Legal
Privacy Policy
Last updated: 2 July 2026
1. Who we are
Loungely ("Loungely", "we", "us") is an airport-lounge discovery service operated from Canada. When we act as the party that decides why and how your personal data is used, we are the data controller. When a third party processes data on our instructions (for example, our email provider), that party is a data processor and we remain accountable for how they handle it.
For anything privacy-related, write to hello@theloungely.com. For requests that are urgent or that concern a rights-holder in the European Economic Area, mark the email "Privacy Request" and we will respond within 30 days.
2. What we collect
We only collect data we need for a specific purpose. Categories:
- Account data. Your email address and, if you provide one, a display name. Required to sign you in and identify your account.
- Product usage. The lounges, airports, and cards you view or save; reviews you write; notifications you schedule for a flight or lounge; searches you run. Required to make the product function for you personally.
- Membership records. If you add loyalty programme details or credit-card memberships, we store the programme name, bank name, tier, and an optional nickname. We never collect card numbers, CVVs, or payment credentials of any kind.
- Consent history. A record of which purposes you have opted into, when you did so, and when you withdrew consent. Retained for audit even after withdrawal.
- Technical logs. IP address, user agent, and timestamps of requests, retained short-term for security and abuse prevention.
3. Why we use it (purposes)
Each purpose below is independent. You can grant or withdraw each one at any time from /profile/privacy, the cookie banner, or by emailing hello@theloungely.com.
- Essential (always on). Signing you in, keeping the site working, protecting against abuse and fraud. Cannot be turned off without breaking the product.
- Anonymized analytics.Aggregated statistics like "how many people searched LAX last month." Individual visitors are never identified in the resulting figures. We use these numbers to decide which airports and lounges get better coverage.
- Partner insights. If you opt in, your travel intent is folded into anonymized aggregates that we may share with vetted airline, airport, and lounge partners so they can improve the products you actually use. The information they receive is aggregate only, with a minimum group size of fifty distinct users per data point (see Section 6). Your individual identity is not shared.
- Product updates & offers. Occasional emails from hello@theloungely.com when a new lounge launches or a partner card unlocks premium access. You can unsubscribe from any such email in one click.
4. Legal basis
For visitors in the European Economic Area and the United Kingdom, our legal bases under the GDPR / UK GDPR are:
- Contract — for essential product functionality tied to your account.
- Consent — for analytics, partner insights, and marketing. Freely given, specific, informed, and unambiguous. Withdrawable at any time.
- Legitimate interest — for security logs, abuse prevention, and defending legal claims. Balanced against your interests before we rely on it.
For visitors in Canada, we rely on meaningful consent as required by PIPEDA and, for residents of Quebec, Law 25. For visitors in California, we follow CCPA / CPRA rules including the right to know, delete, and opt out. For visitors in India, we follow the Digital Personal Data Protection Act, 2023 (DPDPA).
5. We do not sell your personal data
Loungely does not sell identifiable personal information. What we may commercialize is aggregate insights derived from many users at once — never data that points back to an individual.
For clarity under California law: we do not "sell" personal information as the CCPA / CPRA defines it, and we do not "share" personal information for cross-context behavioural advertising. You do not need to use a "Do Not Sell or Share" link because we do neither.
6. Aggregate insights — how it works
If you opt into "Partner insights," your usage is included in nightly aggregation jobs. These jobs compute counts like "X searches for airport Y this week" or "Z members hold card W this month." Every aggregate row that leaves our systems represents at least fifty distinct users. If a bucket would contain fewer, we suppress it entirely — a defence against re-identification called k-anonymity.
The following are never included in aggregate outputs: your email, your name, your IP address, your user agent, your account id, individual timestamps, or precise location coordinates. Location is bucketed to airport (IATA code) at coarsest, and time is bucketed to day, week, or month.
Partners who buy access to these aggregates sign a data licence that forbids resale, re-identification attempts, and any use outside their agreed purpose.
7. Third-party processors
To run the service, we rely on a small number of vetted providers. Each is bound by a data processing agreement that limits what they may do with data on our behalf.
- Supabase (Delaware, USA) — hosts our database and handles authentication. Data at rest is encrypted.
- Vercel (Delaware, USA) — hosts the application and serves web requests. Provides cookieless analytics.
- Resend (Delaware, USA) — sends transactional email (account confirmations, welcome messages, notifications) from our custom domain.
- Upstash (California, USA) — rate-limiting and caching layer, stores only IP hashes and request counts, never account data.
- Cloudflare (California, USA) — bot protection via Turnstile on public forms. Turnstile is privacy-preserving and does not require third-party cookies.
Data may therefore be processed outside your country of residence. Where required (for example, EEA / UK / Swiss residents), we rely on Standard Contractual Clauses and comparable safeguards for these transfers.
8. Retention
- Account data — kept for the life of your account, deleted within 30 days of account deletion.
- Product usage (searches, saved cards, reviews) — kept for the life of your account.
- Notification schedules — kept up to 90 days after the notification window closes, then deleted.
- Consent history — retained after withdrawal for audit purposes for up to 6 years.
- Technical logs — 30 days.
- Aggregate insights — retained indefinitely because they contain no personal data by design.
Longer retention may apply only where required by law (for example, tax or fraud record obligations).
9. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — see what data we hold about you.
- Portability — download a machine-readable copy.
- Correction — fix inaccurate data.
- Deletion — remove your account and associated data.
- Consent withdrawal — turn off any non-essential purpose without giving a reason.
- Object — object to processing based on legitimate interest.
- Complaint— lodge a complaint with your local regulator (for Canadians, the Office of the Privacy Commissioner; for Quebec, the Commission d'accès à l'information; for the EEA, your member-state DPA; for the UK, the ICO; for California, the California Privacy Protection Agency).
Access, portability, deletion, and consent management are available self-service from /profile/privacy. For any right that is not available in the interface, email hello@theloungely.com. We respond within 30 days.
10. Cookies and local storage
We use only first-party cookies and browser storage. We do not use third-party advertising cookies, tracking pixels, or cross-site tracking of any kind.
- Essential cookies — session authentication, security, and preference storage (display currency). Always on.
- Local storage — your consent choices, preferred currency, and small amounts of interface state (last viewed lounge, for example).
- Analytics scripts — Vercel Analytics loads only when you opt in to Anonymized analytics. Even when loaded, it is cookieless and ships no personal identifiers to Vercel.
11. Children
Loungely is not intended for people under 16. We do not knowingly collect data from anyone under 16. If you believe we have, write to hello@theloungely.com and we will delete the account promptly.
12. Security
Data at rest is encrypted by our providers. Data in transit is protected by TLS 1.2 or higher. Access to production systems is restricted, logged, and reviewed. We do not store payment card numbers, banking credentials, or government-issued identifiers.
Despite our controls, no system is invulnerable. If you believe you have found a security issue, email hello@theloungely.com — we welcome responsible disclosure and will acknowledge within two business days.
13. Changes to this policy
When we materially change how we handle your data, we bump the policy version and the cookie banner re-appears so you can review the new choices before continuing. Non-material updates (typos, clarifications) are made in place with the "Last updated" date at the top of this page.
14. Contact
Privacy questions, DSAR requests, complaints, or anything else about your data: write to hello@theloungely.com. We read every message.
