NomadPilot
Privacy Policy
Last updated 2 July 2026
Who we are
Nomad Pilot Inc. ("NomadPilot", "we") is the data controller. Registered address: Nomad Pilot Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA. Contact: [email protected]. Our designated Privacy Contact / Data Protection Officer for privacy-specific requests or questions is [email protected].
What we collect
We collect only what we need to run our travel-compliance tools:
- Email address — when you use a readiness checker or join the waitlist, so we can send your result and (with consent) rule-change alerts.
- Passport nationality & destination — the inputs you give a checker, used to compute your result.
- Marketing consent — whether you opted in to alerts, and when.
- Anonymous usage events — page/tool interactions, referrer, and UTM campaign tags, tied to a random session identifier, not to your name.
We do not ask for, or intentionally store, passport numbers, dates of birth, or payment card details on our checker tools.
Why we use it (legal bases)
- To provide the result you asked for — performance of a service you requested.
- To send rule-change alerts — only with your consent, which you can withdraw anytime.
- To improve our tools and understand demand — our legitimate interest in operating and improving the service, using aggregate, non-identifying data.
Data retention
We keep data only as long as it serves the purpose it was collected for:
- Account & email data — retained while your account is active; deleted within 30 days of an erasure request or account closure.
- Rule-change alert subscriptions — retained until you unsubscribe, at which point we suppress future sends and delete the record within 30 days.
- Anonymous usage events — retained in aggregate for up to 24 months for analytics, then deleted; never tied back to your name or email.
- Billing records — retained for 7 years where required for tax and financial compliance, held by our payment processors (Stripe, PayPal) rather than on our own servers.
Subprocessors
We share data only with service providers (subprocessors) that help us operate, each bound by their own data-processing terms:
- Supabase — database & authentication
- Vercel — application hosting
- Resend — transactional email delivery
- Stripe and PayPal — payment processing (we never store full card numbers or PayPal credentials ourselves)
- Groq and Google Gemini — AI providers used to generate travel/relocation guidance
Some of these process data outside your country; where required (e.g. GDPR/UK GDPR transfers) we rely on their Standard Contractual Clauses or equivalent safeguards.
Encryption
Data in transit is encrypted via TLS on every connection to our application (enforced by our hosting and database providers). Data at rest is encrypted at the storage layer by our database provider (Supabase/Postgres, AES-256). Payment details are never transmitted to or stored on our own servers — they go directly to our PCI-compliant payment processors (Stripe, PayPal).
Your rights
Depending on where you live (GDPR, UK GDPR, India's DPDP Act, CCPA and others), you may have the right to access, correct, delete, or port your data, and to withdraw consent. Exercise any of these here: nomadpilot.app/privacy/request. We verify it's you via an emailed link, then act within 30 days. You may also complain to your local data protection authority.
Cookies
See our Cookie Policy.
Changes
We'll update this page and the date above when our practices change.