Skip to policy
kick itBack to home ↗
TermsPrivacyCommunityLegal notice

KICK IT · Policy review

Privacy policy

This draft explains the website early-access form and the native app separately, including information you provide, location visibility, service providers and your choices.

Draft — not yet effective

Prepared 2 October 2026. Operator details, contact channels and production practices are awaiting confirmation. Read the document status.

On this page

  1. 1. Who is responsible
  2. 2. Website and early-access information
  3. 3. App information
  4. 4. Location and visibility
  5. 5. Why we use information
  6. 6. Who can receive information
  7. 7. International processing
  8. 8. Retention and deletion
  9. 9. Your rights and choices
  10. 10. Cookies device storage and external links
  11. 11. Security and younger users
  12. 12. Updates

1. Who is responsible

KICK IT is the service name. The controller’s legal name, registered address and monitored privacy contact are awaiting confirmation in the Legal notice. This draft must be finalized with those details and the production data inventory before it is used as the operative collection notice.

This policy covers our website, early-access list and app. Venues, independent activity providers, Apple and mapping providers may also process information under their own notices when providing their own services.

2. Website and early-access information

The early-access form collects your email address and phone number; some forms also offer an optional city field. We record the signup source, submission time and the version and time of your contact consent. We use these details to manage the list and contact you about KICK IT early access by the channels you authorize.

You can browse the website without joining the list. Contact details are required to join the current list, while city is optional. The form uses an anti-bot field and a shared request counter to limit abuse. Website hosting may receive IP addresses, browser information, requested URLs and timestamps to serve requests and protect the service.

3. App information

Account and profile: email, authentication identifiers, password hash if you use password sign-in, session tokens, name and profile information you provide, such as age, gender, home country and interests. Sign in with Apple supplies the identifiers and account information you choose to share, which may include a relay email address.

Activities and travel: plans you create or join, meeting places, dates, membership, travel destinations and date ranges. Communications: direct and group messages, photos and selected location pins you send, thread membership, reports, blocks and support correspondence.

Device and preferences: push notification token, notification settings, presence visibility and other account preferences. Operational infrastructure may process request, error and security records needed to run and troubleshoot the service. Do not send passwords, payment-card details or identity documents through ordinary chat.

4. Location and visibility

If you allow device location access and use location features, the app can send precise coordinates to our server to show nearby people and activities. Other users receive a coarse, rounded presence location rather than your precise device coordinates through the presence feature.

A location pin you choose to send in chat shares its exact selected coordinates with that conversation. This is separate from rounded presence and is not live location tracking. Photo uploads are re-encoded to remove embedded location metadata before screening and storage.

Rounding does not make you anonymous. Activity meeting points, messages, travel plans and information you share can reveal where you are or intend to be. Only share a meeting location you are comfortable disclosing to the relevant audience.

You can disable presence visibility in the app; the current server flow clears the stored presence location when that setting is disabled. You can also change location permission in device settings. These controls do not erase meeting points, messages or information already seen by others. Nearby features may be limited without location access.

5. Why we use information

We use information to create and secure accounts, display relevant plans, manage joins and conversations, match overlapping trips, send requested service notifications, provide support, investigate abuse and comply with legal obligations.

Where applicable law requires a legal basis, processing must be supported by the relevant basis: consent for optional contact or device permissions where required, performance of the service agreement for requested features, legal obligations, or a permitted and balanced legitimate interest such as preventing abuse. Device permission alone is not consent to unrelated marketing.

We do not use early-access contact consent as permission for unrelated advertising. Any materially new use, such as a new advertising or analytics integration, requires review, an updated notice and consent where required before it begins.

6. Who can receive information

Other users receive the profile, activity, presence, trip and message information made available by the feature and your settings. Hosts and conversation participants can see information needed for the activities or chats you join. An activity provider receives additional information only where you supply it or it is appropriately disclosed and necessary for the arrangement.

Service providers process information to host the API and database, deliver the website, provide maps, authenticate with Apple and deliver push notifications or transactional email. When photo sharing is enabled, uploaded photos are sent to AWS Rekognition for automated explicit-content screening before delivery. The API does not persist photos it rejects and does not send them to chat recipients. Automated checks can make mistakes; reporting and blocking remain available. The reviewed code integrates AWS Rekognition, Mapbox, Apple services and Resend email, and points to a DigitalOcean-hosted API. The production processor list, configuration and hosting regions still require confirmation before this draft is finalized.

Authorized support or safety personnel may access relevant information to address requests and reports. We may disclose information when legally required or reasonably necessary under applicable law to protect rights or investigate serious abuse. A business transfer would require appropriate safeguards and notice of any material change in control or use.

The reviewed application does not implement a sale of personal data or advertising-audience export. Independent recipients and other users may retain information you send them; avoid sharing information you would not want them to keep.

7. International processing

Providers and authorized personnel may process data outside Indonesia or your home country. Before production publication, the controller must identify relevant destinations and confirm the applicable transfer mechanism and safeguards. A possible Hong Kong parent does not by itself establish where data is hosted.

Where required, transfers must use the protections prescribed by applicable law, such as adequate protection, binding safeguards or valid consent where that is an available basis. You may request information about relevant recipients and safeguards through the confirmed privacy contact.

8. Retention and deletion

We retain personal information only for the purpose for which it is needed or a lawful retention obligation. Relevant factors include whether an account remains active, whether an activity or support matter is ongoing, legal requirements and the minimum records needed for security or disputes.

Account deletion is available through app settings and removes account-linked records through the server’s deletion flow. Uninstalling the app does not trigger that flow. A separate early-access signup must be withdrawn separately. Copies already saved by recipients cannot be removed from their devices by deleting your account.

Backups, infrastructure logs and records that must lawfully be retained may follow separate removal schedules and restricted access. The specific waitlist, log, report and backup periods and purge procedures are still being verified for this draft; no immediate deletion from every backup is promised.

9. Your rights and choices

Depending on applicable law, you may request information about processing, access and a copy of your data, correction, deletion, restriction, objection or portability. You may withdraw consent for future consent-based processing without invalidating processing that occurred lawfully before withdrawal. Some rights are subject to statutory conditions and exceptions.

Use account settings for available privacy controls, notification choices, blocking and deletion. Device settings control location and notification permissions. For early-access withdrawal, access requests or other rights, use the confirmed privacy contact in the Legal notice once supplied. We may ask for proportionate identity confirmation and will respond within applicable legal deadlines.

You may complain to the competent data protection or other authority where you are entitled to do so. We will not require you to waive that right. Essential security or account communications may remain necessary even when promotional contact is stopped.

10. Cookies device storage and external links

The reviewed website does not add advertising cookies or a third-party analytics tracker. It uses browser capabilities to render pages and submit forms. Hosting and security services may create necessary technical records; production configuration must be audited before final publication.

The app stores session credentials in device secure storage and preferences in local storage. Mapping and other SDKs may process technical usage or device data under their configurations and notices; the release inventory must include those SDKs. External links lead to services with their own privacy practices.

If non-essential tracking is introduced, we will explain it and provide the choices required by applicable law before it is activated. A privacy notice is not a substitute for required consent.

11. Security and younger users

We use access controls and authentication to protect information and limit access to those who need it for their role. No online service can guarantee absolute security. We will address incidents and notify affected people and authorities where required by applicable law.

KICK IT is intended for adults aged 18 or older. If you believe a child has provided personal information, contact the confirmed privacy channel so we can assess and address it. We do not ask you to upload identity documents to an ordinary support or chat thread.

12. Updates

Finalized notices will show a version and effective date. Material changes will be communicated appropriately, and new consent obtained where required. This review version is dated 2 October 2026 and is not yet effective.

KICK IT homeBack to top ↑