Privacy Policy
PROVISIONAL: Draft, 2026-08-21. Under attorney review before publication; not yet in effect.
Effective date: [DATE] · Controller: Jauntabout LLC, 2420 Columbia House Blvd Ste 100 PMB 212, Vancouver, WA 98661 · Contact: support@jauntabout.app
Jauntabout is a US-only service for adults (18+). This policy covers the Jauntabout apps and website.
1. The short version
- We collect the minimum needed to build your itineraries: where you are when you ask, when you're free, your vibe and budget picks, your date of birth (once, for the under-21 venue filter), and any food preferences you set.
- We never sell your personal information, and we never share it for targeted advertising.
- Your precise location is sensitive data. We use it to build your itineraries, and we ask consent before collecting it. We may use your location in an anonymized fashion to learn where our app is popular and where we can best improve our services.
- Our systems are built so the itinerary engine, the part that talks to the outside world, cannot access your identity or profile at all (Section 6).
- You can access, correct, delete, and export your data (Section 9).
2. What we collect
You give us:
- Account. Email, password (or sign-in provider), display name.
- Date of birth. Collected once at signup. Used to verify you are 18+ and to derive a single yes/no flag ("is anyone under 21") for filtering alcohol-centric venues. The raw date never leaves our secured profile vault.
- Gender (optional). Only if you choose to provide it. Used for itinerary personalization.
- Food preferences. Cuisines to include and items to avoid. The avoid list may reflect allergies or dietary restrictions, so we treat it as sensitive data (Section 5). It is used only to filter venue suggestions. It is never disclosed and never sold.
- Itinerary requests. Time window, budget tier, vibe, party size and ages.
- Photos you attach to jaunt cards (Section 8).
Collected with your permission:
- Precise location when you request itineraries (to search the area around you) and at app open (to confirm you're in a city we serve).
- Live on-route location. During a jaunt, the live map on your phone uses your continuous location to show your position and walking route; that map is drawn by Google Maps on your device (see below in Section 10). If you turn on jaunt tracking, we record your location roughly every 10 minutes during an active jaunt to build your private jaunt history and we do not receive your continuous location. Off by default. You can stop it any time. See Section 7.
Created as you use Jauntabout:
- Jaunt history. Itineraries delivered, the ones you selected, places you've been.
- Tokens. How many tokens you have, when tokens are added or used, and transfers you send or receive, including a reference to the other account in a transfer.
- Referral attribution. If you signed up through a shared token or referral, a reference linking the sign-up to the sharer. Used to credit rewards. It contains no location or profile data.
- Device and log data. Device type, OS, app version, IP address, timestamps, crash logs.
- Anonymized location data. We use this data to find out where itineraries originate and to improve our service. We always keep this data separated from any other personal data and never re-identify it.
From third parties: payment status from Stripe (we never see your card number; Stripe collects and stores payment details), and sign-in confirmation from your sign-in provider if you use one.
3. What we use it for
- Build and deliver itineraries (location, window, vibe, budget, party, food preferences).
- Run the under-21 venue filter (derived age flag only).
- Manage your tokens: add them with your plan, use them for itineraries, move them when you transfer, and prevent fraud.
- Bill subscriptions (via Stripe) and credit referral rewards.
- Maintain your private jaunt history and any tracking you enabled. If a safety incident or dispute arises from a jaunt, tracking records help establish what happened and where.
- Keep the service secure, prevent fraud, and comply with law.
- Improve curation. When you pick one of your three itineraries, we record an anonymized choice record (the chosen and unchosen itineraries) with no identity attached, to learn what guests prefer.
We do not use your personal information for advertising, do not build advertising profiles, and do not train third-party AI models on it.
4. What we never do
- Never sell personal information (as "sell" is defined in any state law).
- Never share it for cross-context behavioral advertising.
- Never disclose your dietary avoid list or your date of birth to anyone.
- Never put personal information in a QR code or share link. Transfer codes carry only a random claim reference.
- Never give venues or data providers your identity. Venue searches never reveal who is asking.
5. Sensitive information
Three things we hold are sensitive under US state privacy laws: precise geolocation, date of birth, and your food-avoid list (which may indicate health information).
For each, we collect it only with your consent, use it only for the purposes stated in Sections 2 and 3 above, never sell or share it, and never use it to infer anything beyond that purpose. California residents: we do not use or disclose sensitive personal information beyond the purposes allowed by CPRA §7027(m), so no "Limit the Use of My Sensitive Personal Information" action is needed.
6. Built so the engine can't see you
Jauntabout runs as two separated systems. The itinerary engine, the system that searches venue databases and the open web, has no access to guest identities, profiles, or any personal data store. When it needs guest context, a separate broker service verifies your login and hands the engine only a minimal derived packet: an under-21 yes/no and dietary filter IDs. Never your name, birth date, or contact information. Your profile, tokens, and jaunt history live in a separate vault the engine cannot reach, protected by separate infrastructure identities and access controls, with API keys held in a secrets manager.
7. Live tracking and jaunt history
- Jaunt tracking is opt-in per jaunt, visible while running, and stops when the jaunt ends or you stop it.
- Your jaunt history and tracking records are private to your account by default. Sharing is your explicit choice, and shared jaunt cards are stripped of route, timing, and start-location details after the jaunt. Shares reveal what you did, never your movement patterns.
- The tracking record protects both you and Jauntabout: if something goes wrong during a jaunt, it documents where you actually were.
- Jauntabout is not an emergency service. Nobody monitors your location in real time, and tracking must never be relied on for safety or rescue. In an emergency, call 911.
8. Photos and shared cards
Photos you attach are stored with your jaunt history and shown where you choose to share them. We remove location metadata (EXIF/GPS) from shared photos. You are responsible for having permission from people shown. Delete a photo any time; deletion propagates to active shares.
9. Your rights
You can access what we hold about you, correct it, delete it, export it in a portable copy, and opt out of sale, sharing, and targeted advertising, none of which we do. We honor Global Privacy Control signals as an opt-out where applicable. We will never discriminate against you for exercising rights. Submit requests at support@jauntabout.app. We verify by account login or equivalent and respond within 45 days (extendible with notice for a second 45 days). If we refuse a request, you may appeal at the same address.
An authorized agent may act for you where state law provides.
10. Sharing (the complete list)
We share personal information only with:
| Recipient | What | Why |
|---|---|---|
| Google Cloud / Firebase | All service data (hosting) | Our infrastructure |
| Stripe | Billing identity, subscription state | Payments (they hold card data as their own controller) |
| Anthropic | None of your personal information. The AI receives only pre-verified venue data and anonymous request parameters (window, vibe, budget, derived filters) | AI curation of the final three itineraries; our agreement prohibits training on our data |
| Venue-data providers (Foursquare, Ticketmaster, Eventbrite, venue websites) | Search coordinates only, never identity | Finding venues near you |
| Law enforcement / legal | What a valid legal demand compels | Section 12 |
| A successor entity | Service data | Merger or acquisition, under this policy's protections |
No other sharing. We have no advertising or analytics-for-ads SDKs and no data-broker relationships.
Map and walking-route features are provided by Google Maps: your device's location is processed by Google on your device to display the map, and Google's own Terms of Service and Privacy Policy (policies.google.com/privacy) apply to map use.
11. Retention
- Account and profile: kept while your account exists. If you delete your account while you still hold tokens, we keep what your tokens need — your profile and your token records — until the tokens are used or turned over under unclaimed-property law, and we delete the rest, including jaunt history and tracking, within 45 days of your request. Once your last token is used, everything else is deleted within 45 days.
- Precise location used in a request: not retained beyond the request except in your jaunt history.
- Jaunt history and tracking: until you delete it or your account.
- Token records: kept for seven years (a legal obligation under unclaimed-property and tax law), even after account deletion, in minimized form.
- Anonymized choice records: indefinitely (they contain no identity).
- Logs: ninety days.
12. Law enforcement and legal requests
We disclose personal information only under a valid, binding legal demand. We require process appropriate to the data sought (location data demands a warrant or equivalent). We notify you unless legally barred, and we publish no data voluntarily.
13. Security
Encryption in transit and at rest (platform-managed), secrets in a managed secret store, least-privilege service identities, the two-system wall (Section 6), tokens controlled by our servers, and security reviews as a standing engineering practice. No system is perfectly secure. We will notify you and regulators of breaches as law requires.
14. Children
Jauntabout is for adults 18+. We do not knowingly collect information from anyone under 18; a date of birth under 18 blocks signup. If we learn we hold a child's data, we delete it. (Under-13 data is additionally governed by COPPA; the same block-and-delete applies.)
15. Changes
We will notify you of material changes and post changes here with a new effective date. Archive of prior versions on request at support@jauntabout.app.
16. Contact
Jauntabout LLC, 2420 Columbia House Blvd Ste 100 PMB 212, Vancouver, WA 98661. support@jauntabout.app