Skip to main content
The Antidote

Privacy Policy

1. Introduction

Welcome to The Antidote ("The Antidote", "we", "our", or "us").

The Antidote is a digital platform that helps people discover, evaluate and engage with venues, organisations, businesses and services that provide relief from the stress of city living. Our platform also enables venue operators and other organisations to create and manage listings, engage with users, and access subscription-based services.

Respecting your privacy is fundamental to our mission. We recognise that many members of our community place a high value on confidentiality, dignity and trust. We are committed to handling personal information responsibly, transparently and securely.

This Privacy Policy explains:

  • what information we collect;
  • why we collect it;
  • how we use it;
  • how long we retain it;
  • who we share it with;
  • the choices available to you;
  • your legal rights regarding your personal information.

This Privacy Policy applies regardless of whether you access The Antidote through our website, future mobile applications, APIs, integrations, email communications, or any other services we provide.

By using The Antidote you acknowledge that you have read this Privacy Policy.

Where your consent is required by applicable law, we will request it separately before undertaking the relevant processing activity.

2. Scope

This Privacy Policy applies to all individuals who interact with The Antidote, including but not limited to:

  • visitors to our website;
  • users seeking stress relief ("Chillers");
  • venue representatives;
  • professional subscribers;
  • advertisers;
  • prospective customers;
  • suppliers;
  • contractors;
  • job applicants;
  • individuals communicating with our support team;
  • users of future mobile applications;
  • users of future APIs;
  • participants in surveys, competitions or promotional activities.

This Privacy Policy also applies to information collected when:

  • browsing public pages;
  • creating an account;
  • signing into an existing account;
  • saving favourite venues;
  • creating collections or lists;
  • submitting reviews;
  • uploading photographs;
  • communicating with venue operators;
  • claiming or managing business listings;
  • subscribing to paid services;
  • participating in community features;
  • interacting with AI-powered functionality;
  • receiving marketing communications;
  • contacting customer support.

This Privacy Policy does not apply to third-party websites, applications or services that are linked from The Antidote. Those services operate under their own privacy policies.

3. Our Privacy Principles

Our approach to privacy is guided by the following principles.

3.1 Respect

We aim to collect only the information necessary to operate and improve our services.

3.2 Transparency

We explain, in plain language, what information we collect and why.

3.3 User Control

Where reasonably possible, you control your personal information through your account settings and privacy preferences.

3.4 Security

We implement appropriate technical and organisational safeguards designed to protect personal information from unauthorised access, disclosure, alteration and destruction.

3.5 Privacy by Design

Privacy considerations are incorporated into the design and development of new products and features.

3.6 Continuous Improvement

As our platform evolves, we continually review and improve our privacy practices.

4. Definitions

For the purposes of this Privacy Policy:

Account

A registered profile created to access features of The Antidote.

Applicable Privacy Laws

All laws governing the processing of personal information that apply to The Antidote, including but not limited to:

  • the EU General Data Protection Regulation (GDPR);
  • the UK GDPR;
  • the Australian Privacy Act 1988 (Cth);
  • the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
  • and other applicable privacy legislation in jurisdictions in which we operate.

Business Account

An account created for the purpose of managing a venue, organisation or other listing.

Chiller

An individual user of The Antidote.

Personal Information

Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identifiable individual.

Depending upon applicable law, Personal Information may also be referred to as Personal Data.

Processing

Any operation performed on Personal Information including collection, storage, use, disclosure, transmission, analysis, deletion or destruction.

Professional Subscription

Any paid subscription offered by The Antidote for businesses, organisations or other commercial users.

Services

The websites, applications, software, APIs, communications and other products operated by The Antidote.

Venue

Any business, organisation or other location listed on The Antidote.

User Content

Any content submitted by users including:

  • reviews;
  • ratings;
  • photographs;
  • comments;
  • profile information;
  • saved lists;
  • messages;
  • uploaded files;
  • other contributed material.

5. Relationship with our Terms and Conditions

This Privacy Policy should be read together with:

  • our Terms and Conditions;
  • our Cookie Policy;

together with any additional notices provided when specific services are used.

Where there is any inconsistency regarding the processing of Personal Information, this Privacy Policy prevails to the extent required by applicable law.

6. Information We Collect

We collect information in several ways, depending on how you interact with The Antidote.

Some information is provided directly by you, some is collected automatically through your use of our Services, some is obtained from third parties where permitted by law, and some is generated through our operation of the platform.

The categories of information we collect will evolve as our Services evolve. Where new categories of Personal Information require additional notice or consent under applicable law, we will provide this before collecting or processing that information.

7. Information You Provide

7.1 Account Registration

When you create an account, we may collect information including:

  • your name;
  • preferred display name;
  • email address;
  • encrypted password credentials;
  • country or region;
  • preferred language;
  • date your account was created;
  • account preferences;
  • communication preferences.

You are not required to provide your legal name unless necessary for a specific service.

7.2 Optional Profile Information

As additional features become available, you may choose to provide:

  • profile photograph;
  • biography;
  • location;
  • social media links;
  • interests;
  • recovery-related preferences;
  • accessibility preferences;
  • notification preferences.

Providing optional information is entirely voluntary unless clearly identified otherwise.

7.3 Saved Lists and Collections

Where available, we may collect information relating to:

  • favourite venues;
  • saved venues;
  • custom venue collections;
  • wish lists;
  • travel plans;
  • bookmarked content;
  • followed venues;
  • followed organisations.

These features are intended to improve your experience and personalise your use of the Services.

7.4 Reviews and Ratings

When submitting reviews or ratings, we collect:

  • written review content;
  • ratings;
  • uploaded photographs;
  • visit dates (where supplied);
  • edits to reviews;
  • moderation history;
  • reports relating to reviews.

Reviews may become publicly visible in accordance with our Terms and Conditions.

7.5 Communications

When you contact us, we may collect:

  • email correspondence;
  • customer support requests;
  • chat messages;
  • survey responses;
  • feedback;
  • competition entries;
  • feature requests;
  • bug reports;
  • complaint information.

These communications may be retained to improve our Services and resolve disputes.

7.6 Business Accounts

Where you represent a Venue or organisation, we may collect:

  • business contact information;
  • position or role;
  • business email address;
  • telephone number;
  • billing information;
  • subscription information;
  • verification documents;
  • ownership documentation;
  • marketing preferences;
  • support interactions.

8. Information Collected Automatically

When you use our Services, we automatically collect certain technical information.

Depending on your device and browser settings, this may include:

  • IP address;
  • browser type;
  • operating system;
  • device identifiers;
  • device type;
  • screen resolution;
  • language settings;
  • referring website;
  • pages visited;
  • search terms;
  • click paths;
  • timestamps;
  • crash reports;
  • performance metrics;
  • session identifiers;
  • cookie identifiers.

This information helps us:

  • secure the platform;
  • diagnose technical issues;
  • improve performance;
  • understand usage trends;
  • prevent fraud;
  • optimise user experience.

9. Location Information

Depending upon your settings and permissions, we may collect location information.

Location data may include:

9.1 Approximate Location

Derived from:

  • IP address;
  • browser information;
  • regional settings.

Approximate location helps us present locally relevant venues and content.

9.2 Precise Location

Future versions of our Services may request permission to access precise device location.

Precise location may be used for purposes including:

  • finding nearby venues;
  • personalised recommendations;
  • travel assistance;
  • venue navigation;
  • location-based notifications.

You may withdraw access to precise location at any time through your device settings.

10. Cookies and Similar Technologies

We use cookies and similar technologies to operate and improve our Services.

Cookies are small text files stored on your device.

Depending upon applicable law and your consent preferences, cookies may be used for:

  • authentication;
  • remembering preferences;
  • maintaining sessions;
  • measuring performance;
  • analytics;
  • fraud prevention;
  • security;
  • advertising;
  • personalisation.

Where required by law, non-essential cookies will only be used after obtaining your consent.

Further information is available in our Cookie Policy.

11. Analytics

We use analytics technologies to understand how our Services are used.

Analytics information may include:

  • page views;
  • navigation paths;
  • session duration;
  • feature usage;
  • referral sources;
  • aggregated demographic information;
  • conversion metrics;
  • engagement statistics.

Analytics information is generally aggregated or pseudonymised wherever reasonably practicable.

We may use first-party and third-party analytics providers in accordance with applicable privacy laws.

12. Device Information

We may collect information about the devices used to access our Services.

This may include:

  • hardware model;
  • operating system version;
  • browser version;
  • mobile carrier;
  • application version;
  • language settings;
  • accessibility settings;
  • unique device identifiers;
  • push notification tokens.

We use this information to:

  • maintain compatibility;
  • troubleshoot issues;
  • improve reliability;
  • detect abuse;
  • deliver software updates.

13. Information Received from Third Parties

We may receive information from third parties where permitted by law and where doing so supports the operation of our Services.

Examples include:

  • authentication providers;
  • payment processors;
  • fraud prevention providers;
  • analytics providers;
  • advertising partners;
  • business verification services;
  • publicly available sources;
  • venue representatives;
  • social login providers (where used);
  • customer support platforms.

We require service providers processing Personal Information on our behalf to provide appropriate contractual safeguards consistent with applicable privacy laws.

14. Information Generated by Our Services

Some information is created through your use of the platform rather than being directly supplied.

Examples include:

  • account history;
  • moderation records;
  • recommendation history;
  • saved preferences;
  • notification history;
  • customer support history;
  • subscription history;
  • audit logs;
  • fraud detection indicators;
  • AI-generated recommendations;
  • security event logs.

These records help us maintain the integrity, security and functionality of the Services.

15. How We Use Personal Information

We process Personal Information only where we have a legitimate business purpose, a legal obligation, your consent, or another lawful basis under applicable privacy legislation.

Depending on how you use the Services, we may use Personal Information to:

  • provide and maintain the Services;
  • create and manage user accounts;
  • authenticate users;
  • personalise your experience;
  • recommend venues and content;
  • maintain saved lists and favourites;
  • facilitate business account administration;
  • process subscriptions and payments;
  • communicate with you;
  • provide customer support;
  • improve our products and services;
  • develop new features;
  • conduct research and analytics;
  • detect, investigate and prevent fraud;
  • protect users and the platform;
  • enforce our Terms and Conditions;
  • comply with legal obligations;
  • respond to law enforcement requests where legally required;
  • protect our legal rights.

We do not sell Personal Information in the ordinary commercial sense of selling customer databases.

Where certain US privacy laws define "sale" or "sharing" more broadly than ordinary usage, we provide any legally required rights and choices to affected users.

16. Personalisation

One of The Antidote's goals is to provide users with a more relevant and useful experience.

Accordingly, we may use information you provide, together with information generated through your use of the Services, to personalise:

  • search results;
  • venue recommendations;
  • featured content;
  • suggested collections;
  • notifications;
  • marketing communications (where permitted);
  • language preferences;
  • accessibility settings;
  • user interface preferences.

Personalisation is intended to improve usability rather than to make decisions that produce legal or similarly significant effects on individuals.

Where applicable law provides a right to object to certain forms of profiling, we will respect that right.

17. Artificial Intelligence and Automated Processing

The Antidote expects to introduce AI-assisted functionality over time.

AI may be used to assist with activities including:

  • improving search;
  • recommending venues;
  • generating summaries;
  • assisting customer support;
  • detecting spam;
  • identifying fraudulent activity;
  • identifying duplicate listings;
  • moderating submitted content;
  • improving accessibility;
  • improving translations;
  • enhancing platform safety.

AI-generated outputs may occasionally be inaccurate.

Users should exercise their own judgement when relying upon recommendations or generated content.

The Antidote does not use AI to make solely automated decisions that produce legal or similarly significant effects about individuals without appropriate safeguards where required by applicable law.

18. Marketing Communications

We may send communications relating to:

  • account administration;
  • security notifications;
  • service updates;
  • feature announcements;
  • newsletters;
  • venue promotions;
  • events;
  • surveys;
  • product improvements.

Administrative communications are considered necessary for the operation of your account.

Marketing communications will only be sent where permitted under applicable law.

Where consent is required, you may withdraw it at any time.

You may unsubscribe from marketing communications by:

  • following the unsubscribe link in our emails;
  • updating your account preferences;
  • contacting us directly.

Opting out of marketing communications does not prevent us from sending important service-related communications.

19. Sharing Personal Information

We do not disclose Personal Information except where necessary to operate our Services, comply with legal obligations, protect our users, or with your consent.

Depending upon the circumstances, we may share Personal Information with:

  • service providers;
  • cloud hosting providers;
  • payment processors;
  • identity verification providers;
  • analytics providers;
  • customer support providers;
  • fraud prevention providers;
  • security providers;
  • email delivery providers;
  • legal advisers;
  • professional advisers;
  • insurers;
  • auditors;
  • regulators;
  • courts;
  • law enforcement agencies where legally required.

All third-party processors acting on our behalf are required to protect Personal Information through appropriate contractual and organisational safeguards.

20. Business Transfers

If The Antidote undergoes:

  • a merger;
  • acquisition;
  • investment transaction;
  • corporate restructuring;
  • sale of assets;
  • insolvency proceeding;

Personal Information may be transferred as part of that transaction where permitted by law.

Any successor organisation will remain bound by applicable privacy obligations.

Where required, affected users will be notified.

21. International Transfers

As The Antidote expands internationally, Personal Information may be transferred between countries in which we, our affiliates or our service providers operate.

Where required by applicable law, we will implement appropriate safeguards before transferring Personal Information internationally.

These safeguards may include:

  • Standard Contractual Clauses;
  • adequacy decisions;
  • approved certification mechanisms;
  • binding contractual obligations;
  • other legally recognised transfer mechanisms.

We take reasonable steps to ensure transferred information receives an appropriate level of protection consistent with applicable privacy laws.

22. Data Security

Protecting Personal Information is one of our core responsibilities.

We maintain technical and organisational security measures appropriate to the nature of the information we process.

These measures may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • role-based access controls;
  • least-privilege access;
  • authentication controls;
  • audit logging;
  • continuous monitoring;
  • vulnerability management;
  • penetration testing;
  • secure software development practices;
  • backup procedures;
  • disaster recovery planning;
  • incident response procedures.

No security system can guarantee absolute security.

Accordingly, while we take reasonable steps to protect Personal Information, we cannot guarantee that unauthorised access will never occur.

If we become aware of a security incident involving Personal Information, we will respond in accordance with applicable legal requirements, including notification obligations where required.

23. Data Retention

We retain Personal Information only for as long as it is reasonably necessary to fulfil the purposes described in this Privacy Policy, comply with applicable legal obligations, resolve disputes, enforce our agreements, and protect the integrity and security of the Services.

Retention periods vary depending upon the nature of the information and the reason it was collected.

Examples include:

Information CategoryTypical Retention Approach
Account informationUntil account deletion, plus a reasonable period for legal, security and operational purposes
Subscription recordsAs required by financial, accounting and taxation laws
Customer support recordsFor as long as reasonably necessary to resolve enquiries, improve services and protect legal rights
Security logsFor a period appropriate to maintaining platform security and investigating incidents
Analytics informationIn accordance with our operational requirements and applicable law
Marketing preferencesUntil withdrawn or no longer required
Reviews and User ContentUntil removed by the user, removed under our policies, or no longer required for operation of the Services

Where Personal Information is no longer required, we will securely delete, anonymise or de-identify it unless we are required or permitted by law to retain it.

Deletion from active systems may not immediately remove information from encrypted backups, archives or disaster recovery systems. Such copies will be retained only for legitimate operational purposes and will be securely overwritten or deleted in accordance with our backup lifecycle.

24. Your Privacy Rights

Depending upon your location and the laws that apply to you, you may have one or more of the following rights.

These rights are not absolute and may be subject to exceptions permitted by applicable law.

24.1 Right of Access

You may request confirmation of whether we process your Personal Information and request access to that information.

24.2 Right to Correction

You may request correction of inaccurate or incomplete Personal Information.

Where possible, you should first update your information through your account settings.

24.3 Right to Deletion

You may request deletion of your Personal Information where:

  • it is no longer necessary;
  • you withdraw consent where consent is the lawful basis;
  • you successfully object to processing;
  • processing is unlawful;
  • deletion is required by law.

We may retain certain information where permitted or required by law.

24.4 Right to Restrict Processing

You may request that we temporarily restrict certain processing activities while we assess a request or dispute.

24.5 Right to Object

Where processing is based upon our legitimate interests, you may object to that processing.

If we cannot demonstrate compelling legitimate grounds that override your interests, rights and freedoms, we will cease the relevant processing.

24.6 Right to Data Portability

Where applicable, you may request a copy of Personal Information you have provided to us in a structured, commonly used and machine-readable format.

Where technically feasible and legally required, you may request transmission directly to another service provider.

24.7 Right to Withdraw Consent

Where processing relies upon consent, you may withdraw that consent at any time.

Withdrawal of consent does not affect processing undertaken before withdrawal.

24.8 Right to Lodge a Complaint

If you believe we have not complied with applicable privacy laws, you may lodge a complaint with us.

If you remain dissatisfied, you may also contact the relevant supervisory authority or privacy regulator in your jurisdiction.

25. Regional Privacy Rights

25.1 European Economic Area and United Kingdom

Individuals located in the European Economic Area and the United Kingdom may have additional rights under the GDPR and UK GDPR.

Our lawful bases for processing Personal Information may include:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests;
  • consent;
  • protection of vital interests;
  • performance of tasks carried out in the public interest, where applicable.

Where legitimate interests are relied upon, we undertake an assessment to ensure those interests are not overridden by your rights and freedoms.

25.2 California

Residents of California may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Subject to applicable law, these rights may include:

  • the right to know;
  • the right to access;
  • the right to correct;
  • the right to delete;
  • the right to opt out of certain sharing or sale of Personal Information;
  • the right to limit the use of sensitive personal information where applicable;
  • the right not to receive discriminatory treatment for exercising privacy rights.

Where legally required, we will provide methods for exercising these rights.

25.3 Other United States Jurisdictions

Residents of certain US states may have additional rights under applicable privacy legislation.

Where required, we will honour rights provided under those laws, including rights relating to:

  • access;
  • correction;
  • deletion;
  • portability;
  • appeals;
  • targeted advertising;
  • profiling.

25.4 Australia

Individuals located in Australia may have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Where applicable, individuals may request access to or correction of Personal Information and may make privacy complaints in accordance with Australian law.

26. Children's Privacy

The Antidote is intended primarily for adults.

We do not knowingly collect Personal Information from children where doing so is prohibited by applicable law.

If we become aware that Personal Information has been collected from a child in circumstances where parental consent was required but not obtained, we will take reasonable steps to delete that information.

Parents or legal guardians who believe a child has provided Personal Information should contact us using the details provided below.

27. Third-Party Services

Our Services may integrate with or link to third-party products and services.

Examples may include:

  • payment providers;
  • mapping services;
  • authentication providers;
  • analytics providers;
  • communications platforms;
  • social media platforms;
  • cloud infrastructure providers.

We are not responsible for the privacy practices of third-party services.

Users should review the privacy policies of those services before providing Personal Information directly to them.

28. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to our Services;
  • technological developments;
  • legal or regulatory changes;
  • industry best practices;
  • operational improvements.

Where changes are material, we will provide notice through appropriate channels, which may include:

  • publication on our website;
  • account notifications;
  • email communications;
  • other reasonable methods.

The version number and effective date at the beginning of this document will indicate the current version.

Continued use of the Services following the effective date of an updated Privacy Policy constitutes acknowledgement of the revised Policy to the extent permitted by law.

29. Contact Us

Questions, requests and complaints relating to this Privacy Policy or our handling of Personal Information may be directed to:

The Antidote

Email: hello@theantidote.today

Where applicable law requires the appointment of a Data Protection Officer or local representative, their contact details will also be published on our website.

Last updated 3 August 2026

© 2026 The Antidote. All rights reserved.

  • Terms and Conditions
  • Privacy Policy
  • Cookie Policy