Privacy Policy
What we collect, why, where it lives, who can see it, and how you stay in control.
- Version
- 2.3
- Effective
- 11 September 2026
- Last updated
- 14 September 2026, 22:16 CDT
1. Who we are
NexusG8 is operated by Mecca Digital LLC, a Texas limited liability company ("NexusG8", "we", "us"), which runs the platform at nexusg8.com, nxsg8.com, and related addresses (together, the "Service"). We are based in Dallas, Texas, USA.
On the Service, a person's own page is their NexusG8 and an approved organisation's presence is its Community NexusG8. This Policy explains how we handle personal information across both.
This Policy applies to everyone who visits or uses the Service: visitors, members, community administrators, and people who scan a QR code or open a shared link. It does not apply to information a community or business collects from you outside the Service; their own policies cover that.
2. Information we collect
2.1 What you give us
- Account details. Name, email address, a password (stored only as a hash), and, if you sign in with Google or GitHub, the name, email address, and profile picture that provider shares with us. We ask those providers for nothing beyond basic profile and email.
- Your NexusG8. Everything you choose to put on your page: username, photo, headline, bio, links, city or region, profession, skills, goals, needs, offers, and any cards or notes you add. You decide what is public.
- Community information. When you apply to or join a Community NexusG8: your answers to that community's questions, your membership status and role, the date you joined, how you arrived (for example, which QR code or invitation), and community tags.
- Messages to us. Support requests, reports about other members, community applications, and anything else you send us.
- Payment details. If you buy a subscription, our payment partner collects your card details directly. We never see or store your full card number; we receive a record of the purchase, the plan, and its status.
2.2 What is generated when the Service is used
- Page views. When someone opens a NexusG8 page we record the viewer's IP address, browser and device type, the page that referred them, the country, and the time. This powers the analytics the page's owner sees (views, devices, countries, top referrers). One record is kept per viewer per page per hour.
- Link clicks. Which card or link on a page was clicked, with the same technical details.
- Scan and share events. When a QR code, NFC tag, Share Pass, or shared link is used, we record that it was used, from which entry point, and when.
- Security and service records. Login activity, rate-limit counters, error logs, and audit records of administrative actions (for example, who approved a membership).
- Cookies and local storage. See section 8.
2.3 What we do not collect
We do not collect government identification numbers, precise GPS location, biometric data, financial account numbers, or health information, and we ask you not to put such information on your NexusG8. We do not buy data about you from data brokers.
3. How we use information
We use personal information to:
- Run the Service. Create your account, show your NexusG8, keep you signed in, send verification and password emails, and process subscriptions.
- Operate communities. Deliver your application to a Community NexusG8, let its administrators review it, show you the directory you are entitled to see, and deliver community broadcasts.
- Discovery and matching. Suggest people, communities, events, and opportunities that fit your skills, goals, needs, location, and affiliations. Matching starts from the structured fields you provide, not from tracking your behaviour elsewhere.
- The shared-benefit model. NexusG8 shares half of its net profit with approved, active communities, allocated by members, upgrades and activity. To make that work we measure community activity, route sponsorships and opportunities to relevant audiences, and calculate and report each community's share. Sponsors receive aggregate results, not your personal information (section 5.4).
- Improve and build the Service. Understand which features are used, fix problems, test changes, and develop new tools, including AI-assisted discovery and routing. We may use platform data, including your profile fields, to tune our own matching and ranking. We do not hand your data to third-party AI companies for them to train their models.
- Keep the Service safe. Detect fraud, impersonation, spam, scraping, and abuse; enforce our Terms of Service and Community Guidelines; protect members and communities.
- Communicate with you. Service messages (which you cannot opt out of while you have an account) and, where you have opted in, digests and announcements.
- Meet legal obligations and defend legal claims.
3.1 Aggregated and de-identified data
We create statistics and insights that do not identify you, for example "this community has 34 accountants and 12 open mentoring offers". We may use and share aggregated or de-identified data for any purpose, including with Community Partners, sponsors, researchers, and the public. We apply minimum-group-size thresholds so small categories do not point to individuals, and we will not attempt to re-identify anyone from this data.
3.2 Legal bases (for people in the EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (sections 3.1–3.2, 3.7 service messages); legitimate interests (sections 3.3–3.6, 3.8, security, and fraud prevention, balanced against your rights); consent (optional emails, optional features that say they need it, and non-essential cookies if we ever add them); and legal obligation (record-keeping and responding to lawful requests).
4. AI features
If you use an AI feature (for example the bio writer), the text you type and the fields you choose to include are sent to a large-language-model provider through our AI gateway to generate the result. We use these providers under terms that prohibit them from using your content to train their models. AI output is a suggestion; you decide whether to keep it. We do not make automated decisions about you that have legal or similarly significant effects.
5. How information is shared
5.1 What you publish
Anything you set to public on your NexusG8 is visible to anyone who has the address, including search engines. Unlisted, community-only, link-only, and private settings limit who can see an item as described in the product.
5.2 Community NexusG8s you join
A community you join, and its authorised administrators, can see what is reasonably necessary to manage the relationship: your name, photo, headline, the answers you gave them, your role and status, and the fields you have made visible to that community. They do not receive your password, your sign-in provider details, your private items, your activity in other communities, or your payment information. Administrators are bound by the Community Guidelines and, for approved partners, the Community Partner Terms, which prohibit exporting, selling, or misusing member information.
5.3 People you share with
A Share Pass, QR code, or contact download shows exactly the fields you chose for it, nothing else.
5.4 Sponsors and opportunity providers
Where sponsorships or promoted opportunities are offered, we route them to relevant audiences inside the platform. Sponsors receive reach and outcome figures in aggregate. They do not receive your personal information unless you choose to contact or apply to them, at which point what you send them is governed by their policies.
5.5 Service providers
We use a small number of companies to run the Service. They may process personal information only on our instructions and under contracts that protect it:
- Hosting: Hetzner Online GmbH (Nuremberg, Germany) — application servers.
- Database and file storage: Supabase (Frankfurt, Germany region) — your account, page, community, and analytics records; uploaded images.
- Caching and rate limiting: Upstash — short-lived cache entries and abuse counters.
- Email delivery: Resend (United States) — verification, password, and notification emails.
- Sign-in providers: Google LLC and GitHub, Inc. — only if you choose to sign in with them.
- Payments: Stripe, Inc. — subscriptions, one-time purchases, contributions and invoices. Stripe receives your card details directly; we receive a customer reference, the amount and your email.
- AI generation: large-language-model providers via our AI gateway — only when you use an AI feature.
We will update this list when providers change.
5.6 Legal, safety, and corporate
We may disclose information when we reasonably believe it is necessary to comply with law or a valid legal request; to protect the safety, rights, or property of any person or of NexusG8; to investigate fraud or abuse; or in connection with a merger, financing, acquisition, or sale of assets, in which case this Policy continues to apply to the transferred information.
5.7 We do not sell your personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act. We have not done so in the preceding twelve months. We do not run third-party advertising trackers on the Service.
6. Where information is stored and international transfers
Your information is stored in the European Union (Germany). NexusG8 operates from the United States, and some service providers listed in section 5.5 process information in the United States. Where information about people in the EEA, UK, or Switzerland is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. Wherever it is, your information is protected by this Policy.
7. How long we keep information
- Account and page data: for as long as your account exists. After you delete your account we remove or de-identify your personal information within 30 days, except as described below.
- Page analytics (views and clicks): kept while the page exists so its owner's statistics stay accurate; deleted with the page.
- Community records: a community keeps a minimal record that you were a member and when you left, so its history and profit-share reports stay accurate. Your answers and profile details are removed from its view when you leave or delete your account.
- Security, audit, and financial records: up to seven years where needed for fraud prevention, dispute resolution, tax, or legal requirements.
- Backups: encrypted backups roll over within 30 days.
- Aggregated and de-identified data: may be kept indefinitely.
8. Cookies and similar technologies
We use one strictly necessary cookie to keep you signed in, plus security cookies that protect the sign-in process. We store your theme choice and, on demonstration pages, your walkthrough progress in your browser's local storage; that data never leaves your device. We do not use advertising cookies or third-party analytics scripts, so we do not show a cookie banner. If that changes we will ask for your consent first.
9. Security
We protect information with encryption in transit (TLS) and at rest, role-based access controls, row-level security in our database, server-side authorisation on every sensitive action, rate limiting, audit logs, and restricted administrative access. Passwords are stored only as salted hashes. No service is perfectly secure; please use a strong password, keep your devices safe, and tell us at once at privacy@nexusg8.com if you think your account has been compromised. If a breach affects you, we will notify you and any regulator as the law requires.
10. Your rights and choices
Wherever you live, you can:
- Access the personal information we hold about you and receive a copy in a portable format.
- Correct anything inaccurate (most of it you can edit yourself in your account).
- Delete your account and personal information.
- Object to or restrict certain processing, including matching and discovery, by adjusting your visibility settings or by asking us.
- Withdraw consent where processing is based on consent, without affecting what was done before.
- Opt out of non-essential email using the link in any message.
- Complain to us, and to your data protection authority if you are in the EEA, UK, or Switzerland.
California residents additionally have the right to know the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to (all set out above); the right to delete; the right to correct; and the right not to be discriminated against for exercising these rights. Because we do not sell or share personal information, there is nothing to opt out of; we also do not use or disclose sensitive personal information for purposes that require a right to limit. You may use an authorised agent by giving them written permission that we can verify.
To exercise a right, email privacy@nexusg8.com from the address on your account, or contact us through your account settings. We will verify your identity, respond within 30 days (45 days for California requests, extendable once where permitted), and we will not charge you unless a request is clearly unfounded or excessive.
11. Children
The Service is for people aged 18 and over. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect any information from children under 13. If we learn that we have, we delete it. If you believe a child has created an account, email privacy@nexusg8.com. If we ever launch a programme for younger members through schools or community organisations, it will come with guardian consent and its own safeguards, and this Policy will be updated first.
12. Third-party links
NexusG8 pages and Community NexusG8s link out to websites, social networks, payment pages, and event tools that we do not control. Their privacy practices are their own. Check their policies before giving them information.
13. Changes to this Policy
We will post any changes here and update the date at the top. For material changes we will also tell you by email or a notice in the Service at least 14 days before they take effect. Continuing to use the Service after that date means the updated Policy applies.
14. Contact
Privacy questions and requests: privacy@nexusg8.com
Everything else: support@nexusg8.com
Post: Mecca Digital LLC (NexusG8), Dallas, Texas, USA
If you are in the EEA, UK, or Switzerland and are not satisfied with our response, you can lodge a complaint with your local supervisory authority.