1. Who is responsible
KICK IT is the service name. The controller’s legal name, registered address and monitored privacy contact are awaiting confirmation in the Legal notice. This draft must be finalized with those details and the production data inventory before it is used as the operative collection notice.
This policy covers our website, early-access list and app. Venues, independent activity providers, Apple and mapping providers may also process information under their own notices when providing their own services.
2. Website and early-access information
The early-access form collects your email address and phone number; some forms also offer an optional city field. We record the signup source, submission time and the version and time of your contact consent. We use these details to manage the list and contact you about KICK IT early access by the channels you authorize.
You can browse the website without joining the list. Contact details are required to join the current list, while city is optional. The form uses an anti-bot field and a shared request counter to limit abuse. Website hosting may receive IP addresses, browser information, requested URLs and timestamps to serve requests and protect the service.
3. App information
Account and profile: email, authentication identifiers, password hash if you use password sign-in, session tokens, name and profile information you provide, such as age, gender, home country and interests. Sign in with Apple supplies the identifiers and account information you choose to share, which may include a relay email address.
Activities and travel: plans you create or join, meeting places, dates, membership, travel destinations and date ranges. Communications: direct and group messages, photos and selected location pins you send, thread membership, reports, blocks and support correspondence.
Device and preferences: push notification token, notification settings, presence visibility and other account preferences. Operational infrastructure may process request, error and security records needed to run and troubleshoot the service. Do not send passwords, payment-card details or identity documents through ordinary chat.
4. Location and visibility
If you allow device location access and use location features, the app can send precise coordinates to our server to show nearby people and activities. Other users receive a coarse, rounded presence location rather than your precise device coordinates through the presence feature.
A location pin you choose to send in chat shares its exact selected coordinates with that conversation. This is separate from rounded presence and is not live location tracking. Photo uploads are re-encoded to remove embedded location metadata before screening and storage.
Rounding does not make you anonymous. Activity meeting points, messages, travel plans and information you share can reveal where you are or intend to be. Only share a meeting location you are comfortable disclosing to the relevant audience.
You can disable presence visibility in the app; the current server flow clears the stored presence location when that setting is disabled. You can also change location permission in device settings. These controls do not erase meeting points, messages or information already seen by others. Nearby features may be limited without location access.
5. Why we use information
We use information to create and secure accounts, display relevant plans, manage joins and conversations, match overlapping trips, send requested service notifications, provide support, investigate abuse and comply with legal obligations.
Where applicable law requires a legal basis, processing must be supported by the relevant basis: consent for optional contact or device permissions where required, performance of the service agreement for requested features, legal obligations, or a permitted and balanced legitimate interest such as preventing abuse. Device permission alone is not consent to unrelated marketing.
We do not use early-access contact consent as permission for unrelated advertising. Any materially new use, such as a new advertising or analytics integration, requires review, an updated notice and consent where required before it begins.
7. International processing
Providers and authorized personnel may process data outside Indonesia or your home country. Before production publication, the controller must identify relevant destinations and confirm the applicable transfer mechanism and safeguards. A possible Hong Kong parent does not by itself establish where data is hosted.
Where required, transfers must use the protections prescribed by applicable law, such as adequate protection, binding safeguards or valid consent where that is an available basis. You may request information about relevant recipients and safeguards through the confirmed privacy contact.
8. Retention and deletion
We retain personal information only for the purpose for which it is needed or a lawful retention obligation. Relevant factors include whether an account remains active, whether an activity or support matter is ongoing, legal requirements and the minimum records needed for security or disputes.
Account deletion is available through app settings and removes account-linked records through the server’s deletion flow. Uninstalling the app does not trigger that flow. A separate early-access signup must be withdrawn separately. Copies already saved by recipients cannot be removed from their devices by deleting your account.
Backups, infrastructure logs and records that must lawfully be retained may follow separate removal schedules and restricted access. The specific waitlist, log, report and backup periods and purge procedures are still being verified for this draft; no immediate deletion from every backup is promised.
9. Your rights and choices
Depending on applicable law, you may request information about processing, access and a copy of your data, correction, deletion, restriction, objection or portability. You may withdraw consent for future consent-based processing without invalidating processing that occurred lawfully before withdrawal. Some rights are subject to statutory conditions and exceptions.
Use account settings for available privacy controls, notification choices, blocking and deletion. Device settings control location and notification permissions. For early-access withdrawal, access requests or other rights, use the confirmed privacy contact in the Legal notice once supplied. We may ask for proportionate identity confirmation and will respond within applicable legal deadlines.
You may complain to the competent data protection or other authority where you are entitled to do so. We will not require you to waive that right. Essential security or account communications may remain necessary even when promotional contact is stopped.
11. Security and younger users
We use access controls and authentication to protect information and limit access to those who need it for their role. No online service can guarantee absolute security. We will address incidents and notify affected people and authorities where required by applicable law.
KICK IT is intended for adults aged 18 or older. If you believe a child has provided personal information, contact the confirmed privacy channel so we can assess and address it. We do not ask you to upload identity documents to an ordinary support or chat thread.
12. Updates
Finalized notices will show a version and effective date. Material changes will be communicated appropriately, and new consent obtained where required. This review version is dated 2 October 2026 and is not yet effective.