Privacy Policy
Effective: November 1, 2025 · Last Updated: November 1, 2024
Welcome to Lounsy (the "App"). This Privacy Policy explains how Rob Tasker ("we," "us," or "our") collects, uses, and shares information when you use Lounsy (the "Services").
We are committed to protecting your privacy and handling your information responsibly. If you have questions, contact us at rob@robtasker.com.
1) Who We Are & Scope
Controller: Rob Tasker, with registered address Reykjavik, Iceland. If you reside in the European Economic Area (EEA) or the United Kingdom (UK), we are the controller of your personal data under applicable data protection laws.
This Policy covers our processing of personal data through the App and our website. It does not apply to third‑party websites, services, or apps that we do not control.
2) Information We Collect
A. Information you provide
- Account & Login: Email address and password (managed via Firebase Authentication; we do not store plain‑text passwords). You may also sign in using Google or Apple authentication.
- Profile Information: Name, profile photo (optional, can be blurred), bio, interests, preferred airlines, age, nationality, and other profile details you choose to share.
- Location Data: Your current airport location (obtained with your permission) to show you relevant lounge posts and connect you with travelers at the same airport.
- Lounge Posts: Airport code, lounge name, airline, access type (membership, credit card, etc.), guest policy, and availability time when you create a post.
- Messages: Chat messages you send to other users through the in-app messaging system.
- Reviews & Ratings: Reviews, ratings (1-5 stars), and tags you provide about other users after meeting them.
- Communications: Messages or content you send to us (support requests, feedback, reports).
- Subscription & Purchases: Transactional details related to in‑app purchases or premium subscriptions (handled by Apple App Store / Google Play; we receive limited records like transaction IDs and status).
B. Information collected automatically
- Device & Usage: Device identifiers, OS and app version, timezone, language, IP address, and in‑app actions (e.g., screens viewed, posts created, chats initiated, feature usage) to operate and improve the App.
- Location Data: Approximate location derived from IP address or precise location when you grant permission for airport detection.
- Diagnostics: Crash, performance, and error data to maintain reliability.
- Push Notifications: Push notification tokens to deliver alerts such as chat messages, connection requests, and post activity.
- Activity Logs: Information about your interactions within the app including logins, posts viewed, chat activity, and reviews submitted.
C. Information from third parties
- Authentication Providers: We use Google Firebase and may receive basic profile information (email, name, profile photo) when you sign in with Google or Apple.
- Cloud Services: Firebase/Google Cloud for authentication, database storage, and cloud messaging.
- Analytics: We may receive aggregated metrics about installs, sessions, and app performance.
- Payment Platforms: App Store and Google Play provide purchase validation details and subscription status.
Location-based service: Lounsy uses your location to show you airport lounges and posts from travelers at your current airport. You can control location permissions in your device settings. Without location access, some features may not be available.
3) How We Use Information
- Provide, operate, and personalize the Services (including showing relevant lounge posts based on your location and preferences).
- Enable connections between travelers, facilitate lounge access sharing, and coordinate meetups.
- Deliver in-app messaging and real-time notifications about chat messages, connection requests, and post activity.
- Show you who is at your airport and which lounges have available posts.
- Display user reviews, ratings, and verification status to build trust in the community.
- Maintain safety, integrity, and security (fraud prevention, abuse detection, authentication, user verification).
- Process purchases, premium subscriptions, and account changes.
- Provide customer support and respond to requests or reports.
- Monitor usage, fix bugs, and improve performance and features.
- Conduct analytics to understand how travelers use lounges and develop new features.
- Identify partnership opportunities with airports, lounges, and airlines.
- Comply with legal obligations and enforce our Terms of Service.
4) Legal Bases for Processing (EEA/UK)
Where GDPR/UK GDPR applies, we process personal data under these legal bases:
- Contract: To provide the Services you request (account, location-based matching, lounge posts, messaging, reviews, notifications).
- Legitimate Interests: To secure and improve the Services, prevent abuse and fraud, verify users, understand usage patterns, and develop business partnerships. We balance these interests against your rights.
- Consent: For optional features such as precise location tracking, push notifications, certain analytics, photo uploads, and marketing (where applicable). You can withdraw consent in device or in‑app settings.
- Legal Obligations: To meet tax, accounting, regulatory requirements, and respond to lawful requests.
5) Sharing & Disclosure
We do not sell your personal information. We share information in these limited situations:
- Service Providers (Processors): Vendors that host, store, process, and support our Services including Google Firebase/Google Cloud (authentication, database, cloud functions, messaging), Apple and Google (payments, push notifications), analytics providers, cloud storage (for profile photos), and customer support tools.
- Other Users: Your profile information (name, photo, bio, interests, airlines, verification status), lounge posts, reviews you write, and messages you send are visible to other users as necessary to provide the social networking features of the Service. You can control photo visibility (blur/unblur) in settings.
- Community Safety: If you report another user or are reported, we may share relevant information with the other party to resolve the issue or enforce our policies.
- Legal & Safety: To comply with law, respond to lawful requests, protect rights, safety, and property, investigate fraud, security issues, or violations of our Terms of Service.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of assets. We will continue to protect your information and notify you of any changes to this Policy.
- Aggregated Data: We may share aggregated, de-identified information about airport usage, lounge popularity, and travel trends with airports, lounges, and airlines for business development purposes.
6) Advertising, Analytics & Links
- Advertising: We may display ads or promote partnerships with lounges, airlines, and airports. These partners may receive aggregated usage data but not your personal information unless you explicitly engage with their offers.
- Analytics: We use Firebase Analytics and may use other analytics tools to understand usage patterns, popular airports, feature adoption, and app performance. Where required, we seek consent.
- Third‑Party Links: The Services may link to airport websites, lounge websites, airline sites, or other services we do not control. Their privacy practices govern those services.
7) International Transfers
Lounsy connects travelers globally. We may transfer personal data to countries outside your own (including the EEA/UK to the United States) where our providers (Firebase, Google Cloud) operate. When we do, we rely on lawful safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, and/or other transfer mechanisms permitted by law, and we implement appropriate technical and organizational measures.
8) Security
We implement measures aimed at protecting your information, including:
- Encryption in transit (HTTPS/TLS) and at rest for sensitive data
- Firebase Authentication security best practices
- Access controls and least‑privilege practices
- IP address logging for security and fraud prevention
- User verification features (email, photo verification)
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at support@lounsy.com.
9) Data Retention
- We keep personal data for as long as necessary to provide the Services and for legitimate business needs (e.g., security, fraud prevention, user safety) and legal obligations.
- Account data: Retained until you delete your account. Upon deletion, your profile, posts, and messages are removed from active systems within 30 days, subject to backups and legal retention.
- Reviews: Reviews you write are retained even after account deletion to maintain integrity of the review system, but your identifying information is anonymized.
- IP logs and activity data: Retained for up to 90 days for security and fraud prevention purposes.
- Transactional records: Kept for up to 7 years as required by tax and accounting laws.
- Diagnostic logs and analytics: Typically retained for 12–24 months.
- Backup data: May be retained for up to 90 days in secure backups.
10) Your Rights & Choices
In‑App Controls
- Profile Settings: Edit your name, bio, interests, airlines, and visibility preferences.
- Photo Privacy: Choose to blur or unblur your profile photo for specific users.
- Location Permissions: Enable/disable location access in device settings. Some features require location access.
- Push Notifications: Enable/disable in device settings and in‑app notification preferences.
- Blocking Users: Block users to prevent them from contacting you or viewing your posts.
- Delete Account: In the App, go to Profile → Settings → Account → Delete Account (or contact us). Deleting your account removes your profile, posts (within 30 days), and messages from our primary systems. Reviews you've written will be anonymized. Some data may persist in backups for up to 90 days.
EEA/UK Residents (GDPR)
You may request:
- Access: A copy of the personal data we hold about you
- Correction: Updates to inaccurate or incomplete data
- Deletion: Removal of your data ("right to be forgotten")
- Restriction: Limitation on how we process your data
- Portability: Your data in a structured, machine-readable format
- Object: To processing based on legitimate interests
Contact us at rob@robtasker.com with the subject "Lounsy GDPR Request." You also have the right to lodge a complaint with your local supervisory authority. If you are in Iceland, the authority is Persónuvernd (Icelandic Data Protection Authority).
US State Privacy Rights (California, Virginia, Colorado, Connecticut, etc.)
Depending on your state, you may have rights to:
- Access and receive a copy of your personal information
- Correct inaccuracies in your personal information
- Delete your personal information
- Opt out of the sale or sharing of personal information for targeted advertising
We do not sell personal information, and we do not share it for cross‑context behavioral advertising as those terms are defined by California law. To exercise rights, email rob@robtasker.com with the subject "Lounsy Privacy Request." We will verify your request consistent with applicable law.
California Notice at Collection
| Category | Examples | Purpose | Shared With | Retention |
| Identifiers |
Email, name, device IDs, IP address |
Account management, security, authentication, fraud prevention |
Firebase/Google Cloud, app stores, analytics providers |
Account life + up to 7 years for legal compliance |
| Personal Info |
Profile details, photo, bio, interests, age, nationality |
Create profile, match travelers, enable connections |
Other users, Firebase/Google Cloud, cloud storage |
Account life + 30 days |
| Location Data |
Airport location, GPS coordinates, IP-derived location |
Show relevant lounge posts, connect travelers at same airport |
Firebase/Google Cloud, other users (airport level) |
90 days for precise location; longer for IP logs |
| Customer Records |
Purchase history, subscription status |
Provide premium features, support |
App stores, payment providers |
Up to 7 years for legal compliance |
| Internet/Network Activity |
App interactions, posts viewed, chats, logins, diagnostics |
Improve the App, security, fraud prevention |
Analytics/diagnostics providers, Firebase |
12–24 months |
| Communications |
Chat messages, reviews, support requests |
Enable messaging, display reviews, provide support |
Other users (chats/reviews), support tools |
Account life + 30 days (messages); reviews anonymized after deletion |
| Inferences |
Travel preferences, lounge usage patterns, engagement trends |
Improve features, personalize experience, business development |
Analytics providers (aggregated) |
Aggregated/indefinite |
Sensitive information (passwords) is handled by Firebase Authentication; we do not store plain‑text passwords. We collect precise geolocation data with your consent for airport detection. We do not use or disclose sensitive personal information for inferring characteristics about you.
11) Children's Privacy
The Services are directed to adults (18+) traveling through airports and are not intended for children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us immediately at rob@robtasker.com so we can take appropriate steps.
12) "Do Not Track"
Some browsers transmit "Do Not Track" signals. We currently do not respond to such signals in the browser context. You can use device privacy settings to limit location access, ads personalization, and analytics where available.
13) Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will change the "Last Updated" date above and, where material changes occur, notify you through the App, by email, or by other means. Your continued use of the Services after an update constitutes acceptance of the revised Policy.
Lounsy - Rob Tasker
Reykjavik, Iceland
Email: rob@robtasker.com
Privacy Requests
For privacy-related requests (access, deletion, correction, etc.), email us at rob@robtasker.com with the subject line "Privacy Request" and include:
- Your full name and email address associated with your account
- A description of your request
- Any verification information we may reasonably request
We will respond to verified requests within the timeframes required by applicable law (typically 30-45 days).
Additional Disclosures
- Appeals: If we decline your privacy request, you may appeal by replying to our decision email with the subject "Lounsy Privacy Request Appeal." We will review and respond within the time required by law.
- Data Protection Officer: For GDPR-related inquiries, you may contact our data protection representative at rob@robtasker.com.
Last updated: November 1, 2025. This Privacy Policy is effective immediately for new users and will become effective on November 15, 2025 for existing users.
© 2025 Lounsy. All rights reserved.