Privacy Policy
Last updated: 11 October 2026
Your night is yours.
OONITE is a city experience and nightlife platform built around places, moments and how people experience a city after dark.
Using OONITE may involve information about where you go, when you visit a venue, what you share with the community and how you describe your own night. We recognize that some of this information can be particularly personal.
Our privacy principles are straightforward:
- Clear visibility choices. Private account history stays private. Public posting and optional Nearby presence have separate controls; review the displayed audience before sharing.
- Collect less. We aim to collect only the information reasonably necessary to operate, improve and protect OONITE.
- Explain at the moment. When a feature requires information such as location, we aim to explain why it is needed when you use that feature.
- You stay in control. You can manage your content, exercise your privacy rights and delete your account.
- Sensitive nightlife data is not an advertising product. We do not sell your precise location, personal check-in history or private nightlife preferences.
This Privacy Policy explains how OONITE collects, uses, stores, shares and protects information when you use oonite.com, the OONITE iOS app, the installed web app and related OONITE services and features (collectively, the “Service”).
1. About OONITE
OONITE is currently an independently operated digital platform.
For the purposes of this Privacy Policy, “OONITE,” “we,” “us” and “our” refer to the operator of the OONITE Service.
For privacy questions, requests or concerns, contact:
open@oonite.com
2. Who Can Use OONITE
OONITE is intended only for people aged 18 or older.
The Service is not intended for children or anyone under 18.
If we become aware that a person under 18 has created an account or provided personal information through OONITE, we may suspend the account and take reasonable steps to remove the relevant information.
3. Information We Collect
The information OONITE processes depends on how you use the Service.
Account information
When you create or manage an account, we may process:
- your email address;
- username or display name;
- profile image or avatar;
- profile information you choose to provide;
- internal user ID;
- authentication information;
- account creation and update timestamps;
- account preferences; and
- account status.
We do not require you to publicly disclose your legal name, sexual orientation or other unnecessary identity information simply to maintain a basic OONITE account.
Content you create
When you contribute content, we may process:
- Night Cards;
- Moments;
- photographs and other media;
- titles and descriptions;
- tags;
- comments;
- reactions and +1 interactions;
- saved content or venues;
- reports;
- public responses; and
- other information you choose to submit.
Content you deliberately publish may be visible to other OONITE users or visitors.
Information identified by OONITE as private is handled separately from public content.
4. Check-In Information
When you use OONITE's check-in features, we may process information including:
- venue ID;
- venue name;
- check-in time;
- check-out time;
- Night session information;
- check-in verification status;
- associated Night Card information; and
- limited technical information necessary to prevent fraudulent, duplicated or abusive check-ins.
A Verified check-in means that OONITE determined that the relevant verification requirements were satisfied.
It does not mean that your precise location is publicly displayed.
Because check-in history may reveal patterns about your nightlife activity, OONITE treats this information as private account information unless a specific feature clearly tells you otherwise.
5. Location and Check-In Verification
Some OONITE features may request access to your device location.
For example, OONITE may use your location to determine whether you are sufficiently close to a venue to complete a verified check-in.
When you use location-based verification:
- location is used for the purpose explained when permission is requested;
- your precise coordinates are not displayed publicly;
- your live location is not automatically shared with other users;
- precise location is not added to your public Night Card;
- precise location is not provided to venues as an individual user location; and
- routine raw latitude and longitude used for successful check-in verification are not retained as part of your permanent Night history.
For ordinary verified check-ins, OONITE is designed to retain the result of the verification — for example, that a particular venue visit was verified — rather than permanently storing the raw precise coordinates used to perform that verification.
Temporary location-related information may be processed for the minimum period reasonably necessary to:
- complete check-in verification;
- prevent fraud or abuse;
- diagnose a technical problem; or
- protect the security of the Service.
You can deny or revoke location access through your device or browser settings.
Doing so may prevent location-dependent verification features from working. Nearby can still display its non-location feed.
Nearby also uses location to order nearby content and display distances. For a community post shared with location, stored coordinates are rounded to a coarse area (increments of 0.05 degrees); these are separate from the precise coordinates used transiently for venue verification. An approximate country may also be derived from the network request for usage measurement. We do not use background location updates to continuously track your movement.
6. Public and Private Information
OONITE distinguishes between information you share with the community and information intended only for you or for internal Service operation.
Depending on the feature, public information may include:
- username;
- avatar;
- public profile information;
- published Night Cards;
- published Moments;
- photographs you choose to publish;
- tags;
- comments;
- reactions; and
- other content you deliberately make public.
A voluntarily public Night Card can also show its venue, current check-in status and five-minute-rounded recency so members can see who is nearby. Publishing it is an explicit choice. Private check-ins remain private.
Private information may include:
- account email;
- authentication information;
- precise location used for verification;
- private Night history;
- private notes;
- unpublished activity;
- personal experience fields;
- personal statistics; and
- information specifically labelled Private, Only You or similar.
Posting audience and Nearby presence
New Moment and Night Card forms currently start with Public selected. You can choose Only me before publishing. The selected audience applies to the submitted content; a public selection is not a promise that content will pass publication review. Changing content to private limits future access through OONITE, but cannot recall copies already saved or shared by others.
Nearby can show opted-in check-ins and public community posts to signed-in members. Your Nearby preference is separate from a Night Card's audience. If you enable automatic Nearby visibility, later check-ins can appear there without creating a public Night Card. Check-ins created before that preference are not automatically published. Public presence can disclose your profile, venue and approximate visit recency, but not your precise coordinates. You can change the Nearby visibility preference.
A green presence dot is a recent verified check-in indicator, not continuous location tracking. It requires GPS verification to be enabled, a server-verified venue check-in and a visit less than two hours old. It does not confirm that you have remained at the venue. Unrestricted or unverified check-ins do not qualify.
A field being processed internally by OONITE does not make that information public.
7. Private Night Information
OONITE may allow you to record information about your night for your own history.
This may include:
- private notes;
- visit details;
- personal experience information;
- personal Night statistics;
- nightlife preferences;
- the purpose or intention of a visit; and
- other information clearly identified as private.
Unless you actively choose to publish information through a separate public feature, information labelled as private will not appear on your public profile, public Night Card or public Moment.
8. Sensitive Information
OONITE relates to nightlife and LGBTQ+ city experiences.
Certain information provided through the Service may therefore be sensitive or may become sensitive when combined with other information.
This may include information relating to:
- sexual behaviour;
- sexual orientation;
- health;
- highly personal nightlife preferences;
- precise location; or
- attendance at particular places.
OONITE does not require users to publicly disclose their sexual orientation or sexual behaviour in order to use the basic Service.
Where OONITE intentionally requests information that requires explicit consent under applicable law, we will request that consent separately and clearly.
Optional sensitive information labelled private is not made public merely because you provide it. Profile community labels and information included in a public post are public when you choose to save or publish them in those surfaces.
Where processing relies on your consent, you may withdraw that consent, subject to applicable law.
9. “What Are You Here For?” and Similar Fields
OONITE may offer optional experience fields such as:
- Just vibe;
- Meet people;
- Hook up;
- See what happens; or
- similar categories.
Unless clearly stated otherwise before you submit your response, these fields are:
- optional;
- private by default;
- not shown on your public profile;
- not shown on your public Night Card;
- not provided to venues as individual-level user information; and
- not sold to advertisers.
OONITE may use these responses to produce anonymous or aggregated nightlife insights.
For example, individual responses may contribute to a statistic describing the general intentions or experiences of users during a particular period.
OONITE will not intentionally expose which individual users contributed a particular private response.
Where a group is too small to reasonably protect individual privacy, OONITE may suppress, delay, combine or not publish the statistic.
10. Information Collected Automatically
When you use OONITE, we may automatically process limited technical information such as:
- IP address;
- browser type;
- operating system;
- device type;
- language;
- timestamps;
- session information;
- authentication events;
- referring pages;
- feature usage;
- error information;
- diagnostic information; and
- security or fraud-prevention signals.
We use this information to operate, secure, troubleshoot and improve OONITE.
Our first-party usage measurement records page categories, public venue identifiers where relevant, selected actions, timestamps, broad device type, referral category and approximate country. Random browser visitor and session identifiers help count visits. When you are signed in, measurement may be associated with your internal account ID; it is not all anonymous. The measurement payload does not include passwords, private message text, raw search queries or the private content of your posts. We do not use these identifiers to track you across other companies' apps and websites for advertising.
11. How We Use Information
We may use information to provide and maintain OONITE, including to:
- create and maintain accounts;
- authenticate users;
- provide venue and city discovery;
- process check-ins;
- verify venue visits;
- create and display Night Cards;
- publish Moments;
- provide comments and community interactions;
- maintain your personal Night history;
- save preferences;
- operate social features; and
- provide features you request.
We may also use information to:
Personalize your experience
We may organize your own Night history and tailor features or recommendations based on your use of OONITE.
Private information does not need to become public in order for OONITE to personalize your experience.
Understand cities and nightlife
OONITE may analyze activity to understand patterns such as:
- activity levels;
- venue popularity;
- time-of-night patterns;
- repeat visits;
- nightlife flows;
- general experience trends; and
- aggregated user responses.
Where appropriate, these insights are produced using aggregated or de-identified information.
Protect users and OONITE
We may process information to:
- prevent spam;
- detect fraudulent check-ins;
- detect duplicate or abusive activity;
- investigate reports;
- enforce our Terms and Community Guidelines;
- protect accounts;
- maintain system integrity; and
- prevent misuse of the Service.
Communicate with you
We may use your contact information to send:
- authentication emails;
- account notifications;
- security alerts;
- important Service notices;
- privacy notices; and
- replies to support requests.
Essential account communications are separate from optional marketing communications.
Comply with applicable law
We may process or preserve information where reasonably necessary to comply with applicable legal obligations, valid legal process or the establishment, exercise or defence of legal claims.
12. Legal Bases
Depending on the information involved and applicable law, OONITE may rely on one or more legal bases for processing.
These may include:
Providing the Service
Processing reasonably necessary to provide a feature or Service you requested.
Consent
Processing you have freely agreed to.
Where required by law, consent for sensitive information will be obtained separately.
Legitimate interests
Processing reasonably necessary to operate, improve, protect and secure OONITE, provided those interests are not overridden by your rights and interests.
Legal obligations
Processing necessary to comply with applicable law.
Safety and legal claims
Processing permitted by law where reasonably necessary to protect users, investigate serious misuse or establish, exercise or defend legal rights.
13. Aggregated and Anonymous City Data
One of OONITE's purposes is to understand nightlife and city behaviour without unnecessarily exposing the identities of individual users.
Individual activity may therefore contribute to aggregated statistics.
For example, an individual venue visit may contribute to information such as:
> 168 verified visits occurred in this area during this time period.
Once personal information has been genuinely and irreversibly anonymized so that it can no longer reasonably be linked to an individual, OONITE may retain and use that anonymous information for:
- city statistics;
- nightlife trends;
- venue trends;
- historical analysis;
- product research; and
- other statistical purposes.
Removing a username or `user_id` alone is not treated by OONITE as sufficient anonymization if the remaining information could still reasonably identify a person.
Deleting your account therefore does not necessarily remove genuinely anonymous statistics that can no longer be linked back to you.
14. Messages and Social Interactions
Where OONITE provides features such as Say Hi, replies, comments or other user-to-user interactions, we may process:
- sender and recipient identifiers;
- message or interaction content;
- timestamps;
- interaction status; and
- associated safety or abuse reports.
Where a feature is described as temporary or expiring, access to ordinary user-facing content will expire according to the rules of that feature.
Messages and attached photos are processed to deliver conversations to their participants. Do not assume that private messages are end-to-end encrypted: OONITE's current service uses encrypted connections and access controls. Authorized staff may access reported content for safety review. A report's public outcome can be shown to its reporter; internal handling notes and another member's private information are not part of that outcome.
Limited records may be retained for longer when reasonably necessary for:
- security;
- abuse prevention;
- investigation of reports;
- dispute handling; or
- compliance with applicable law.
15. Cookies and Similar Technologies
OONITE may use cookies, local storage and similar technologies.
Some are necessary for:
- authentication;
- login;
- session management;
- security;
- preferences; and
- core Service functionality.
OONITE may also use analytics technologies to understand general Service usage, errors and performance.
Where applicable law requires consent before non-essential technologies are used, OONITE will request that consent.
Local storage also keeps selected language/theme, saved preferences, cached public content and identifiers used for first-party measurement. The measurement session expires after 30 minutes of inactivity; the coarse referral attribution lasts up to seven days. The browser visitor identifier remains until local storage is cleared or replaced. These local lifetimes are not the retention period for server-side measurement records. Clearing website data removes these local copies and may sign you out.
16. Service Providers
OONITE uses third-party infrastructure and service providers to operate the Service.
These providers may perform services relating to:
- hosting;
- databases;
- authentication;
- storage;
- image delivery;
- automated content moderation;
- push notification delivery;
- content delivery;
- network security;
- email delivery;
- logging;
- analytics;
- customer support; and
- other technical infrastructure.
They may process information on OONITE's behalf only as reasonably necessary to provide their services or as otherwise permitted by applicable law and their agreements with OONITE.
OONITE aims to provide service providers only with information reasonably necessary for their function.
Current technical providers include Vercel for hosted pages and OONITE API forwarding, Supabase for authentication, database and media storage, Tencent Cloud for authentication-email delivery and automatic image safety checks, and Apple Push Notification service or the browser's push service for requested notifications. OONITE's hosted forwarding passes the user's authentication identity to the backend; it does not make private content public.
Photos submitted for publication may be made available to Tencent Cloud's image moderation service through a short-lived access link to check compliance with our Community Guidelines. The service may receive original submitted photos, including sensitive images, for this purpose. Review decisions and revision records are retained for publication and safety handling. Content requiring manual review remains held for authorized OONITE staff; a sensitive-photo display control does not permit prohibited content. Text is checked against our current safety rules; this is not a claim that every harmful statement is detected.
We require providers handling personal information on our behalf to protect it consistently with this policy and applicable requirements. We do not authorize infrastructure providers to use your private Night information or personal check-in history for their own targeted advertising.
17. We Do Not Sell Sensitive Nightlife Data
OONITE does not sell:
- your email address;
- your precise location;
- your identifiable check-in history;
- your private Night information; or
- your sensitive nightlife preferences.
OONITE also does not provide these categories of information to venues so that venues can identify individual users, unless:
- you specifically choose to share information;
- doing so is necessary to provide a feature you explicitly requested; or
- disclosure is required by applicable law.
If OONITE's business model materially changes in the future, any new use of personal information will be assessed and this Privacy Policy and consent mechanisms will be updated where necessary before that processing begins.
18. Venue and City Insights
OONITE may provide venues, partners or the public with aggregated information such as:
- general activity levels;
- busy periods;
- anonymous visitor trends;
- popularity trends;
- aggregated responses; and
- city or venue statistics.
These products are intended to describe places and cities, not expose identifiable individual visitors.
Where appropriate, OONITE may use measures such as:
- minimum group sizes;
- time grouping;
- geographic grouping;
- delayed publication;
- suppression of small datasets; or
- other safeguards
to reduce the risk of identifying individual users.
19. When We May Share Information
We may share limited information in the following circumstances.
With service providers
Where necessary to operate OONITE.
When required by law
We may preserve or disclose information where we reasonably believe we are legally required to do so in response to valid legal process or another binding legal obligation.
We do not treat an informal request for sensitive user information as equivalent to legally binding process.
Where legally permitted and appropriate, OONITE may seek to narrow requests that are disproportionately broad.
Safety and security
We may disclose information where permitted by law and reasonably necessary to:
- protect a person's safety;
- investigate serious fraud or abuse;
- respond to a significant security incident; or
- protect OONITE and its users.
Business transactions
If OONITE is involved in a merger, acquisition, restructuring, financing or transfer of the Service, information may be transferred as part of that transaction subject to appropriate safeguards and applicable law.
20. International Data Processing
OONITE is an online service.
Our users and technology providers may be located in different countries.
Information may therefore be processed or stored outside the country in which you are located, including outside Thailand.
Where applicable law requires safeguards for international transfers of personal information, OONITE will use appropriate measures to protect the transferred information.
Particular care will be taken where international processing involves sensitive information.
21. Data Security
OONITE uses reasonable technical and organizational measures designed to protect personal information.
These may include:
- encrypted network connections;
- authentication controls;
- database access controls;
- separation between public and private data;
- security monitoring;
- rate limiting;
- logging;
- abuse detection;
- backups; and
- limiting administrative access to those who reasonably need it.
No internet-based Service can guarantee absolute security.
If OONITE becomes aware of a personal data breach, we will investigate it and make notifications where required by applicable law.
22. How Long We Keep Information
Account information and identifiable personal history are ordinarily retained while your account is active and the information is needed to provide the Service. You can delete your content or request account deletion.
Raw precise coordinates used for ordinary successful check-in verification are discarded after verification and do not form part of your permanent check-in history.
Limited records necessary for security, abuse prevention or legal obligations may be retained separately. Such records are access-restricted and are not treated as anonymous merely because an account identifier has been replaced or removed.
23. Delete Your Account
You can request deletion yourself through Settings → Delete account. Password verification and a separate confirmation are required. You do not need to email us to begin the process.
Your profile and public content are hidden and normal posting, check-ins and messages are paused during the 7-day recovery period. Signing in again before the exact deadline automatically cancels deletion. The deadline is shown in Bangkok time.
Once the recovery period ends, permanent deletion begins and the account cannot be restored. We remove your profile, account information, Night Cards, Moments, photos, identifiable check-in history, private Night information, comments, saved content and identifiable social activity. Your outgoing private messages and associated media are covered by deletion.
Personal data covered by the request will be removed or irreversibly de-identified from active OONITE systems within 30 days after permanent deletion begins. Backup copies will expire within 90 days. Limited security, abuse or legally required records may be retained separately where necessary. Genuinely anonymous city statistics may remain only if they can no longer be linked back to you.
Deletion uses a retryable process. We do not mark an account as deleted while its covered media cleanup or authentication removal remains incomplete. If a backup is restored, applicable deletion requests must be reapplied before restored personal data is returned to normal use.
24. Your Privacy Rights
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of your information; withdraw consent; object to or restrict certain processing; and complain to the relevant data protection authority. Some requests may require identity verification, and lawful exceptions may apply.
Manage your profile and content in your account. For requests not available in the Service, contact open@oonite.com. Withdrawing a permission may affect features that need it. While either account is signed in, blocking prevents contact and normally hides each member's profile and public community content from the other. Public content may still be visible after signing out.
25. Notifications and NITE TYPE
If you enable notifications, we process a device push token or browser subscription endpoint and its delivery keys, your account association and notification preferences. Apple or your browser's push provider processes delivery information. You can change supported categories in OONITE and revoke notification permission in device/browser settings. Permission to send notifications does not grant access to your address book.
NITE TYPE is optional. Quiz answers and optional role selections can reveal personal or sensitive preferences. They are used to calculate the result; when you request a saved identity, they are also sent to OONITE to verify that result. The saved identity contains the resulting type, any applicable role, configuration version and your chosen hidden-title visibility. Raw quiz answers are not stored in that saved identity record. A pending claim token may be kept on your device until completion or expiry. Choose carefully before exporting or sharing a result card: the card and link may disclose the visible identity and any hidden title you elected to include. NITE TYPE does not use live location or your check-in history to calculate the result.
26. Changes and Contact
We may update this policy to reflect changes in the Service or processing. The revision date appears above. Material changes will be communicated where required.
Operator: OONITE. Privacy questions and requests: open@oonite.com.
Private data download during account deletion
When you request account deletion, we provide a private download link directly on screen. No email is sent. Keep this link private and save it: it can be used without signing in. Downloading does not cancel deletion. Your own account records and linked media are prepared in one or more ZIP files; download every part before your deletion deadline. Passwords, login credentials, internal moderation notes and private messages sent by other members are excluded.
The link expires when the recovery period ends or you cancel deletion. Generated ZIP files and temporary export snapshots are automatically removed when deletion is cancelled or permanently completed. Failed cleanup is retried; permanent deletion is not marked complete until generated copies have been removed. This operational export is separate from Supabase database backups.