Contents
- 1. Who this policy is from
- 2. What personal information we collect
- 3. How we use your information
- 4. Who we share information with
- 5. International data transfers
- 6. How long we keep information
- 7. Your rights and how to exercise them
- 8. Sign in with Apple and “Hide My Email”
- 9. Children
- 10. Security
- 11. Third-party links and services
- 12. Changes to this policy
- 13. Contact us
1.Who this policy is from
This Privacy Policy explains how we collect, use, share, and protect personal information when you use:
- The Krossee Consumer app (iOS, bundle identifier
com.servicepoints.krossee) - The Krossee Business app (iOS, bundle identifier
com.servicepoints.krosseebusiness) - The Krossee website at https://www.krossee.com and related subdomains
- Any support channels operated under the Krossee brand
We refer to all of the above together as the Service.
The data controller (and, for California residents, the “business”) is:
2.What personal information we collect
We collect only what we need to make Krossee work. Information falls into the categories below.
2.1Account and sign-in
- Sign in with Apple identifier — the opaque Apple user ID we receive when you sign in.
- Email address — either your real Apple ID email, or the private-relay address (
@privaterelay.appleid.com) that Apple generates when you choose “Hide My Email.” We store this address so we can send you welcome messages, security notices, and account-related communications. - Krossee ID — an internal identifier we assign to your account (e.g.
I0000001for Consumer users,B0000001for Business users) used to reference your account inside the Service.
2.2Profile information you provide
- Dummy profile: a nickname (first / last), an avatar image, and interest tags. This is the identity other Krossees see before you reveal more.
- Private profile: your real first and last name, real phone number, real photo, optional business card image, and interest tags. Shared only when you explicitly reveal it.
- Social profile: optional social platform handles you choose to associate with your account.
- Business profile: your role/title, organization name, work phone, work email, organization address, website, and optional business card image.
- Preferences: your discovery modes (Individual / Party / Street / Townhall / Conference / Business), Auto-Kross settings, Auto-Accept settings, broadcast audience and mode, and other in-app preferences.
2.3Photos and documents you upload
- Real photo (Private profile).
- Custom avatar (Dummy profile).
- Business card image, captured using Apple’s VisionKit document scanner from the device camera or selected from your photo library.
- Promotional documents and brochures you accept from Krossee Business users.
Images are stored on our backend (see Section 4).
2.4Proximity-discovery data
Krossee uses Bluetooth Low Energy (BLE) to discover other Krossees near you.
- Broadcast: while Krossee is running (foreground or background), your device advertises your Krossee ID and active discovery modes so nearby Krossees can identify you. Your real name, email, phone, and photo are never broadcast over Bluetooth.
- Receive: your device scans for nearby Krossee advertisements and reads their Krossee ID via a Bluetooth GATT read.
- Interaction records: when two Krossees discover each other, we record the discovery event (Krossee IDs of both parties, timestamp, and approximate location if location permission is granted) so you can remember whom you met and where.
2.5Location
If you grant “While Using the App” location permission, we capture your approximate location at the moment you discover another Krossee, so the Service can show you “met at” information on your connection card.
2.6Push notification tokens
If you allow push notifications, we store your Apple Push Notification service (APNs) device token so we can send you notifications about connection requests, accepts, revealed identity, direct messages, and other in-app events. Tokens are stored per device; they are not identifiers about you personally.
2.7Contacts
If you turn on Auto-add revealed Krossees to Contacts in Settings, we ask iOS for permission to write to your device’s Contacts database. When another Krossee reveals their identity to you and their reveal includes contact fields (name, email, phone), we write a single contact entry per revealed Krossee.
2.8Camera
The camera is used only when you explicitly tap “Take Photo” for a real photo, business card, or promotional document. Images are not captured in the background.
2.9Communications
- Emails we send you (welcome, transactional, support replies) are delivered via Microsoft 365 Graph on our behalf.
- Live Chat in the app connects you to a HubSpot-hosted support chat. If you use Live Chat, the conversation is stored inside HubSpot for the purposes of servicing your request.
- Support tickets submitted from the app are stored in HubSpot.
2.10Analytics and technical data
We log limited first-party analytics inside the Service — screen views, feature-use counts, and error / diagnostic events — to help us understand which features are used and to debug problems. Diagnostic records may include your Krossee ID, app version, iOS version, session ID, and event context. Diagnostic events do not include the text of your messages, your real photo, or your private profile fields. Krossee does not use third-party advertising SDKs and does not use the iOS App Tracking Transparency (ATT) framework, because Krossee does not track you across apps and websites owned by other companies.
3.How we use your information
We use the information above to:
- Provide the Service — sign you in, run BLE proximity discovery, deliver messages, save your profiles, remember whom you have met.
- Send you transactional emails and push notifications tied to your account activity.
- Respond to your support requests, including through Live Chat.
- Detect, prevent, and investigate abuse, fraud, and violations of our Terms.
- Comply with legal obligations and lawful requests.
- Improve Krossee by analyzing aggregate patterns.
We do not sell your personal information. We do not share your information with advertisers. We do not use your Contacts, Photos, HealthKit, HomeKit, or Clinical Records data for marketing, advertising, or use-based data mining.
4.Who we share information with (sub-processors)
We share personal information only with the following service providers, each of which is contractually required to process the information under confidentiality and to provide at least the same level of protection this policy states:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Backend database, storage, authentication, edge functions | United States |
| Apple Inc. — APNs | Push notification delivery | United States / global |
| Microsoft Corporation — Microsoft 365 Graph API | Outbound email delivery from krossee.com addresses | United States / global |
| HubSpot Inc. | Live Chat, support tickets, CRM | United States |
| Apple Inc. — Sign in with Apple | Identity verification at sign-in | United States / global |
| GoDaddy | DNS hosting for krossee.com | United States |
We may also disclose information (i) to comply with a valid legal process, subpoena, court order, or lawful governmental request, (ii) to protect the rights, property, or safety of Krossee, our users, or the public, or (iii) in connection with a merger, acquisition, or sale of assets, in which case successors are bound by this policy.
5.International data transfers
You are using a service operated from Canada with backend infrastructure primarily in the United States. When you use Krossee, your personal information may be transferred to and processed in Canada, the United States, and other countries where our sub-processors operate. For transfers of data originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses and equivalent safeguards.
6.How long we keep information
- Account, profile, and identity fields — kept for as long as your account is active. Removed within 30 days of a Cancel Account request (see Section 7).
- Discovery interactions — kept for as long as the counterparty remains an accepted connection; automatically purged when either side deletes the connection.
- Received Message My Network broadcasts — kept for 24 hours from receipt, after which they expire automatically.
- Push notification tokens — kept while the app is installed and active; refreshed on reinstall.
- Email delivery records — kept for 90 days for troubleshooting and audit.
- Support tickets and Live Chat transcripts — kept for 2 years for service-quality auditing.
- Backups — encrypted backups may contain data for up to 30 days after deletion from live systems, after which they are overwritten.
- Legal-hold data — we may retain specific records longer where required by law (for example, tax, subpoena, or fraud investigation).
7.Your rights and how to exercise them
Regardless of where you live, you can:
- Access — see the profile information stored about you inside the app.
- Correct — edit your dummy, private, social, and business profiles from Settings.
- Delete — tap Settings → Cancel Account inside the Krossee Consumer or Krossee Business app. This starts a permanent account-deletion process that removes your profile records, connections, messages, uploaded images, and preferences from live systems within 30 days. A confirmation email is sent to your account address once deletion completes.
- Revoke consent — turn off any permission (Bluetooth, Location, Contacts, Camera, Push) from iOS Settings → Krossee; the corresponding features will stop working.
- Ask us questions or file complaints — email krossee-security-report@krossee.com.
7.1If you are in the European Economic Area, the United Kingdom, or Switzerland (GDPR / UK-GDPR)
In addition, you have the right to portability (receive your data in a structured, machine-readable format), the right to object to processing, the right to restriction, and the right to lodge a complaint with your national data protection authority. Our legal bases for processing are: (a) performance of the contract with you, (b) legitimate interest in providing and securing the Service, (c) your consent for optional features (e.g. Contacts auto-add), and (d) legal obligation.
7.2If you are in California (CCPA / CPRA)
You have the right to know what personal information we collect and disclose, the right to delete, the right to correct, the right to opt out of the sale or sharing of your personal information (we do neither), and the right to non-discrimination for exercising your rights. Email krossee-security-report@krossee.com to make a request. We do not knowingly sell or share the personal information of anyone.
7.3If you are in Canada (PIPEDA)
You have the right of access to your personal information and the right to challenge its accuracy. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada.
8.Sign in with Apple and “Hide My Email”
Krossee uses Sign in with Apple as its identity provider. If you choose “Hide My Email” during sign-in, Apple gives Krossee a private-relay address in place of your real address. We save this address as your email of record and use it for all transactional emails; Apple forwards those emails to your real Apple ID inbox. You can disable this forwarding at any time from appleid.apple.com → Sign-In and Security → Sign in with Apple.
9.Children
Krossee is not directed to, and we do not knowingly collect information from, users under the age of 18. The apps present an age gate at sign-up. If you are under 18, do not use Krossee. If you believe we have inadvertently collected information from a child under 18, contact krossee-security-report@krossee.com and we will delete it.
10.Security
We protect your information using industry-standard measures: TLS in transit, encryption at rest for the database and object storage, principle-of-least-privilege access for our team, row-level security on all user tables, security definer procedures for sensitive operations, and audit logging of administrative actions. No system is perfectly secure; we encourage you to use a strong Apple ID passcode and enable two-factor authentication on your Apple ID.
11.Third-party links and services
The Service may contain links to third-party websites or services (for example, from a Business profile’s Website field). We are not responsible for the privacy practices of those third parties. Please review their policies before providing any information.
12.Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date at the top and, if the change is significant, notify you via in-app banner or email. Continued use of the Service after the effective date of the updated policy constitutes acceptance.
13.Contact us
Questions, comments, or requests about this policy or your data:
Contact Krossee
Email: krossee-security-report@krossee.com
General: krossee-info@krossee.com
Mail: Service Points Inc., 336 – 901 3rd Street West, North Vancouver, BC V7P 3P9, Canada
This policy is written in English. Translations, if provided, are for convenience; the English version governs.