This Privacy Policy applies to KMSTRY FZ-LLC ('KMSTRY', 'we', 'our', 'us') and governs the collection, use, storage, and sharing of personal data through:
- The KMSTRY mobile application (iOS and Android)
- The KMSTRY external beta website at staging.kmstry.net
- The KMSTRY Venue Partner dashboard and advertising tools
- Any APIs or integrations provided by KMSTRY
By using KMSTRY, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the platform.
1. Data Controller
KMSTRY processes personal data as a data controller. In certain circumstances (such as when processing data on behalf of Venue Partners), we may act as a data processor. These roles are described where relevant in this Policy.
2. Legal Framework
KMSTRY operates primarily under UAE law and takes guidance from:
- UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data ('PDPL')
- UAE Federal Decree Law No. 34 of 2021 on Cybercrime
- DIFC Data Protection Law No. 5 of 2020 (where applicable)
- GDPR (EU) 2016/679 — applied as a standard of good practice for users in the European Economic Area
- UAE Telecom Regulatory Authority (TRA) guidance on digital services
Our legal bases for processing personal data include: (a) performance of a contract with you; (b) your explicit consent; (c) compliance with a legal obligation; and (d) our legitimate interests, where these are not overridden by your fundamental rights.
3. Data We Collect
3.1 Data You Provide Directly
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Full name | Account creation and identification | Contract performance |
| Email address | Account login, communications, security | Contract performance |
| Date of birth | Age verification (18+ requirement) | Legal obligation |
| Gender | Personalisation, attendee breakdown display | Consent |
| Username & password (hashed) | Account authentication | Contract performance |
| Profile bio | Public profile display | Consent |
| Profile & check-in photos | Venue presence display (temporary) | Consent |
| Vibe text & intents | Venue matching and display to nearby users | Consent |
| Support messages | Customer service | Legitimate interest |
3.2 Data Collected Automatically
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Device location (GPS) | Venue discovery, check-in, proximity matching | Consent |
| IP address | Security, fraud prevention, approximate location | Legitimate interest |
| Device type & OS version | App functionality and compatibility | Legitimate interest |
| App usage data | Feature improvement, crash diagnostics | Legitimate interest |
| Push notification token | Sending connection and message alerts | Consent |
| Session & activity logs | Security monitoring, abuse detection | Legitimate interest |
| Check-in timestamps | Service delivery, expiry management | Contract performance |
3.3 Data From Venue Partners
Venue Partners provide business registration data (trade licence, address, contact details) and campaign creative content. This data is processed for the Venue Partner program and is subject to separate agreements with Venue Partners.
3.4 Data We Do Not Collect
We do not collect or process:
- Biometric data (fingerprints, face ID data — your device handles this locally)
- Financial account numbers, full card details, or other payment credentials; paid services are not available during the external beta
- Data from your device contacts, calendar, or other apps
- Any data from children under 18 years of age
4. How We Use Your Data
4.1 Core Service Delivery
- Matching you with users at the same venue during an active check-in
- Displaying your profile, vibe, intents, and temporary photos to users at your venue
- Enabling connection requests, messaging, and notifications
- Maintaining your account and assigned beta feature access
4.2 Safety & Security
- Detecting and preventing fraud, spam, abuse, and prohibited conduct
- Investigating reported content and enforcing our Terms and Conditions
- Complying with legal orders, warrants, or regulatory requests from UAE authorities
4.3 Platform Improvement
- Analysing aggregated usage patterns to improve app features
- Conducting internal research using anonymised or pseudonymised datasets
- Testing and debugging new features in development environments
4.4 Advertising (Venue Partner Targeted Campaigns)
KMSTRY operates an advertising system for Venue Partners. Targeted campaign delivery works as follows:
- Venue Partners define audience parameters (location radius, age range, gender, intents, time of day)
- KMSTRY's own systems match these parameters against active user sessions internally
- Venue Partners receive only aggregated, anonymised campaign performance reports (impressions, estimated reach, click-throughs)
- Individual user data is never shared with or sold to Venue Partners
- Ad targeting uses pseudonymised session data and does not build long-term behavioural profiles
4.5 Communications
- Sending transactional emails: account confirmation, password reset, safety notices, and service updates
- Push notifications: connection requests, messages, check-in activity
- Marketing emails: new features, promotions (opt-out available at any time)
5. Data Sharing & Disclosure
5.1 Other Users
When you are checked in at a venue, the following is visible to other users at the same venue:
- Your display name and username
- Your profile photo (if set)
- Your check-in photos (temporary — deleted on checkout)
- Your vibe text and intent tags
- Your gender (used for the venue's gender breakdown display)
Your email address, date of birth, and precise device data are never shared with other users.
5.2 Service Providers
We share data with trusted third-party service providers who process data on our behalf under strict confidentiality agreements. These include:
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Cloud Hosting (Railway / AWS) | Server infrastructure and file storage | USA / EU |
| Push Notifications (Firebase FCM) | Sending in-app notifications | USA |
| Analytics (internal / privacy-first tool) | Aggregated usage analytics | UAE / EU |
| Email Provider (e.g. SendGrid) | Transactional and marketing emails | USA |
All providers are required to process data only as instructed by KMSTRY and to implement appropriate security measures. Transfers outside the UAE and GCC are governed by appropriate safeguards (standard contractual clauses or adequacy decisions where applicable).
5.3 Legal Disclosure
We may disclose personal data to government authorities, law enforcement, or courts where required by applicable UAE law, including in response to lawful orders issued by UAE federal or local authorities. We will notify you of such disclosures where legally permissible.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity. You will be notified of any such transfer and your rights under applicable data protection law will be preserved.
5.5 What We Never Do
- Sell personal data to advertisers, data brokers, or third parties
- Share individual user data with Venue Partners
- Use your data to create profiles for third-party advertising networks
- Transfer data to countries without adequate protection unless appropriate safeguards are in place
6. Location Data — Special Consideration
Location is central to how KMSTRY works. We collect your device's GPS location when:
- You open the app and have granted location permissions
- You search for nearby venues
- You are actively checked in at a venue
You can revoke location permissions at any time in your device settings. Without location access, core features (venue discovery and check-in) will not function. The app will continue to work for messaging and connections without location access.
7. Check-In Photos — Temporary by Design
Specifically:
- Photos are uploaded to secure, encrypted storage on check-in
- They are visible only to users at the same venue during the active check-in
- They are not indexed by search engines or shared on any public page
- They are permanently deleted from our servers within minutes of check-out or expiry
- KMSTRY does not retain copies of deleted check-in photos in backups beyond our standard 30-day backup rotation, after which they are purged entirely
Profile photos (not linked to a check-in) are retained until you delete them or close your account.
8. Data Retention
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Account data (name, email, username) | Duration of account; removed from live systems on confirmed account deletion | Service delivery and user control |
| Check-in photos | Deleted on checkout or expiry (max 8 hours) | Privacy by design |
| Profile photos | Until deleted by user or account closure | User control |
| Messages & chat history | Until account deletion, unless removed earlier by the user or an expiry rule | Service continuity |
| Security & fraud logs | Up to 12 months; direct identifiers are deleted or anonymised after account deletion unless required for an active legal claim | Legitimate interest |
| Anonymised analytics data | Indefinitely (no personal identifiers) | Research |
| Backup snapshots | 30-day rolling window, then purged | Business continuity |
When you confirm full account deletion, your account and associated personal data are removed from our live systems. Uploaded media is deleted from our object storage as part of the deletion process. Residual copies may remain in encrypted backup snapshots for no longer than the 30-day backup rotation and are not restored except for disaster recovery. We retain only the minimum information required by applicable law or an active legal claim; where possible, retained operational records are anonymised and are deleted when that requirement ends. Deleting only a personal profile or leaving a venue does not delete your root KMSTRY account.
9. Your Privacy Rights
Under UAE PDPL and as a matter of KMSTRY policy, you have the following rights:
To exercise any of these rights, contact us at adops@brightmindshub.net. We will respond within 30 days. We may require identity verification before processing your request. You will not be charged for making a rights request.
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) or other competent supervisory authority.
10. Cookies & Tracking Technologies
10.1 App
The KMSTRY mobile app does not use cookies. We use:
- Secure local storage for authentication tokens (stored encrypted on your device)
- Device identifiers for push notification delivery (Firebase FCM token)
- Crash reporting SDK (may collect anonymous device and crash data)
10.2 Website
Our external beta website (staging.kmstry.net) uses the following:
- Strictly necessary cookies: session management and security (cannot be disabled)
- Analytics cookies: anonymised visitor counts and page performance (can be disabled via cookie banner)
- Marketing cookies: retargeting and advertising attribution (requires your explicit consent)
You can manage your cookie preferences through our cookie consent banner or by configuring your browser settings. Disabling certain cookies may affect website functionality.
11. Children's Privacy
If we discover that a user is under 18, we will immediately suspend the account, delete all associated personal data, and take appropriate action to prevent further access. If you believe a minor has created a KMSTRY account, please report it immediately to adops@brightmindshub.net.
12. Data Security
KMSTRY implements industry-standard technical and organisational measures to protect your personal data, including:
- Encryption in transit: all data transmitted between the app and servers uses TLS 1.2 or higher
- Encryption at rest: sensitive data fields (passwords, tokens) are stored using bcrypt hashing and AES-256 encryption
- Access controls: only authorised KMSTRY staff with a legitimate need can access personal data
- Infrastructure security: hosted on SOC 2-compliant cloud infrastructure with automated monitoring
- Vulnerability management: regular security audits and penetration testing
- Incident response: a documented data breach response plan with notification procedures
In the event of a data breach that poses a risk to your rights and freedoms, KMSTRY will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law.
13. International Data Transfers
KMSTRY is based in Dubai, UAE. Your data may be processed by our service providers in the United States and European Union. Where data is transferred outside the UAE, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses (SCCs) with service providers
- Use of providers certified under recognised privacy frameworks
- Adequacy assessments for destination countries
By using KMSTRY, you consent to the transfer of your personal data to the countries and regions described in this Policy, subject to these safeguards.
14. Venue Partner Data Practices
14.1 Targeting Data
Venue Partners use KMSTRY's self-serve advertising tools to create targeted campaigns. They select targeting criteria (location, age range, gender, intents) and KMSTRY's platform identifies matching users internally. The matching process is fully automated and no individual user data is transmitted to the Venue Partner.
14.2 Campaign Analytics
Venue Partners receive performance reports that contain only aggregated, anonymised metrics. Reports will never identify individual users, show personally identifiable information, or provide any data that could be used to reverse-engineer user identities. Minimum thresholds apply (e.g. reports will not display results for audiences below 50 users).
14.3 Venue Partner Obligations
Venue Partners who upload creative content (images, text) represent that they own or have the necessary rights to that content, that it complies with applicable law and KMSTRY's policies, and that it does not involve the processing of personal data beyond what is described in this Policy. Venue Partners must maintain their own privacy notices where required by law.
15. Automated Decision-Making
KMSTRY uses automated systems to:
- Rank and display venue attendees based on proximity, intents, and check-in time
- Match targeted advertising campaigns to users based on defined criteria
- Detect suspicious account activity and potential policy violations
These automated processes do not produce legal or similarly significant effects on users. No significant decisions are made solely by automated means without the ability for human review. You may request human review of any decision that materially affects your account by contacting adops@brightmindshub.net.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by: (a) sending an email to your registered address; (b) displaying a prominent in-app notice; or (c) requiring acknowledgment upon next login. The 'Effective Date' at the top of this Policy will reflect the date of the most recent update. We encourage you to review this Policy periodically.
Your continued use of KMSTRY after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with any changes, you must stop using the platform and may delete your account.
17. Contact & Privacy Requests
For all privacy-related matters — including data subject rights requests, breach notifications, legal inquiries, and Data Protection Officer contact:
For faster resolution of account-specific issues, please include your registered email address and username in all privacy correspondence.
This Privacy Policy was last updated on 1 July 2025.
© 2026 KMSTRY FZ-LLC. All rights reserved.