- Zero Data Selling: Détour never sells your personal information or location data to third parties or advertisers.
- Obfuscated Geolocation: Your exact GPS coordinates are never broadcast to other users. Distance is always presented as a general radius or neighborhood context.
- Context-First Control: Direct messages only unlock when a Vibe interaction or Match Request is mutually accepted.
- Full Control: You can export, update, or permanently delete your account and personal data at any time.
1. Introduction & Scope
Welcome to Détour. Your privacy and safety are foundational to everything we build. This Privacy Policy explains how Détour Inc. (“Détour”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal information when you use the Détour mobile applications (iOS and Android), website (joindetour.me), and related services (collectively, the “Services”).
By creating a Détour account or accessing our Services, you acknowledge the practices described in this Privacy Policy. If you do not agree with our data practices, please do not use our Services.
Détour Inc. is the data controller responsible for your personal information under applicable data protection laws, including the European Union General Data Protection Regulation (EU GDPR), the UK GDPR, and applicable United States federal and state privacy statutes.
2. Information We Collect
To provide a dynamic, moment-based discovery experience while maintaining community safety, we collect three primary categories of information:
A. Information You Provide Directly
- Account Setup Data: When creating an account, you provide your first name, date of birth (to verify you are 18+), phone number (for SMS OTP verification), email address, gender identity, sexual orientation, and dating/romantic preferences.
- Profile Information: Profile photos, bio text, Icebreaker prompt responses, interests, lifestyle habits, and optional profile details.
- User-Generated Content ("Vibes"): Photos, short-form video clips, and captions you post to the local Vibe feed.
- Interactions & Messages: Vibe passes, match requests, and direct message content sent after a mutual connection is established.
- Verification Data: Photo selfie verification data used strictly to confirm identity, prevent impersonation, and award profile verification badges.
- Customer Support & Feedback: Information, screenshots, and contact details provided when contacting support or reporting safety incidents.
B. Information Collected Automatically
- Precise & Coarse Geolocation: With your permission, we collect precise location data (latitude/longitude) from your mobile device while the app is active to surface nearby Vibes, enable local discovery, and calculate distance.
- App Usage & Activity Logs: Timestamps, features accessed, vibes viewed, match requests accepted, app navigation paths, and session duration.
- Device & Technical Identifiers: Mobile device model, operating system version, unique device identifiers (e.g., IDFV, GAID), IP address, mobile network provider, app crashes, and language preferences.
- Cookies & Local Storage Technologies: Session tokens, security cookies, and local data storage used for authentication and app performance monitoring.
C. Information We Receive From Third Parties
- Social & Third-Party Login Services: If you register using Apple Sign-In or Google Sign-In, we receive basic profile details (such as email and verified identity tokens) permitted by your third-party privacy settings.
- Safety & Anti-Fraud Partners: Information from risk assessment services, phone reputation providers, and law enforcement agencies to identify spam, bots, or malicious accounts.
- User Safety Reports: Other users may submit reports mentioning your account in connection with alleged violations of our Terms of Service or Safety Guidelines.
3. How We Use Your Data
We process your personal information based on specific lawful bases, including contractual necessity, legitimate interests, legal obligations, and your explicit consent:
| Purpose of Processing | Categories of Data | Lawful Basis |
|---|---|---|
| Operating the Discovery Service: Creating accounts, surfacing nearby Vibes, calculating distance, and opening chat channels upon mutual consent. | Account Data, Location, Profile, Vibes, Messages | Contractual Necessity |
| Safety & Trust Enforcement: Detecting bots, preventing harassment, running selfie verification, and moderating explicit content. | Profile, Verification Data, Device Logs, Reports | Legitimate Interests / Legal Obligation |
| Service Personalization: Recommending relevant Vibe feeds and local moments aligned with your preferences. | Usage Logs, Profile Data, Location | Legitimate Interests |
| Service Communication: Sending push notifications for new matches, message responses, and security alerts. | Contact Info, Push Tokens | Contractual / Consent |
| Legal Compliance: Fulfilling subpoenas, tax/accounting requirements, and law enforcement directives. | Account Data, Financial Records, Safety Logs | Legal Obligation |
5. Geolocation & Location Privacy Guarantee
Location is essential for discovering nearby moments, but your personal safety always comes first.
Our Obfuscated Location Commitment
Détour processes precise location data from your mobile device while the app is active solely to calculate proximity. When displaying your distance to other users, we intentionally obfuscate exact GPS coordinates. Other users see only that you are within a general neighborhood context or distance radius (e.g., "2 miles away"), never your exact street address, real-time map marker, or movement path.
Location Controls: You can grant or revoke location access at any time via your device settings:
- iOS: Settings → Détour → Location → Select "Never", "Ask Next Time", or "While Using the App".
- Android: Settings → Apps → Détour → Permissions → Location → Select "Allow only while using the app" or "Don't allow".
Note: If location permissions are disabled, local Vibe discovery will reflect your last known general area or require manual location input.
6. Your Privacy Rights & Choices
Regardless of your geographic location, Détour empowers you with comprehensive control over your personal data:
Right to Access & Know
You can request a copy of the personal information we hold about your account.
Right to Rectification
You can edit or update your profile details directly inside the app at any time.
Right to Erasure (Deletion)
You can permanently delete your account and all associated data via app Settings or email.
Right to Data Portability
You can request an exported copy of your user data in a structured, machine-readable format.
Managing Push Notifications: You can manage notification preferences inside the app under Settings → Notifications or directly within your mobile device settings.
7. United States Regional Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or other US states with comprehensive privacy legislation, you have specific statutory rights:
- California Consumer Privacy Act (CCPA / CPRA): You have the right to request information regarding the categories of personal information collected, the business purpose for collection, and the specific pieces of information retained.
- No Sale / No Sharing for Cross-Context Behavioral Advertising: Détour does not sell your personal information for monetary consideration, nor do we share your personal data with third parties for cross-context behavioral advertising.
- Shine the Light Law (California Civil Code § 1798.83): California residents may request a list of third parties to whom we disclosed personal information for direct marketing purposes during the preceding calendar year. (Détour makes zero such disclosures).
- Non-Discrimination: We will never discriminate against you, deny services, or alter service quality for exercising any of your statutory privacy rights.
To exercise your US state privacy rights, email our legal team at support@joindetour.me with the subject line "US Privacy Rights Request".
8. Data Retention & Account Deletion Policy
We retain your personal data only as long as your account remains active or as needed to provide our Services, resolve disputes, and comply with legal obligations.
Active Data Schedules
- Profile Data & Account Info: Retained while your account is active.
- Vibes Content: Temporary video/photo Vibes expire and are removed from active feeds in accordance with standard feature expiration timers.
- Chat Logs: Messages are stored securely to support your active conversations until you delete the chat or your account.
Account Deletion Process
You can delete your Détour account at any time:
- In-App: Go to Profile → Settings → Account → Delete Account.
- Via Email: Send an email to support@joindetour.me from the email address registered to your account with the subject line "Delete my account".
30-Day Safety Window: Upon account deletion, your profile, Vibes, matches, and chats are immediately hidden from all other users. Your data is permanently purged from our active databases within 30 days. Limited data may be retained in encrypted backups for up to 90 days or where required for legitimate anti-fraud, safety investigations, or legal compliance.
9. Children’s Privacy & Age Restrictions (Strict 18+)
Détour is strictly for adults aged 18 and older. We have zero tolerance for underage account creation.
We do not knowingly collect or solicit personal information from anyone under the age of 18. We enforce date-of-birth verification at signup and utilize selfie verification tools to detect potential age misrepresentation.
If you suspect that a user is under the age of 18, please report them immediately in-app or email support@joindetour.me. If we discover an account belongs to a minor under 18, we will immediately terminate the account and purge all associated personal data.
10. Security & Protection Safeguards
We implement robust administrative, technical, and physical security safeguards designed to protect your personal information against unauthorized access, loss, misuse, or alteration:
- Encryption in Transit: All communications between your mobile device and our cloud servers are encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: Sensitive databases and media files are encrypted at rest using AES-256 standards.
- Strict Access Controls: Internal data access is restricted on a strict need-to-know basis and protected by multi-factor authentication (MFA).
- Continuous Vulnerability Audits: We conduct regular code reviews, automated security scanning, and infrastructure monitoring to safeguard against emerging cyber threats.
While we employ industry-standard security protections, no electronic transmission over the Internet or storage system can be guaranteed to be 100% secure.
11. International Data Transfers
Détour is based in the United States and operates global cloud infrastructure. Information collected through our Services may be stored, processed, or transferred to servers located in the United States or other jurisdictions where our cloud service providers operate.
When transferring personal data outside the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on legal transfer mechanisms including the European Commission’s Standard Contractual Clauses (SCCs), UK Addendum, and equivalent contractual protections to ensure your data receives an adequate level of protection under applicable law.
12. How to Contact Us & Data Protection Officer
If you have any questions, concerns, or privacy requests regarding this Privacy Policy or our data practices, please reach out to our legal and data protection team:
Détour Inc. — Privacy & Legal Team
Email: support@joindetour.me
Website: joindetour.me
Subject Line for Inquiries: "Privacy Policy & Data Inquiry"
EU/UK Data Subjects also have the right to lodge a complaint with their local supervisory authority (such as the Information Commissioner's Office in the UK or relevant EU Data Protection Authority) if they believe our data processing violates applicable law.