Privacy Policy
Last updated: July 2026
This Privacy Policy explains how Nomad Life ("we", "us") collects, uses and protects your personal data. We comply with the EU General Data Protection Regulation (GDPR) and Swedish data-protection law.
1. Data controller
Nomad Life is the data controller for personal data collected through this platform. For any privacy question, please contact support.
2. What we collect
- Account data: email, password (hashed with bcrypt), legal name, signup date.
- Profile data: citizenship, current location, reason for joining, optional goals, interests, bio, profile photo (if you upload one).
- Government ID photo: during onboarding you upload a passport, national ID or driver's licence. See section 3 for full details.
- Community content: forum threads and replies, ads you post, newsletter inclusions you submit, direct messages.
- Payment metadata: processed by Stripe — we receive customer ID, subscription status, and invoice metadata. We never receive card numbers.
- Technical data: IP address, browser, basic usage logs needed to deliver the service and prevent abuse.
- Analytics data: anonymised pageview and event data via Google Analytics 4 (see section 5). Only fires after you accept analytics cookies.
3. Government ID verification
Nomad Life is a real-name community — accounts are registered under members' legal names, not aliases. To keep the community safe and to prevent impersonation, every new member must upload a photo of a government-issued ID (passport, national ID card or driver's licence) during onboarding.
How it works: the file is sent over HTTPS to our servers, reviewed by a human administrator, and used only to confirm that the name on the ID matches the legal name on the account. The ID is deleted from our servers as soon as the review is complete. It is never shared with other members or third parties.
Legal basis: legitimate interest (protecting members from impersonation and fraud) and contract (real-name membership is a condition of the service).
4. Why we process it
| Purpose | Legal basis |
|---|---|
| Account creation, login, providing the platform | Contract |
| ID verification (real-name check) | Legitimate interest + contract |
| Subscriptions, payments, invoices | Contract + legal obligation |
| Direct messaging between members | Contract |
| Monthly newsletter dispatch (opt-out available) | Contract (members) / consent (open subscribers) |
| Website analytics (visitor traffic measurement) | Consent (cookie banner) |
| Security, abuse prevention | Legitimate interest |
5. Who we share it with
- Stripe (Ireland / USA) — subscription billing and payment processing.
- Sender.net (Lithuania, EU) — transactional email (password resets, account notifications) and delivery of the monthly newsletter. Newsletter dispatch is opt-out — every member can turn it off at any time from Profile → Communication preferences, or via the unsubscribe link at the bottom of each newsletter.
- Google Analytics 4 (Google Ireland Ltd.) — used solely to measure visitor traffic and understand which pages are most useful. IP addresses are truncated and no advertising cookies are set. Only loads after you accept analytics cookies on the banner.
- Emergent Cloud — our hosting infrastructure provider. Application data and encrypted media are stored on their servers with encryption at rest.
We never sell or rent your personal data. International transfers (Stripe, Google) rely on the EU Standard Contractual Clauses.
6. Cookies & local storage
We use a small set of strictly-necessary cookies for authentication (httpOnly session tokens) and a Stripe checkout state cookie. These do not require consent because the service cannot function without them.
Optional analytics cookies (Google Analytics 4) are only set after you click "Accept analytics" on the cookie banner. You can revisit your choice at any time by clearing the nl_cookie_consent value from your browser storage. Full detail lives on the Cookie Notice.
Offline data on your device (PWA): when installed as a Progressive Web App or added to your home screen, Nomad Life registers a service worker that caches static assets (logo, fonts, offline fallback page) inside your browser so the app opens quickly and shows a friendly message when you're offline. No personal data is stored in that cache — only public files. Uninstalling the app or clearing site data removes the cache entirely.
7. Push notifications
We do not use push notifications. The installed app will never send notifications to your phone or desktop, and we do not request notification permission from your device.
8. How long we keep it
- Account & profile data: as long as your account is active, plus up to 24 months for legal records.
- Government ID image: deleted immediately after the admin completes verification (typically within 48 hours of upload).
- Payment records: 7 years (Swedish bookkeeping law). User identity is anonymised on these rows if the account is deleted.
- Direct messages: retained while at least one participant has an active account.
- Server logs: 12 months.
- Analytics data: retained in Google Analytics for 14 months (default).
9. Deleting your account or individual data
Delete individual pieces of data (without closing your account): most content you have added is self-service editable from your own profile — you can remove your profile photo, clear optional fields (bio, goals, interests, current location), untag interests, and delete individual forum posts, ads and direct messages you have authored. This lets you shrink the personal data we hold about you while keeping your membership active.
Delete your entire account: from Contact support → Danger zone → Delete my account, or the same section at the bottom of your Profile page. Deletion is confirmed with your current password and takes effect immediately: your user record, profile, forum posts, ads, direct messages and newsletter inclusions are permanently erased. Payment audit rows are retained (in anonymised form) to satisfy Swedish bookkeeping law.
Prefer a manual review before deletion, or need help exporting your data first? Contact support and we will respond within 30 days.
10. Your rights (GDPR)
You may request access, correction, erasure (see section 9), restriction or objection to processing, and data portability. You may withdraw consent at any time without affecting prior lawful processing. You may also lodge a complaint with the Swedish data-protection authority (Integritetsskyddsmyndigheten — IMY).
To exercise any right, please contact support. We respond within 30 days.
11. Security
Encrypted transport (HTTPS), bcrypt password hashing, httpOnly session cookies, role-based access controls, and basic event logging. Uploaded IDs and profile photos are stored with encryption at rest.
12. Children
The Platform is not directed at children under 18. We do not knowingly collect personal data from minors.
13. Changes
Material changes will be notified in-app or by email at least 14 days in advance.