OONITE

Tonight starts here.

Privacy Policy

Last updated: 11 October 2026

Your night is yours.

OONITE is a city experience and nightlife platform built around places, moments and how people experience a city after dark.

Using OONITE may involve information about where you go, when you visit a venue, what you share with the community and how you describe your own night. We recognize that some of this information can be particularly personal.

Our privacy principles are straightforward:

This Privacy Policy explains how OONITE collects, uses, stores, shares and protects information when you use oonite.com, the OONITE iOS app, the installed web app and related OONITE services and features (collectively, the “Service”).


1. About OONITE

OONITE is currently an independently operated digital platform.

For the purposes of this Privacy Policy, “OONITE,” “we,” “us” and “our” refer to the operator of the OONITE Service.

For privacy questions, requests or concerns, contact:

open@oonite.com


2. Who Can Use OONITE

OONITE is intended only for people aged 18 or older.

The Service is not intended for children or anyone under 18.

If we become aware that a person under 18 has created an account or provided personal information through OONITE, we may suspend the account and take reasonable steps to remove the relevant information.


3. Information We Collect

The information OONITE processes depends on how you use the Service.

Account information

When you create or manage an account, we may process:

We do not require you to publicly disclose your legal name, sexual orientation or other unnecessary identity information simply to maintain a basic OONITE account.

Content you create

When you contribute content, we may process:

Content you deliberately publish may be visible to other OONITE users or visitors.

Information identified by OONITE as private is handled separately from public content.


4. Check-In Information

When you use OONITE's check-in features, we may process information including:

A Verified check-in means that OONITE determined that the relevant verification requirements were satisfied.

It does not mean that your precise location is publicly displayed.

Because check-in history may reveal patterns about your nightlife activity, OONITE treats this information as private account information unless a specific feature clearly tells you otherwise.


5. Location and Check-In Verification

Some OONITE features may request access to your device location.

For example, OONITE may use your location to determine whether you are sufficiently close to a venue to complete a verified check-in.

When you use location-based verification:

For ordinary verified check-ins, OONITE is designed to retain the result of the verification — for example, that a particular venue visit was verified — rather than permanently storing the raw precise coordinates used to perform that verification.

Temporary location-related information may be processed for the minimum period reasonably necessary to:

You can deny or revoke location access through your device or browser settings.

Doing so may prevent location-dependent verification features from working. Nearby can still display its non-location feed.

Nearby also uses location to order nearby content and display distances. For a community post shared with location, stored coordinates are rounded to a coarse area (increments of 0.05 degrees); these are separate from the precise coordinates used transiently for venue verification. An approximate country may also be derived from the network request for usage measurement. We do not use background location updates to continuously track your movement.


6. Public and Private Information

OONITE distinguishes between information you share with the community and information intended only for you or for internal Service operation.

Depending on the feature, public information may include:

A voluntarily public Night Card can also show its venue, current check-in status and five-minute-rounded recency so members can see who is nearby. Publishing it is an explicit choice. Private check-ins remain private.

Private information may include:

Posting audience and Nearby presence

New Moment and Night Card forms currently start with Public selected. You can choose Only me before publishing. The selected audience applies to the submitted content; a public selection is not a promise that content will pass publication review. Changing content to private limits future access through OONITE, but cannot recall copies already saved or shared by others.

Nearby can show opted-in check-ins and public community posts to signed-in members. Your Nearby preference is separate from a Night Card's audience. If you enable automatic Nearby visibility, later check-ins can appear there without creating a public Night Card. Check-ins created before that preference are not automatically published. Public presence can disclose your profile, venue and approximate visit recency, but not your precise coordinates. You can change the Nearby visibility preference.

A green presence dot is a recent verified check-in indicator, not continuous location tracking. It requires GPS verification to be enabled, a server-verified venue check-in and a visit less than two hours old. It does not confirm that you have remained at the venue. Unrestricted or unverified check-ins do not qualify.

A field being processed internally by OONITE does not make that information public.


7. Private Night Information

OONITE may allow you to record information about your night for your own history.

This may include:

Unless you actively choose to publish information through a separate public feature, information labelled as private will not appear on your public profile, public Night Card or public Moment.


8. Sensitive Information

OONITE relates to nightlife and LGBTQ+ city experiences.

Certain information provided through the Service may therefore be sensitive or may become sensitive when combined with other information.

This may include information relating to:

OONITE does not require users to publicly disclose their sexual orientation or sexual behaviour in order to use the basic Service.

Where OONITE intentionally requests information that requires explicit consent under applicable law, we will request that consent separately and clearly.

Optional sensitive information labelled private is not made public merely because you provide it. Profile community labels and information included in a public post are public when you choose to save or publish them in those surfaces.

Where processing relies on your consent, you may withdraw that consent, subject to applicable law.


9. “What Are You Here For?” and Similar Fields

OONITE may offer optional experience fields such as:

Unless clearly stated otherwise before you submit your response, these fields are:

OONITE may use these responses to produce anonymous or aggregated nightlife insights.

For example, individual responses may contribute to a statistic describing the general intentions or experiences of users during a particular period.

OONITE will not intentionally expose which individual users contributed a particular private response.

Where a group is too small to reasonably protect individual privacy, OONITE may suppress, delay, combine or not publish the statistic.


10. Information Collected Automatically

When you use OONITE, we may automatically process limited technical information such as:

We use this information to operate, secure, troubleshoot and improve OONITE.

Our first-party usage measurement records page categories, public venue identifiers where relevant, selected actions, timestamps, broad device type, referral category and approximate country. Random browser visitor and session identifiers help count visits. When you are signed in, measurement may be associated with your internal account ID; it is not all anonymous. The measurement payload does not include passwords, private message text, raw search queries or the private content of your posts. We do not use these identifiers to track you across other companies' apps and websites for advertising.


11. How We Use Information

We may use information to provide and maintain OONITE, including to:

We may also use information to:

Personalize your experience

We may organize your own Night history and tailor features or recommendations based on your use of OONITE.

Private information does not need to become public in order for OONITE to personalize your experience.

Understand cities and nightlife

OONITE may analyze activity to understand patterns such as:

Where appropriate, these insights are produced using aggregated or de-identified information.

Protect users and OONITE

We may process information to:

Communicate with you

We may use your contact information to send:

Essential account communications are separate from optional marketing communications.

Comply with applicable law

We may process or preserve information where reasonably necessary to comply with applicable legal obligations, valid legal process or the establishment, exercise or defence of legal claims.


12. Legal Bases

Depending on the information involved and applicable law, OONITE may rely on one or more legal bases for processing.

These may include:

Providing the Service

Processing reasonably necessary to provide a feature or Service you requested.

Consent

Processing you have freely agreed to.

Where required by law, consent for sensitive information will be obtained separately.

Legitimate interests

Processing reasonably necessary to operate, improve, protect and secure OONITE, provided those interests are not overridden by your rights and interests.

Legal obligations

Processing necessary to comply with applicable law.

Safety and legal claims

Processing permitted by law where reasonably necessary to protect users, investigate serious misuse or establish, exercise or defend legal rights.


13. Aggregated and Anonymous City Data

One of OONITE's purposes is to understand nightlife and city behaviour without unnecessarily exposing the identities of individual users.

Individual activity may therefore contribute to aggregated statistics.

For example, an individual venue visit may contribute to information such as:

> 168 verified visits occurred in this area during this time period.

Once personal information has been genuinely and irreversibly anonymized so that it can no longer reasonably be linked to an individual, OONITE may retain and use that anonymous information for:

Removing a username or `user_id` alone is not treated by OONITE as sufficient anonymization if the remaining information could still reasonably identify a person.

Deleting your account therefore does not necessarily remove genuinely anonymous statistics that can no longer be linked back to you.


14. Messages and Social Interactions

Where OONITE provides features such as Say Hi, replies, comments or other user-to-user interactions, we may process:

Where a feature is described as temporary or expiring, access to ordinary user-facing content will expire according to the rules of that feature.

Messages and attached photos are processed to deliver conversations to their participants. Do not assume that private messages are end-to-end encrypted: OONITE's current service uses encrypted connections and access controls. Authorized staff may access reported content for safety review. A report's public outcome can be shown to its reporter; internal handling notes and another member's private information are not part of that outcome.

Limited records may be retained for longer when reasonably necessary for:


15. Cookies and Similar Technologies

OONITE may use cookies, local storage and similar technologies.

Some are necessary for:

OONITE may also use analytics technologies to understand general Service usage, errors and performance.

Where applicable law requires consent before non-essential technologies are used, OONITE will request that consent.

Local storage also keeps selected language/theme, saved preferences, cached public content and identifiers used for first-party measurement. The measurement session expires after 30 minutes of inactivity; the coarse referral attribution lasts up to seven days. The browser visitor identifier remains until local storage is cleared or replaced. These local lifetimes are not the retention period for server-side measurement records. Clearing website data removes these local copies and may sign you out.


16. Service Providers

OONITE uses third-party infrastructure and service providers to operate the Service.

These providers may perform services relating to:

They may process information on OONITE's behalf only as reasonably necessary to provide their services or as otherwise permitted by applicable law and their agreements with OONITE.

OONITE aims to provide service providers only with information reasonably necessary for their function.

Current technical providers include Vercel for hosted pages and OONITE API forwarding, Supabase for authentication, database and media storage, Tencent Cloud for authentication-email delivery and automatic image safety checks, and Apple Push Notification service or the browser's push service for requested notifications. OONITE's hosted forwarding passes the user's authentication identity to the backend; it does not make private content public.

Photos submitted for publication may be made available to Tencent Cloud's image moderation service through a short-lived access link to check compliance with our Community Guidelines. The service may receive original submitted photos, including sensitive images, for this purpose. Review decisions and revision records are retained for publication and safety handling. Content requiring manual review remains held for authorized OONITE staff; a sensitive-photo display control does not permit prohibited content. Text is checked against our current safety rules; this is not a claim that every harmful statement is detected.

We require providers handling personal information on our behalf to protect it consistently with this policy and applicable requirements. We do not authorize infrastructure providers to use your private Night information or personal check-in history for their own targeted advertising.


17. We Do Not Sell Sensitive Nightlife Data

OONITE does not sell:

OONITE also does not provide these categories of information to venues so that venues can identify individual users, unless:

If OONITE's business model materially changes in the future, any new use of personal information will be assessed and this Privacy Policy and consent mechanisms will be updated where necessary before that processing begins.


18. Venue and City Insights

OONITE may provide venues, partners or the public with aggregated information such as:

These products are intended to describe places and cities, not expose identifiable individual visitors.

Where appropriate, OONITE may use measures such as:

to reduce the risk of identifying individual users.


19. When We May Share Information

We may share limited information in the following circumstances.

With service providers

Where necessary to operate OONITE.

When required by law

We may preserve or disclose information where we reasonably believe we are legally required to do so in response to valid legal process or another binding legal obligation.

We do not treat an informal request for sensitive user information as equivalent to legally binding process.

Where legally permitted and appropriate, OONITE may seek to narrow requests that are disproportionately broad.

Safety and security

We may disclose information where permitted by law and reasonably necessary to:

Business transactions

If OONITE is involved in a merger, acquisition, restructuring, financing or transfer of the Service, information may be transferred as part of that transaction subject to appropriate safeguards and applicable law.


20. International Data Processing

OONITE is an online service.

Our users and technology providers may be located in different countries.

Information may therefore be processed or stored outside the country in which you are located, including outside Thailand.

Where applicable law requires safeguards for international transfers of personal information, OONITE will use appropriate measures to protect the transferred information.

Particular care will be taken where international processing involves sensitive information.


21. Data Security

OONITE uses reasonable technical and organizational measures designed to protect personal information.

These may include:

No internet-based Service can guarantee absolute security.

If OONITE becomes aware of a personal data breach, we will investigate it and make notifications where required by applicable law.


22. How Long We Keep Information

Account information and identifiable personal history are ordinarily retained while your account is active and the information is needed to provide the Service. You can delete your content or request account deletion.

Raw precise coordinates used for ordinary successful check-in verification are discarded after verification and do not form part of your permanent check-in history.

Limited records necessary for security, abuse prevention or legal obligations may be retained separately. Such records are access-restricted and are not treated as anonymous merely because an account identifier has been replaced or removed.

23. Delete Your Account

You can request deletion yourself through Settings → Delete account. Password verification and a separate confirmation are required. You do not need to email us to begin the process.

Your profile and public content are hidden and normal posting, check-ins and messages are paused during the 7-day recovery period. Signing in again before the exact deadline automatically cancels deletion. The deadline is shown in Bangkok time.

Once the recovery period ends, permanent deletion begins and the account cannot be restored. We remove your profile, account information, Night Cards, Moments, photos, identifiable check-in history, private Night information, comments, saved content and identifiable social activity. Your outgoing private messages and associated media are covered by deletion.

Personal data covered by the request will be removed or irreversibly de-identified from active OONITE systems within 30 days after permanent deletion begins. Backup copies will expire within 90 days. Limited security, abuse or legally required records may be retained separately where necessary. Genuinely anonymous city statistics may remain only if they can no longer be linked back to you.

Deletion uses a retryable process. We do not mark an account as deleted while its covered media cleanup or authentication removal remains incomplete. If a backup is restored, applicable deletion requests must be reapplied before restored personal data is returned to normal use.

24. Your Privacy Rights

Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of your information; withdraw consent; object to or restrict certain processing; and complain to the relevant data protection authority. Some requests may require identity verification, and lawful exceptions may apply.

Manage your profile and content in your account. For requests not available in the Service, contact open@oonite.com. Withdrawing a permission may affect features that need it. While either account is signed in, blocking prevents contact and normally hides each member's profile and public community content from the other. Public content may still be visible after signing out.

25. Notifications and NITE TYPE

If you enable notifications, we process a device push token or browser subscription endpoint and its delivery keys, your account association and notification preferences. Apple or your browser's push provider processes delivery information. You can change supported categories in OONITE and revoke notification permission in device/browser settings. Permission to send notifications does not grant access to your address book.

NITE TYPE is optional. Quiz answers and optional role selections can reveal personal or sensitive preferences. They are used to calculate the result; when you request a saved identity, they are also sent to OONITE to verify that result. The saved identity contains the resulting type, any applicable role, configuration version and your chosen hidden-title visibility. Raw quiz answers are not stored in that saved identity record. A pending claim token may be kept on your device until completion or expiry. Choose carefully before exporting or sharing a result card: the card and link may disclose the visible identity and any hidden title you elected to include. NITE TYPE does not use live location or your check-in history to calculate the result.

26. Changes and Contact

We may update this policy to reflect changes in the Service or processing. The revision date appears above. Material changes will be communicated where required.

Operator: OONITE. Privacy questions and requests: open@oonite.com.

Private data download during account deletion

When you request account deletion, we provide a private download link directly on screen. No email is sent. Keep this link private and save it: it can be used without signing in. Downloading does not cancel deletion. Your own account records and linked media are prepared in one or more ZIP files; download every part before your deletion deadline. Passwords, login credentials, internal moderation notes and private messages sent by other members are excluded.

The link expires when the recovery period ends or you cancel deletion. Generated ZIP files and temporary export snapshots are automatically removed when deletion is cancelled or permanently completed. Failed cleanup is retried; permanent deletion is not marked complete until generated copies have been removed. This operational export is separate from Supabase database backups.