (direct messages and group chats) and push notification routing | Internal user ID, device ID and platform, APNs/FCM push tokens, message channel payloads (the content of messages you send and receive) | Global / United States |
| OpenAI | Automated content moderation before publishing, and language understanding for AI member search (interpreting search requests and indexing profile text by meaning) | Profile text, event text, uploaded images, and the text of member search requests. Content is sent in isolation with no account identifiers attached, and is not used to train OpenAI’s models. | United States |
| Anthropic (Claude) | AI member search (Frontier Intelligence): reading shortlisted member profiles to suggest relevant founders and explain why they may be worth meeting | Member name and profile information you share with the community (bio, what you are building, help offered and needed, interests, challenges and wins), plus the search request. Revenue information is never included. Not used to train Anthropic’s models; retained briefly by Anthropic for abuse monitoring only. | United States |
| Meta (Facebook/Instagram) | Advertising, conversion tracking, and remarketing via the Meta Pixel and Meta Conversions API | Pixel events (page views, sign-ups, subscription starts, button clicks), SHA-256 hashed email and phone number, IP address, browser and device User-Agent, fbclid and UTM attribution parameters, event identifiers, subscription value and currency. On iOS, the device advertising identifier (IDFA) only if you have granted App Tracking Transparency permission. | United States |
| MinIO (object storage) | Storage for profile photos and event banner images | Image binary and MIME type; the storage key contains your internal user ID | Self-hosted |
| Apple Push (APNs) / Google FCM | Mobile push notification delivery (routed via Ably) | Device push token, notification payload | United States |
6.2 Other Members
Onfound is a member directory. When your profile is approved, the profile content you have chosen to publish — your first name, last name, profile photo, city, what you’re working on, your biggest challenge, your biggest win, business name and website, and any social links you have added — is visible to other approved Onfound members.
If you send a direct message or post in a group chat, the contents of those messages are visible to the other people in the conversation. If you RSVP to a city event, your first name, last name, and profile photo are visible on the event’s attendee list to other approved members.
Your email address, phone number, date of birth, and gender are not displayed in the directory or to other members. Other members can message you within the Onfound app, but cannot see your email or phone number unless you choose to share them in a message.
You can request that your profile be hidden from the directory by contacting us, though this may limit your ability to participate in the community.
6.3 Legal and Safety Disclosures
We may disclose your personal data if we are required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation, court order, or regulatory request.
- Protect the rights, safety, or property of Onfound, our members, or the public.
- Investigate or prevent fraud, security incidents, or violations of our Terms.
- Respond to an emergency involving potential harm to any person.
6.4 Business Transfers
If Onfound is involved in a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and ensure the receiving party is bound by obligations consistent with this Privacy Policy.
7 International Data Transfers
Onfound is based in the United States. If you are located in the United Kingdom, European Economic Area, South Africa, or any other jurisdiction with data protection laws that restrict international data transfers, your personal data will be transferred to and processed in the United States and potentially other countries where our service providers operate.
We ensure that international transfers of personal data are protected by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the UK Information Commissioner’s Office (ICO), incorporated into our agreements with service providers.
- Adequacy decisions, where the European Commission or UK government has determined that a country provides an adequate level of data protection.
- Other lawful transfer mechanisms as recognised under applicable law.
Under Section 72 of POPIA, cross-border transfers are permitted where the recipient is subject to laws or binding agreements that provide an adequate level of protection, or where you have consented to the transfer. Our agreements with service providers include data protection obligations substantially similar to those required by POPIA.
Under Sections 28 and 29 of the Personal Data Protection Act B.E. 2562 (2019), cross-border transfers of personal data are permitted where the recipient country has adequate protection, or where the transfer is necessary for the performance of a contract with you, your consent has been obtained, or appropriate safeguards (such as contractual data protection clauses substantially similar to Standard Contractual Clauses) are in place. Our agreements with service providers include such safeguards.
8 Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and profile data | Duration of membership plus 12 months after account deletion | Account reactivation inquiries and post-cancellation disputes |
| Financial and billing data | 7 years after the transaction | Tax, accounting, and legal compliance obligations |
| Communication data | 3 years after last interaction | Service quality improvement and recurring issue resolution |
| Analytics and usage data | 26 months (aggregated and pseudonymised) | Service improvement and trend analysis |
| Member-to-member content (direct messages, group chat messages, profile views and saves, event RSVPs) | Duration of membership plus 6 months | Suggestion engine improvement and dispute resolution |
| Moderation records (excerpts of flagged content, classifier scores) | Duration of membership plus 12 months | Audit trail and appeals review |
| Marketing consent records | Duration of membership plus 3 years | Demonstrate compliance with consent requirements |
After the applicable retention period, we will securely delete or anonymise your personal data so that it can no longer be associated with you.
9 Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it, including:
- Encryption of data in transit using TLS/SSL and encryption at rest for stored data.
- Secure authentication mechanisms, including hashed and salted passwords.
- Access controls limiting who within Onfound can access personal data, on a need-to-know basis.
- Regular security reviews and monitoring of our infrastructure.
- PCI-DSS compliant payment processing through Stripe (Onfound never stores full card details).
- Incident response procedures to detect, investigate, and respond to data breaches.
While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.
10 Your Rights
Depending on where you are located, you have certain rights regarding your personal data. We are committed to helping you exercise these rights.
If you are located in the United Kingdom or European Economic Area, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request that we correct inaccurate or incomplete data.
- Right to erasure: Request that we delete your personal data (“right to be forgotten”), subject to certain legal exceptions.
- Right to restrict processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Request a copy of your data in a structured, machine-readable format and have it transferred to another controller.
- Right to object: Object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: Complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or your local supervisory authority.
If you are located in South Africa, you have the following rights under the Protection of Personal Information Act 4 of 2013:
- Right to be notified: Be informed when your personal information is being collected and the purpose of the collection.
- Right of access: Request confirmation of whether we hold personal information about you, and request access to that information.
- Right to correction: Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
- Right to deletion: Request destruction or deletion of personal information that we are no longer authorised to retain.
- Right to object: Object to the processing of your personal information on reasonable grounds, and object to receiving direct marketing.
- Right to submit a complaint: Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
If you are located in Thailand, you have the following rights under the Personal Data Protection Act B.E. 2562 (2019):
- Right of access: Request access to, and a copy of, the personal data we hold about you, and to be informed of how that data was obtained without your consent.
- Right to data portability: Request that your personal data be sent to another data controller in a readable format, where technically feasible.
- Right to object: Object to the processing of your personal data in certain circumstances, including for direct marketing.
- Right to erasure or anonymisation: Request that we delete, destroy, or anonymise your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful.
- Right to restrict processing: Request that we restrict use of your personal data in certain circumstances.
- Right to rectification: Request that we correct personal data that is inaccurate, out of date, incomplete, or misleading.
- Right to withdraw consent: Withdraw any consent you have previously given, at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: Submit a complaint to the Office of the Personal Data Protection Committee (PDPC) at pdpc.or.th.
How to Exercise Your Rights
To exercise any of these rights, please contact us at with the subject line “Data Rights Request.” We may ask you to verify your identity before processing your request.
We will respond to your request within:
- 30 days for requests under UK GDPR / EU GDPR (extendable by a further 60 days for complex requests, with notice).
- A reasonable period for requests under POPIA (generally within 30 days).
We will not charge a fee for most requests. However, we may charge a reasonable administrative fee if your request is manifestly unfounded, excessive, or repetitive, or we may refuse to act on the request in such cases.
11 Children’s Privacy
Onfound is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at and we will take steps to delete that information promptly.
12 Marketing and Communications
12.1 Marketing Consent
We will only send you marketing communications (such as newsletters, promotional offers, and community content) where you have given us your explicit consent or where we are permitted to do so under applicable law.
We rely on your opt-in consent for electronic marketing communications, in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and ePrivacy rules.
We rely on your opt-in consent for direct marketing, in accordance with Section 69 of POPIA and the Consumer Protection Act.
We rely on your opt-in consent for direct marketing communications, in accordance with the Personal Data Protection Act B.E. 2562 (2019). You may withdraw consent at any time.
12.2 Opting Out
You can opt out of marketing communications at any time by:
- Clicking the “Unsubscribe” link in any marketing email.
- Updating your communication preferences in your account dashboard.
- Contacting us at .
Opting out of marketing does not affect transactional communications necessary for the operation of your account (such as billing receipts, message and event notifications, and service updates).
13 Automated Decision-Making and Profiling
Onfound uses an automated suggestion engine (“Why Connects”) to surface members from the directory who may be relevant to you, based on factors such as city, what you’re working on, interests, and goals.
Onfound also offers an optional AI-powered member search (“Frontier Intelligence”). When you use it, your search request and the community profile information of potentially relevant members are processed by the AI providers listed in Section 6.1 to identify and briefly explain relevant suggestions. Suggestions are informational only, you can always browse the full directory without using this feature, and the data involved is never used to train the providers’ models. Search requests are also stored on Onfound’s own systems, linked to your account, so we can improve the feature and understand what members are looking for; they are visible only to Onfound administrators.
This suggestion process constitutes profiling under GDPR but does not produce legal effects or similarly significant effects on you. It is used to help you discover potentially relevant members in the directory, not to make decisions about you, and you can browse the directory freely without relying on these suggestions.
You have the right to request information about the logic involved in the suggestion process and to object to automated decision-making. To do so, please contact us at .
We do not use automated decision-making for any purpose that produces legal effects or significantly affects you (such as credit decisions, employment, or access to essential services).
14 Do Not Track Signals
Some browsers transmit “Do Not Track” (DNT) signals. There is currently no industry standard for how to respond to DNT signals. Our website does not currently respond to DNT signals, but you can manage tracking preferences through your browser settings and cookie choices as described in Section 5.
15 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.
If we make material changes, we will notify you by:
- Sending an email to the address associated with your account.
- Displaying a prominent notice within the platform or app.
- Updating the “Last Updated” date at the top of this policy.
We will provide at least 14 days’ notice before material changes take effect, except where changes are required by law. Your continued use of the Services after the updated policy takes effect constitutes your acceptance of the changes. If you do not agree, you should stop using the Services and delete your account from within the app or member dashboard.
16 Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your personal data, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority: