Privacy Policy

Privacy
Policy

Last Updated: May 2, 2026

Serendipity, Inc. operates an invite-only social dining service that matches strangers for curated group dinners in Atlanta, Georgia. This policy explains what information we collect, how we use it, who we share it with, and the rights you have over it. It applies to our mobile application, our website, and any related services (the “Service”). If you do not agree with this Policy, please do not use the Service.

01

Scope

This Policy covers personal information we collect from users, applicants, and guests of the Service. It does not cover the independent practices of restaurants or third parties you interact with off-platform.

1.1

This Policy applies to information we collect when you apply for access, create an account, complete onboarding, attend events, or otherwise interact with Serendipity.

1.2

Our relationship with restaurants is limited to booking reservations on your behalf. Restaurants are independent businesses with their own privacy practices, which we do not control.

1.3

This Policy should be read together with our Terms of Service, Community Guidelines, and Acceptable Use Policy.

02

Information We Collect

We collect what we need to run the matching, host the events, and keep guests safe — nothing more. Membership payments are handled by Apple, not us.

2.1

Account Data. Name, email address, phone number, date of birth (for age verification), city, and profile photo.

2.2

Onboarding Questionnaire Responses. Your answers to our 22-question onboarding, including the “Famous Table” selection, music and film lists, behavioral slider inputs, intention-tier responses, and identity-tier responses (which may include demographic information such as gender, age range, and industry).

2.3

Membership & Purchase Data. Membership to Serendipity is sold as a monthly subscription through Apple In-App Purchase. All payments are processed by Apple under the App Store’s terms; Apple shares with us only the limited purchase metadata required to provision your membership (such as the anonymized transaction identifier, product identifier, and subscription status). We do not collect, receive, or store your billing name, billing address, card number, or any other payment instrument details. Refunds, cancellations, and billing disputes are handled by Apple through your App Store account.

2.4

Phone Number & SMS Metadata. Processed via Twilio for one-time passcodes, event reminders, and day-of venue reveal messages. See our SMS Consent Disclosure.

2.5

Device & Usage Data. IP address, device type, operating system, app version, crash logs, session timestamps, and in-app interaction events. Collected via our backend (Supabase) and standard mobile telemetry.

2.6

Location at Event Time. On the day of a confirmed event, we may process approximate location to coordinate logistics (for example, to confirm arrival or troubleshoot last-mile issues). We do not passively track your location outside event windows.

2.7

Constellation Notes. Private notes you write about guests you have met at Serendipity events. These notes are visible only to you and to limited Serendipity personnel for safety review and matching-algorithm inputs. They are not shared with the subject of the note. See our Acceptable Use Policy.

2.8

Communications with Us. Emails, in-app messages, incident reports, and support tickets, including any attachments you provide.

2.9

Information from Referrers. If you were invited by an existing user, we may record the fact of the referral.

03

How We Use Information

Primarily: to match you thoughtfully, to run events, to keep guests safe, and to bill correctly.

3.1

Matching. Onboarding responses and Constellation notes are processed algorithmically to generate table assignments across six archetypes scored on five hidden social dimensions (Energy, Depth, Chaos, Warmth, Edge).

3.2

Event Operations. Booking reservations, confirming headcounts, sending reminders, revealing venues, and coordinating day-of logistics.

3.3

Safety. Investigating incident reports, enforcing our Community Guidelines and Acceptable Use Policy, and protecting guests.

3.4

Membership. Provisioning and maintaining your monthly Serendipity membership purchased through Apple In-App Purchase. Payment, renewal, refund, and cancellation processing is performed by Apple under the App Store’s terms.

3.5

Service Improvement. Debugging, analytics, and product development. Where possible, we use aggregated or de-identified data for these purposes.

3.6

Marketing to Existing Users. Event announcements and product updates. You can opt out at any time without affecting transactional communications.

3.7

Legal & Compliance. Responding to lawful requests, enforcing our agreements, and defending our rights.

04

Legal Bases for Processing

For users in jurisdictions that require them, here are the legal grounds we rely on.

4.1

Contract. Processing necessary to provide the Service you signed up for.

4.2

Legitimate Interests. Safety, fraud prevention, product improvement, and internal analytics, balanced against your rights.

4.3

Consent. Marketing SMS and any processing of sensitive categories of data. You may withdraw consent at any time.

4.4

Legal Obligation. Compliance with applicable law, including tax and accounting requirements.

05

How We Share Information

We share only with the vendors who help us run the Service, the venues who need to know you’re coming, and anyone the law compels us to notify.

5.1

Subprocessors. We use the following third-party service providers. Each is bound by contract to confidentiality and data-security obligations consistent with this Policy:

  • Supabase — authentication, database, real-time sync, edge functions
  • Apple — app distribution, push notifications, and processing of monthly membership purchases via Apple In-App Purchase (governed by Apple’s privacy policy and the App Store terms)
  • Google — app distribution and push notifications
  • Twilio — SMS and one-time passcodes
  • Vercel — admin panel hosting
  • Transactional email provider — [e.g., Postmark, Resend, or SendGrid; specify before launch]
5.2

Restaurants and Venues. We share only the reservation name and headcount with venues. Venues do not receive your questionnaire responses, Constellation notes, or contact information from us.

5.3

Other Guests. Other guests at your table see only the information you present in person and any profile elements you choose to display. We do not disclose your phone number, email, questionnaire responses, or Constellation notes to other guests.

5.4

Law Enforcement & Legal Process. We may disclose information in response to lawful subpoenas, court orders, or where we believe in good faith that disclosure is necessary to prevent imminent harm.

5.5

Business Transfers. In the event of a merger, acquisition, financing, or sale of assets, user information may transfer as part of the transaction. We will notify you of any change in ownership or use of your personal information.

5.6

With Your Consent. Any other sharing will be done only with your explicit permission.

5.7

No Sale of Personal Information. We do not sell your personal information. See Section 10 for California-specific disclosures.

06

The Matching Algorithm & Automated Processing

You are matched by software, not by hand. Here’s what that means and how to get a human involved if you’d like.

6.1

Your questionnaire responses are processed algorithmically to generate compatibility scores and table assignments. The algorithm scores five hidden social dimensions and maps guests to six table archetypes.

6.2

Human operators review and can override algorithmic suggestions before events are finalized.

6.3

You may request human review of a table assignment or removal from algorithmic processing by writing to hello@serendipity.day. Opting out of automated matching may limit your ability to use the Service.

6.4

The algorithm does not make decisions with legal or similarly significant effects on you within the meaning of GDPR Article 22.

07

Data Retention

We keep information only as long as we need it — and longer only when the law or our legitimate interests require.

7.1

Active Account. We retain account data for as long as your account is active.

7.2

Post-Deletion. After account deletion, we delete or de-identify personal information within 90 days, except as noted below.

7.3

Legal & Safety Holds. We retain incident records, safety-related logs, and records subject to legal hold for seven (7) years, or longer where required by law.

7.4

Financial Records. Retained for seven (7) years to comply with tax and accounting obligations.

7.5

Aggregated & De-identified Data. May be retained indefinitely for analytics and product development.

7.6

Constellation Notes. Deleted with your account, except where flagged as part of an open safety investigation.

08

Your Rights

If you’d like to see, correct, export, or delete your data, you can. Here’s how.

8.1

Depending on your jurisdiction, you have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
8.2

To exercise any of these rights, email hello@serendipity.day from the email address on your account. We will verify your identity before acting on the request.

8.3

We will respond within the timeframes required by applicable law — typically 30 to 45 days.

8.4

You have the right to lodge a complaint with your local data protection authority.

09

SMS & Push Notification Consent

SMS and push messages are how we reach you about your table. Here’s how consent works.

9.1

Transactional SMS. By providing your phone number and logging in with it, you consent to receive one-time passcodes, booking confirmations, event reminders, day-of venue reveals, and reservation changes via SMS. These are required to use the Service.

9.2

Marketing SMS. Separate opt-in is required. You can opt out at any time by replying STOP.

9.3

Push Notifications. You can disable push notifications in your device settings without affecting other Service functionality.

9.4

See our SMS Consent Disclosure for full terms.

10

California Privacy Rights (CCPA/CPRA)

If you’re a California resident, here’s what we collect, why, and what you can do about it.

10.1

Categories of Personal Information Collected in the Past 12 Months: identifiers (name, email, phone, IP address); commercial information (Apple In-App Purchase transaction identifiers, subscription status, and event history; we do not collect or store payment card or billing information, which is handled solely by Apple); protected classification characteristics (age, and optionally gender, from onboarding); internet/network activity (usage data); geolocation (approximate, at event time); inferences drawn from questionnaire responses (matching dimensions); and sensitive personal information (precise geolocation on event days; account credentials).

10.2

Sources. Directly from you; automatically from your device; from referring users; from our service providers.

10.3

Business Purposes. As described in Section 3.

10.4

Sales and Sharing. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.

10.5

Sensitive Personal Information. We use sensitive personal information only to provide the Service as reasonably expected and not for inferring characteristics about you for advertising.

10.6

Your Rights. Right to know; right to delete; right to correct; right to limit use of sensitive personal information; right to opt out of sale or sharing (inapplicable, as we do neither); and right to non-discrimination for exercising any of these rights.

10.7

How to Exercise. Email hello@serendipity.day. You may designate an authorized agent to make requests on your behalf.

11

Cookies & Similar Technologies

We use a light touch here — mostly what’s needed to keep you signed in and the app working.

11.1

Our mobile app uses local storage (AsyncStorage) to persist session data.

11.2

Our website and admin panel may use essential cookies for authentication and analytics cookies for aggregated usage measurement.

11.3

We do not use cookies or SDKs for cross-site advertising.

11.4

Do Not Track: because there is no industry consensus on how to interpret Do Not Track signals, we do not currently respond to them. We honor opt-out preferences communicated through supported methods described in this Policy.

12

Children Under 18

Serendipity is strictly 18+.

12.1

The Service is not intended for, marketed to, or available to anyone under 18. We do not knowingly collect personal information from minors.

12.2

If we learn that we have collected personal information from a person under 18, we will delete it promptly. Contact hello@serendipity.day to report such cases.

13

International Users & Data Transfers

Today, Serendipity operates in the United States. If that changes, this section will too.

13.1

The Service is currently offered only to users in the United States. Our infrastructure (Supabase, Twilio, Vercel) operates primarily in the U.S. Apple processes In-App Purchase transactions in accordance with its own privacy practices and App Store terms.

13.2

If you access the Service from outside the U.S., you understand that your information will be processed in the U.S.

13.3

International expansion will trigger additional disclosures and, where applicable, Standard Contractual Clauses or equivalent transfer mechanisms.

14

Security Measures

We take reasonable steps to protect your information, and we hold our vendors to the same standard.

14.1

Encryption in transit (TLS) and at rest for sensitive data.

14.2

Access controls: least-privilege credentials, role-based access in the admin panel, and audit logging.

14.3

Contractor and employee access governed by confidentiality and data-security obligations.

14.4

Incident response procedures described in our internal Incident & Safety Response Protocol.

14.5

No system is perfectly secure. In the event of a material data breach, we will notify affected users and, where applicable, regulators within the timeframes required by law.

15

Changes to This Policy

We’ll tell you when something important changes. Check back from time to time.

15.1

We may update this Policy. Material changes will be announced via in-app notice or email at least 14 days before they take effect.

15.2

Continued use of the Service after the effective date constitutes acceptance.

16

Contact & Data Requests

All privacy inquiries and rights requests should be sent to:

Serendipity, Inc.
Email: hello@serendipity.day
Subject line: “Privacy Request”