Legal
Privacy Policy
Last updated 4 July 2026
1. Who we are
The company that operates Kaki (the “Company”) is the data controller for the personal data described here. Its registered company details are not published on this page yet; until they are, the contact point for anything in this policy is support@kakiapp.co.
Because our users and venues are based in Indonesia, this policy is written with reference to Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, “UU PDP”). Where you are located elsewhere, additional local rights may apply.
2. What data we collect and why
We only collect data we need to run the Services. The table below maps each category to why we collect it. If a row describes something you have never used, we do not hold that data about you.
| Data | Why we collect it |
|---|---|
| Account & identity | Email address, your name, a username/handle, and a profile image if you set one — to create and secure your account, identify you to friends, clubs, and venues, and personalise the app. |
| Sign-up profile answers | The mahjong styles you play, how long you have played each, and your overall experience level — to match you to the right games, tables, classes, and tournaments. You answer these during sign-up. |
| Phone / WhatsApp number | A number asked for during sign-up, stored on your account so venues and organisers can reach you about a booking. Verifying it with a one-time code is OPTIONAL and sits outside the sign-up steps: if you skip it, we keep the number and mark it unverified. A number is only ever marked verified when the service that issued the code confirms the code you typed back. If you do ask for a code, your number — and the code you type back — goes to the one-time-code service the app is set up to use; section 5 describes both possible routes and what each one receives. |
| Authentication data | Email one-time sign-in codes; the identifier returned by Sign in with Apple or Google Sign-In when you use them; a password if you hold a Kaki for Hosts venue account; and a session cookie. Kaki also issues temporary guest sessions so you can open a shared invite link before you sign up. |
| Bookings & tournament data | Table reservations, tournament registrations, seatings, results, your booking code, and whether you checked in — to deliver the core booking and competition features and show your history. |
| Website bookings without an account | If you book a table or an event on the website without signing in, we take your name and email and create an account record keyed to that email so the booking, the confirmation email, and your check-in code have somewhere to live. You can ask us to delete it (see section 10). |
| Payment data (bookings & tournaments) | Amounts, order references, and payment status for real-world services paid by QRIS/e-wallet/card. Card and payment-instrument credentials are collected and processed by our payment gateway (Pivot) and are NOT stored by Kaki — to take payment for table and venue bookings, in-person tournament entry, and related purchases. |
| Subscription data (in-app purchases) | Whether you hold a premium organiser or coach subscription, its status, period end, and a purchase/transaction identifier. Apple or Google process the actual payment; we never see your card, bank, or store account credentials — to grant and manage premium access. |
| Device location | Your device location, requested only with your permission and only while you are using the app, to show mahjong venues and open games near you. We ask the operating system for balanced (roughly neighbourhood-level) accuracy rather than the most precise fix, and we use the position to place you on a map and sort venues by distance. On Android the app declares both the coarse and the precise location permission. You can decline or revoke location access in your device settings. |
| User-generated content | Clubs, friends, open-seat posts, chat messages, and profile content you create — to power community features you choose to use. |
| Photos & images you send | Images you attach in chat. They are uploaded to Cloudflare R2 object storage and served from a public image address (img.kakiapp.co) under a long random filename: the address is unguessable, but it is not password-protected, so anyone you send it to can open it. We do not automatically scan images before they are sent; see section 4 on moderation. |
| Reports, blocks & moderation records | If you report a message we keep the report, who filed it, who was reported, the reason, and how it was resolved. If you block someone we keep that block. This is how safety complaints get acted on — see our Community Guidelines. |
| Push notification token | A device push token issued by the platform (Apple / Google) when you enable notifications, processed via Expo's push service — to deliver notifications about messages, requests, and activity. You can disable notifications in your device settings. |
| Event & venue sign-up forms (leads) | At pop-up events, roadshows, and venue booths we run a short sign-up form (often behind a QR code) that collects a name, a WhatsApp number, whether the player is an adult or a child, optionally a home city, playing experience, and which programme they are interested in — so the venue can follow up about classes and sessions. No Kaki account is created by this form. See section 8 for how this works when the player is a child. |
| Device & technical data | IP address, device type, app version, and similar technical data automatically received when you connect — for security, rate limiting, fraud prevention, and reliability. |
What we do not collect. Kaki runs no advertising and no third-party analytics, attribution, or crash-reporting SDK. We do not collect an advertising identifier, we do not track you across other companies’ apps or websites, and we do not build advertising profiles.
3. Legal bases for processing
Under UU PDP we rely on one or more of the following lawful bases:
- Consent — for optional processing such as device location, push notifications, phone-number verification, and marketing communications, which you can withdraw at any time.
- Consent of a parent or guardian — for the limited child data described in section 8.
- Performance of a contract — to provide the account, bookings, tournaments, and payments you request under our Terms of Service.
- Legal obligation — to keep transaction and tax records and to respond to lawful requests.
- Legitimate interests — to keep the Services secure, prevent fraud and abuse, moderate reported content, and improve our features, balanced against your rights.
4. How we use your data
- Create, secure, and operate your account and sign-in.
- Provide bookings, tournaments, clubs, friends, open seats, and chat.
- Process payments for bookings and in-person tournaments via Pivot, grant premium access from store subscriptions, and issue receipts, refunds, and records.
- Show you nearby venues and games (with your permission).
- Send transactional email — booking confirmations and check-in codes, one-time sign-in codes, password resets, and important notices — through our email provider, Resend.
- Send a one-time code to your phone number, and check the code you type back, on the occasions you ask us to verify that number. See section 5 for the two routes that code can travel by and what each one receives.
- Deliver realtime chat and live updates over our self-hosted messaging gateway, store chat photos on Cloudflare R2, and send push notifications via Expo.
- Moderate reported content. Kaki does not pre-screen or automatically filter messages and images before they are sent. When someone reports a message, our staff and the relevant club or event admin can read that message and the surrounding conversation in order to decide what to do about it — see our Community Guidelines and Child Safety Standards.
- Rate-limit and protect public endpoints (using your IP address), prevent fraud and abuse, enforce our terms, and comply with law.
5. Third-party processors we share with
We do not sell your personal data. We share it with the service providers below strictly to run the Services. Each is bound to process data only on our instructions.
| Provider | Purpose | Data involved |
|---|---|---|
| Pivot | Payment processing for real-world services (QRIS, e-wallet, card) — table/venue bookings, joining a table, in-person tournament entry | Payment amount, currency, our order/booking reference, payment purpose and status, and the payment-session identifier; card/instrument credentials are collected and held by Pivot, not stored by Kaki |
| Apple | Sign in with Apple | Auth identifier, name/relay email |
| Google Sign-In (OAuth) | Auth identifier, email address, name, profile image URL | |
| Apple (App Store) / Google (Google Play) | Billing and management of in-app auto-renewing subscriptions (premium organiser and coach tiers) | Your store account handles the payment; we receive back only the transaction/subscription identifier, product, and renewal or cancellation status. Kaki never receives your card, bank, or store account credentials. |
| Neon | Database hosting (Postgres, Singapore region ap-southeast-1) | Account, bookings, tournaments, community content, chat messages, reports and blocks, event sign-up forms |
| Cloudflare R2 | Object storage and public delivery for images you send in chat | Photos/images you upload in conversations |
| Expo (Expo push service) | Delivering push notifications, which Expo hands to Apple (APNs) and Google (FCM) for delivery to your device | Device push token, notification title and body |
| Resend | Transactional email delivery (sign-in codes, booking confirmations, check-in codes, notices) | Email address, message content including your booking code |
| Twilio (Verify) | Sending and checking a one-time code for phone verification, on the requests that travel this route — either because it is the service the app is set up to use, or because our own send queue was too busy and handed the request over | Your phone number in E.164 form and the one-time code. Twilio generates, holds, and checks the code on its own servers, so on this route Kaki never has the code. The message arrives as an SMS, a WhatsApp message, or a voice call depending on the channel configured. |
| Our own one-time-code service, and the mobile network of the SIM it sends from | Sending and checking a one-time code without a commercial messaging provider: a service we run hands the message to an Android phone holding an ordinary SIM card, which sends it as a normal text message | Your phone number, and a keyed hash of the code — never the code itself — kept until the code expires or is used. The message itself is then carried by that SIM's mobile network operator, exactly as any text message is. |
| Upstash (Redis) | Rate limiting the public, unauthenticated booking endpoints so they cannot be flooded | A short-lived counter keyed to your IP address |
| Vercel | Hosting for kakiapp.co and the Kaki for Hosts web apps | Requests you make to those sites, including IP address and standard server-log data |
| RevenueCat, Inc. | Reconciling in-app subscription purchases and unlocking entitlements | Store purchase/transaction data, subscription status, and an app user identifier |
| Our hosting provider | Running the Kaki API and realtime messaging servers (api.kakiapp.co, ws.kakiapp.co) | All data described above passes through these servers in the course of serving your requests |
One-time codes for phone numbers — the two routes
Kaki can send a one-time code by two different routes. Which one carries a given code is a deployment setting, so this policy describes both rather than promising you one:
- Our own one-time-code service. A service we run generates the code, stores only a keyed hash of it against your account, and hands the message to an Android phone with an ordinary SIM card, which texts it to you. On this route your number is not given to a commercial messaging provider — but it is still handled by the mobile network operator carrying that SIM, the same way any text message is. Sends are paced, and if the queue behind that phone is too deep the request is handed to Twilio instead, so a code you asked for on this route can still reach you through Twilio.
- Twilio Verify. Twilio generates, sends, and checks the code on its own servers. We send Twilio your number and, when you type the code back, the code — and Twilio tells us only whether it matched.
If neither route is configured where the app is running, asking for a code returns an error saying verification is unavailable, no code is sent, no number leaves our servers for this purpose, and the number stays on your account marked unverified. Your number is used this way only when you ask for a code, and nothing but a confirmation from the service that issued that code can mark your number verified.
What we share with payment providers
Because payments run on two separate rails, different data goes to different providers. In neither case does Kaki hold your card or bank credentials.
- With Pivot, for real-world services (table and venue bookings, joining a table, in-person tournament entry): we send the amount, currency, our internal booking/payment reference, the payment purpose, and an identifier for your Kaki account so the payment can be matched back to your booking. Pivot returns the QRIS payload, transaction status, and its own session identifier. Your card, e-wallet, or bank details are entered with and held by Pivot and its partners under their own privacy terms — Kaki never receives them.
- With Apple and Google, for premium organiser and coach subscriptions: the purchase happens entirely inside the App Store or Google Play. We do not send them your Kaki profile, and we do not receive your payment details. We receive only confirmation of the purchase — product, transaction identifier, and renewal or cancellation status — via RevenueCat, so we can grant or remove premium access. Apple and Google act as independent controllers for the billing relationship; their handling of your store account is governed by their own privacy policies.
- Refunds and disputes. If you request a refund or file a chargeback for a Pivot payment, we may share transaction records (booking reference, amount, timestamps, and the venue or organiser involved) with Pivot, the card scheme, or your bank to handle it. Refunds and disputes for store subscriptions are handled by Apple or Google, not by us.
What we share with venues and organisers
When you book a table, join a game, register for a tournament, or fill in a venue sign-up form, the venue, host, or organiser you booked with sees what they need to receive you: your name or display name, your booking details and code, your check-in status, the amount paid, and — where you gave one — your contact email or WhatsApp number. Venues and organisers use that information to run the session you booked. They are responsible for their own handling of it.
We may also disclose data to comply with law, enforce our terms, protect rights and safety, or in connection with a merger, acquisition, or asset transfer (with notice where required).
6. International data transfers
Our primary database is hosted by Neon in the Singapore region, and several processors listed above — including Cloudflare, Vercel, Resend, Expo, Upstash, RevenueCat, Apple, Google, and Twilio on the one-time-code requests that reach it — operate outside Indonesia. Where personal data is transferred abroad, we take steps consistent with UU PDP to ensure an adequate level of protection, including contractual safeguards with our processors.
7. Data retention
We keep personal data only as long as needed for the purposes above. Concretely, today:
- Account, profile, bookings, and payment records — kept for as long as your account exists. When you delete your account these are deleted with it, including your booking and payment history. See Account & Data Deletion for exactly what goes and what stays.
- Records our payment gateway holds — Pivot keeps its own transaction records under its own retention rules, and deleting your Kaki account does not erase them.
- Chat messages and photos— kept for as long as the conversation exists. After you delete your account your messages remain in other participants’ conversations without your name attached, and images you sent remain in our image storage.
- One-time code records— when you ask for a code, we keep one record per account holding your number, the code’s expiry, and — on the route where we own the code — a keyed hash of it rather than the code. Asking for another code replaces that record, and it is deleted with your account.
- Reports and moderation records — kept while we need them to handle the complaint and to enforce repeat-offence decisions.
- Event and venue sign-up forms (leads) — kept by the venue in Kaki for Hosts so they can follow up. These are not linked to a Kaki account, so deleting an account does not remove them; email us to have one deleted.
- Technical and security data — rate-limit counters expire within minutes. Server logs are kept for a limited period for security and reliability.
8. Children
Kaki accounts are for adults. You must be at least 17 years old (or the age of majority in your jurisdiction) to create an account, and the app is not directed to children. We do not knowingly let anyone below that age hold an account; if we learn of one, we remove it.
Children’s classes at venues.Some venues run mahjong classes for children. When a child is signed up for one of those, the venue sign-up form described in section 2 records the child’s name, a WhatsApp contact number, that they are a child, optionally a home city, and their experience level, so the venue can arrange the class. No Kaki account is created for the child, the child gets no login, and the child is not added to chat or any community feature.
We rely on the parent or guardianto complete that form and to give consent for it. If a child’s details have reached us without a parent or guardian’s consent, email support@kakiapp.co and we will delete them. A parent or guardian can also ask us at any time to show or delete what we hold about their child.
Separately, we have zero tolerance for any content or conduct that sexualises or endangers a child — see our Child Safety Standards.
9. Your rights
Under UU PDP and generally, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal retention (see Account & Data Deletion).
- Object to or restrict certain processing, and withdraw consent you previously gave.
- Data portability — receive certain data in a usable format.
- Lodge a complaint with the relevant Indonesian data protection authority.
To exercise any right, edit your profile in-app or email support@kakiapp.co. We may need to verify your identity before acting on a request.
10. Account & data deletion
You can delete your account and associated data from inside the app or by email. Full steps and what is kept versus removed are on our Account & Data Deletion page.
11. Cookies & tracking
The website uses a small number of cookies and similar technologies — principally a session cookie for authentication, plus local storage the app needs to work. We do not use advertising cookies, and we run no third-party analytics or tracking SDK. See our Cookie Notice for details.
12. Security
We use technical and organisational measures — encryption in transit, access controls, rate limiting on public endpoints, and a payment gateway that handles card data so we never store it — to protect your data. Note that images you send in chat are served from a public address under an unguessable filename rather than behind a login, so treat a chat photo as shareable by whoever receives it. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the authorities of a data breach where required by law.
13. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, notify you in-app or by email. Continuing to use the Services after an update means you accept the revised policy.
14. Contact us
Questions or privacy requests? Email support@kakiapp.co or visit our Support page. To report content or behaviour on Kaki, see the reporting routes in our Community Guidelines.
Kaki · support@kakiapp.co · Last updated 4 July 2026