Last updated ·

Privacy Policy

Clear rules for how KUPELY handles account data, referral activity, fraud prevention, and city requests.

Email privacy team
Data minimization

Track visits, not private lives

The data model stays focused on verified visits, transparent payouts, fraud prevention, and support requests.

Plain language draft

Privacy policy mapped to product data

Each section explains what data KUPELY handles, why it is needed, and where that behavior appears in the prototype.


01

Data collected

KUPELY collects account, profile, offer, referral-link, visit, and support data needed to run the service.

  • Account & profile: your name, email, role (creator, business, or admin), password hash, and any handle or avatar you add.

  • Business & offer data: business name, location, category, operating hours, and the per-visit terms set on an offer.

  • Referral & visit data: the links creators generate, the verified visits they drive, timestamps, and basic fraud signals.

  • Support & city requests: messages you send the team and any “Bring KUPELY to my city” submissions.

Product map · Accounts, offers, visit logs
02

How data is used

Data supports routing, verified visits, fraud prevention, payouts, reporting, and support.

  • Run the core loop: publish offers, generate referral links, and verify in-person visits.

  • Calculate and display owed payouts, earnings, and performance in the creator and business dashboards.

  • Detect and screen duplicate or suspicious visits before they count toward a payout.

  • Answer support requests and gauge demand for launching in new cities.

Product map · Dashboards, verification
03

Referral and visit data

Referral links and verified visits are tracked so creators and businesses can see status and owed amounts.

  • Each referral link is tied to the creator who made it and the offer it promotes, with the payout rate locked at creation.

  • A verified visit records the referring link, a check-in, and a timestamp — never the guest’s personal identity.

  • Link status (pending, cleared, paid) and owed amounts surface to both sides in real time.

  • Repeat scans from the same guest are deduplicated so one person can’t generate multiple payouts.

Product map · Link status, payout ledger
04

Sharing and processors

KUPELY shares data only with service providers, partners, or role-based workspaces needed to operate the product.

  • Infrastructure providers (hosting, database, email, routing) process data solely to deliver the service.

  • Role-based workspaces: businesses see their own offers and visits, creators see their own links and earnings, admins see review and oversight tools.

  • We never sell personal data and don’t share it for cross-context behavioral advertising.

  • Where a business or city partner needs data to operate, access is scoped to what that role requires.

Product map · Vendors, role access
05

Privacy choices

Users can request access, correction, deletion, and Do Not Sell / Share handling through the privacy team.

  • Request a copy of your data, or ask us to correct anything that’s inaccurate.

  • Delete your account and the data tied to it, subject to legal and fraud-record retention.

  • Exercise Do Not Sell / Share — and even though we don’t sell data, the request is honored and logged.

  • Reach all of this through the privacy team; requests are confirmed and actioned from your account.

Product map · Support request flow
06

Retention and security

Data is kept while needed for service, legal, fraud, and accounting reasons, with reasonable safeguards.

  • Account and ledger data is kept while your account is active and as long as payouts or disputes may need it.

  • Fraud and accounting records are retained as required by law, even after an account closes.

  • Data is protected with encryption in transit, access controls, and role-scoped permissions.

  • When data is no longer needed for any of these purposes, it’s deleted or anonymized.

Product map · Retention, safeguards

Questions about privacy?

Email kupely@kupely.com for access, correction, deletion, or Do Not Sell / Share requests.

Email privacy team