Legal · Last updated May 2026

Privacy Policy

This Privacy Policy explains how NomOut (operated by Sidhartha Verma as a sole proprietorship and its future corporate successors) collects, uses, secures, and discloses your information when you access our applications and services. We operate in compliance with PIPEDA and applicable Canadian privacy law.

1.1 Geographic Scope

NomOut is a Canadian business headquartered and operated in Ontario, Canada. The Platform is not intended for residents of Quebec (Law 25, Bill 96 disclaimed) or the European Economic Area / United Kingdom (GDPR disavowed). If you access the Platform from outside our intended scope, you do so entirely at your own risk regarding local data transfer laws.

1.2 Children's Privacy

The Platform is strictly restricted to individuals who have reached the age of majority (18 in Ontario). If we obtain actual knowledge that we have inadvertently collected Personal Information from a minor, we will immediately terminate the account and irreversibly purge all associated data.

1.3 Material Change Protocol

For minor administrative changes, we will update the "Last Updated" date; continued use constitutes implied consent. For Material Changes — fundamental alterations in how we collect, share, or monetize Personal Information — you will be provided advance notice and a mandatory Click-to-Accept prompt upon your next launch.

1.5 Corporate Succession

NomOut is currently a sole proprietorship. If the business incorporates or reorganizes, all rights, obligations, and custody of Personal Information will automatically transfer to the successor entity (e.g., NomOut Inc.), without requiring additional or renewed consent from you.

2.1 Information You Provide

When you register, upgrade, or contact support, we collect identity and contact data (name, email, mobile phone), cryptographically hashed passwords, and communications records with our support team.

2.2 Financial Data & PCI-DSS Severance

NomOut uses third-party PCI-DSS compliant payment processors (e.g., Stripe). NomOut never directly collects, processes, or stores your raw credit card numbers or CVV codes. We receive only encrypted payment tokens and limited KYC data necessary for fraud verification and receipts.

2.3 Automated Telemetry & Anti-Bot Shield

We automatically collect technical identifiers (device model, OS, unique device identifiers, IP address) and behavioral telemetry (scroll patterns, tap locations, session duration). This is used strictly for security telemetry to distinguish human users from automated Discount Brokers or scripts.

2.4 Precision Geolocation

With your OS-level permission, we collect precise geolocation to show nearby Merchants and authenticate Validated Codes. Primarily collected while the app is in use. Opting out via device settings will render discovery and claiming features inoperable.

2.5 Third-Party SSO (Apple/Google)

If you use an email-masking proxy (e.g., "Hide My Email"), NomOut bears zero liability for undelivered transactional emails or account lockouts caused by third-party relay failures.

2.6 Biometric Firewall (FaceID / TouchID)

NomOut does not collect or store biometric data. All authentication occurs locally on your device's secure enclave. We receive only a Success/Fail token.

2.7 User-Generated Content & Metadata

If you upload a profile photograph or review, we may collect metadata (e.g., EXIF data including time and location the photo was taken). You grant NomOut a license to process this metadata to verify content authenticity.

2.8 Inferred Data & Algorithmic Profiling

NomOut generates Inferred Data based on your Platform activity (e.g., cuisine preference from claim history) to optimize "For You" recommendations. You agree that NomOut may de-identify and aggregate this data to create Anonymized Market Analytics, which NomOut owns and may monetize without restriction.

3. OS Modification & Compromised Hardware

Our security relies on native, uncompromised secure enclaves. If you access the Platform using a jailbroken, rooted, or otherwise modified operating system, all privacy and security guarantees are immediately and permanently voided. NomOut bears zero liability for token theft or data interception on compromised hardware.

3.3 Global Data Residency

NomOut operates a global cloud computing architecture. To provide scalable, low-latency services, your data is not stored exclusively in Canada and may be processed in foreign jurisdictions subject to their laws.

5. Third-Party Transfers & Prospective Business Transactions

Pursuant to Section 7.2(1) of PIPEDA, NomOut may disclose Personal Information to a prospective buyer or corporate successor without your explicit consent, strictly for the purpose of evaluating the transaction, subject to a strict NDA requiring the prospective buyer to secure the data and destroy it if the transaction fails to close.

5. Commercial Rights in Anonymized Information

NomOut retains the permanent, unencumbered right to freely use, license, publish, and monetize Anonymized Information (e.g., market trends, neighborhood dining densities, demographic preferences) with investors, Merchants, and third-party analytics firms.

6.4 CASL Communications Protocol

NomOut executes a rigid, multi-tiered communications architecture to ensure compliance with Canada's Anti-Spam Legislation. OS-level push notifications are governed by your device's Operating System; you may revoke access at any time via device settings.

7. Data Retention & Erasure Exemptions

If an account is encumbered by an active Merchant reservation, unsettled negative balance, or ongoing chargeback dispute, the erasure protocol is paused until the obligation is legally resolved. We will refuse data erasure when retention is mandated by law.

7. Member Deceased Protocol

In the event of a Member's passing, NomOut will refuse to grant account access, transfer credentials, or provide historical dining data to next-of-kin, absent a direct court order. Upon receipt of a verified death certificate, NomOut will terminate the account and execute standard erasure protocols.

8. Data Integrity & Physical Harm Exemption

In the event of a Data Poisoning or integrity attack that alters your profile data (including voluntarily submitted dietary restrictions or allergies), NomOut bears zero liability for physical or medical consequences. You retain the non-delegable responsibility to verbally verify all dietary restrictions directly with the Merchant's staff prior to consumption.

9. Core Functionality Waiver

You acknowledge that NomOut's value proposition — matching users with dynamic, yield-managed Merchant discounts — is inextricably reliant upon algorithmic profiling.

Contact

Privacy questions: support@nomout.com · NomOut, Ontario, Canada.