1. Scope
This Privacy Policy applies to Nommad public pages, account workspaces, forms, requests, events, reviews, vendor tools, QR experiences, support interactions, and related services that link to this Policy. Third-party services have their own privacy practices.
2. Legal operator
Nommad is a product and service offering of OneTap LLC. OneTap LLC is responsible for the Nommad practices described in this Policy. Privacy questions may be sent to office@wherefoodroams.com.
3. Information you provide
We may collect information you submit through forms, account settings, uploads, requests, reviews, messages, support contacts, data requests, organization tools, and other Nommad features. The information collected depends on the feature and your role.
4. Account information
Account information may include name, email address, password hash, role, preferences, notification choices, authentication and recovery records, session and device information, and account status. Passwords are not stored in plain text.
5. Vendor information
Vendor information may include business identity, owner and staff contact information, service areas, food type, public phone or email, social links, profile details, schedules, locations, menus, photos, FAQs, reviews and replies, request responses, booking settings, analytics, QR records, and operational records.
6. Host, Organizer, and organization information
Host & Organizer and organization information may include identity and contact details, organization name, members, roles, invitations, saved locations, events, recurring activity, requests, vendor selections, notes, and audit history.
7. Customer requests and reviews
Customer records may include saved or followed content, recently viewed items, contact details, event or gathering dates and times, guest count, location, preferences, request notes, vendor responses and selections, review ratings, comments, status, and moderation history.
8. Location information
Location information may be provided directly, selected through a browser location feature, associated with a Vendor schedule or public status, saved privately to an account, or submitted for an event or Spot. Public Vendor location or status may be displayed when intentionally published. Private saved locations and notes are limited to authorized contexts.
9. Uploaded files and media
Nommad may receive logos, photographs, menu artwork, documents, and other files. Files may be associated with a Vendor and an intended purpose, reviewed or moderated, stored outside the public document root where configured, and published only when their state and purpose allow it.
10. Menu, profile, and event content
Approved and visible profile, menu, event, Spot, location, FAQ, review, and related content may be public. Pending, hidden, rejected, private, or administrative content is not intended for public publication.
11. Usage, search, and analytics information
We may record searches, filters, page and feature activity, route or action events, approximate technical information, QR or scan summaries, errors, and operational diagnostics to provide, secure, understand, and improve Nommad. Optional GA4 or Mixpanel integrations are configuration-controlled and are intended to respect analytics consent when required.
12. QR and TAP information
Nommad may integrate with TAP Connected Sites, QR, scan, and related services. Records may include Nommad resource references, public scan destinations, provider identifiers, scan counts, timestamps, status, and synchronization history. Server credentials and provider secrets are not public data.
13. Billing status and administrative records
Nommad may store subscription or billing eligibility and administrative billing records, including status, dates, notes or references, actor, target, and audit information. The current manual or offline billing process does not require Nommad to store card or bank information. If third-party payment processing is enabled later, that provider's terms and privacy practices may also apply.
14. Support and contact records
We may retain communications, issue reports, support requests, privacy requests, verification information, and records of how a request was handled.
15. Authentication, security, and audit records
We may collect authentication events, session and device records, MFA and recovery state, CSRF and request identifiers, administrative actions, moderation history, security events, access decisions, error references, and audit records. Sensitive credentials and recovery values are handled as private security material.
16. Cookies and browser technology
Nommad uses necessary cookies or browser storage for sessions, security, login, CSRF protection, and core operation. Preference, analytics, and marketing categories are described in the Cookie Policy. Optional analytics and marketing technology is used only when configured and subject to applicable consent choices.
17. Sources of information
Information may come from you, another authorized member of your organization or Vendor, public business information, an administrator acting within an authorized workflow, your browser or device, application activity, service providers, TAP or QR integrations, or other users interacting with Nommad.
18. How information is used
We use information to provide and maintain Nommad; authenticate users; manage accounts and workspaces; publish approved content; process requests and reviews; support customers, Vendors, and Hosts; provide QR and integration features; communicate about the service; enforce agreements; moderate content; detect and prevent abuse or fraud; protect security; maintain audit and history integrity; diagnose errors; improve Nommad; and comply with legal obligations.
19. Public and private information
Information submitted to public profile, menu, event, Spot, review, reply, status, or location fields may be publicly displayed after applicable publication or moderation steps. Account credentials, exact private request or location details, administrative notes, provider credentials, private file paths, and internal diagnostics are not intended for public disclosure. Review a field's purpose before submitting sensitive information.
20. Service providers and integrations
We may use providers for hosting, databases, storage, maps, email, analytics, monitoring, QR, TAP, authentication, support, and other service functions. Providers may receive information reasonably needed to perform their services and are governed by their own terms and privacy practices. A provider listed in configuration is not necessarily active.
21. Legal and safety disclosures
We may preserve, use, or disclose information when reasonably necessary to comply with law or legal process; protect rights, safety, security, or property; investigate abuse, fraud, or security incidents; enforce agreements; respond to lawful requests; or support a merger, financing, acquisition, reorganization, or transfer of relevant business assets, subject to applicable law.
22. Data retention
OneTap LLC may retain information for as long as reasonably necessary to provide and maintain Nommad; maintain accounts and business records; fulfill requests and transactions; provide support; protect security; prevent abuse and fraud; preserve audit and history integrity; support backup and disaster recovery; resolve disputes; enforce agreements; protect legal rights; satisfy tax or accounting needs; and comply with legal obligations. Some billing, accounting, security, audit, dispute, fraud, abuse, backup, and legal-claim records may remain after account deletion where reasonably necessary or legally permitted. Backups may persist until normal rotation or replacement. De-identified or aggregated information may be kept for longer periods, including indefinitely where lawful and it no longer reasonably identifies a person.
23. Security
OneTap LLC uses administrative, technical, and organizational safeguards intended to protect information, including role and workspace checks, server-side sessions, CSRF protections, password hashing, access controls, and audit records. No system or transmission method is completely secure, and we cannot guarantee absolute security.
24. Privacy requests and choices
Depending on where you live, applicable law may give you rights regarding your personal information, which may include access, correction, deletion, portability, restriction, or objection or opt-out rights. Submit a request through the Data Request page. OneTap LLC will verify and evaluate requests under applicable law. A deletion request does not require deletion of information that may lawfully be retained for the purposes described above.
25. Location choices
You may decline browser location access and search by city or area instead. Account users can limit location information they choose to provide, subject to information needed for a requested feature. Vendors control whether applicable public location or status information is published through authorized tools.
26. Marketing and analytics choices
Use Nommad cookie controls and browser settings to manage optional analytics or marketing technology when available. Marketing cookies are disabled by default unless later configured. Transactional or service communications may still be needed for account, security, request, or support functions, subject to configuration and applicable law.
27. Age and children
A person must be at least 18 years old to create or manage a Nommad account. Nommad does not knowingly permit children to create accounts. Public pages may be visible without an account. A parent or guardian who believes a minor improperly provided account or personal information may use the Data Request process or contact office@wherefoodroams.com.
28. Changes to this Policy
OneTap LLC may update this Policy to reflect changes in Nommad, law, providers, or business practices. The current version will be posted with its effective date, and additional notice will be provided when required by law.
29. Contact information
Privacy, legal, and general questions: office@wherefoodroams.com. Ordinary account help: support@wherefoodroams.com. The Data Request page is the primary in-product request path. For notices or requests that must be delivered by mail, contact office@wherefoodroams.com for current mailing instructions. This email instruction does not replace formal service of process where applicable.