Privacy Policy
Last updated: August 23, 2026 · Applies to neervo.com and Neervo mobile apps
1. Introduction
Neervo Inc. ("Neervo", "we", "us", "our") takes your privacy seriously. This Privacy Policy explains what personal information we collect when you use our platform — including our website at neervo.com and our mobile applications — how we use it, who we share it with, and the choices you have.
Important context: Neervo is a technology marketplace platform. We connect Guests who want to rent private pools with Hosts who list those spaces. Neervo is not a rental provider, does not own any listed properties, and is not a party to rental agreements between Guests and Hosts. This Privacy Policy governs how Neervo handles the personal data you share with us — it does not cover how Hosts may use any information they receive about Guests through completed bookings, which is governed separately by our Terms of Service.
This policy applies to all Neervo users: Guests who book pools and spaces, Hosts who list them, and visitors who browse without an account. By using Neervo, you agree to the practices described here. If you disagree, please discontinue use of our services.
Neervo is operated from the United States. If you access our services from another country, your information may be processed in the US under US privacy laws.
2. What We Collect
Information you provide directly:
- Account details: display name, email address, phone number, password (stored as a one-way hash — never readable), and profile photo
- Bio and preferences: short bio, notification preferences, billing address
- Listings (Hosts only): pool address, photos, description, amenities, pricing, availability calendar, house rules, and cancellation policy
- Booking information: dates, start/end times, guest count, add-on selections, and notes to hosts
- Payment details: billing name and address. Card numbers are collected and stored exclusively by our payment processor Stripe — Neervo never stores or processes raw card data
- Reviews: written reviews and star ratings you submit for completed bookings
- Messages: text content of messages sent through our in-platform messaging system
- Support communications: emails and chat messages sent to our support team or AI assistant
- Identity documents: if you request or are required to complete enhanced verification, you may provide a government-issued ID. This is processed securely and not stored beyond verification purposes
Information we collect automatically when you use Neervo:
- Log data: pages visited, searches performed, listings viewed, bookings initiated, timestamps, referring URLs, and features used
- Device information: IP address, browser type and version, operating system, device type (mobile/desktop), and unique device identifiers
- Location: approximate location derived from your IP address (city/region level). Precise GPS location is collected only on our mobile app and only with your explicit permission
- Cookies and similar technologies: see Section 8 for details
- Transaction data: booking amounts, payout calculations, refund history, and platform fee records
Activity events — what you did on the site:
We record specific things you do so we can see where the site is confusing and fix it, and so we can tell Hosts how their listings are performing. Each record holds a random identifier for your browser, what happened, which listing it involved, and when.
- What we record: searches you run and how many results came back, listings you open, when you pick a date and time, when you start a booking, when a booking is created, when you save a listing, and when you begin or complete signing up
- The identifier: a random string generated in your browser. It is not derived from anything about you, it is never shared with anyone else, and it only becomes connected to your account if you sign in
- What these records do not contain: your IP address, your browser’s user-agent string, or anything you typed other than a search term. That is a deliberate limit — the data is for measuring a funnel, and none of those are needed to do it
- How long: 180 days. After that the individual records are deleted and only day-by-day totals per listing remain, which are not about any particular person
- Your choice: you can turn this off entirely at Your Privacy Choices, and if your browser sends a Global Privacy Control signal we treat that as off without you having to do anything. In the EU, EEA, UK and Switzerland we do not record any of it unless you have told us we may
Hosts see only totals for their own listings — how many people viewed, picked dates, or booked. A Host is never shown who those people were, and never sees anything about a listing that is not theirs.
Information from third parties:
- Stripe: payment status, payout account verification results, and dispute information
- IP geolocation services: approximate city-level location to show relevant search results and weather
- App stores: if you download our app, app stores may share basic download and usage statistics with us
3. How We Use Your Data
We use your information for the following purposes, always limited to what is necessary for each purpose:
Platform operations
Create and manage your account; process bookings and payments; connect Guests with Hosts; send booking confirmations, reminders, and receipts; enable in-platform messaging; reveal listing addresses at the appropriate time before a booking.
Safety & trust
Detect fraud, fake listings, and abusive behaviour; moderate content; investigate reported safety incidents; verify identities where required; comply with legal obligations including responding to lawful government requests.
Product improvement
Analyse how users interact with the platform (using aggregated, anonymised data) to improve search, booking flows, and features; conduct A/B tests; identify and fix bugs.
Communications
Send transactional notifications (booking updates, payment receipts, payout confirmations); provide customer support via email, chat, and our AI assistant.
Separately, we may send promotional email — tips, offers, and reminders about pools you looked at but did not book. Every promotional message carries a one-click unsubscribe link that works without signing in, along with our postal address. Unsubscribing stops promotional email and nothing else: booking confirmations, receipts, cancellation notices and messages about your reservations are not promotional and will keep arriving, because you need them.
We keep a copy of the messages we send you for 90 days, so that support can see exactly what you received when something goes wrong. After 90 days the content is deleted and only a record that the message was sent remains.
Legal & financial compliance
Maintain records required by tax law; respond to audits; enforce our Terms of Service; protect Neervo's legal rights.
Our legal grounds, if you are in the EEA, the UK or Switzerland. Running your bookings and taking payment is performance of a contract. Fraud prevention, security and keeping the platform safe rest on our legitimate interests, balanced against your rights. Tax and accounting records are a legal obligation. Measuring how the site is used, and sending promotional email, rest on your consent — which is why you are asked first, and why you can withdraw it at any time as easily as you gave it, at Your Privacy Choices. Withdrawing consent does not make our earlier processing unlawful, and it never affects a booking you have already made.
We do not use your personal information for automated profiling or decision-making that produces legal or similarly significant effects on you without human review.
5. Data Retention
We keep your personal information only as long as necessary for the purposes described in this policy, and no longer than required by law:
| Data type | Retention period | Reason |
|---|---|---|
| Account & profile data | Active account + 30 days after deletion | Platform operations |
| Booking records | 7 years after completion | Tax & financial compliance |
| Payment records | 7 years | IRS / financial regulations |
| In-platform messages | 2 years | Dispute resolution |
| Support communications | 3 years | Service quality & legal |
| Audit logs (security) | 2 years | Security & fraud investigation |
| IP / access logs | 90 days | Security & debugging |
| Activity events (browsing) | 180 days, then aggregated | Product improvement; Host performance totals |
| Copies of emails & texts we sent you | 90 days | Support & delivery investigation |
| Marketing preferences | Until opt-out + 30 days | Compliance |
| Record of your privacy choices | Account lifetime + 3 years | Proof of consent (GDPR Art. 7(1)) |
| Unsubscribe / suppression list | Indefinitely — see note below | Honouring your opt-out |
When data is deleted, it is permanently removed from our live systems within 30 days and from backups within 90 days.
Why we keep your address on the unsubscribe list even after you leave. If you unsubscribe and later close your account, deleting the record of your unsubscribe would mean we no longer know you asked us to stop — and if your address ever came back to us, we would email you again. Keeping the minimum needed to honour the request is what makes the request permanent. The entry holds your email address and the fact that you opted out, nothing else. You can ask us to remove it, but that removes the protection along with the record.
6. Your Rights & Choices
Most of this you can do yourself, right now.
You should not have to email anyone to change your own settings, so you do not have to:
- Your Privacy Choices — turn usage measurement on or off, opt out of any sharing for advertising, choose what email you receive, and see a dated record of every choice you have made
- Unsubscribe without signing in — the link at the bottom of any promotional email works on its own, and keeps working for as long as you have the message
- Your profile → Security — download everything we hold about you as a JSON file, or close your account
- Global Privacy Control — if your browser sends this signal we honour it automatically, wherever you are, and whether or not you have an account
Depending on where you live, you may have some or all of the following rights regarding your personal information:
To exercise any right, email privacy@neervo.com. We will respond within 30 days. We may need to verify your identity before processing your request.
7. Security
We implement layered security controls to protect your personal information:
- Encryption in transit: all data transferred between your device and our servers uses TLS 1.2+ (HTTPS)
- Encryption at rest: sensitive data fields are encrypted at the database level
- Password protection: passwords are hashed using bcrypt with a high work factor — we cannot read your password
- Authentication: short-lived JWT access tokens (24 hours) with 90-day refresh tokens; automatic session expiry
- Payment security: Stripe is PCI-DSS Level 1 certified; we never handle raw card data
- Access controls: internal access to personal data is role-based and logged
- Infrastructure: hosted on AWS with VPC isolation, security groups, and automated vulnerability scanning
Despite these measures, no system is perfectly secure. In the event of a security incident affecting your personal data, we will notify affected users within 72 hours as required by applicable law, and we will provide information about what happened, what data was involved, and what you can do to protect yourself.
Your role: Use a strong, unique password for your Neervo account and do not share your login credentials with anyone.
9. Children's Privacy
Neervo is intended for users 18 and older. We do not knowingly collect personal information from individuals under 18. If you believe a child has created an account or provided us with personal data, please contact us immediately at privacy@neervo.com. We will investigate and delete any such data promptly.
Children under 18 may use Neervo only under direct supervision of a parent or legal guardian who has accepted these Terms and this Privacy Policy on their behalf.
10. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights:
- Right to Know: request disclosure of personal information we collect, use, disclose, and sell
- Right to Delete: request deletion of your personal information, subject to legal exceptions
- Right to Correct: request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: Neervo does not sell your personal information for money and does not share it for cross-context behavioural advertising. You can still register the opt-out, and we honour it — at Your Privacy Choices, or automatically via a Global Privacy Control signal from your browser. The opt-out works whether or not you have an account, because the regulations require it to reach a pseudonymous profile too
- Right to Limit Use of Sensitive Personal Information: we use sensitive personal information (payment data, precise location) only as necessary to provide our services
- Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights
To submit a California privacy request, email privacy@neervo.com with the subject line "California Privacy Request". We will respond within 45 days. You may submit a request on behalf of another person with appropriate proof of authorisation.
Categories of personal information collected in the last 12 months: Identifiers (name, email, IP, and the random browser identifier described in Section 2); commercial information (bookings, transactions); internet or other electronic network activity (usage logs, device data, and the activity events in Section 2 — searches run, listings viewed, dates picked, bookings started); geolocation (approximate); communications (messages, support records, and copies of email we sent you); financial data (billing details, via Stripe); inferences drawn from the above to understand preferences.
Categories sold or shared: none. Categories disclosed for a business purpose: identifiers, commercial information and financial data, to the processors named in Section 4 — payment, hosting, email and SMS delivery, and support — each of which may use it only as we direct.
Sensitive personal information. We collect payment details (through Stripe) and, on the mobile app with your permission, precise location. We use both only to provide the service you asked for, and we do not use or disclose either to infer characteristics about you — so the “right to limit” has nothing further to restrict.
11. International Transfers
Neervo's servers are located in the United States (AWS us-east-1, N. Virginia). If you access our services from outside the US — including from the European Economic Area, United Kingdom, or other jurisdictions with data protection laws — your personal information will be transferred to and processed in the US.
For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as the legal mechanism for transfer. By using Neervo, you acknowledge that US privacy laws may differ from those in your country.
12. Policy Changes
We may update this Privacy Policy to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send an email notification to registered users at least 14 days before changes take effect
- Display a prominent notice in the app
Continued use of Neervo after the effective date of any update constitutes acceptance of the revised policy. Previous versions of this policy are available upon request.
13. Contact Us
Questions, concerns, or requests about this Privacy Policy or your personal data? Reach our Privacy Team:
For urgent safety or security concerns, email safety@neervo.com — monitored daily.