Legal
Privacy and personal-data notice
Preamble and scope
This privacy notice (the “Notice”) is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree 196/2003 as amended, and applicable ePrivacy rules, including the Italian Data Protection Authority’s guidance on cookies and other tracking technologies.
It governs processing in connection with: (i) the Nomad mobile application for iOS and Android (the “App”); (ii) the institutional website nomadtravel.guru and its pages, including this Notice and the Terms of Service (the “Site”); and (iii) cloud sync, authentication, notifications, and support (together, the “Service”).
The Notice applies when you create an account, sign in with email or third-party identity providers (Apple, Google), sync content with Nomad Cloud, browse the Site, or otherwise interact with the Service.
The current text is always the version published at https://nomadtravel.guru/en/privacy/ and, in the App, the text bound to the calendar version shown in the notice. The Terms of Service, which govern contractual use of the Service, are available at https://nomadtravel.guru/en/terms/. If this Notice and the Terms conflict on personal-data processing, this Notice prevails.
Controller
The controller is the operator of the Nomad Service, identified to users as Stackhouse, which operates the App and the Site nomadtravel.guru (the “Controller”).
To exercise your rights or raise any processing question, contact the Controller through the channels published on the Site and, where available, in the App, stating the email address linked to the account.
If the Controller appoints a data protection officer under Article 37 GDPR, the DPO’s details will be published on the Site and in this Notice without undue delay.
Categories of data processed
Depending on the features you choose to use, the Controller processes the following categories:
(a) Account data: email address, display name, linked sign-in method, email verification date, technical session identifiers, and refresh tokens.
(b) Trip content you or expressly invited companions enter: titles, dates, places, notes, checklists, expenses, attachment metadata, and visibility settings. Attachment files remain on-device except for local-network transfer between companions; the cloud stores metadata and, where applicable, references, not binary content for advertising.
(c) Technical operations data: operating system, App version, language, device time zone, sync identifiers, anonymised or pseudonymised error logs, and information strictly required for security (abuse prevention, rate limiting).
(d) Location data: coordinates and addresses only when you voluntarily save them on a place or activity. We do not track background location for marketing or profiling.
(e) Product telemetry (only if configured — see the dedicated section): a random install identifier, screens viewed, feature-use events, and platform (iOS/Android/web). These data do not include trip content, email addresses, names, GPS coordinates, advertising identifiers (IDFA/AAID), or the Nomad account User-ID.
The Controller does not intentionally process special categories of data (Article 9 GDPR). You must not enter health, political, religious, or other Article 9 data into the Service except under your own exclusive responsibility.
Purposes of processing
Data are processed for the following purposes, lawfully, fairly, and transparently:
(i) providing the Service: account creation and management, authentication, trip organisation, multi-device sync, companion invites, .nomad backup, service notifications, and sync conflict resolution;
(ii) security and integrity: abuse prevention, infrastructure protection, fault diagnosis, and aggregated or pseudonymised client-error handling;
(iii) legal obligations and establishment, exercise, or defence of legal claims;
(iv) internal first-party statistical analysis in aggregated form not attributable to the individual, for service quality and product planning (see “First-party internal statistics”);
(v) product telemetry via Google Analytics 4, where the Controller has enabled that tool, within the limits and safeguards in the dedicated section;
(vi) communications strictly necessary to perform the contract (email verification, password reset, trip invites). Direct marketing is not sent without a specific, separate, withdrawable consent.
The Controller does not sell personal data and does not disclose it to third parties for advertising profiling or behavioural targeting.
Legal bases
Each purpose rests on an autonomous legal basis under Article 6 GDPR:
— performance of a contract or pre-contractual steps (Article 6(1)(b)): account, sync, invites, backup, and App features you request;
— legal obligation (Article 6(1)(c)): mandated records, responses to authorities;
— legitimate interest (Article 6(1)(f)), after balancing: security, abuse prevention, diagnostics, aggregated first-party statistics, and — where enabled — product telemetry strictly limited to improving the Service, without advertising, automated decisions, or intentional identification of the data subject in events;
— consent (Article 6(1)(a)), where a special rule requires it (for example future promotional messages, or further processing not covered above). Consent is freely given, specific, informed, unambiguous, and withdrawable at any time without affecting prior lawfulness.
In-app acceptance of this Notice constitutes acknowledgement and, for processing necessary to use the cloud, a condition of using Nomad Cloud. Processing based on legitimate interest is not made a take-it-or-leave-it condition of that acceptance, without prejudice to the right to object under Article 21 GDPR.
First-party internal statistics (aggregated, non-identifying processing)
The Controller runs internal statistical analyses of how the Service operates, accessible only to authorised personnel through a restricted operations console. Those analyses use aggregated data produced by automated ETL into statistical tables separate from account data and trip content.
In particular, the following may be examined in a form not attributable to the individual: active account counts; App versions in use; platforms (iOS/Android); geographic areas derived from trip places (continents or countries), subject to k-anonymity thresholds where volumes are low; sync volumes; and use of core features. Those tables do not store names, email addresses, device identifiers, trip titles, or other elements suited to re-identifying the data subject.
This is the only analytics flow described in this Notice as not attributable to the person. It is based on the Controller’s legitimate interest in understanding Service use and maintaining quality (Article 6(1)(f) GDPR), in line with data minimisation and privacy by design and by default (Articles 5 and 25 GDPR). Aggregated data are not used to take decisions producing legal effects or similarly significantly affecting the data subject (Article 22 GDPR).
Product telemetry and Google Analytics 4
Where the Controller configures a Google Analytics 4 (GA4) measurement identifier, the App and/or the Site may send usage events to Google for statistical and product-improvement purposes. This processing is distinct from the first-party internal statistics in the previous section and is not described as “anonymous” in the strict sense.
Nature of processing. GA4 assigns a random identifier to the install or browser (client ID), creates sessions, and records: screen or page views (using parameterised route patterns, without user-resource identifiers); feature events (for example sign-in, trip creation, backup export); platform and language. We do not transmit: email, name, Nomad account User-ID, trip titles or notes, geographic coordinates, file names, session tokens, or advertising identifiers (IDFA, GAID/AAID). Advertising features, Google signals, and ad personalisation are disabled. No profiling aimed at automated decisions is performed.
Google’s role. Google Ireland Limited and, where applicable, Google LLC act as processors (Article 28 GDPR) for the Analytics platform, under Google’s Data Processing Terms and the standard contractual clauses or other transfer tool described under “International transfers”. Google may process the connection IP address; the Controller requests IP anonymisation where available and configures Consent Mode to deny advertising storage.
Legal basis. Legitimate interest (Article 6(1)(f)) in improving the Service, with minimisation safeguards, a ban on advertising use, and no intentional re-identification. You may object under Article 21 by contacting the Controller. Where ePrivacy law requires prior consent for persistent identifiers on the Site, the Controller will adjust activation (including omitting the script when unconfigured).
Opt-out. If the measurement identifier is not configured, no events are sent to Google and no client ID is created for that purpose. You may also restrict browser cookies and, on mobile, system tracking settings; the App does not prompt for Apple App Tracking Transparency because it does not access the advertising identifier.
The Controller does not warrant that data received by Google are anonymous in the legal sense; they are personal data or, at least, data that may constitute personal data. Any contrary statement would be inaccurate.
Storage, sync, and security
Content remains on your device in a local database (SQLite) even offline. With a linked account, a copy is transmitted in transit-encrypted form (TLS) to the Controller’s servers (Nomad Cloud) for backup and multi-device use, according to the documented Service architecture.
The Controller implements technical and organisational measures appropriate to the risk (Article 32 GDPR), including access control, least privilege on the admin console, audit logs for account actions, and logical deletion (soft delete) followed by purge under the retention policy.
You may export a full .nomad archive from settings. Security also depends on your conduct (credential hygiene, OS updates). To the extent permitted by mandatory law, the Controller is not liable for data loss caused by compromise of your device or failure to keep a local backup.
Recipients and categories of recipients
Data are disclosed, within the limits of purpose and minimisation, to the following categories:
(a) authentication providers (Apple, Google) when you choose federated sign-in;
(b) cloud infrastructure and API/database hosts, appointed as processors under Article 28 GDPR;
(c) map or geocoding services, only when you search for or save a place;
(d) Google Ireland Limited / Google LLC, as processor, for GA4 where enabled, as described in the telemetry section;
(e) public authorities, where disclosure is required by law or a binding order;
(f) professionals bound by secrecy, for the Controller’s legal defence.
Trip companions see only what you expressly share in the trip (entry visibility, attachments, roles). The Controller does not license trip content to third parties for advertising.
International transfers
Some recipients, in particular Google LLC and certain authentication or hosting infrastructure, may process data in the United States or other third countries.
Where the third country is not covered by an adequacy decision of the European Commission, the transfer takes place with appropriate safeguards under Article 46 GDPR, in particular the Commission’s Standard Contractual Clauses, supplemented where needed, and/or — for certified organisations — the EU-US Data Privacy Framework, within the limits of its validity and applicability.
A copy of the safeguards or information on the mechanism used may be requested from the Controller, subject to trade secrets and security.
Retention
Account data and synced content are kept for the life of the relationship and, after account deletion or an erasure request, for the time needed for soft delete, purge, and legal obligations (for example legal defence or tax duties, if and to the extent applicable), under the documented Service policy.
Legal-consent records (acceptance of this Notice) are kept for as long as needed to demonstrate compliance (Article 5(2) GDPR — accountability), and in any event no longer than the limitation period of the related claims.
First-party aggregated data are kept according to analytical need and may be further anonymised.
GA4 events are retained according to the Controller’s Analytics property settings and Google’s policy, and in any case no longer than needed for the statistical purposes, with the Controller free to adopt the shortest available retention window.
Your rights
You may exercise, within the limits of the law, the rights in Articles 15–22 GDPR: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.
In the App you can access profile data, export trips, correct content, revoke invites, and request account deletion. To object to GA4 telemetry or for requests the App cannot fulfil on its own, contact the Controller.
You have the right to lodge a complaint with the competent supervisory authority. For data subjects in Italy, that authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it). This is without prejudice to any other administrative or judicial remedy.
The Controller answers requests without undue delay and in any event within one month, extendable in the cases in Article 12 GDPR.
Contact
For privacy and personal-data questions, write to the Controller through the support channels indicated on the official Site nomadtravel.guru or in the App when available, including the account email so we can identify you and respond more quickly.
Current Notice: https://nomadtravel.guru/en/privacy/ Terms of Service: https://nomadtravel.guru/en/terms/
Changes to this Notice
The Controller may update this Notice to reflect new features, organisational changes, or legal requirements. The version is identified by a calendar date (YYYY-MM-DD) published in the App, on the Site, and in the Service codebase.
For material changes, you will be notified in the App and a new acceptance may be required before you continue to use Nomad Cloud. Use of the Site after publication of the new version constitutes acknowledgement of the updated text for processing related to browsing.
Prior versions remain in consent records for accountability. Please consult https://nomadtravel.guru/en/privacy/ periodically.
See also: Terms