Privacy Policy
Last updated: 27 May 2026
Joiyin (operated by Phokasa, a sole proprietorship) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our mobile app and website (the “Service”). By accessing or using the Service, you acknowledge that you have read and understood this policy.
Language. The English version of this Privacy Policy controls. Translations, if any, are provided for convenience only.
1. Accountability (Who We Are)
Operator: Phokasa (sole proprietorship), doing business as Joiyin
Website: joiyin.com
Privacy contact: privacy@joiyin.com
General support: support@joiyin.com
Business contact (PIPEDA):
Phokasa
Ontario, Canada
For privacy correspondence or our business mailing address, contact privacy@joiyin.com.
Privacy inquiries: For access, correction, deletion, or complaints, email privacy@joiyin.com. You may also contact the Office of the Privacy Commissioner of Canada if you are not satisfied with our response.
Quebec (Law 25): If we materially target Quebec users with a French-language Service, additional disclosures and a French version may be required. Our initial global launch uses English as the controlling language; a Quebec/French package will be added when we enter that market.
2. Information We Collect
- Account Information: Email address, password (hashed), username, real name (where provided), and profile settings.
- User Content: Text, images, and other materials you submit when posting Activities or messages.
- Usage Data: Device type, OS version, app version, IP address, timestamps, and log data.
- Activity Tracking: We record
last_active_at(timestamp of last app use) for virtual currency decay logic. We do not track which screens you visit or detailed behavioral profiles—only last-activity time while your account exists. - Location Data: GPS or network-based location when you enable location for Activities. Location privacy: Non-participants typically see only an approximate area (about 500 m radius). Participants usually see the precise meeting point only within two (2) hours before the scheduled start time, unless the product shows otherwise for a given Activity.
- Activity Participation Logs: When you join or leave activities, we log approximate device location (rounded to a 1 km grid), IP address, and basic device information for security, trust scores, and abuse prevention. Retained 60 days; administrator access only.
- Payment & Transaction Data (real money): Purchase history and payment metadata processed by Stripe (web) or Apple / Google (in-app). Card data is handled by the payment processor, not stored on our servers in full.
- Virtual Currency Data (Joiys): Records of Joiys gifts, balances, and credit grants. Joiys are virtual currency, not fiat money, with no cash value. This data is separate from card processing and is used for in-app economy integrity and audit.
- Content Moderation Data:
- User Reports: Reporter ID (if you report), reported user ID, reason, optional description, timestamp, status
- Creator actions: Creator ID, removed user ID, activity ID, reason, timestamp
- Admin actions: Admin ID, decisions, notes, sanctions
- Chat & Media: Activity-scoped messages and optional photos, subject to ephemeral retention (messages expire after approximately 24 hours; see retention below).
- Third-Party Sign-In: Information from Apple or Google when you use those sign-in options.
3. How We Use Your Information
- Service Delivery: Accounts, Activities, chat, maps, notifications, and Joiys features.
- Virtual Currency Management: Prevent decay for active users; maintain economy health.
- Security & Trust: Abuse detection, trust scores, join/leave analysis.
- Community Safety & Moderation: Reports, enforcement, legal obligations regarding illegal content.
- Improvement & Analytics: Product analytics (e.g., Sentry, Firebase, privacy-oriented web analytics where configured).
- Communication: Transactional messages, security alerts, and marketing with consent where required.
- Legal & Security: Fraud prevention, law enforcement requests, Terms enforcement.
Automated moderation: Report counts may trigger priority flags and admin notifications (e.g., at 3, 5, 10+ reports). Moderation decisions are made by humans, not solely by automation.
4. How We Protect Your Information
We use administrative, technical, and physical safeguards (encryption in transit and at rest where applicable, access controls, least-privilege admin access). No system is perfectly secure—protect your credentials and devices.
Automated Data Cleanup
- Logs past retention are deleted automatically (daily cleanup, ~2:00 UTC).
- Deletions are logged for compliance where required.
Data Minimization
We retain data only as long as needed for legal compliance, service delivery, and security, then delete or anonymize it.
5. Disclosure & Sharing
- Service Providers (subprocessors): Supabase (backend, database, storage); Stripe (web payments); Apple and Google (IAP and sign-in); OpenStreetMap contributors (map tiles); Sentry (errors); Firebase (analytics, push, App Check); OneSignal (push); hosting providers for joiyin.com.
- Legal Obligations: When required by law or to protect rights, safety, or property.
- Business Transfers: In a merger, acquisition, or asset sale, subject to confidentiality and notice where required.
We do not sell your personal information.
6. Data Retention & Deletion
| Category | Retention period |
|---|---|
| Profile / account | While active + 30 days after deletion request |
| Activity participation logs | 60 days |
| Chat messages | ~24 hours TTL per message; activity-related data up to ~30 days after activity ends where applicable |
| Virtual currency / wallet audit | 1 year (purchases, gifts, reversals) |
| Purchase records (fiat) | 1 year |
| Transaction events (fraud) | 90 days |
| Security / decryption logs | 60 days |
| Trust / points ledger | 1 year |
| Moderation — resolved reports | 90 days |
| Activity ban lists | Duration of activity (up to ~24 h lifecycle) |
| Moderation action records | 1 year |
| Admin audit logs | 7 years |
| Notifications (read / unread) | 7 / 14 days |
You may request deletion or export by contacting privacy@joiyin.com. Some data may be retained where required by law or for disputes, security, or audit.
7. International Data Transfers
Your information may be processed in Canada, the United States, or other countries where our providers operate. We use contractual and legal safeguards (e.g., standard contractual clauses, adequacy decisions, or consent) where required by GDPR, PIPEDA, and other laws.
8. Your Rights & Choices
Depending on your location, you may have rights to:
- Access and receive a copy of your personal information
- Correct inaccurate data
- Delete your data (subject to legal exceptions)
- Portability (machine-readable export where feasible)
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Opt out of marketing communications
Canada (PIPEDA): Contact privacy@joiyin.com. You may complain to the Office of the Privacy Commissioner of Canada.
EEA/UK (GDPR-style): If you are in the EEA or UK, you may have additional rights. We do not claim to be established in the EU; we apply these principles to international users where appropriate. Contact privacy@joiyin.com; you may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): California residents may have rights to know, delete, and opt out of certain sharing. We do not sell personal information. Contact privacy@joiyin.com.
Response time: We aim to respond within 30 days (or as required by applicable law).
9. Cookies & Similar Technologies (Web)
On joiyin.com and the web app we may use:
- Essential cookies / storage: Session and security (e.g., authentication state).
- Analytics: Privacy-oriented analytics (e.g., Plausible) where configured—aggregated, no cross-site ad profiles in our default setup.
- App technologies: Local storage and similar APIs for preferences.
You can control cookies through your browser settings. Blocking essential cookies may limit functionality. Our mobile apps use device identifiers and SDKs (Firebase, etc.) as described above—not browser cookies.
10. Children’s Privacy
Joiyin is for users 18+ only. We do not knowingly collect data from anyone under 18. If we learn we have collected such data, we will delete it and may terminate the account.
11. Security Measures
See Section 4. Report suspected account compromise to support@joiyin.com.
12. Changes to This Policy
We may update this Privacy Policy. We will post the new version with an updated “Last updated” date and provide additional notice for material changes where required. Continued use after the effective date constitutes acknowledgment unless law requires explicit consent.
13. Contact Us
| Purpose | Contact |
|---|---|
| Privacy rights, access, deletion | privacy@joiyin.com |
| General support | support@joiyin.com |
| Legal notices | legal@joiyin.com |