Nocturne Finder

Privacy Policy

Nocturne Finder Operated by Experts SEA (experts-sea.com)

Effective date: 26 May 2026 Last updated: 16 September 2026


1. Who we are

This Privacy Policy describes how Experts SEA ("we", "us", "our") collects, uses, and shares your personal data when you use Nocturne Finder, our nightlife and place discovery platform (the "Service"). We act as the data controller for the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 ("GDPR").

If you have questions about this policy or wish to exercise your rights, contact us at info@nocturnefinder.com.

2. Scope

This policy applies to personal data we process when you:

It does not cover third-party websites or services linked from the Service. Their own privacy policies apply.

3. Personal data we collect

We collect personal data in the following ways:

3.1 Data you provide when creating an account

When you register or update your profile, we collect:

3.2 Data generated when you use the Service

3.3 Data from third parties

3.4 Guests (no account)

If you use the Service without an account, we generate an ad session identifier stored in your browser to apply frequency caps and prevent abuse. We also process the IP address you connect from to apply rate limits. Place search requires an account, so its daily quota is counted against your account rather than against a browser identifier.

3.5 Device permissions, and data that stays on your device

The mobile app asks for a small number of operating-system permissions. Each one is requested only at the moment you tap the feature that needs it, and each can be withdrawn at any time in your device settings. Granting a permission is not the same as giving us the data behind it:

4. Legal bases for processing (GDPR Article 6)

We process your personal data on the following legal bases:

PurposeLegal basis
Creating and maintaining your account; providing the core Service; processing payments and Ad Wallet transactionsPerformance of a contract with you (Art. 6(1)(b))
Sending transactional emails (verification codes, password resets, billing receipts, service notices)Performance of a contract (Art. 6(1)(b))
Preventing fraud, abuse, scraping, and unauthorised access; enforcing rate limits and security; debugging and improving the Service; analytics in aggregated formLegitimate interests (Art. 6(1)(f)) — namely, securing the Service and improving its quality
Sending optional marketing communicationsConsent (Art. 6(1)(a)) — you can withdraw consent at any time
Cookies and similar technologies that are not strictly necessaryConsent (Art. 6(1)(a))
Complying with legal obligations (tax, accounting, lawful requests from authorities)Legal obligation (Art. 6(1)(c))
Defending or asserting legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing assessment to ensure your rights and freedoms are not overridden. You may object to such processing as described in Section 9.

5. How we use your data

We use your personal data to:

We do not carry out automated decision-making producing legal or similarly significant effects on you within the meaning of Article 22 GDPR.

6. Who we share your data with

We share personal data only as described below. We do not sell your personal data.

6.1 Service providers (processors)

We rely on the following categories of processors, who act on our behalf under written contracts that include the safeguards required by Article 28 GDPR:

ProcessorPurposeData categories
StripePayment processing for Ad Wallet top-ups and premium subscriptionsName, email, payment card data (collected directly by Stripe), transaction metadata
Google (OAuth, Maps / Places API)Sign-in with Google; place data; geocodingGoogle account identifier, profile basics, search queries containing location text
Resend and our SMTP relay providerSending transactional emails (verification, notifications, receipts)Email address, message content
Cloud hosting and infrastructureHosting the Service, databases, and backupsAll categories described in Section 3
Redis cache providerRate-limit counters, session/cache storageHashed IP, account identifiers, session identifiers

6.2 Other recipients

6.3 Public information

Information you choose to make public — for example, a business profile or a claimed-place listing — is visible to other users of the Service.

7. Cookies and similar technologies

We use a small number of cookies and similar identifiers:

Cookie / identifierPurposeType
Session / authentication cookies and access tokensKeeping you signed inStrictly necessary
Ad session ID (browser session storage)Frequency capping for advertisingStrictly necessary
Rate-limit counters (server-side, keyed on hashed IP and, for signed-in requests, your account identifier)Preventing abuse and scrapingStrictly necessary
Optional analytics or marketing cookies (if enabled)Measuring usage and (where applicable) marketingOnly set with your consent

Strictly necessary cookies do not require consent under the EU ePrivacy Directive because they are essential for the Service to function. Any non-essential cookies are set only after you give consent through our cookie banner, and you can withdraw consent at any time via the cookie settings link in the Service footer.

8. International transfers

The Service is operated for users in the European Union and beyond. Some of our processors and data sources (notably Google, Meta, and Stripe) may process personal data outside the European Economic Area, including in the United States. Where this is the case, we rely on appropriate safeguards under Articles 45–46 GDPR, in particular:

You may obtain a copy of the safeguards in place for a specific transfer by contacting info@nocturnefinder.com.

9. Your rights under the GDPR

If your personal data is processed by us, you have the following rights:

To exercise any of these rights, email info@nocturnefinder.com. We will respond within one (1) month, extendable by a further two months for complex requests, in accordance with Article 12 GDPR. We may need to verify your identity before acting on your request.

9.1 Deleting your account and your data

You can delete your account yourself, at any time, without contacting us:

  1. Sign in on the web app or the mobile app;
  2. Open Settings → Manage account (on the web, the Danger zone section of Settings);
  3. Choose Delete account and type your username to confirm.

This permanently deletes your account and the personal data attached to it — profile details, avatar, search and place-interaction history, events, saved places, messages, and any social connections. Communities you own are handed over to their longest-serving remaining admin (or member) so that other members do not lose their content; a community with no other active members is deleted with your account.

This is also how you delete data we received from Facebook Login: deleting your account removes the email address and username that originated from your Facebook profile. We hold no Facebook access token and no Facebook user ID to delete. You can additionally remove our app's access from Facebook → Settings & privacy → Settings → Apps and websites.

Two exceptions survive account deletion, because the law requires it: payment and ticketing records needed for tax and accounting purposes, and security logs containing hashed (non-reversible) IP addresses. Retention periods for both are in Section 10. Backups are overwritten on their normal rotation.

If you cannot sign in, email info@nocturnefinder.com from the address on the account and we will delete it for you within one (1) month.

You also have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or where you believe an infringement has occurred. A list of EU data protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

10. Data retention

We retain personal data only for as long as necessary for the purposes set out in this policy or as required by law:

Data categoryRetention period
Account data (profile, credentials)Until your account is deleted, plus a short technical buffer for backups
Search events and place-interaction logsUp to 24 months from creation, or earlier upon valid request
Hashed IP addresses in security/rate-limit logsUp to 24 months
Payment and Ad Wallet transaction recordsAs required by applicable tax/accounting law (typically up to 10 years in the EU)
Email correspondenceUp to 36 months from last interaction
CookiesPer the lifetime declared in the cookie banner

After the retention period, we delete or anonymise the data. Aggregated, non-identifying analytics may be kept indefinitely.

11. Security

We implement appropriate technical and organisational measures designed to protect your personal data, including:

No system is perfectly secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required, notify affected users without undue delay, in accordance with Articles 33–34 GDPR.

12. Children

The Service is not directed to children under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, please contact info@nocturnefinder.com so we can delete the data and close the account.

13. Third-party services

The Service displays content and integrates services from third parties (such as Google Maps and Stripe). When you interact with those features, the third party may collect personal data directly. Their own privacy policies govern that processing. We encourage you to review them:

14. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will indicate the most recent revision. For material changes, we will provide notice in the Service or by email before the change takes effect. Please review this Policy periodically.

15. Contact and Data Protection Officer

You can reach our privacy team at any time:

If we appoint a Data Protection Officer ("DPO") in accordance with Article 37 GDPR, we will update this section with the DPO's contact details. Until then, all privacy queries should be sent to info@nocturnefinder.com.