Legal

Privacy Policy

How we protect your data and respect your privacy

Last Updated: September 12, 2026 · Effective Date: December 10, 2025

1. Introduction

Konectr ("we", "us", "our") operates the Konectr mobile application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using Konectr, you agree to the collection and use of information in accordance with this policy.

2. Data Controller & Company Information

For the purposes of the Malaysian Personal Data Protection Act 2010 ("PDPA"), the data controller (the PDPA "data user") responsible for your personal data is Deepak Porwal (founder of Konectr), operating from Kuala Lumpur, Malaysia, contactable at privacy@konectr.app. Konectr is in the process of incorporation; upon completion, the incorporated entity will become the data controller and this section will be updated.

Data Controller:
Deepak Porwal — founder, Konectr (incorporation in progress)
Contact Address:
Kuala Lumpur, Federal Territory of Kuala Lumpur 50000, Malaysia
Data Protection Contact:
privacy@konectr.app
Website:
https://konectr.app

3. Data We Collect

👤

Personal Information

  • Email address (for sign-in and account recovery)
  • Phone number (optional, if you choose to add it)
  • Name (display name for your profile)
  • Date of birth (you must be 18 or over to create an account)
  • Gender (for profile display)
  • Profile photo (optional)
  • Bio, interests, and languages spoken
  • What you say you are looking for (optional — it stays until you change or clear it)
  • Photos you send in a plan's chat, and any of those you or another attendee choose to publish to This Week
📍

Location Data

  • Your precise location while the app is open, used on your device to find plans within 5 km of you — plans show a venue, never your position
  • Your city, so we show you the right area
  • A location you choose to share in a chat (visible to that chat for 15 minutes)
  • Your location at the moment you confirm a meetup, used only to verify attendance
🎯

Activity Data

  • Venues visited (to suggest similar activities)
  • Activities you started
  • Matches made (to improve matching algorithm)
  • Messages sent (retained while the conversation exists)
📊

Usage Data

  • App interactions (features used, screens viewed)
  • Crash logs (to fix bugs and improve stability)
  • Device information (OS version, app version, device model)

4. How We Use Your Data

We use your information to:

  • Match you with other users for in-person activities
  • Verify your identity and maintain a safe community
  • Improve our Service through analytics
  • Comply with legal obligations under PDPA 2010
  • Send service-related notifications
  • Prevent fraud and abuse

We do NOT:

  • Send marketing emails without your explicit consent
  • Sell your data to third parties
  • Use your data for purposes unrelated to the Service

5. Data Sharing

With Other Users

We share your profile information (name, photo, bio, interests), approximate location, and activity preferences with matched users.

This Week wall (photos you choose to publish)

A photo sent in a plan's group chat can be shared to This Week by anyone who was on that plan. A published photo is visible to every signed-in Konectr member in your city for 14 days, shown only as the venue, the kind of plan and the group size — never a name, a date, or a link to the plan. Any attendee of that plan can take it down at any time, we review every photo before it goes live, location data is stripped from the image, and the file is deleted from our storage when the 14 days end. Only share photos that everyone in them is comfortable with.

We NEVER Share

  • Your phone number
  • Your exact location
  • Your private messages with others
  • Your personal contact information

Service Providers

We work with these service providers, each of which processes data only to perform its function for us: Supabase (database, authentication and file storage, hosted in Singapore); Firebase Cloud Messaging and Firebase Crashlytics (push delivery and crash reports); PostHog (first-party product analytics, hosted in the United States); Brevo (transactional and lifecycle email); Mapbox (map display and reverse geocoding — the map SDK on your device may send anonymised usage telemetry to Mapbox); Google Places (venue search and venue photos); and Google ML Kit (on-device translation model downloads). None of them may use your data for their own purposes.

6. Your Rights Under PDPA 2010

Right to Access

Request a copy of your personal data in JSON format.

Right to Correction

Update or correct inaccurate information in your profile.

Right to Deletion

Delete your account. Personal data is erased within 30 days; see Section 10 for what is anonymised or retained and why.

Right to Data Portability

Export your data in a structured, machine-readable format.

Right to Withdraw Consent

Stop us from processing your data at any time.

Right to Complaint

File a complaint with the Personal Data Protection Commissioner.

To exercise these rights, contact: privacy@konectr.app

7. Location Data Specifics

🚫NEVER tracked in background — only when the app is active
🔵Plans and profiles never store your position — only the venue you picked
🗑️A location you share in a chat expires after 15 minutes; any coordinates we hold are erased when your account is deleted
⚙️You can disable location permissions in device settings anytime

8. Children’s Privacy

Konectr is strictly 18+ only. You must enter a date of birth showing you are 18 or over to create an account; we do not verify identity documents. We do not knowingly collect data from anyone under 18. Accounts found to belong to minors are removed.

If we learn we have collected personal data from anyone under 18, we will delete that information immediately. Parents should contact privacy@konectr.app if they discover their child is using Konectr.

9. Data Security

Technical Safeguards

  • Messages are encrypted in transit and at rest; they are not end-to-end encrypted, so we can act on safety reports
  • Encrypted data storage via Singapore data center
  • Secure HTTPS transmission for all data transfers
  • Row-level security: each account can read only the data it is allowed to see

Organizational Safeguards

  • Access to production data is limited to the founder
  • Security review of every change that touches personal data
  • Data breaches are reported to affected users and the Commissioner as PDPA requires

10. Data Retention

Data TypeRetention Period
Active accountsRetained while your account is open
Deleted accountsHidden immediately, 30 days to change your mind, then permanently erased
MessagesRetained while the conversation exists. If you delete your account, your messages stay in other people's conversations but are no longer linked to you
Activity and availability historyRetained while your account is open
Location dataChat location shares expire after 15 minutes. Meetup-confirmation coordinates are kept while your account is open and erased on deletion
Crash logsRetained for 90 days by Firebase Crashlytics
Safety reportsRetained after account deletion, so that deleting an account cannot erase a report

11. International Data Transfers

Your data is stored in Singapore (via Supabase Asia region). We are building Konectr to the standards set by Malaysia's PDPA 2010 and the EU GDPR — the rights described in this policy, including access, correction, download, and deletion, are honoured today. Our formal compliance review is still in progress, and we will say so here when it is complete.

When transferring data internationally, we ensure adequate safeguards including standard contractual clauses, data processing agreements, and compliance with local data protection laws.

12. Cookies and Tracking

The Konectr mobile app does not use advertising cookies, advertising SDKs, or cross-app tracking. In-app analytics are first-party (crash reporting and feature usage, tied to your account ID, never sold or shared for advertising).

Our website (konectr.app) uses: PostHog product analytics in cookieless mode (no cookies or device storage); and — only if you accept the cookie banner — Meta and Google advertising pixels that measure whether our ads brought you here. Declining or ignoring the banner keeps all advertising pixels off. Full details: konectr.app/cookies.

We do NOT sell your personal data to advertisers, build advertising profiles of you, or track you across other apps.

13. Changes to Privacy Policy

We may update this policy periodically. You will be notified via in-app notification. Continued use after changes constitutes acceptance. Major changes require explicit re-consent.

14. Contact & Complaints

If you are not satisfied with our response, you may escalate to the Personal Data Protection Department, Ministry of Communications and Digital, Level 5, MCMC Tower 1, Jalan Impact, Cyberjaya, 63000 Selangor, Malaysia (pdpa@pdp.gov.my).

Privacy Questions:
privacy@konectr.app
General Support:
support@konectr.app
Legal Matters:
legal@konectr.app
Response Time:
Within 48–72 hours

This Privacy Policy is governed by the laws of Malaysia. Any disputes shall be resolved in the courts of Kuala Lumpur.

Questions? Contact us at privacy@konectr.app · Also read our Terms of Service