PRIVACY & DATA
Privacy Policy
Locale ("we", "us", "our") operates the Locale platform, a service for connecting people through curated social dinners in their city. This policy explains what personal data we collect, how we use it, and what rights you have over it.
Effective date: May 2025
Data We Collect
We collect the following categories of personal data:
Account data
Name and email address, collected when you create an account. Your email is used to authenticate you via one-time code (OTP).
Profile data
Date of birth (birthday) is required: we collect it to verify you are at least 18 years old, which is a condition of using Locale. We process it on the basis of contractual necessity — we cannot provide the service to under-18s. Profession and country are optional and help us form compatible dinner groups and enable group stats reveals after events.
Preference data
Preferred city, spoken languages, dietary restrictions (e.g. vegetarian, vegan, halal), food allergies, allergy notes, and budget tier. This data is used to match you with suitable events and to inform hosts of dietary needs.
Billing data
Stripe customer ID and subscription status. We do not store full payment card details — these are held by Stripe. We retain records of subscription activation dates and billing history for accounting purposes.
Technical / session data
IP address and user-agent string, stored as part of your session record when you sign in. This data is used for security purposes (detecting unauthorised access) and expires when your session ends.
Participation data
Records of events you have joined or cancelled, participation status, and any strikes recorded against your account.
Referral data
If you share a referral link or sign up through one, we store the social graph of who referred whom. Specifically: your unique referral code, the user ID of the person who referred you (if any), and per-referral records including status, relevant Stripe object identifiers, and timestamps. This data is used to operate the referral reward program and to detect fraud. Referral relationships are never shared with third parties for marketing purposes.
Blind Date data
If you choose to apply for a Blind Date event, we collect: your gender, your partner gender preference, an age range, whether you are open to a partner slightly outside that range, a stated intent, a short free-text answer describing your ideal evening, and your interests and hobbies (chosen from a list, or added as free text). Because partner gender preference can reveal sexual orientation, we treat this data as a special category under the Swiss Federal Act on Data Protection and, where applicable, GDPR Article 9. We collect it only on the basis of your explicit, opt-in consent, given before any of these fields are shown or saved. This data is stored separately from your regular preferences, is used solely for hand-matching Blind Date participants, and is visible only to Locale staff performing that matching — never to the person you may be matched with, before or after the event. You can withdraw consent at any time in Account settings; withdrawal permanently deletes your answers (a minimal audit record of the consent itself is retained) and pauses future Blind Date applications until you apply again. We also verify your identity before you can join a Blind Date event — see Stripe Identity below.
How We Use Your Data
- Event matching and grouping: Profession, country, languages, dietary preferences, and budget tier are used to form compatible dinner groups.
- Authentication: Email is used to send one-time sign-in codes.
- Billing and subscription management: We use your billing data to manage your subscription, process payments, and send billing notifications (e.g. upcoming renewal, payment failed).
- Service communications: We may send transactional emails about your events, account status, or policy changes. We do not send marketing emails without your consent.
- Safety and moderation: Session data (IP, user agent) and participation records (strikes) are used to detect abuse and enforce our Terms of Service.
Third-Party Data Processors
We share your data with the following third parties solely to provide the service:
Stripe, Inc. — payment processing
Stripe processes subscription payments and stores your payment method. Stripe acts as a data controller for payment data under their own privacy policy. See stripe.com/privacy.
Stripe Identity — identity verification
If you apply to join a Blind Date event, Stripe verifies your identity using a government-issued document and a selfie match, via its Stripe Identity product. Your document image and biometric selfie data are processed and retained by Stripe, not by Locale — we store only the verification status (verified, pending, or failed) and a reference to the Stripe session. Stripe acts as a data processor for this check under their own privacy policy. See stripe.com/privacy.
SMTP provider — transactional email
We use an SMTP service to deliver sign-in codes and billing notifications. Your email address is transmitted to this provider only for the purpose of email delivery.
Database host — data storage
Your personal data is stored in a PostgreSQL database hosted on a cloud infrastructure provider. Data is encrypted at rest and in transit.
Meta Platforms, Inc. — advertising measurement
When you give your consent, we send conversion events to Meta using the Meta Conversions API. This allows us to measure the effectiveness of our advertising campaigns on Facebook and Instagram. The following data is shared with Meta:
- Your email address, irreversibly hashed with SHA-256 before transmission (we never send it in plain text).
- A hashed user identifier (SHA-256 of your internal Locale user ID).
- Browser identifiers: the
_fbcand_fbpcookies set by the Meta Pixel, where present. - Conversion events: account creation and subscription purchase.
Purpose:Advertising optimisation — to help Meta's algorithm identify users similar to Locale subscribers.
Retention:Hashed identifiers are transmitted in real time and not stored by Locale beyond your account lifetime. Meta's own retention policy applies to data held on their servers; see Meta's Privacy Policy.
Opt-out: You can withdraw your tracking consent at any time on this page. For the server-side conversion events (account creation, subscription), data sharing is based on our legitimate interest in measuring our advertising return. To request exclusion, email [email protected].
We do not sell your personal data to third parties.
Data Retention
- Account and profile data is retained for as long as your account exists. On deletion request, we remove your personal data within 30 days, except where retention is required by law.
- Session data (IP address, user agent) is purged automatically when a session expires.
- Billing recordsare retained in accordance with Stripe's data retention policy and applicable financial record-keeping requirements, typically 7 years.
Your Rights & Choices
GDPR (EU / EEA residents)
Under the General Data Protection Regulation you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Deleteyour personal data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
CCPA (California residents)
Locale does not sell personal information as defined under the California Consumer Privacy Act. You have the right to know what personal data we collect, to request deletion of your data, and to non-discrimination for exercising your rights. Contact [email protected] to submit a request.
Changes to This Policy
We may update this policy from time to time. We will notify you by email of material changes. Continued use of Locale after the effective date constitutes your acceptance of the updated policy.