InnerTables

Privacy Policy

Last updated: August 4, 2026

1. Who We Are

This Privacy Policy explains how InnerTables (the “App” or the “Service”) collects, uses, shares, and protects personal information. “InnerTables”, “we”, “us”, and “our” refer to the operator of the Service.

InnerTables is operated by its operator(s), and/or a legal coroprating entity. Our users are today primarily in Israel; the Service may also be used from the EEA/EU, the UK, and the US, and this policy applies to users in all of these regions. Although we operate from Israel, your personal information is primarily stored on servers in the European Union operated by our hosting providers (see Section 18).

Where the EU or UK GDPR applies, InnerTables is the data controller of the personal data described in this policy. For users in Israel, we are the entity that owns and manages the relevant database(s) under the Protection of Privacy Law, 5741-1981.

Contact us at: support@innertables.com for privacy matters and data protection requests (this address also serves as our privacy/DPO point of contact); legal@innertables.com for legal and corporate matters, including our full legal identity and postal address; and support@innertables.com for general help.

2. Scope of This Policy

This policy applies to personal information we collect through the InnerTables mobile and web applications and any related websites, features, and services that link to it (together, the “Service”), including when you contact us for support. In this policy, “personal information” and “personal data” are used interchangeably and mean information relating to an identified or identifiable individual; “cookies” also covers similar technologies such as browser local storage, secure device storage, and SDKs.

This policy does not apply to third parties we do not control - including the independent venues where meetings take place, other users, and third-party websites and services linked from the App - which have their own privacy practices.

By creating an account or using the Service, you acknowledge that you have read and understood this policy. Your use of the Service is also governed by our Terms of Service and Code of Conduct; our Cookie Policy covers cookies and similar technologies. Where we rely on consent, we ask for it separately and you may withdraw it as described in Section 19. If you do not agree with this policy, do not use the Service.

3. Eligibility (18+) and Children's Privacy

The Service is intended solely for individuals 18 years of age or older. Because InnerTables introduces people who then may meet in person or virtually, minors may not use the Service; by using it you represent that you are at least 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete that information and terminate the associated account. If you believe a person under 18 is using the Service, contact support@innertables.com.

4. Information We Collect

Information reaches us in three ways: you provide it directly ( through the app, e.g when you register, complete your profile, create or join meetings, upload photos, send messages, submit ratings, or contact support); it is generated automatically as you use the Service; or we receive it from others - other members (ratings, feedback, and reports about you) and third parties such as a login provider you choose to use. Some information is required for core features; the rest is optional.

4.1 Identifiers and account information

4.2 Profile content

4.3 Location information

The approximate region or city you select, and the approximate distance used to generate suggestions and display venues on a map. Precise device GPS is optional and feature-specific - see Section 10.

4.4 Device and usage data

4.5 Device permissions (camera, photo library, notifications)

Some features use device capabilities behind an operating-system permission prompt. We access them only with your prior permission and only for the purpose described, and you can revoke each permission at any time in your device settings:

4.6 User content

4.7 Meeting participation history

Meetings (tables) you create, join, are invited to, saved, suggested, or interact with in any other way, as well as attendance and participation records, including the other participants and the venue.

4.8 Payment information (if paid features are offered)

If we offer paid features, payments will be handled by a third-party payment processor; we would receive only limited information such as a transaction identifier, payment status, and partial card details. We do not store full payment card numbers.

4.9 Support communications

When you contact us, we collect the contents of your communications, any attachments you include, and related details such as your contact information and the date of the request.

4.10 Information from third parties and other members

5. How and Why We Use Your Information - Purposes and Legal Bases

We use personal information for the purposes below. Where the GDPR or UK GDPR applies, the legal bases we rely on are performance of a contract with you, your consent, our legitimate interests (balanced against your rights), and compliance with a legal obligation, as indicated per purpose. Under Israeli law, we process personal information based on your consent where required, where you voluntarily provide information for a stated purpose, and as otherwise permitted or required by applicable law.

6. Cookies, SDKs and Analytics Technologies

This section is a summary; full details are in our Cookie Policy. We currently use two kinds of technologies:

Separately from the analytics we run ourselves, our hosting and infrastructure providers generate their own operational records in the course of running the platform - such as request and error logs, IP addresses, and infrastructure metrics - which they process to operate, secure, and support their services, and which may include limited built-in usage statistics we do not control.

Signed-in users are identified to our analytics provider by a pseudonymous internal user ID only - never your name or email as the analytics identifier - and the analytics identity is reset when you sign out. Our public landing page runs the analytics provider's JavaScript snippet, which stores a device identifier in cookies and/or local storage.

We use no advertising cookies and no cross-context behavioral advertising. Our no-sale commitment in Section 8 applies equally to information collected through these technologies.

The Service is currently offered to users in Israel, and we do not operate a cookie-consent banner: we rely on the notice given in this policy and our legitimate interests in operating, securing, and improving the Service. If we make the Service available where prior consent is legally required we will request it through a separate, unbundled choice before those technologies are used for you, refusing will be as easy as accepting, and you may withdraw consent at any time without affecting your access. You may ask us to stop analytics processing relating to you at any time by writing to support@innertables.com. Most browsers let you block or delete cookies and local storage, but blocking strictly necessary storage will sign you out and may prevent core functions from working. If we introduce further categories (such as preference cookies), we will update the Cookie Policy first and, where required, request consent before use.

7. Third-Party Service Providers

We use a small number of service providers (“processors”) and may engage more as the Service grows. Providers act on our behalf under our documented instructions, are bound by data-processing agreements (including under Article 28 GDPR, where applicable) and confidentiality obligations, may use personal information only to provide their services to us - not for their own purposes - and must protect it. Except where a provider is expressly named as currently in use, names in this policy are illustrative (“such as”) and may be replaced by similar providers; we will update this policy when our use of providers changes materially. A current list is available from support@innertables.com. Where data is stored and how it is transferred: Section 18.

Providers we currently use:

Categories we may engage: transactional and marketing email/SMS delivery; push notification delivery; crash and error reporting; payment processing; maps and geocoding; and safety, moderation, and identity-verification tools, including AI/ML providers (see Section 14).

8. How We Share Information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as follows:

9. Profile Visibility

Some of your information is designed to be seen by other users so the Service can facilitate connections and meetings. Treat anything in your profile or shared in the App as information other users may see.

9.1 What other users can see

9.2 What is never visible to other users (unless allowed by you)

You can edit much of your profile in the App. Other users may remember, copy, or re-share information you have shown them, and we cannot control what they do outside the Service; our Code of Conduct asks every member to respect other members' privacy off the Service as well.

10. Location Data

Location on InnerTables is approximate. We use it to suggest relevant people, meetings, and venues and to display approximate distances and venues on a map, and we store it as part of your profile, updating it when you change it. Other members see only your approximate distance and/or selected region - never your precise coordinates or real-time position (see Section 9).

Precise device GPS is not required to use the Service. We use it only if you enable a feature that requests it through your device's permission prompt, only for that feature while you use it, and we retain it only as long as necessary for that purpose - we do not build a history of your precise movements.

You can withdraw or limit location (a) in the App, by changing or (where available) removing your selected region, and (b) on your device, by disabling or limiting the location permission - your device settings always take precedence. If you do, suggestions of nearby people, meetings, and venues and the display of approximate distances will degrade or become unavailable; the rest of the Service continues to work.

11. Messaging

The Service includes in-app chat. We store messages to deliver them, maintain conversation history, and support safety and troubleshooting; they are held on our systems and those of our hosting providers, primarily on servers in the European Union (see Section 18). Messages may be reviewed by us (including trusted moderators) when reported or flagged, or where we reasonably believe review is necessary for safety, security, legal compliance, or enforcement of our Terms of Service or Code of Conduct. Automated systems may scan messages and related content to help detect spam, fraud, and safety issues; as explained in Section 14, such systems are imperfect and do not detect all problematic content.

Messages are not end-to-end encrypted. Do not share sensitive information through chat that you would not want retained or, if reported, reviewed.

12. Ratings, Feedback and Data About Other Users

After meetings, users may rate and give feedback about other users. We collect the ratings and feedback you give and those others give about you, with related context such as the associated meeting and timestamps. Ratings about you may be visible to other users as described in Section 9. We use ratings and feedback to provide and improve the Service and for trust and safety, including identifying potentially unsafe behavior.

When you rate someone else, you are providing personal information about another person; keep it accurate, relevant, and respectful, consistent with our Code of Conduct and Terms of Service. If and where the App offers a private feedback or safety-report option, feedback submitted through it is not displayed to other members and is handled as a report under Section 13.

13. Blocking and Reporting

You can block other users and report content or behavior you believe violates our Code of Conduct or Terms of Service (the process is described in the Terms of Service and the Code of Conduct). Blocking and reporting are important safety tools, though not a guarantee of safety.

If you believe you are in immediate danger, contact local emergency services first.

14. Automated Processing and Verification

We may use automated processing, including AI and machine-learning techniques (our own or a provider's), to generate connection and meeting suggestions, power optional features, and support safety functions such as content moderation and detection of spam, fraud, and fake or duplicate accounts. User content (such as messages, profile content, and reports) may be processed automatically for these purposes. Automated systems are not perfect: they may produce errors, miss harmful content, or flag content incorrectly, and we do not represent that they detect all abuse, remove all fake accounts, or keep anyone completely safe. For significant safety decisions, we aim to provide meaningful human involvement where appropriate; where the GDPR applies, you have rights regarding decisions based solely on automated processing (see Section 19).

If we offer verification features (for example, verifying an email address, phone number, selfie, or government-issued ID), verification is optional and performed with your consent; we may use third-party verification providers (Section 7), and we aim to retain verification data only as long as necessary for the verification purpose and legal and safety obligations, handling sensitive materials such as ID images with heightened care. We do not represent that all users are verified or that verification guarantees anyone's identity, intentions, or safety.

15. Sensitive Personal Information

Some information you choose to share may be sensitive or “special category” data - for example, dietary preferences may reveal information about your health, religion, or ethnicity. We do not require any sensitive information to use the Service. Providing it is entirely your choice; if you add such details to your profile, they may be displayed to other users under the visibility rules in Section 9. We process this information to provide the Service (for example, to help accommodate dietary needs when suggesting venues or meetings).

We may process sensitive information as defined under applicable Israeli privacy law. We process such information only for the purposes described in this Privacy Policy and in accordance with the requirements of the Protection of Privacy Law, 5741-1981, and the Privacy Protection (Data Security) Regulations, 5777-2017, as applicable.

16. Data Retention

We keep personal information only as long as necessary for the purposes in this policy, unless a longer period is required or permitted by law. In setting retention periods we consider the amount, nature, and sensitivity of the information, the purposes of processing, whether those purposes can be achieved by other means, and applicable legal, accounting, safety, and reporting requirements.

16.1 Indicative retention periods

The periods below are what we typically aim for - indicative rather than fixed promises:

We retain information beyond these periods where needed to comply with a legal obligation, to establish, exercise, or defend legal claims, at your explicit request, or because of technical limitations of our backup systems.

16.2 The safety retention window

The “safety retention window” is the period during which we keep reports, records of violations, ban and account-removal records, and related safety evidence - for as long as reasonably necessary for safety, security, dispute resolution, and legal purposes, even after the related content or account is removed, and including after account deletion. It may include keeping a minimal set of identifiers, where practicable in hashed or otherwise protected form, sufficient to help keep users removed for safety or fraud reasons from re-registering. Content you shared with others (such as messages you sent) may remain visible to those recipients.

16.3 Deletion, backups, and anonymized data

17. Data Security

We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, use, alteration, disclosure, loss, or destruction - such as encryption in transit, access controls, and internal policies, adjusted to the sensitivity of the information - consistent with the Privacy Protection (Data Security) Regulations, 5777-2017, and the security requirements of the GDPR. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keep your credentials confidential and use the Service safely; if you believe your account has been compromised, contact support@innertables.com.

If a security incident affecting personal information occurs, we will respond and, where required, notify affected individuals and the relevant authorities within the timeframes applicable law requires, including under Israeli data-security requirements and the GDPR.

18. Where Your Data Is Stored and International Transfers

our information may be stored and processed in multiple countries, including but not limited to the European Union and Israel. We select hosting providers and infrastructure that we believe offer reasonable security and reliability, but we reserve the right to change providers, server locations, or processing arrangements at any time without prior notice. Our team operates from Israel. Depending on operational needs, your data may be accessed from or transferred to other jurisdictions. Where personal data is transferred across borders, we endeavor to rely on applicable legal mechanisms such as adequacy decisions, Standard Contractual Clauses, or other lawful bases recognized under applicable data protection laws. However, no transfer mechanism eliminates all risk, and we cannot guarantee that the data protection laws of every country in which your data may be processed will be equivalent to those in your jurisdiction. By using the Service, you acknowledge and consent to the transfer, storage, and processing of your information in countries outside your country of residence, which may have different data protection rules. For questions: support@innertables.com.

19. Your Rights and Choices

You have rights over your personal information; the specific rights depend on where you live. To exercise any right, contact support@innertables.com. We may ask you to verify your identity before acting on a request (and use that information only for verification), and we will respond within the time required by applicable law. You may use an authorized agent where the law permits; we may require proof of the agent's authorization. If we decline a request, we will explain why to the extent the law allows, and you may appeal where an appeal right applies.

19.1 All users, and users in Israel

Regardless of where you live, you can access personal information we hold about you, correct information that is inaccurate, incomplete, or out of date, delete information where supported (see Section 21), object to certain processing, and update your communication preferences. Users in Israel additionally have the rights in the Protection of Privacy Law, 5741-1981, including the right to review information held about them (Section 13) and to request correction or deletion of inaccurate, incomplete, or outdated information (Section 14). We honor the strengthened rights under Amendment No. 13 to the Law, including enhanced access, correction, and deletion rights and transparency about our processing.

19.2 EEA and UK (GDPR)

If you are in the EEA or the UK, you also have the rights the GDPR/UK GDPR provides: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests or for direct marketing, withdrawal of consent at any time (without affecting prior processing), and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as permitted by law (see Section 14). You may lodge a complaint with a supervisory authority - in the UK, the Information Commissioner's Office (ICO); in the EEA, the authority in your country of residence, place of work, or the place of the alleged infringement.

19.3 United States

If you use the Service from the United States, state privacy laws may give you rights to know and access the personal information we hold about you, to correct or delete it, to opt out of "sales," "sharing," and targeted advertising (we engage in none of these - see Section 8), and to exercise your rights without discriminatory treatment. Submit requests to support@innertables.com.

19.4 Privacy controls in the App

In addition to your legal rights, the Service includes day-to-day controls (exact controls may vary by platform and App version):

20. Communications, Marketing and Push Notifications

Transactional messages - account, security, and meeting-related notices - are necessary to operate the Service, are not marketing, and generally cannot be opted out of while you maintain an account (though you can control push notifications as described below).

Marketing. We send marketing communications only where permitted and with your consent where required - including under the anti-spam provisions of Section 30A of the Israeli Communications (Telecommunications and Broadcasting) Law, 5742-1982, and, for the EEA/UK, the GDPR and ePrivacy rules - and every message includes a way to opt out. You can opt out at any time by contacting support@innertables.com.

Push notifications. If you enable them, we process a device push token and deliver notifications via the providers described in Section 7. You can manage or turn them off at any time in your device settings and, where available, in the App.

21. Account Deletion

You can delete your account in the App where that option is available, or by contacting support@innertables.com. When you do:

22. Changes to This Privacy Policy

We may update this policy to reflect changes in our practices, the Service, technology, or applicable law - including when we incorporate the operating legal entity, change service providers, or change where data is stored. When we do, we will revise the “Last updated” date above. If the changes are material, we will notify you in advance, before they take effect - such as by email and/or a prominent notice in the Service - so you can review the updated policy and, if you wish, exercise your rights (including deleting your account) before the changes apply to you. Where required by law, we will seek your consent. Continued use of the Service after an update becomes effective indicates that you have reviewed the updated policy.

23. How to Contact Us and Complaints

Our full legal identity and postal address are available on request from legal@innertables.com.

We encourage you to contact us first so we can address your concern. You also have the right to complain to a supervisory authority: in Israel, the Israeli Privacy Protection Authority; in the EEA, the authority in your country of residence, place of work, or the place of the alleged infringement; in the UK, the Information Commissioner's Office (ICO).

This Privacy Policy works together with our Terms of Service, Cookie Policy, and Code of Conduct, which together govern your use of InnerTables.