HomePrivacy Policy
Privacy Policy
How Kinly collects, uses, shares, and protects personal information when you use our apps, websites, and related services.
Last updated August 2026
Kinly privacy policy draft v0.3 ·
INTERNAL DRAFTING NOTE — remove before publishing
v0.3 applies your approved corrections from the v0.2 factual validation (kinly-privacy-policy-v0.2-validation.md), exactly as you decided them — nothing else was touched. Changed sections: §3.4 (added the Place/Destination governance explainer you provided), §3.6 (restored the location-history open flag, dropped in v0.2), §3.7 (softened the message-visibility claim), §3.10 (removed "advertising identifiers," limited to session/auth/analytics-SDK language), §5 (softened the sale/ad-network statement, added a pixel/SDK confirmation flag), §6 (disaggregated AI purposes into per-feature status tags), §13 (split markets into primary launch vs. configured/staging), §15 (stripped the number "16" entirely), §17 (stripped the affirmative "no DPO" claim). §3.11 (facial/voice recognition) wasn't part of this round's decisions, so it's unchanged from v0.2.
Escalated to counsel (per your list — not resolved here, carried forward for pre-launch sign-off):
Confirm the designated Singapore DPO contact (e.g., a dpo@kinly.app-style address) to satisfy PDPA Section 11's designation requirement. Review whether any third-party analytics in use (once named) trigger broader statutory "sale/sharing" opt-out obligations in secondary expansion markets. Confirm cross-border transfer mechanisms (e.g., SCCs or an intra-group data transfer agreement) between the Singapore entity and any regional operations in Malaysia, Thailand, or the Philippines.
Still open from earlier rounds, unresolved by this pass: data hosting/residency location(s); minimum age itself (now a clean placeholder, not a number); DPO identity; privacy-contact address; whether Kinly performs image/audio AI analysis (§3.11); whether Kinly retains location history (§3.6, now explicitly reopened); recommendations/classification/media-generation AI status (§6, only two of five purposes got a status from you this round — the rest are still [CONFIRM WITH KINLY]).
Kinly Privacy Policy
Version: 0.3 (draft — not published) Effective date: [to be set on publication] Controller: G Prestiges Resources Pte Ltd (UEN 201004189E), 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051, incorporated in Singapore ("Kinly," "we," "us") Applies to: the Kinly website, mobile application(s), and related services at kinlypin.com
1. Introduction
This Privacy Policy explains what personal data Kinly collects, why, how it's used and shared, and the choices and rights available to you. It applies to everyone who uses Kinly — people discovering places and talent ("Users" or "Persons"), businesses and destinations with a Kinly listing ("Businesses"), and talent/creator profiles ("Talent"). Where a section applies to only one of these groups, that's stated explicitly.
This Policy should be read alongside Kinly's Consumer Terms, Business Terms, Talent Terms, and Payments & Refund Policy, which govern the underlying relationships and payment mechanics this Policy describes the data side of (see §16).
Kinly is not one thing to one kind of person — it's a platform connecting several different parties. So before the detailed sections, it's worth being explicit about who those parties are, because this Policy treats them as genuinely different data subjects rather than folding them into one generic "user."
2. Kinly's data subjects, briefly Person / User — an individual with a consumer account, discovering places and talent, saving items, messaging, applying to jobs, booking, and purchasing. Business — an entity (or its authorised staff) operating a Place, publishing listings, vouchers, or campaigns, and receiving Leads or bookings. Talent — an individual or entity offering a professional service, maintaining a profile and portfolio, and receiving bookings or job applications. Place / Destination — the location or venue itself. This is not a person, but Place data appears throughout this Policy because it's often linked to a Business's personal/contact data — see §3.4.
A single individual can hold more than one of these roles (for example, a Talent who is also a consumer User) — where that happens, each role's data is still governed by the section relevant to that role.
3. Information we collect 3.1 Person / Consumer information Account information — name, email and/or phone number, password/authentication credential. Public profile — photo, bio, and any other field you choose to make visible (see §7 for the public/private distinction). Preferences & saved items — settings, saved places, saved vouchers/deals. Location — see §3.6 (kept separate from Place data, §3.4). Vouchers/deals — which offers you've collected and redeemed. Bookings, orders, tickets — details of what you've booked, ordered, or purchased. Job applications — the content of applications you submit, and your Employment Profile where you've built one (see §3.2 for how this differs from your Public Profile). Messages & leads — see §3.7. Interactions & reviews — your activity on Kinly (views, saves) and any reviews or feedback you post. 3.2 Business information Business account & identity — registration details, admin/staff contact information, and information submitted to claim or verify a listing. Business profile — public listing content, category, hours, description. Place/Destination relationship — which Place(s) the Business operates, and any Destination/tenant relationship (for example, a shop's relationship to the mall it's in) — see §3.4. Offers, vouchers, deals, and campaign participation — content and terms the Business publishes, and its participation in Kinly Campaigns. Bookings/orders received, and payment/payout information — see §3.8 and the Payments & Refund Policy. Customer/Lead information — contact and inquiry details a User sends the Business through Kinly (see §11). Uploaded media — photos, video, and other content the Business posts. Analytics — data about the Business's own performance on Kinly, shown back to the Business. 3.3 Talent information
Talent profiles have two distinct layers, and this Policy treats them as such rather than as one blended "profile":
Public Profile — what's discoverable: bio, portfolio media, categories, and any other field the Talent chooses to make public. Employment Profile — skills, experience, and employment-relevant details the Talent maintains privately as source material for job applications. This is not itself public — it only becomes visible to a specific employer when the Talent chooses to apply using it (see §10).
Also collected: booking information, availability, messages, payout information (§3.8), verification information (submitted to confirm identity/authority), and analytics about the Talent's own activity.
3.4 Place & Destination information
Kinly also maintains information about physical Places and Destinations (for example, a shopping mall and its tenant businesses) that is not necessarily collected from any individual's device. This includes place identity, address, coordinates, category, and — where legally permitted — information from public or licensed third-party map/place data sources, in addition to what a Business or Destination directly provides.
In Kinly's data model, a Place (for example, a specific store or venue) and a Destination (for example, a shopping mall, district, or event complex hosting multiple Places) are distinct entities. Where a Place sits within a Destination, either the verified Business operating that Place or the Destination's own manager may be authorised to update the shared location/venue metadata for it, depending on Kinly's internal place-governance rules; a Place record can persist on Kinly even if the Business operating it changes or the venue is vacated. This section is only about how Place/Destination data is governed and updated — it remains separate from, and is not derived from, an individual User's device location (§3.6).
Where Place/Destination information is linked to a Business's own account data (for example, an admin contact for a specific Place), that link is treated as Business information under §3.2, not as location data collected from a User.
3.5 User-generated content
Photos, videos, reviews, listing descriptions, and portfolio material you, a Business, or Talent uploads. You're responsible for having the rights to what you upload — see the Consumer Terms for the licence you grant Kinly to host and display it.
3.6 Location information
Location is core to how Kinly works. We collect approximate location (from IP or coarse device signals) for general-area relevance, and — only with explicit device permission — precise location (GPS) for nearby discovery, map positioning, and distance-based recommendations. We use this to show relevant places, let you confirm a market/city, rank search and recommendations, and surface nearby deals or campaigns. You can deny or revoke location permission any time via device settings or Settings → Privacy & Legal → Location; Kinly falls back to approximate location or manual city selection.
Real-time location is used to power discovery for that session. Whether Kinly also retains a persistent history of your past locations, beyond what's needed in the moment, is currently [CONFIRM WITH KINLY], pending engineering confirmation — this section will state the actual retention behavior, in either direction, once confirmed, rather than assuming one.
This section covers your location as a User. It's separate from Place data (§3.4), which describes where a business or venue is, not where you are.
3.7 Messages, leads & interactions
When you message another User, or send a Lead to a Business, we process the content, metadata (timestamps, participants), and your interaction history. A message is transmitted solely to the designated participant(s) of that conversation through Kinly's Inbox service. This Policy does not make specific technical claims about end-to-end encryption or the underlying server-storage architecture for messages beyond that — those details are [CONFIRM WITH KINLY / Engineering] and will be added once confirmed. Sending a Lead to a Business means we share your contact details and inquiry with that Business specifically, for the purpose of them responding to you — see §11 for how Lead data is handled once received.
We also process correspondence you send directly to Kinly support, and any records generated in resolving that correspondence.
3.8 Payment, order & booking information
Covered at the level relevant to this Policy — full mechanics live in the Payments & Refund Policy, which this section cross-references rather than duplicates. Where Kinly processes payment, we (or our payment processors, Stripe and Fiuu) collect transaction ID, payment status, amount, currency, its relationship to the order/booking/ticket/voucher it's for, refund status, and — where applicable — payout information and fraud/risk signals from the processor. Kinly does not store full card numbers; payment credentials are tokenised and held by Stripe/Fiuu. Billing information is collected only where actually gathered at checkout for a given product.
3.9 Device, analytics & technical information
Device identifiers, IP address, browser/OS, app version, crash/performance logs, and usage/analytics events, collected automatically to operate, secure, debug, and improve Kinly.
3.10 Cookies & similar technologies
Kinly's website uses cookies and similar local-storage technologies — session/authentication tokens, security, and preferences. Kinly's mobile app(s) use comparable session and authentication tokens, local storage, and functional usage-analytics SDKs to support core app functionality and measure usage. Whether any advertising-specific device identifiers are used is addressed in §5, not here. You can control browser cookies through your browser settings and app-level analytics/permissions through your device's privacy settings; some Kinly functionality may be affected if you disable these.
3.11 Image and audio information
Kinly stores and displays the photos, video, and audio you, a Business, or Talent upload, as content — for example, a Talent's portfolio video, or a Place's listing photos. Kinly does not perform facial recognition or voice identification analysis on this content. Whether any AI-assisted content moderation uses automated image classification (as opposed to human review) is currently [CONFIRM WITH KINLY] — this section will be updated to describe that accurately, in either direction, once confirmed, rather than silently omitting it or overclaiming it.
3.12 Inferred information
Kinly personalizes search, discovery, and recommendations based on your activity (what you view, save, and search for) — that necessarily involves some in-the-moment inference about relevance. Whether Kinly maintains a persistent inferred-interest profile beyond this, or uses inference for anything resembling advertising-audience targeting, is currently [CONFIRM WITH KINLY]; this Policy does not currently describe such a profile because it isn't confirmed to exist.
3.13 Information we receive from other sources
In addition to what you provide directly, Kinly may receive information from: a Business or Talent you interact with (for example, a Lead response); other Users (for example, a message sent to you); our payment processors (Stripe, Fiuu); mapping/place data providers, where used; and public or licensed sources for Place information (§3.4). We only use information from these sources for the purpose relevant to why it was shared.
4. How we use information To operate Kinly — create/manage accounts and profiles, provide the map and search, run Places, bookings, orders, tickets, Jobs, messaging, and vouchers/deals, and process payments and payouts. To personalize — search ranking, discovery, map context, and recommendations (§3.12). To power Business and Talent functionality — account management, Lead handling, analytics, campaigns, bookings, customer communication, and applications. For safety — fraud prevention, abuse detection, security, content moderation, and account protection. To improve the platform — analytics, testing, product development, and — where legally permitted — improving Kinly's AI-assisted features (§6). For legal reasons — compliance, responding to legal requests, resolving disputes, and enforcing our agreements. 5. How we share information With the Business or Talent you interact with — only the information necessary for that specific interaction: a Booking, order, Lead, application, message, or voucher/deal redemption. With service providers — companies that help us run Kinly, under contracts limiting their use of your data to providing that service. Categories: payment processors (Stripe, Fiuu — confirmed); hosting/infrastructure, analytics, AI, security, communications, and moderation tooling (category-level; specific vendors not yet confirmed). With other Users — only information you've chosen to make public, or that's inherent to a public interaction (a public review, a public profile). For legal reasons — with authorities, courts, or regulators where required or permitted by law. In a corporate transaction — a merger, acquisition, restructuring, or asset sale, subject to this Policy's protections continuing to apply. As aggregated or de-identified data — only if and when Kinly actually creates and uses this; not currently confirmed as a live practice.
Kinly does not sell personal data for monetary consideration, and does not share personal data with third-party advertising networks for external retargeting as a core part of how Kinly operates. Kinly's Boost and Campaign features are self-serve promotional tools a Business pays for directly — this is not the same as a third-party advertising network buying access to Kinly users' data. Whether any third-party tracking pixels or measurement SDKs are used on Kinly (for example, for internal marketing measurement) is currently [CONFIRM WITH KINLY], and will be disclosed here by name before this Policy is published.
6. AI processing (Kinly AI Service)
Kinly's AI-assisted features run through a single underlying "Kinly AI Service" rather than several disconnected products. Current status by purpose:
Search & discovery ranking — Live / In development. Recommendations — [CONFIRM WITH KINLY]. Business reply assistance — Planned / In evaluation. Content-moderation assistance — Planned / In evaluation. Classification (for example, categorising listings or content) — [CONFIRM WITH KINLY]. Image/media generation — only where actually enabled; status [CONFIRM WITH KINLY].
This Policy describes a feature as live only once Kinly confirms it has shipped, rather than describing planned functionality as though it's already available to users. AI-assisted processing supports a suggestion, ranking, or classification; it does not, on its own, make legally or similarly significant decisions about you without appropriate human oversight. Where the Kinly AI Service calls a third-party AI/model provider rather than processing entirely internally, that provider needs naming as a service-provider category — currently [CONFIRM WITH KINLY]. See §3.11 for what this section does not include (facial/voice recognition).
7. Public vs. private information
Because Kinly has public profiles, public listings, and a public map, it's worth being explicit about what's public and what isn't, rather than leaving it implied.
Generally public: your Public Profile (name, photo, bio you've chosen to share), a Business's public listing, a Talent's Public Profile and portfolio, public reviews and posts, and public Place/listing information.
Generally private: login credentials, private contact information, payment information, private messages, your Employment Profile and any non-public application information (distinct from your Public Profile — see §3.3), and internal verification data.
We don't promise absolute privacy for information you've intentionally made public — that's a different commitment from protecting information you haven't chosen to share.
8. Vouchers, deals & campaigns
When you collect or redeem a voucher or deal, we process your collection and redemption activity, offer eligibility, purchase information where the offer is paid, and transaction/expiry status, so the interaction can be fulfilled between you and the issuing Business. The Business issuing the offer receives redemption information relevant to fulfilling it. Campaign participation and performance data is processed to run the Campaign and to give participating Businesses analytics about their own activity in it.
9. Jobs & applications
Your Employment Profile (§3.3) is information you maintain privately. When you apply to a role a Business has posted, Kinly uses your Employment Profile to help present your application, and the application itself is processed and shared with the hiring Business for recruitment purposes. Per Kinly's intended application handling, an application reflects your Employment Profile as it stood at the time you applied — a later edit to your Employment Profile is not intended to silently rewrite an application you've already submitted. Whether this historical-snapshot behavior is currently implemented as described is [CONFIRM WITH KINLY].
10. Leads / business-customer connections
Sending a Lead to a Business shares your contact details and inquiry with that specific Business. Once received, Kinly's platform-side data (source, type, status, which Business owns it, its relationship to any resulting conversation, and Kinly-side analytics about lead activity) is distinct from what the Business does with your contact information after receiving it — the Business's own handling of your data at that point is governed by its own privacy practices and the Business Terms, not by this Policy.
11. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, authentication safeguards, and vendor security requirements; payment credentials specifically are tokenised by Stripe/Fiuu rather than stored by Kinly (§3.8). We conduct security monitoring and testing appropriate to the data we hold, and maintain an incident-response process. No system is completely secure, and we can't guarantee absolute security — if we become aware of a breach affecting your personal data, we'll notify you and relevant authorities as required by applicable law.
12. Data retention
Retention isn't a single blanket period — it depends on the category of data and why we're holding it:
Account data — retained while your account is active, plus a limited period after closure for security and legal purposes. Transaction, payment & payout records — retained per financial record-keeping obligations, which are often legally mandated and may vary by market (a Country Addendum item). Messages & leads — retained for a limited, purpose-linked period (support, safety, dispute resolution). Application records — retained per the recruitment purpose and any applicable employment-record requirements. Business/Talent verification records — retained for the fraud-prevention and account-authorisation purpose they were collected for. Dispute, fraud & security records — retained as needed to investigate and resolve the specific matter. Regulatory requirements — where a specific market mandates a retention period different from Kinly's general practice, that's addressed through that market's Country Addendum, not invented here.
You can request deletion of your account and associated personal data any time via Settings → Privacy & Legal → Delete my account, or by contacting us (§17). Some data may be retained after deletion where law requires it or a dispute is open.
13. International data transfers
Kinly's Data Controller is based in Singapore, its primary launch market. Malaysia, Thailand, the Philippines, Taiwan, and Mauritius are configured/staging markets for planned expansion and are not necessarily active at the time you're reading this — this Policy will be updated, and relevant Country Addenda published, as each market actually goes live.
This means personal data may be processed in a country other than the one you're in, including [data hosting location(s) — still open]. Where we transfer personal data internationally — including between Kinly's Singapore entity and any regional operations in expansion markets — we use appropriate safeguards required by applicable law, which may include mechanisms such as standard contractual clauses where required.
14. Your rights
Depending on where you're located, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it (for example, marketing or precise location). Most of these can be exercised directly in Settings → Privacy & Legal → Your data, or by contacting us (§17). We'll respond within the timeframe applicable law in your jurisdiction requires. Automated-decision-related rights apply only to the extent Kinly's processing actually involves solely-automated decisions with legal or similarly significant effect — see §6. You may also have the right to complain to your local data protection authority.
15. Children & teens
Kinly is not directed at, and is not intended for use by, anyone below the applicable minimum age: [CONFIRM MINIMUM AGE & PARENTAL CONSENT THRESHOLD PER LAUNCH MARKET]. We don't knowingly collect personal data from anyone below that age. Whether this is enforced by active age verification or a self-declared age requirement at signup is currently [CONFIRM WITH KINLY]. If you believe a child has created an account or provided us personal data, contact us at [privacy contact — TBD] and we'll take appropriate steps to remove it. Where a launch market has its own minimum-age or parental-consent requirement, that's addressed through that market's Country Addendum.
16. Relationship with other Kinly documents
This Policy should be read together with: the Consumer Terms, Business Terms, Talent Terms, the Payments & Refund Policy, and, once published, any Country Addenda and Community/Content rules. Where those documents allocate responsibility between Kinly, a Business, and Talent for a given module, this Policy describes the data-processing side of that same allocation rather than restating it — see the Legal & Responsibility Matrix for the underlying source-of-truth mapping.
17. Contact & data protection
G Prestiges Resources Pte Ltd (UEN 201004189E) 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 Email: [privacy contact — [CONFIRM WITH KINLY] whether legal@kinly.app is the intended privacy-specific contact, or a dedicated address should be used instead]
[CONFIRM DPO DESIGNATION / APPOINTMENT STATUS UNDER SINGAPORE PDPA]. Privacy requests and complaints can be directed to the contact above; this section will name Kinly's designated Data Protection Officer or equivalent role once that status is confirmed.
18. Changes to this Policy
We may update this Policy as Kinly's products and legal obligations evolve. Material changes will be flagged in-app and require renewed acknowledgement where law requires it; minor changes may be posted here with an updated effective date and version number.