Legal
Privacy Policy
Updated
This policy explains what Nomad Life stores about you, why, for how long, who helps us run the service, and the rights you have. Nemax Tech LLC is the data controller.
What we store, and why
- Your account: email address, a protected (hashed) password, your first and last name if you give them, your plan, and your two-factor methods (an authenticator key, the public part of your passkeys). We need these to give you an account and keep it safe.
- What you enter: years, your base, stays with dates, places and notes, and the receipts you upload. This is the service itself; we use it only to show it to you and build the files you ask for.
- Security records: sign ins, failed attempts and account changes, with their time and network (IP) address, plus the IP you signed up from and last signed in from. We keep these to protect your account and the service, which is our legitimate interest. They are deleted after 365 days.
- Support: the messages you send through Support.
- Payments: for a paid plan, Stripe handles your card and billing address. We store only a Stripe customer and subscription reference, your plan and its renewal date. Invoices are kept as long as accounting law requires.
We do not sell your data, show ads, or use analytics or tracking cookies.
Cookies
Nomad Life sets only cookies it needs to work: one that keeps you signed in, one for "Remember me" if you choose it, one that recognizes a device you signed in from (so failed attempts by others do not lock you out), and a short one while a download starts. Your light or dark theme is remembered in your browser only.
Who helps us run the service
- Hetzner (Germany and Finland): the server and its backups.
- Cloudflare: delivers the site and protects it from attacks.
- Google (Gmail): sends our emails, such as confirmations and security alerts.
- hCaptcha: checks that sign ups and password resets come from people.
- Stripe: processes payments for paid plans.
- Have I Been Pwned: when you choose a password, we check whether it appears in known data breaches by sending only the first characters of its hash, never the password.
Some of them may process data outside the European Economic Area; they do so under the safeguards the GDPR requires, such as the European Commission's standard contractual clauses.
How long we keep it
- Your account and everything in it: until you delete the account. Deleting removes your stays and receipts at once.
- Unconfirmed sign ups: deleted after 20 minutes.
- Security records: 365 days. A browser unused for 31 days is signed out.
- Backups roll over within a few weeks, so deleted data leaves them too.
- Billing records: as long as accounting and tax law requires.
Your rights
You can see and change your data in the app, download your receipts, and delete your account on the Settings page. You also have the right to access, correct, delete or move your data, to restrict or object to how we use it, and to withdraw consent you gave. Write to [email protected] from your account's email address and we answer within one month.
You may also complain to a data protection authority: in Bulgaria the Commission for Personal Data Protection, or the authority of the country where you live.
Security
Connections are encrypted, passwords are stored only as strong hashes, the server and backups are access controlled, and you can protect your account with two-factor sign in. We tell you without delay if a breach puts your data at risk.
Who we are
Nomad Life is run by Nemax Tech LLC, Sofia, Bulgaria. Company number (UIC) 207405380, VAT number BG207405380. Write to [email protected], or about your account to [email protected].