Overview
InOnIt is a lifestyle deals marketplace. To operate the platform, we need to collect certain personal information. We are committed to collecting only what is necessary, keeping it secure, and never selling it to third parties for advertising purposes.
Data We Collect
We collect the following categories of information:
| Category | Examples | Source |
|---|---|---|
| Identity Data | First name, last name, username | You, at registration |
| Contact Data | Email address, phone number | You, at registration |
| Transaction Data | Deals purchased, amounts paid, voucher redemption records | Platform activity |
| Payment Data | Card type, last 4 digits, billing zip (full card data held by Stripe) | Stripe, at checkout |
| Device & Technical Data | Device type, OS, app version, IP address, crash logs | Automatically collected |
| Usage Data | Deals viewed, searches, taps, session duration | Automatically collected |
| Location Data | Approximate or precise location (if permission granted) | Your device, if enabled |
| Communications Data | Support messages sent to InOnIt | You |
We do not collect sensitive personal information such as Social Security numbers, government-issued ID numbers (except for vendors via Stripe's verification process), biometric data, or health information.
How We Use Your Data
We use the information we collect to:
- Create and manage your account.
- Process transactions and generate QR vouchers.
- Deliver relevant deal recommendations based on your location and browsing behavior.
- Send transactional notifications (purchase confirmations, voucher reminders, expiry alerts).
- Send promotional communications, if you have opted in.
- Provide customer support and resolve disputes.
- Improve platform features, fix bugs, and analyze usage patterns.
- Detect and prevent fraud, abuse, and policy violations.
- Comply with legal obligations.
We rely on the following legal bases for processing your data: contract performance (to provide the service you signed up for), legitimate interests (to improve and protect the platform), and consent (for marketing communications).
Data Sharing
We do not sell your personal data. We share data only in the following limited circumstances:
- Vendors: When you redeem a voucher, the vendor receives only your first name and booking reference number — the minimum required to complete the transaction.
- Stripe: Your payment information is processed by Stripe, Inc. Stripe's privacy policy governs how they handle your payment data. See stripe.com/privacy.
- Analytics Providers: We may share anonymized, aggregated usage data with analytics tools to understand how the app is used. This data cannot identify you individually.
- Legal Requirements: We may disclose data when required by law, court order, or to protect the rights, property, or safety of InOnIt, its users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
Payment Data
All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. InOnIt does not store full card numbers, CVV codes, or bank account details on our servers. We store only tokenized references and non-sensitive identifiers (such as card type and last 4 digits) to display saved cards in your profile.
Stripe may retain payment data in accordance with their own privacy policy and applicable financial regulations.
Location Data
InOnIt requests access to your device's location to show you deals near you. Location access is optional — you can use the app without granting location permissions, though deal recommendations may be less relevant.
We collect location data only while the app is in use (foreground only). We do not track your location in the background. You can revoke location permissions at any time through your device settings.
Push Notifications
We may send push notifications for purchase confirmations, voucher expiry reminders, and (if opted in) new deals in your area. You can manage or disable notifications at any time through your device settings or within the app under Profile → Notifications.
Cookies & Analytics
The InOnIt app may use lightweight in-app analytics tools to collect anonymous usage data (such as screen views and feature interactions). This helps us understand how the app is being used and identify areas for improvement.
Our website (inonit.com) may use cookies for session management and analytics. You can control cookie preferences through your browser settings. Essential cookies required for website functionality cannot be disabled.
Data Retention
We retain your personal data for as long as your account is active. When you delete your account, InOnIt deletes your personal data from our active systems. We do not sell, transfer, or use your data after account deletion. The following limited exceptions apply only where required by law:
- Account & identity data: Deleted upon account closure. A minimal record of the account's existence may be retained for up to 90 days solely to process any in-flight transactions or disputes, then permanently deleted.
- Transaction data: Retained for up to 7 years to comply with IRS and financial recordkeeping requirements. This data is held in a restricted archive and is not used for any commercial purpose.
- Support communications: Retained for up to 3 years to support dispute resolution, then deleted.
- Analytics data: Any analytics data associated with your account is anonymized or deleted upon account closure. Fully anonymized aggregate data (which cannot identify you) may be retained indefinitely for platform improvement purposes.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your account and personal data, subject to legal retention requirements.
- Opt-Out: Opt out of marketing communications at any time via the unsubscribe link in any email or through app settings.
- Portability: Request your data in a structured, machine-readable format.
To exercise any of these rights, email us at info@inonitapp.com. We will respond within 30 days.
California Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:
- Right to Know: You can request a full disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. You will receive the same quality of service regardless.
- Right to Opt-Out of Sale: We do not sell personal information. This right is therefore not applicable, but we honor it by commitment.
To submit a CCPA request, email info@inonitapp.com with the subject line "CCPA Request."
Children's Privacy
InOnIt is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately. If you believe a child under 13 has registered on our platform, please contact us at info@inonitapp.com.
Users between the ages of 13 and 17 may use the platform only with verifiable parental or guardian consent. Purchases require a user to be at least 18 years of age.
Data Security
We implement industry-standard security measures to protect your personal data, including:
- TLS/SSL encryption for all data transmitted between your device and our servers.
- Tokenization of payment data via Stripe (we never touch raw card numbers).
- Access controls limiting who within InOnIt can access personal data.
- Regular security reviews and vulnerability assessments.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.
Third-Party Links
The InOnIt app or website may contain links to third-party websites or services (such as vendor websites). InOnIt is not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before submitting any personal information.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification or email at least 14 days before the changes take effect. The current version will always be available at inonit.com/privacy.
Contact
For privacy-related questions, requests, or concerns:
Email: info@inonitapp.com
Subject line: Privacy Inquiry
Response time: Within 30 days
SMS Communications & TCPA Compliance
17.1 Consent to SMS. By providing your phone number during registration, you consent to receive transactional SMS messages from InOnIt, including purchase confirmations, voucher expiry reminders, account alerts, and (if opted in) promotional messages. These messages are sent via our SMS provider, Twilio, Inc.
17.2 Opt-Out. You may opt out of promotional SMS at any time by replying STOP to any InOnIt text message, or by updating your preferences in the app. Transactional messages (e.g., purchase confirmations) cannot be opted out of while your account is active, as they are essential to safe use of the platform. After opting out of promotional messages, you may receive a single confirmation text — no further marketing messages will follow.
17.3 Data Used for SMS. Your phone number is shared with Twilio solely for the purpose of message delivery. Twilio's privacy practices are governed by their own policy at twilio.com/legal/privacy. InOnIt does not use your phone number for any other purpose and does not sell it to third parties.
17.4 Carrier Fees. Standard message and data rates may apply depending on your mobile carrier and plan. InOnIt is not responsible for carrier-imposed charges.
Email Marketing & CAN-SPAM Compliance
18.1 Transactional Emails. We send transactional emails (purchase receipts, voucher confirmations, account updates, and support responses) to your registered email address. These are required for platform operation and cannot be unsubscribed from while your account is active.
18.2 Marketing Emails. Promotional or marketing emails are only sent with your opt-in consent. In compliance with the CAN-SPAM Act, every marketing email from InOnIt will:
- Clearly identify InOnIt, Inc. as the sender.
- Include our mailing address.
- Contain a clearly visible, functional unsubscribe link.
- Honor unsubscribe requests within 10 business days.
18.3 Unsubscribe. You may opt out of marketing emails at any time using the unsubscribe link in any InOnIt email, or by emailing info@inonitapp.com with the subject line "Unsubscribe."
Do Not Track Signals
Some browsers and devices allow users to send a "Do Not Track" (DNT) signal to websites and applications. Currently, InOnIt's website does not respond to DNT signals in a standardized way, as no universally accepted standard for DNT compliance exists. We will revisit this position as industry standards develop.
Within the InOnIt app, you can limit data collection for analytics purposes by adjusting your notification and tracking preferences under Profile → Privacy Settings. We do not use cross-app tracking or share your device's advertising identifier with third-party advertisers.
International Users
InOnIt is operated from the United States and is intended for use by US residents. If you access the Platform from outside the United States, you do so at your own initiative and are responsible for compliance with applicable local laws. By using the Platform, you consent to the transfer, processing, and storage of your personal data in the United States, which may have different data protection standards than your country of residence.
Waiver & Severability
Waiver. No failure or delay by InOnIt in enforcing any provision of this Privacy Policy shall constitute a waiver of the right to enforce it in the future.
Severability. If any provision of this Privacy Policy is found to be invalid or unenforceable under applicable law, that provision will be modified or severed, and the remaining provisions will continue in full effect.
