KMSTRYKMSTRY

Privacy Policy

Last updated: August 25, 2026

🔒 Your privacy is fundamental to how we built KMSTRY. This Policy explains exactly what data we collect, why, and how you can control it. We do not sell your personal data to advertisers or third parties.

This Privacy Policy applies to KMSTRY FZ-LLC ('KMSTRY', 'we', 'our', 'us') and governs the collection, use, storage, and sharing of personal data through:

  • The KMSTRY mobile application (iOS and Android)
  • The KMSTRY external beta website at staging.kmstry.net
  • The KMSTRY Venue Partner dashboard and advertising tools
  • Any APIs or integrations provided by KMSTRY

By using KMSTRY, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the platform.

1. Data Controller
ControllerKMSTRY FZ-LLC, registered and operating in Dubai, UAE.
Contactadops@brightmindshub.net
DPOData Protection Officer reachable at adops@brightmindshub.net

KMSTRY processes personal data as a data controller. In certain circumstances (such as when processing data on behalf of Venue Partners), we may act as a data processor. These roles are described where relevant in this Policy.

2. Legal Framework

KMSTRY operates primarily under UAE law and takes guidance from:

  • UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data ('PDPL')
  • UAE Federal Decree Law No. 34 of 2021 on Cybercrime
  • DIFC Data Protection Law No. 5 of 2020 (where applicable)
  • GDPR (EU) 2016/679 — applied as a standard of good practice for users in the European Economic Area
  • UAE Telecom Regulatory Authority (TRA) guidance on digital services

Our legal bases for processing personal data include: (a) performance of a contract with you; (b) your explicit consent; (c) compliance with a legal obligation; and (d) our legitimate interests, where these are not overridden by your fundamental rights.

3. Data We Collect

3.1 Data You Provide Directly

Data TypePurposeLegal Basis
Full nameAccount creation and identificationContract performance
Email addressAccount login, communications, securityContract performance
Date of birthAge verification (18+ requirement)Legal obligation
GenderPersonalisation, attendee breakdown displayConsent
Username & password (hashed)Account authenticationContract performance
Profile bioPublic profile displayConsent
Profile & check-in photosVenue presence display (temporary)Consent
Vibe text & intentsVenue matching and display to nearby usersConsent
Support messagesCustomer serviceLegitimate interest

3.2 Data Collected Automatically

Data TypePurposeLegal Basis
Device location (GPS)Venue discovery, check-in, proximity matchingConsent
IP addressSecurity, fraud prevention, approximate locationLegitimate interest
Device type & OS versionApp functionality and compatibilityLegitimate interest
App usage dataFeature improvement, crash diagnosticsLegitimate interest
Push notification tokenSending connection and message alertsConsent
Session & activity logsSecurity monitoring, abuse detectionLegitimate interest
Check-in timestampsService delivery, expiry managementContract performance

3.3 Data From Venue Partners

Venue Partners provide business registration data (trade licence, address, contact details) and campaign creative content. This data is processed for the Venue Partner program and is subject to separate agreements with Venue Partners.

3.4 Data We Do Not Collect

We do not collect or process:

  • Biometric data (fingerprints, face ID data — your device handles this locally)
  • Financial account numbers, full card details, or other payment credentials; paid services are not available during the external beta
  • Data from your device contacts, calendar, or other apps
  • Any data from children under 18 years of age
4. How We Use Your Data

4.1 Core Service Delivery

  • Matching you with users at the same venue during an active check-in
  • Displaying your profile, vibe, intents, and temporary photos to users at your venue
  • Enabling connection requests, messaging, and notifications
  • Maintaining your account and assigned beta feature access

4.2 Safety & Security

  • Detecting and preventing fraud, spam, abuse, and prohibited conduct
  • Investigating reported content and enforcing our Terms and Conditions
  • Complying with legal orders, warrants, or regulatory requests from UAE authorities

4.3 Platform Improvement

  • Analysing aggregated usage patterns to improve app features
  • Conducting internal research using anonymised or pseudonymised datasets
  • Testing and debugging new features in development environments

4.4 Advertising (Venue Partner Targeted Campaigns)

KMSTRY operates an advertising system for Venue Partners. Targeted campaign delivery works as follows:

  • Venue Partners define audience parameters (location radius, age range, gender, intents, time of day)
  • KMSTRY's own systems match these parameters against active user sessions internally
  • Venue Partners receive only aggregated, anonymised campaign performance reports (impressions, estimated reach, click-throughs)
  • Individual user data is never shared with or sold to Venue Partners
  • Ad targeting uses pseudonymised session data and does not build long-term behavioural profiles
⚠ We do not sell your personal data to anyone. Targeted campaign tools are not available during the external beta. If venue promotions are introduced later, Venue Partners will not receive your name, contact details, or individual data.

4.5 Communications

  • Sending transactional emails: account confirmation, password reset, safety notices, and service updates
  • Push notifications: connection requests, messages, check-in activity
  • Marketing emails: new features, promotions (opt-out available at any time)
5. Data Sharing & Disclosure

5.1 Other Users

When you are checked in at a venue, the following is visible to other users at the same venue:

  • Your display name and username
  • Your profile photo (if set)
  • Your check-in photos (temporary — deleted on checkout)
  • Your vibe text and intent tags
  • Your gender (used for the venue's gender breakdown display)

Your email address, date of birth, and precise device data are never shared with other users.

5.2 Service Providers

We share data with trusted third-party service providers who process data on our behalf under strict confidentiality agreements. These include:

Data TypePurposeLegal Basis
Cloud Hosting (Railway / AWS)Server infrastructure and file storageUSA / EU
Push Notifications (Firebase FCM)Sending in-app notificationsUSA
Analytics (internal / privacy-first tool)Aggregated usage analyticsUAE / EU
Email Provider (e.g. SendGrid)Transactional and marketing emailsUSA

All providers are required to process data only as instructed by KMSTRY and to implement appropriate security measures. Transfers outside the UAE and GCC are governed by appropriate safeguards (standard contractual clauses or adequacy decisions where applicable).

5.3 Legal Disclosure

We may disclose personal data to government authorities, law enforcement, or courts where required by applicable UAE law, including in response to lawful orders issued by UAE federal or local authorities. We will notify you of such disclosures where legally permissible.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity. You will be notified of any such transfer and your rights under applicable data protection law will be preserved.

5.5 What We Never Do

  • Sell personal data to advertisers, data brokers, or third parties
  • Share individual user data with Venue Partners
  • Use your data to create profiles for third-party advertising networks
  • Transfer data to countries without adequate protection unless appropriate safeguards are in place
6. Location Data — Special Consideration

Location is central to how KMSTRY works. We collect your device's GPS location when:

  • You open the app and have granted location permissions
  • You search for nearby venues
  • You are actively checked in at a venue
⚠ We use your location in real time to power the service. We do not continuously track your location in the background, store a history of your location, or share your precise coordinates with any third party.

You can revoke location permissions at any time in your device settings. Without location access, core features (venue discovery and check-in) will not function. The app will continue to work for messaging and connections without location access.

7. Check-In Photos — Temporary by Design
🔒 Check-in photos are automatically and permanently deleted when you check out or your check-in expires (8 hours maximum). This is a core privacy feature, not a recoverable action.

Specifically:

  • Photos are uploaded to secure, encrypted storage on check-in
  • They are visible only to users at the same venue during the active check-in
  • They are not indexed by search engines or shared on any public page
  • They are permanently deleted from our servers within minutes of check-out or expiry
  • KMSTRY does not retain copies of deleted check-in photos in backups beyond our standard 30-day backup rotation, after which they are purged entirely

Profile photos (not linked to a check-in) are retained until you delete them or close your account.

8. Data Retention
Data TypePurposeLegal Basis
Account data (name, email, username)Duration of account; removed from live systems on confirmed account deletionService delivery and user control
Check-in photosDeleted on checkout or expiry (max 8 hours)Privacy by design
Profile photosUntil deleted by user or account closureUser control
Messages & chat historyUntil account deletion, unless removed earlier by the user or an expiry ruleService continuity
Security & fraud logsUp to 12 months; direct identifiers are deleted or anonymised after account deletion unless required for an active legal claimLegitimate interest
Anonymised analytics dataIndefinitely (no personal identifiers)Research
Backup snapshots30-day rolling window, then purgedBusiness continuity

When you confirm full account deletion, your account and associated personal data are removed from our live systems. Uploaded media is deleted from our object storage as part of the deletion process. Residual copies may remain in encrypted backup snapshots for no longer than the 30-day backup rotation and are not restored except for disaster recovery. We retain only the minimum information required by applicable law or an active legal claim; where possible, retained operational records are anonymised and are deleted when that requirement ends. Deleting only a personal profile or leaving a venue does not delete your root KMSTRY account.

9. Your Privacy Rights

Under UAE PDPL and as a matter of KMSTRY policy, you have the following rights:

AccessRequest a copy of the personal data we hold about you.
CorrectionRequest that inaccurate or incomplete data be corrected.
DeletionRequest deletion of your personal data ('right to be forgotten'), subject to legal retention obligations.
PortabilityRequest your data in a commonly used machine-readable format.
ObjectionObject to processing based on legitimate interests, including for advertising personalisation.
Withdraw ConsentWithdraw consent at any time for processing based on consent (e.g. location access, marketing emails).
RestrictionRequest that we restrict processing of your data while a complaint is being investigated.

To exercise any of these rights, contact us at adops@brightmindshub.net. We will respond within 30 days. We may require identity verification before processing your request. You will not be charged for making a rights request.

If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) or other competent supervisory authority.

10. Cookies & Tracking Technologies

10.1 App

The KMSTRY mobile app does not use cookies. We use:

  • Secure local storage for authentication tokens (stored encrypted on your device)
  • Device identifiers for push notification delivery (Firebase FCM token)
  • Crash reporting SDK (may collect anonymous device and crash data)

10.2 Website

Our external beta website (staging.kmstry.net) uses the following:

  • Strictly necessary cookies: session management and security (cannot be disabled)
  • Analytics cookies: anonymised visitor counts and page performance (can be disabled via cookie banner)
  • Marketing cookies: retargeting and advertising attribution (requires your explicit consent)

You can manage your cookie preferences through our cookie consent banner or by configuring your browser settings. Disabling certain cookies may affect website functionality.

11. Children's Privacy
⚠ KMSTRY is strictly for users aged 18 and over. We do not knowingly collect data from anyone under 18.

If we discover that a user is under 18, we will immediately suspend the account, delete all associated personal data, and take appropriate action to prevent further access. If you believe a minor has created a KMSTRY account, please report it immediately to adops@brightmindshub.net.

12. Data Security

KMSTRY implements industry-standard technical and organisational measures to protect your personal data, including:

  • Encryption in transit: all data transmitted between the app and servers uses TLS 1.2 or higher
  • Encryption at rest: sensitive data fields (passwords, tokens) are stored using bcrypt hashing and AES-256 encryption
  • Access controls: only authorised KMSTRY staff with a legitimate need can access personal data
  • Infrastructure security: hosted on SOC 2-compliant cloud infrastructure with automated monitoring
  • Vulnerability management: regular security audits and penetration testing
  • Incident response: a documented data breach response plan with notification procedures

In the event of a data breach that poses a risk to your rights and freedoms, KMSTRY will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law.

13. International Data Transfers

KMSTRY is based in Dubai, UAE. Your data may be processed by our service providers in the United States and European Union. Where data is transferred outside the UAE, we ensure appropriate safeguards are in place, including:

  • Standard contractual clauses (SCCs) with service providers
  • Use of providers certified under recognised privacy frameworks
  • Adequacy assessments for destination countries

By using KMSTRY, you consent to the transfer of your personal data to the countries and regions described in this Policy, subject to these safeguards.

14. Venue Partner Data Practices

14.1 Targeting Data

Venue Partners use KMSTRY's self-serve advertising tools to create targeted campaigns. They select targeting criteria (location, age range, gender, intents) and KMSTRY's platform identifies matching users internally. The matching process is fully automated and no individual user data is transmitted to the Venue Partner.

14.2 Campaign Analytics

Venue Partners receive performance reports that contain only aggregated, anonymised metrics. Reports will never identify individual users, show personally identifiable information, or provide any data that could be used to reverse-engineer user identities. Minimum thresholds apply (e.g. reports will not display results for audiences below 50 users).

14.3 Venue Partner Obligations

Venue Partners who upload creative content (images, text) represent that they own or have the necessary rights to that content, that it complies with applicable law and KMSTRY's policies, and that it does not involve the processing of personal data beyond what is described in this Policy. Venue Partners must maintain their own privacy notices where required by law.

15. Automated Decision-Making

KMSTRY uses automated systems to:

  • Rank and display venue attendees based on proximity, intents, and check-in time
  • Match targeted advertising campaigns to users based on defined criteria
  • Detect suspicious account activity and potential policy violations

These automated processes do not produce legal or similarly significant effects on users. No significant decisions are made solely by automated means without the ability for human review. You may request human review of any decision that materially affects your account by contacting adops@brightmindshub.net.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by: (a) sending an email to your registered address; (b) displaying a prominent in-app notice; or (c) requiring acknowledgment upon next login. The 'Effective Date' at the top of this Policy will reflect the date of the most recent update. We encourage you to review this Policy periodically.

Your continued use of KMSTRY after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with any changes, you must stop using the platform and may delete your account.

17. Contact & Privacy Requests

For all privacy-related matters — including data subject rights requests, breach notifications, legal inquiries, and Data Protection Officer contact:

Privacy Emailadops@brightmindshub.net
Legal AddressKMSTRY FZ-LLC, Dubai, United Arab Emirates
Response TimeWe respond to all privacy requests within 30 calendar days.

For faster resolution of account-specific issues, please include your registered email address and username in all privacy correspondence.

This Privacy Policy was last updated on 1 July 2025.

© 2026 KMSTRY FZ-LLC. All rights reserved.