Skip to content

Privacy Policy

Last updated: September 20, 2026

We hold a small amount of information about you, most of which you typed in yourself, and we use it to put you in an age-matched group.

This page says exactly what that is, who else touches it, and how to get it back or have it deleted. Where the honest answer is awkward, the awkward answer is written down.

1. Who is holding your information

Meet40 is operated by Digital Apps LLC, a limited liability company organised in Washington. Digital Apps LLC is the business responsible for the information described here. Two people run it, and both of them can see everything in this policy.

There is no data protection officer, because there are two of us. Write to support@meet40.com and one of the two answers.

2. What we collect, and when

When you take the quiz

  • Your first name. Not your last name — we stopped asking on 12 August 2026 and nothing in the product records one any more. If you signed up before that and gave one, it is still on your record and you can have it removed with a line to support@meet40.com.
  • Your email address.
  • Your mobile phone number. Text reminders are optional. If you opt in, section 5 explains exactly what we send and how to stop them.
  • Which five-year age range you are in — 40 to 44, 45 to 49, 50 to 54, 55 to 59, or 60 and over. Not your date of birth. Section 3 explains why, and why the range cannot be changed afterwards.
  • Your gender, if you tell us. You can decline, and declining does not stop you booking a mixed group.
  • Your postal code, so we can seat you near where you actually are.
  • Your preferences: what sort of thing you would turn up to, a few interests, and a sentence about yourself if you write one.
  • Your profile picture, if you add one. It is stored privately and is not shown before an event. After you and another member have both attended the same approved group, it may appear only in your 1-1 chat and private Meet Again connection page. You can replace or remove it from Profile at any time.

When you ask us to tell you when we open near you

Meet40 runs in part of the Seattle metro. If you put in a postal code we do not cover yet, we offer to let you know when we do — and if you take that offer, we keep two things: the email address and the ZIP code you typed, and nothing else.

  • You do not have to be a member, and most people who do this are not. There is no account, no password and no way to sign in. It is a row with an email address, a ZIP, and the date you asked.
  • We use it for exactly one message — that we have opened near you — and we send nothing else to it. No newsletter, no reminders, no marketing. Today we have sent none at all, because we have not opened anywhere new.
  • It also tells us which city to open next, counted as ZIP codes rather than as people.
  • Ask and we delete it, with no membership to prove and no account to close. Use the form in section 13 or write to support@meet40.com — a request by email is looked up in this list as well as in the member records.

When you book and pay

  • Which meetup you booked, what you paid, and whether it was refunded. Amounts, not card numbers.
  • Stripe handles the card itself. We never see or store your card number. We keep Stripe’s reference for the payment so we can find it to refund it.
  • A password, if you set one on the screen straight after paying. It is hashed by Supabase and we never hold or see the password itself — section 15 says what that means and what it does not.

Around the meetup

  • Whether you came, cancelled, or did not come.
  • Everything you write in your group’s chat, and the time you wrote it. Section 10 is about that in full, because it is the one place on Meet40 where what we hold about you is something you said to another person rather than a fact about you.
  • The short feedback you send the next morning, including anything you write in your own words.
  • If you ask not to be grouped with someone again, we write that down. It is a note a person reads before making a group, and it never feeds anything automatic.
  • If you or somebody else reports an incident, we keep the report. The code of conduct says who reads it, how fast, and what happens to it afterwards.

Automatically, just from visiting

Our host, Vercel, records ordinary server logs — the page requested, a timestamp, a browser string, an IP address — and keeps them for a short period. That happens on every website; it is how a server works, not a decision we made about you.

What we deliberately do not collect

We used to ask about dietary requirements, and we have stopped. The question existed to be passed to a restaurant. We no longer book anywhere and nobody from Meet40 comes along, so there was nobody to pass it to — and nothing in our systems ever read it. We removed the question on 13 August 2026. Anything already recorded is shown only to the two of us and goes to nobody outside this company; we are deleting it. Until then, if you would rather we did not have yours, write to support@meet40.com and we will remove it from your record.

3. Your age range, and why it locks

Meet40 sells one promise: everyone in your group is 40 or over. The first question in the signup is which five-year range you are in, and that answer is how we keep the promise. We use it to check you are eligible, and then a person uses it when building a group, so a group of 41-year-olds and a group of 60-year-olds are not the same group.

Once you have signed up, your age range cannot be changed — not by you on the site, and not by us on request. That is enforced in the database, not by a rule somebody remembers. An answer that can be edited afterwards is not a promise, it is a preference, and the whole product rests on it being a promise.

If you picked the wrong one, write to support@meet40.com. A person will look at it. Correcting a genuine mis-tap is something we can do; quietly moving somebody across the 40 line is not.

We do not ask for a driving licence or a passport and we do not check your age against any document or database. What we have is what you told us, held to honestly.

4. What we use it for

  • To seat you. A person, not a program, builds every group, reading your age, your neighbourhood, your preferences and your note. There is no matching algorithm and we are not building one.
  • To take payment and to refund it. Through Stripe.
  • To email you about your booking. Four messages, and no others: the confirmation and calendar invite when you pay; a notice when registration for your date closes, which is also when free cancellation ends, carrying the exact date and time; one email a few hours before you meet carrying the meeting point and which group you are in, together rather than as two separate messages; and one note the next morning asking how it went.
  • To make the next meetup better. Feedback tells us which meeting points are too loud or too hard to park at, which times of day work, and which groups did.
  • To keep meetups safe. Reports, notes and blocks are read by a person before a group is finalised.
  • To answer you when you write to support.
  • To count how the website is doing, in the limited way described in section 7.

That is the list. We do not use your information to build a profile of you, to score you, or to train anything.

5. How we contact you

Email remains the complete record, plus a calendar invite for the meetup. Opting out of texts does not affect your booking emails or your place.

Message frequency varies with what you book. Message and data rates may apply. Texting is not a safety line; in an emergency call 911.

You can ask us to remove your phone number entirely and still keep your membership. Email support@meet40.com.

6. Cookies, and why there is no banner

We do not show a cookie banner. That is a deliberate decision, not an oversight, and here is the reasoning so you can judge it yourself. The one cookie we set ourselves is strictly functional — it does the thing you asked for by finishing the quiz — and functional cookies do not require prior consent under the law that applies to us. We serve one metro, in Washington State. If we begin advertising into a place that requires consent before any non-essential cookie is set, we will put a banner up before we run the first ad there, not after.

What that means honestly: if you are reading this from the EU or the UK, our ads are not aimed at you, and this page is not claiming to meet a consent standard we have not built.

You can delete our cookie any time in your browser settings. Nothing breaks — the site simply stops recognising you and the quiz starts fresh.

7. Analytics and advertising

Counting visits, without a cookie

We count page views and how far people get through signing up, using PostHog. It is configured with no person profiles, which means it records that a step happened and does not build a record of you across visits. It sets no cookie of ours and it never receives your name, your email, your phone number, your age range or anything you typed in a free-text box — those are stripped before anything is sent.

The Meta pixel, when we are running ads

Most people find Meet40 through a Facebook or Instagram ad, and we have to be able to tell which ads bring people who actually book. When our advertising is switched on, our marketing pages and the signup and booking pages load Meta’s pixel. Meta’s pixel sets its own cookies in your browser — typically _fbp, and _fbc if you arrived by clicking one of our ads — and tells Meta that a browser reached that page. That is advertising technology and we are not going to describe it as anything else.

Three limits we do impose, and they are enforced in the code, not by memory:

  • It never runs on this page, or on any legal page. Reading a privacy policy should not be tracked by the thing the policy describes.
  • It never runs anywhere in your account — your meetups, the people you have met, your settings — or in the founders’ admin tools. Those pages are about you specifically.
  • Meta’s automatic advanced matching is turned off. Left on, it reads the form fields on the page and sends Meta whatever looks like an email address or a phone number. Our signup form has both on it. We switched it off so that cannot happen.

When a booking is paid, our server tells Meta that a purchase happened, so the ad system can learn. It is sent from our server rather than your browser, and it carries the booking reference and the amount, not who you are.

To limit this generally, browser settings and tracker blockers work on us as they do on any site, and Meta’s own ad preferences control what Meta does with what it collects. Blocking any of it has no effect on your booking.

8. Who else sees it

These are the companies that touch your information because they run part of Meet40. Each one gets only what its job needs.

  • Stripe — takes the payment and issues refunds. Stripe gets your email and the amount; Stripe, not us, handles the card.
  • Supabase — the database your record sits in, and where your group’s chat is stored. They host it; they are not reading it.
  • Vercel — runs the website and keeps ordinary server logs.
  • Resend — sends our email, so it handles your email address and the contents of what we send you.
  • Twilio — sends optional transactional text reminders, so it handles your mobile number, the text contents and delivery status.
  • Forward Email — forwards mail sent to our support address to the two founders, so it handles your email address and the contents of what you send us.
  • OpenAI — may draft answers to ordinary in-app support questions. We remove recognizable email addresses, phone numbers and card-number patterns before a question is sent, and we ask OpenAI not to store the response. Safety, legal, privacy and payment disputes go to a founder instead.
  • PostHog — the visit counting in section 7, with no personal details attached.
  • Meta — the advertising pixel in section 7, when ads are running.
  • Nobody at the meeting point. This used to read “the café, or whoever else we book with — gets a first name and a head count”. We do not book anywhere any more: we choose a public place, tell your group to meet there, and that is the end of our involvement. No café, park or anybody else is told your name, that a group is coming, or that Meet40 exists.
  • A lawyer, an accountant, or the authorities — if the law requires it, or to deal with a serious safety matter. We will tell you if that happens to your information unless we are not allowed to. Section 14 says what a legal request means now that we hold messages.

If Meet40 is ever sold or merged, your information would move with the business. We would email you before that happened.

9. What the other people in your group see

A few hours before you meet, everyone booked into your group sees the same small card about each other person: first name, decade of age, the neighbourhood you gave, and the sentence you wrote about yourself. That is about six hours ahead — or by eight the previous evening, if you are meeting early enough that six hours would put it in the middle of the night.

They do not see your email address, your phone number, your postal code, your feedback, or anything you have reported to us — nor a last name or a date of birth, which we no longer hold for anybody who joined after 12 August 2026 and never show for anybody who did. There nobody outside people you have already attended with can look you up. A prior attendee may see a limited first-name-only connection page if both of you have enabled 1-1 chat.

Group chat opens when the meeting point is revealed. After you both attend, either person may start a private conversation if both have enabled 1-1 chat. Nobody can search the wider membership or reach someone they did not attend with. For Your next still-bookable event may appear on that private connection page so an eligible prior attendee can book the same event. That never reveals your meeting point, roster or group, and it never promises that somebody who books will be placed with you. Section 10 is about messaging in full.

Whatever you write in that sentence about yourself is the one thing your group will read. Write it accordingly.

10. Group and 1-1 chat, and who can read it

What the chat is

Each group gets one chat, shared by the people booked into that group and nobody else — the members assigned to it. It opens when the meeting point is revealed. It is text only — no photographs, no files, no attachments — and a link someone types is shown as plain text rather than something you can tap.

Profile pictures are separate from chat: they are never attached to a message or shown in a group chat. They are visible only after recorded shared attendance, in the private 1-1 and Meet Again surfaces described above.

Group chat remains open until you leave it. No chat notifications are sent today; your mute choice will silence them if they are introduced. A 1-1 thread exists only between two prior attendees who have both enabled private chat; either person turning that setting off closes the thread to new messages.

What we store

  • The words of every message, who wrote it, which group it was, and the time.
  • You can take one of your own messages back at any time — there is no time limit. The group stops seeing it and sees a removed message in its place. We still hold what it said, in a place only the two of us can read. A message that caused a report at nine in the evening has to still exist when a founder reads that report the next morning, and somebody who has just frightened another member must not be able to erase the evidence by tapping twice. That copy is held for as long as we hold the rest of the conversation, and it is destroyed if you delete your account.
  • If you block someone in your group, we store that you did, permanently. Nothing tells them, and they never see your name attached to it — but it works in both directions, so their side of that conversation goes quiet too and they will notice. It is not a silent step and we would rather you knew that before you took it. You will never be grouped with that person again — and if the two of you are already booked into the same upcoming group, they are taken off it there and then and one of us finds them another seat. They are not told why. Your own seat does not move.
  • If you report a message, we store the report and which message it was, and it is read by a founder. The person you reported is not told who reported them.

Messages are screened automatically, and delivered anyway

A message containing a web address, a payment-app handle or something shaped like a crypto wallet is marked for a founder to look at. It is still delivered — we do not block or silently alter what you write. The mark exists because the most common way somebody is defrauded after meeting a stranger starts with exactly that sort of message.

Nothing else reads your chat. No advertising system, no analytics tool, and nothing that trains a model. It is not used to decide who you are grouped with.

If you delete your account

This is the one place where deleting everything about you and leaving five other people’s conversation intact pull in opposite directions, and you should know how we resolved it.

Your messages are replaced, not removed. Where your words were, the people in that group see a message from a member who has left, and your name comes off it. The words are destroyed, including the copies of anything you had unsent. What survives is the shape of the conversation, so the other members are not left reading half a discussion with their own replies pointing at nothing.

One exception, and we would rather say it than let you find it. If a message of yours was reported, a copy of that message is inside the report, and reports are kept — section 12 says for how long and why. So “nothing survives” is true of your group’s chat and not quite true of everything: a message somebody reported outlives your account.

If that is not good enough for you, say so at support@meet40.com and a person will talk to you about it rather than pointing at this paragraph.

11. What we never do

  • We do not sell your personal information, and we do not share it for anyone else’s advertising. Under Washington and California law you have a right to opt out of sale — there is nothing to opt out of, because there is no sale.
  • We do not publish member lists, and there is no directory, feed or public profile anywhere in Meet40.
  • We do not use your information for anything romantic. Meet40 is a service for making friends. Nobody is being matched on that basis, ever.
  • We do not read your group’s chat for entertainment or for research. A founder opens one when something has been reported or something is wrong, and every time one of us does, it is written down.
  • We do not send marketing email to people who did not ask for it, and every non-essential email we do send has an unsubscribe link that works.

12. How long we keep it

  • Your member record — for as long as you are a member, and up to two years after your last meetup, so that if you come back we still know you and can avoid re-grouping you with somebody you asked to avoid.
  • Your group’s chat — the same: while you are a member, and up to two years after your last meetup. It is the one thing here we keep for longer than we need to, and the reason is that it is a conversation between six people rather than a record about one, so we cannot expire your half of it without taking pieces out of theirs. Anything a report or a court has attached itself to is kept until that is finished, which can be longer.
  • Payment records — seven years. That one is not our choice; tax law requires it, and it survives a deletion request. It is the amount, the date and the Stripe reference, not your card.
  • Incident reports — three years, or longer if the matter is unresolved or has become a legal one. A report is kept even if the person who filed it, or the person it is about, deletes their account, because deleting a record of harm on request is how the same thing happens to somebody else. Where the report is about a chat message, the report contains a copy of that message, and it is kept with the report.
  • “Tell me when you open near me” — the email address and ZIP from section 2, for up to two years from the day you asked, or until we have opened near you and told you, whichever comes first. If you ask for it to go before then, it goes. Two years is our policy, and today it is enforced by us remembering rather than by anything automatic — there is no job that sweeps the list. We would rather write that here than describe a deletion schedule nothing performs.
  • Server logs — a short period set by Vercel, then gone.
  • Analytics — kept as counts with nothing personal attached, so there is nothing in there to delete.

13. Your rights, and the form

Whatever state you live in, we will do all of this for you. We are not going to make you prove you live somewhere with a good privacy law first.

  • Ask what we hold, and get a copy of it.
  • Correct it if it is wrong — with the one exception in section 3.
  • Have it deleted, apart from the payment and incident records above, and with the one thing section 10 describes: what you wrote in a group’s chat is replaced with a marker rather than lifted out of five other people’s conversation.
  • Stop the email, or take your phone number off our records, without leaving.
  • Complain, to us or to your state Attorney General. Nobody is penalised for asking any of this.

Use the form below, or email support@meet40.com. An email carries exactly the same weight as the form.

Signed-in members can delete their account from Profile without waiting for us. We first cancel any future places, then remove account access and personal information. The public form remains a human-reviewed route because typing an email address does not prove that the person typing it owns that address.

You do not need to be a member to use any of this. Every request is keyed to an email address, not to an account, and we look that address up in both places we could be holding it: the member records, and the “tell me when you open near me” list in section 2. If you only ever typed a ZIP code and an email into that box, this is still your form.

We reply to this address. We cannot act on a request for an address we cannot write back to.

What would you like us to do

Not required. Helpful if you signed up under a different name or a second address.

Now that we hold a conversation between members, this stops being theoretical, so here is the plain version.

A court order, a subpoena or a police request can compel us to hand over what we hold — including your group’s chat. That is true of every company that holds messages, and it is true of us. We are two people with no lawyer on retainer, so what actually happens is that one of us reads the request and takes advice.

  • We do not hand anything over because somebody asked nicely. Not a spouse, not an employer, not a private investigator, not somebody claiming to be police on the phone. A legal request, in writing, or nothing.
  • We give what is asked for and nothing more. A request about one meetup does not get somebody’s year.
  • We will tell you it happened — unless we are legally prevented from telling you, which does happen with police matters.
  • A preservation request stops the clock. If we are told to preserve something, it is held past the retention in section 12 until the matter ends.

The honest summary: the safest message is one nobody is holding. Everything in your group’s chat is being held by us, and could one day be read by somebody neither of us chose. That is a reason to keep the chat for arranging the meetup, and to say the rest of it in person.

15. Security

Your information sits in a managed database that is not reachable from the public internet, behind a service key held by the two founders. The website is served over HTTPS. We do not store card numbers at all — there is nothing there to steal.

Your account has a password, which you choose on the confirm-your-account screen straight after your first booking. We never see it. It is hashed and held by Supabase, who run our sign-in, and there is no screen anywhere in Meet40 — including the two admin screens only the founders can reach — that can show it back to you. We cannot tell you what your password is, and an email from “support” asking you for it did not come from us.

Meet40’s public sign-in page does not email one-time login links. You can use the password you chose after booking, or a Google or Facebook account when that option is shown. If you use another company’s account, it must share the same email address as your Meet40 booking for us to recognise you.

We may also offer signing in through another company’s account. This website is built to accept Google and Facebook, and each is offered only when it is switched on and working: the sign-in page asks our provider what is actually enabled rather than assuming, so a button you can see is a button that works. The company whose button you use learns that you signed in to Meet40, and we receive the name and email address it shares with us. Sign in with Apple is not available yet. Apple can substitute a private relay address for the address you booked with; we will not offer that button until we can link the two only after you prove both belong to you.

Until August 2026 the link we emailed you opened your booking with no sign-in at all, and anyone who was forwarded that email could see the meeting point, your group and the first names of the five people you were meeting. We removed it. Every page about a meetup now asks you to sign in, old links included — they take you to the sign-in page and then on to the right one. It is a step we did not use to ask for, and we think it is the right one: the people in your group agreed to meet you, not to be visible to whoever your inbox reaches.

Your group’s chat is stored as ordinary text, not encrypted end-to-end. It is protected the way the rest of your record is — a database that is not reachable from the public internet, behind a key the two of us hold — and no more than that. Anybody who got that key would be able to read it. We would rather say so than let the word “secure” do work it has not earned.

No small company can promise perfect security and we are not going to. If we ever discover a breach that affects you, we will email you and say plainly what happened and what it means for you.

16. Children, and people under 40

Meet40 is for adults 40 and over. We do not knowingly collect information from anyone under 18, and the site has nothing to offer them.

If somebody under 40 completes the quiz, we tell them they are not eligible and we do not take their money. We keep the record of their answers only briefly.

17. Changes to this policy

We will update this page when what we do changes. The date at the top changes when the words change.

If a change is significant, we will email members rather than quietly editing the page and hoping.

18. How to reach us

Questions about this policy, or about anything we hold: support@meet40.com. A person reads that address, and you will get a person’s answer.