Privacy Policy
This Privacy Policy explains how Onfound (“Onfound”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use our website, mobile application, and related services. It also explains your rights regarding your personal data and how to exercise them.
Please read this policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy. This policy should be read together with our Terms and Conditions and our Community Guidelines.
1 Who We Are (Data Controller)
Onfound Inc. is the data controller responsible for your personal data.
Entity: Onfound Inc.
Registered address: 1111B S Governors Ave STE 29782, Dover, DE 19904, United States
Email: support@onfound.com
Website: https://onfound.com
Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), we are the “data controller.” Under South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA), we are the “responsible party.” Under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA), we are the “data controller.”
2 What This Policy Covers
This Privacy Policy applies to personal data collected through:
- Our website at onfound.com
- The Onfound mobile application (iOS and Android)
- The Onfound web app and member dashboard used in a browser
- Meetups, communities, and other activities organised or hosted through Onfound
- Email, WhatsApp, and other communications with us
It does not apply to third-party websites, apps, or services you reach by following a link from Onfound, such as Stripe’s checkout pages, WhatsApp, a map or calendar app you open to get directions to a meetup, a member’s LinkedIn or Instagram profile, or a partner venue’s website. Those services have their own privacy policies, which we encourage you to review.
3 Personal Data We Collect
3.1 Data You Provide Directly
When you register, complete onboarding, use the platform, or contact us, we may collect:
| Category | Examples | When Collected |
|---|---|---|
| Identity data | First name, last name, date of birth, gender | Registration and onboarding |
| Contact data | Email address, WhatsApp/phone number in international format, selected city | Registration and onboarding |
| Account credentials | Your password (stored only as a salted hash), or, if you sign up with Google, the account identifier and name, email, and profile photo that Google shares with us | Registration and sign-in |
| Profile data | Profile photo, member type, what you’re working on, your goals (including any goals you write in your own words), industry, your biggest challenge, your biggest win, business name, business website, funding context, social links (LinkedIn, Instagram, X, personal website), and any other profile text you choose to share | Onboarding and profile editing |
| Member-to-member content | Direct messages, group chat messages, message edits and reactions, images and GIFs you send in chat, profile views, saved (“hearted”) profiles, connect invites | When you use the directory and messaging features |
| Community content | Posts, comments, replies, likes, images, GIFs, and links (including YouTube links) you share in communities, community join requests, communities you create | When you use Communities |
| Meetup content | Meetup title, description, meeting point, arrival instructions, what to expect, banner image, venue searched and selected on the map, your RSVPs, join requests, invitations, and attendance | When you create, join, or are invited to a meetup |
| Search and AI requests | The text of requests you type into Onfound Intelligence (our AI member search) and the goal you set for AutoPilot | When you use Onfound Intelligence or AutoPilot |
| Financial data | Subscription plan, billing events, currency, cancellation reason and feedback, and purchases of paid meetup seats (card brand and last 4 digits only; full card details are handled by Stripe) | Subscription checkout and paid meetup checkout |
| Reports and blocks | Reports you file about a member, message, post, comment, or meetup, and members you block | When you use the report or block features |
| Communication data | Messages to support, feedback, survey responses, meetup suggestions | When you contact us or respond to in-app prompts |
3.2 Data We Collect Automatically
When you use the website or app, we automatically collect:
| Category | Examples | Purpose |
|---|---|---|
| Device and technical data | IP address, browser type, operating system, device type, screen resolution, per-device identifiers used for push notifications (Capacitor device ID, APNs/FCM push tokens), and User-Agent string | Platform security, push notification routing, debugging |
| Usage data | Pages and screens visited, features used, profile views, profiles you save, direct message initiations, message read events, meetup views and RSVPs, community post reads and likes, AutoPilot suggestions you receive and your feedback on them | Service improvement and product personalisation |
| Product analytics (web only) | When you use Onfound in a web browser, we collect page views, clicks, and named product events (such as opening a feature or completing a step) linked to your member ID, together with your IP address. The Onfound iOS and Android apps do not run product analytics. See Section 5. | Understanding how the product is used, fixing friction |
| Location data | City-level location from the city you select during onboarding (or from your IP address), plus the map area you are viewing and any venue you search for when you use the meetup map. We do not collect precise GPS location from your device. | Surfacing members and meetups in your city, placing meetups on the map |
| Log data | Access times, error logs, referring URLs (held in our hosting provider’s console) | Security monitoring, troubleshooting |
| Advertising data | Data collected via the Meta Pixel and Meta Conversions API, including page views, button clicks, sign-up and subscription conversion events, browser and device data, IP address, User-Agent, and hashed identifiers (SHA-256 hashed email address and phone number) used to attribute conversions to your Meta account. On iOS, the device advertising identifier (IDFA) is only accessed if you grant permission via the App Tracking Transparency prompt. | Measuring ad effectiveness, remarketing, and audience building |
3.3 Data from Third Parties
We may receive limited data from third parties, including:
- Google (Sign in with Google): if you choose to create your account or sign in with Google on the web, Google shares your verified name, email address, a Google account identifier, and your Google profile photo. We copy the photo into your Onfound profile, where you can change or remove it.
- Stripe: payment confirmation status, subscription status, refund status, and billing events (not full card details).
- Meta (Facebook/Instagram): conversion data and ad interaction data used to measure campaign performance and serve relevant ads.
- App stores (Apple App Store, Google Play): download and installation data, crash reports.
We do not purchase personal data from data brokers or third-party marketing databases.
4 How We Use Your Personal Data
We use your personal data for the following purposes:
| Purpose | What We Do | Legal Basis (GDPR) | Legal Basis (POPIA) |
|---|---|---|---|
| Provide the Services | Create and manage your account, run the city directory, deliver direct messages and group chats, run Communities, list and manage meetups, manage subscriptions and billing | Contractual necessity | Processing necessary for a contract |
| Onfound Intelligence (AI member search) | When you type a request, read your request together with the community profiles of potentially relevant members to suggest people worth meeting and explain the reason. Profile text is also converted into a numerical representation (an “embedding”) so that searches can find members by meaning rather than exact words. | Contractual necessity / Legitimate interest | Contract / Legitimate interest of the responsible party |
| AutoPilot | If you turn on AutoPilot and set a goal, read your goal and profile each week alongside the profiles of other members and upcoming meetups to deliver a small set of suggested people and meetups, and learn from your feedback on them | Contractual necessity / Legitimate interest | Contract / Legitimate interest of the responsible party |
| Communicate with you | Send transactional email (billing receipts, account notifications, digests), push notifications, service updates, and respond to support requests | Contractual necessity | Processing necessary for a contract |
| Improve the Services | Analyse usage patterns, test new features, refine Onfound Intelligence and AutoPilot, fix bugs | Legitimate interest | Legitimate interest of the responsible party |
| Moderate member content | Before publication, automatically screen profile text, meetup text, community posts, comments and replies, and uploaded profile, meetup, and community images for safety risks (for example abuse, sexual content, or violence) using a third-party classification service. Maintain a moderation queue, review reports from members, and keep an audit trail of flagged content. See Section 13. | Legitimate interest | Legitimate interest of the responsible party |
| Ensure safety and security | Detect and prevent fraud, enforce our Terms and Community Guidelines, investigate misconduct, act on reports and blocks, protect members | Legitimate interest | Legitimate interest of the responsible party |
| Paid meetups | Sell seats to paid meetups hosted through Onfound, confirm your place, grant access to the meetup chat, and process refunds where they are due | Contractual necessity | Processing necessary for a contract |
| Marketing | Send newsletters, feature announcements, promotions, and community content (only with your consent) | Consent | Consent |
| Push notifications | Send message alerts, meetup reminders, and community updates via the mobile app (only with your consent) | Consent | Consent |
| Legal compliance | Comply with tax, accounting, regulatory, and legal obligations | Legal obligation | Processing necessary for legal compliance |
| Advertising and remarketing | Measure the effectiveness of our advertising campaigns, serve relevant ads on Meta (Facebook/Instagram), and retarget visitors who have interacted with our website or app | Consent | Consent |
5 Cookies, Analytics, and Tracking Technologies
We use cookies and similar technologies on our website and web app to keep you signed in, improve your experience, and understand how the Services are used.
5.1 Types of Cookies and Similar Technologies We Use
| Type | Purpose | Examples | Duration |
|---|---|---|---|
| Strictly necessary | Required for the website and app to function (authentication, security, session management) | Session cookies, CSRF tokens, authentication tokens | Session or up to 12 months |
| Functional | Remember your preferences and settings | Language preference, city selection, an in-progress sign-up draft saved in your browser | Up to 12 months |
| Analytics | Measure how the web app is used so we can improve it | PostHog (hosted in the European Union) | Up to 12 months |
| Marketing | Used to deliver targeted advertising, measure ad performance, and serve remarketing ads on third-party platforms (only with consent) | Meta Pixel, email campaign tracking pixels | Up to 12 months |
5.2 Product Analytics (PostHog)
We use PostHog, hosted in the European Union, for product analytics when you use Onfound in a web browser. PostHog records page views, clicks, and named product events linked to your member ID, together with your IP address. We do not record your screen or replay your sessions. The Onfound iOS and Android apps do not run PostHog or any other product analytics.
5.3 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling strictly necessary cookies may affect the functionality of the Services.
For advertising cookies, you can manage your preferences through Meta Ad Preferences. You can also opt out of interest-based advertising from participating companies at aboutads.info.
5.4 Mobile App Tracking (iOS App Tracking Transparency and Android)
Our mobile app uses the Meta Pixel and Meta Conversions API to measure conversions and serve relevant ads on third-party platforms. Meta receives a SHA-256 hashed version of your email address and phone number, the names of conversion events (such as sign-up, onboarding complete, or subscription started), your IP address and device User-Agent, and any advertising identifiers attached to the link you arrived through.
iOS (App Tracking Transparency): Before any of this data leaves your device on an iPhone or iPad, the Onfound app shows Apple’s App Tracking Transparency (ATT) prompt asking whether you allow Onfound to track your activity across other companies’ apps and websites.
- If you allow tracking, we and our advertising partner (Meta) may access your device’s Identifier for Advertisers (IDFA) and use the data above to measure the performance of ads you have seen and to serve you more relevant ads.
- If you ask the app not to track, we will not access the IDFA and will not send identifying data to our advertising partner from the iOS app. We may still measure conversions using aggregated, privacy-preserving methods (such as Apple’s SKAdNetwork), which do not identify you individually.
- You can change your choice at any time in iOS Settings › Privacy & Security › Tracking, or in Settings › Onfound.
Android: On Android devices, conversion and ad measurement is performed using the Google Advertising ID (GAID) by our advertising partner (Meta). You can reset your GAID or opt out of personalised ads at any time in Settings › Google › Ads.
Declining tracking does not affect your ability to use the Onfound app or any of its core features.
6 Who We Share Your Data With
We do not sell your personal data to anyone. We share your data only in the following circumstances:
6.1 Service Providers
We use trusted third-party service providers to operate and improve the Services. These providers process data on our behalf and are contractually required to protect your data:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing for subscriptions and paid meetup seats. Full card details are entered on Stripe’s own hosted checkout and never reach Onfound’s servers. Onfound is the merchant of record for paid meetup seats sold through the app, which means your payment is made to Onfound and your receipt comes from Onfound, even though the meetup is run by a member host. | Card details (held by Stripe only), email, name, internal user ID, attribution parameters (fbclid, UTMs), subscription plan and status, meetup seat purchases and refunds | United States |
| Railway | Cloud hosting and infrastructure | All platform data (encrypted at rest and in transit). Application logs may contain internal user and device IDs. | United States |
| Postmark | Transactional email delivery (account, billing, digests, password reset) | Recipient name and email, profile photo URL, city name, sender name and channel-list phrases used in digests, short-lived URL tokens for password reset and onboarding | United States |
| Mailchimp (Intuit) | Contact-list sync, segmentation, and tagging for marketing email | Name, email address (plain and MD5-hashed for lookup), phone number, date of birth, city, subscription-status tags | United States |
| Ably | Real-time messaging (direct messages, group chats, and live updates) and push notification routing | Internal user ID, device ID and platform, APNs/FCM push tokens, message channel payloads (the content of messages you send and receive) | Global / United States |
| Anthropic (Claude) | Powers Onfound Intelligence and AutoPilot. Your search request or goal, together with short summaries of potentially relevant member profiles, is sent to Anthropic to generate suggestions and the reason for each one. | The text of your search request, your AutoPilot goal, and the community profile information of candidate members (name, city, industry, what they are working on). Revenue information is never included. Anthropic does not use this data to train its models and retains it only briefly for safety and abuse monitoring. | United States |
| OpenAI | Two uses. (1) Automated moderation: every profile text, meetup text, community post, comment and reply, and every uploaded profile, meetup, and community image is screened before it is published. (2) Embeddings: your profile text is converted into a numerical representation so Onfound Intelligence can search by meaning. | The content being screened or indexed. Content is sent in isolation with no account identifiers attached. OpenAI does not use this data to train its models. OpenAI may retain API inputs for up to 30 days for abuse monitoring before deleting them. | United States |
| PostHog | Product analytics on the web app only (see Section 5.2). Not present in the iOS or Android apps. | Member ID, page views, clicks, named product events, IP address, browser and device information | European Union |
| Mapbox | Powers the meetup map, venue search, and turning a chosen location into a place name | Your IP address, the area of the map you are viewing, and the venue searches you type. Sent directly from your device to Mapbox. | United States |
| GIPHY | GIF search and delivery in community posts, comments, and chat | When you search for a GIF, your search term (sent through our server, so GIPHY does not see your IP address). When a GIF is displayed to you, whether or not you posted it, your device loads it from GIPHY’s servers and GIPHY receives your IP address and device information. | United States |
| Google / YouTube | Inline video preview when a member shares a YouTube link in a community post | When a post containing a YouTube link is displayed to you, your device loads the preview from YouTube and Google receives your IP address and device information. We use YouTube’s privacy-enhanced (“nocookie”) player, which limits Google’s ability to use this to build an advertising profile. | United States |
| Google (Sign in with Google) | Optional account creation and sign-in on the web | If you choose Sign in with Google, Google receives your IP address and device information on the sign-up page and shares your verified name, email, account identifier, and profile photo with us. | United States |
| Meta (Facebook/Instagram) | Advertising, conversion tracking, and remarketing via the Meta Pixel and Meta Conversions API | Pixel events (page views, sign-ups, onboarding completion, subscription starts, button clicks), SHA-256 hashed email and phone number, IP address, browser and device User-Agent, fbclid and UTM attribution parameters, event identifiers, subscription value and currency. On iOS, the device advertising identifier (IDFA) only if you have granted App Tracking Transparency permission. | United States |
| MinIO (object storage) | Storage for profile photos, meetup banner images, and images shared in communities and chat | Image binary and MIME type; the storage key contains your internal user ID | Self-hosted |
| Apple Push (APNs) / Google FCM | Mobile push notification delivery (routed via Ably) | Device push token, notification payload | United States |
6.2 Other Members
Onfound is a member directory. When your profile is approved, the profile content you have chosen to publish (your first name, last name, profile photo, city, member type, industry, what you’re working on, your goals, your biggest challenge, your biggest win, business name and website, and any social links you have added) is visible to other approved Onfound members. Onfound Intelligence and AutoPilot may show your published profile to other members as a suggestion, together with a short reason based on that profile.
If you send a direct message or post in a group chat, the contents of those messages are visible to the other people in the conversation. If you post or comment in a community, that content is visible to the other members of that community. If you RSVP to or buy a seat at a meetup, your first name, last name, and profile photo are visible on the meetup’s attendee list and in the meetup chat to the host and other attendees. If you host a meetup or create a community, your name and photo are shown as the host or founder.
Your email address, phone number, date of birth, and gender are not displayed in the directory or to other members. Other members can message you within the Onfound app, but cannot see your email or phone number unless you choose to share them in a message.
Before you create an account, our sign-up page may show a small number of recent members’ profile photos as social proof. These are shown without names.
You can request that your profile be hidden from the directory by contacting us, though this may limit your ability to participate in the community.
6.3 Meetup Hosts
When you RSVP to a meetup, the host can see your name and profile photo and, for paid meetups, whether your seat is confirmed or refunded. Hosts do not receive your payment details, email address, or phone number from us.
6.4 Legal and Safety Disclosures
We may disclose your personal data if we are required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation, court order, or regulatory request.
- Protect the rights, safety, or property of Onfound, our members, or the public.
- Investigate or prevent fraud, security incidents, or violations of our Terms or Community Guidelines.
- Respond to an emergency involving potential harm to any person.
6.5 Business Transfers
If Onfound is involved in a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and ensure the receiving party is bound by obligations consistent with this Privacy Policy.
7 International Data Transfers
Onfound is based in the United States. If you are located in the United Kingdom, European Economic Area, South Africa, Thailand, or any other jurisdiction with data protection laws that restrict international data transfers, your personal data will be transferred to and processed in the United States and potentially other countries where our service providers operate. Our product analytics provider (PostHog) stores its data in the European Union.
We ensure that international transfers of personal data are protected by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the UK Information Commissioner’s Office (ICO), incorporated into our agreements with service providers.
- Adequacy decisions, where the European Commission or UK government has determined that a country provides an adequate level of data protection.
- Other lawful transfer mechanisms as recognised under applicable law.
Under Section 72 of POPIA, cross-border transfers are permitted where the recipient is subject to laws or binding agreements that provide an adequate level of protection, or where you have consented to the transfer. Our agreements with service providers include data protection obligations substantially similar to those required by POPIA.
Under Sections 28 and 29 of the Personal Data Protection Act B.E. 2562 (2019), cross-border transfers of personal data are permitted where the recipient country has adequate protection, or where the transfer is necessary for the performance of a contract with you, your consent has been obtained, or appropriate safeguards (such as contractual data protection clauses substantially similar to Standard Contractual Clauses) are in place. Our agreements with service providers include such safeguards.
8 Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and profile data (including your profile photo, profile embedding, AutoPilot goal, and stored search requests) | Duration of membership. Deleted when you delete your account. | Providing the Services |
| Content you posted into shared spaces (direct messages, group chat messages, community posts and comments, meetups you hosted, communities you created) | Remains after account deletion, no longer linked to you or your name | Keeping other members’ conversations and communities intact |
| Financial and billing data | 7 years after the transaction | Tax, accounting, and legal compliance obligations |
| Communication data (support requests, feedback) | 3 years after last interaction | Service quality improvement and recurring issue resolution |
| Product analytics data (web only) | Up to 26 months | Service improvement and trend analysis |
| Moderation and safety records (excerpts of flagged content, classifier scores, reports filed about you, admin decisions) | Duration of membership plus 12 months. Reports filed about a member may be kept, anonymised, after that member deletes their account. | Audit trail, appeals review, preventing a reported member from erasing their history by deleting and re-registering |
| Marketing consent records | Duration of membership plus 3 years | Demonstrate compliance with consent requirements |
| Data held by AI providers | Anthropic retains inputs briefly for safety monitoring. OpenAI may retain inputs for up to 30 days for abuse monitoring, then deletes them. Neither uses member data to train its models. | Provider abuse and safety monitoring |
After the applicable retention period, we will securely delete or anonymise your personal data so that it can no longer be associated with you.
9 Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it, including:
- Encryption of data in transit using TLS/SSL and encryption at rest for stored data.
- Secure authentication mechanisms, including hashed and salted passwords.
- Access controls limiting who within Onfound can access personal data, on a need-to-know basis.
- Regular security reviews and monitoring of our infrastructure.
- PCI-DSS compliant payment processing through Stripe (Onfound never stores full card details).
- Incident response procedures to detect, investigate, and respond to data breaches.
While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.
10 Your Rights and Deleting Your Account
Depending on where you are located, you have certain rights regarding your personal data. We are committed to helping you exercise these rights.
If you are located in the United Kingdom or European Economic Area, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request that we correct inaccurate or incomplete data.
- Right to erasure: Request that we delete your personal data (“right to be forgotten”), subject to certain legal exceptions.
- Right to restrict processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Request a copy of your data in a structured, machine-readable format and have it transferred to another controller.
- Right to object: Object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Rights related to automated decisions: Ask for human review of an automated decision that affects you (see Section 13).
- Right to lodge a complaint: Complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or your local supervisory authority.
If you are located in South Africa, you have the following rights under the Protection of Personal Information Act 4 of 2013:
- Right to be notified: Be informed when your personal information is being collected and the purpose of the collection.
- Right of access: Request confirmation of whether we hold personal information about you, and request access to that information.
- Right to correction: Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
- Right to deletion: Request destruction or deletion of personal information that we are no longer authorised to retain.
- Right to object: Object to the processing of your personal information on reasonable grounds, and object to receiving direct marketing.
- Right to submit a complaint: Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
If you are located in Thailand, you have the following rights under the Personal Data Protection Act B.E. 2562 (2019):
- Right of access: Request access to, and a copy of, the personal data we hold about you, and to be informed of how that data was obtained without your consent.
- Right to data portability: Request that your personal data be sent to another data controller in a readable format, where technically feasible.
- Right to object: Object to the processing of your personal data in certain circumstances, including for direct marketing.
- Right to erasure or anonymisation: Request that we delete, destroy, or anonymise your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful.
- Right to restrict processing: Request that we restrict use of your personal data in certain circumstances.
- Right to rectification: Request that we correct personal data that is inaccurate, out of date, incomplete, or misleading.
- Right to withdraw consent: Withdraw any consent you have previously given, at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: Submit a complaint to the Office of the Personal Data Protection Committee (PDPC) at pdpc.or.th.
Deleting Your Account
You can delete your Onfound account yourself, at any time, from inside the app: open Settings › Danger Zone › Delete account and confirm with your password. Deletion takes effect immediately.
We delete your account and your personal information. Content you posted into shared spaces (messages, community posts and comments) remains, but is no longer linked to you or your name. Where that content is shown, it appears as posted by a member who has left Onfound.
Deleting your account also: cancels any active subscription immediately, without a refund for the remaining part of the billing period; cancels any meetups you are hosting and notifies attendees; refunds any paid meetup seats you hold where a refund is due; removes your profile photo; and removes you from our marketing list. Some records are kept for the periods set out in Section 8 (Data Retention) where required for legal, financial, or safety reasons.
If you cannot access your account, email support@onfound.com from the address on the account and we will delete it for you.
How to Exercise Your Other Rights
To exercise any of these rights, please contact us at support@onfound.com with the subject line “Data Rights Request.” We may ask you to verify your identity before processing your request.
We will respond to your request within:
- 30 days for requests under UK GDPR / EU GDPR (extendable by a further 60 days for complex requests, with notice).
- A reasonable period for requests under POPIA and PDPA (generally within 30 days).
We will not charge a fee for most requests. However, we may charge a reasonable administrative fee if your request is manifestly unfounded, excessive, or repetitive, or we may refuse to act on the request in such cases.
11 Children’s Privacy
Onfound is not directed at individuals under the age of 18. We ask for your date of birth at sign-up and do not create accounts for anyone under 18. We do not knowingly collect personal data from anyone under 18 years of age. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@onfound.com and we will take steps to delete that information promptly.
12 Marketing and Communications
12.1 Marketing Consent
We will only send you marketing communications (such as newsletters, promotional offers, and community content) where you have given us your explicit consent or where we are permitted to do so under applicable law.
We rely on your opt-in consent for electronic marketing communications, in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and ePrivacy rules.
We rely on your opt-in consent for direct marketing, in accordance with Section 69 of POPIA and the Consumer Protection Act.
We rely on your opt-in consent for direct marketing communications, in accordance with the Personal Data Protection Act B.E. 2562 (2019). You may withdraw consent at any time.
12.2 Opting Out
You can opt out of marketing communications at any time by:
- Clicking the “Unsubscribe” link in any marketing email.
- Contacting us at support@onfound.com.
Opting out of marketing does not affect transactional communications necessary for the operation of your account (such as billing receipts, message and meetup notifications, and service updates).
13 AI Features, Automated Moderation, and Automated Decisions
13.1 Onfound Intelligence and AutoPilot
Onfound offers two AI-assisted features. Onfound Intelligence is a member search: you describe who you are looking for, and it suggests relevant members with a short reason for each. AutoPilot is optional: if you turn it on and set a goal, it delivers a small set of suggested people and meetups each week based on that goal. Both read your request or goal together with the community profile information of potentially relevant members, and both are powered by the AI providers listed in Section 6.1.
Suggestions are informational only. You can always browse the full directory and every meetup without using these features. The data involved is never used to train the providers’ models. Your search requests and AutoPilot goal are also stored on Onfound’s own systems, linked to your account, so we can improve the features and understand what members are looking for; they are visible only to Onfound administrators and are deleted with your account.
This suggestion process constitutes profiling under GDPR but does not produce legal effects or similarly significant effects on you. It helps you discover potentially relevant members and meetups; it does not make decisions about you.
13.2 Automated Content Screening
To keep the community safe, content is screened automatically before it is published. This applies to profile text and photos, meetup descriptions and images, and community posts, comments, replies, and images. Direct messages and group chats are not screened automatically, but any message can be reported by a member and reviewed by a person. The screening uses a third-party classification service (OpenAI, see Section 6.1) to detect content such as harassment, hate, sexual content, or violence.
If the screening flags your content, it may be blocked from publishing, and your profile may be placed in a review queue for an Onfound team member to look at. Members can also report content, and those reports are reviewed by a person.
13.3 Other Automated Decisions
We do not use automated decision-making for any purpose that produces legal effects or similarly significant effects on you (such as credit decisions, employment, or access to essential services). You have the right to request information about the logic involved in the suggestion and screening processes and to object to automated decision-making. To do so, please contact us at support@onfound.com.
14 Do Not Track Signals
Some browsers transmit “Do Not Track” (DNT) signals. There is currently no industry standard for how to respond to DNT signals. Our website does not currently respond to DNT signals, but you can manage tracking preferences through your browser settings and cookie choices as described in Section 5.
15 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.
If we make material changes, we will notify you by:
- Sending an email to the address associated with your account.
- Displaying a prominent notice within the platform or app.
- Updating the “Last Updated” date at the top of this policy.
We will provide at least 14 days’ notice before material changes take effect, except where changes are required by law. Your continued use of the Services after the updated policy takes effect constitutes your acceptance of the changes. If you do not agree, you should stop using the Services and delete your account from within the app (Settings › Danger Zone › Delete account).
16 Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your personal data, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority: