Kissmet — Privacy Policy
TEMPLATE — REVIEW BEFORE PUBLISHING. First-draft template, not legal advice. The biometric/verification, California (CCPA/CPRA), and Canada (PIPEDA/Quebec Law 25/CASL) sections in particular should be confirmed by counsel and matched to what your app actually collects. Fill every [BRACKETED] placeholder.Effective date: [EFFECTIVE DATE] Controller: [LEGAL ENTITY NAME] ("Kissmet," "we," "us") Privacy contact: [PRIVACY EMAIL] · kissmet.app
1. Who this applies to
This policy covers Kissmet, an 18+ dating service for the South Asian diaspora, available in our supported launch regions. It explains what we collect, how we use it, who we share it with, and your choices.
2. Information we collect
You provide:
- Account details — name, date of birth, email and/or phone number, password
- Profile content — photos, prompts, bio, preferences, dealbreakers
- Verification media — selfie/photo used to verify your profile (see Section 4)
- Messages and content you exchange with other users
- Support communications
Collected automatically:
- Approximate location/region (used to gate access to launch regions and surface nearby profiles)
- Device and usage data — device model, OS, app version, identifiers, interactions, diagnostics
- Push notification token
From third parties:
- Subscription and purchase status from the Apple App Store / Google Play via RevenueCat (we do not receive your full card details)
3. How we use your information
To create and operate your account; build your profile and the discovery deck; run matching and messaging; verify identity and fight fraud, spam, and abuse; gate access to launch regions; process subscriptions; send transactional and (with consent) promotional notifications; provide support; comply with law; and keep the community safe.
4. Verification and biometric information
If you use selfie/photo verification, we and our verification provider process the media to confirm your profile photos match you. *[CONFIRM with your vendor: if the process extracts a facial-geometry template or other biometric identifier, this section must disclose that, the specific purpose, the retention schedule, and obtain separate consent — required under Illinois BIPA, Texas CUBI, and similar laws. If no biometric template is created or retained, state that verification media is used only for matching and deleted within [N] days.]* We do not sell biometric information.
5. How we share information
- With other users — your profile content is visible to users you may match with; your messages are visible to your conversation partner
- Service providers — Google Firebase / Google Cloud (hosting, auth, database), RevenueCat (subscriptions), Expo (push), and analytics/diagnostics providers, all bound to process data on our behalf
- Safety and legal — to respond to legal process, enforce our Terms, or protect users
- Business transfers — in a merger, acquisition, or asset sale
We do not sell your personal information for money. *[If any SDK shares data for cross-context advertising under CCPA/CPRA, disclose "sharing" and provide an opt-out.]*
6. Data retention and deletion
We keep personal information for as long as your account is active or as needed to provide the Service and meet legal obligations. You can delete your account in-app (Settings → Account), which triggers deletion of your profile, photos, matches, and messages across our systems, subject to limited retention required by law or for fraud prevention. Some logs may persist in backups for a limited period before expiring.
7. Your privacy choices and rights
You can edit profile data, manage notification preferences, and delete your account in-app.
California residents (CCPA/CPRA): you have the right to know, access, correct, and delete personal information, to opt out of "sale"/"sharing" (we do not sell; see Section 5), and to not be discriminated against for exercising these rights. Submit requests to [PRIVACY EMAIL].
Canada (PIPEDA / Quebec Law 25): you may access and correct your personal information and withdraw consent, subject to legal limits. Commercial electronic messages are sent only with consent and always include an unsubscribe option (CASL).
Other regions: where applicable law grants additional rights (access, portability, objection, erasure), we honor them. Contact [PRIVACY EMAIL].
8. Security
We use technical and organizational safeguards (encryption in transit, access controls, security rules). No system is perfectly secure; please use a strong, unique password.
9. Children
Kissmet is strictly for adults 18 and older. We do not knowingly collect information from anyone under 18 and will delete such accounts.
10. International data transfers
We are based in the United States and process data in the U.S. If you use Kissmet from Canada or elsewhere, your information is transferred to and processed in the U.S. under appropriate safeguards.
11. Changes to this policy
We may update this policy and will revise the effective date above; material changes will be notified in-app or by email.
12. Contact
Privacy questions or requests: [PRIVACY EMAIL] · [LEGAL ENTITY NAME], [MAILING ADDRESS].