Privacy Policy

Last updated: 21 June 2026

1. Purpose

Kempire is a members-only community platform. We built it so that people can communicate, share skills and services, and support each other in a private space. You are here by choice — found by choice, not exposed by accident. This policy explains what information we collect, why we collect it, and how we protect it.

2. Who Is Responsible

Kempire is managed by Rah. For privacy questions or requests, contact: admin@kempire.example.com (placeholder — to be updated with real contact).

3. Data We Collect

  • Account data: username, email address, hashed password, timestamps for account creation and last login, and which version of our terms and privacy policy you accepted.
  • Optional profile data: display name, town (area only, not exact address), skills and services, a short description, languages, interests, a free-text employment history summary, a free-text education history summary, preferred contact method, and optional contact email or WhatsApp — all written in your own words, none of it verified or structured.
  • Optional business data: if you register a business, its name, type, description, country/city, and optional contact email, phone, WhatsApp, and website — visible to members only after admin verification.
  • Booking data: if you book an Outing listing, the listing, your requested check-in/check-out dates, booking status, and the price charged in internal credits. Only visible to you, the listing's business owner, and admins.
  • Order data: if you order a Shop, Publishing, or Art listing, the listing, quantity requested, order status, and the price charged in internal credits. Only visible to you, the listing's business owner, and admins.
  • Appointment data: if you request a Consulting, Music, Sports, Technology, or Education listing, the listing, your requested date and time for the session, appointment status, and the price charged in internal credits. Only visible to you, the listing's business owner, and admins. No consultation notes, transcripts, or recordings are collected. Education session listings may include a third-party meeting link (e.g. Zoom, Google Meet) in the listing's free-text description, provided by the instructor — no video/audio/chat session happens on this platform itself.
  • Internal credit balance: your wallet balance and ledger of credit movements (bookings, orders, appointments, admin adjustments, payouts) — an internal points system, not real money or payment card data. Businesses and departments also have wallets; an internal "Treasury" wallet is the ledger counterparty for admin-issued credit grants and payouts, holding no personal data of its own.
  • Payout request data: if a business owner requests a payout from their business's wallet, the requested amount, an optional free-text note, status (pending/rejected/paid), and who requested and processed it. Only visible to the requesting business's owner and admins. This is internal bookkeeping only — no bank details are collected and no real money moves as part of this record.
  • Job posting data: if a verified business posts a job, its title, description, country/city, and an optional free-text compensation note. No structured salary data or payment is involved. Visible to members only once admin-approved.
  • Application data: if you apply to a job posting, the job posting, your optional free-text cover note, and application status (submitted/shortlisted/hired/rejected/withdrawn). Only visible to you, the job posting's business owner, and admins.
  • Resume data (optional): if you choose to attach a resume file (PDF or DOC/DOCX, 5MB max) when applying to a job posting, it is stored outside our public web files and only accessible through an authenticated download link. Only visible to you, the specific business owner of the job posting you applied to, and admins — never to any other member, and not to other businesses. This is optional; applying without a resume is fully supported. We do not use resume uploads to collect identity documents — no passport, government ID, or similar should ever be attached here.
  • Kemunity data: if you post, comment, or vote on a Kemunity's (local community hub) wall, that content is stored the same way as any other wall post. A Kemunity's staff roster (title, person's name, contact info, appointment date) is admin-managed, free-text, and descriptive only — it does not grant any account extra permissions. A Kemunity's "members" list is a read-only view of approved profiles whose town matches the Kemunity's city; it does not require a separate join or approval step.
  • Content: posts, comments, and votes you make on the platform.
  • Technical data: server access logs, login timestamps, and admin moderation logs.
  • Consent records: timestamps and version numbers recording when you accepted our terms.

4. Data We Do NOT Collect

We do not collect and do not allow members to submit:

  • Exact home or work address
  • GPS or precise location data
  • Passport, national ID, or government identification
  • Date of birth
  • Data about children
  • Health or medical status
  • Religious or political views
  • Immigration or legal status
  • Payment or financial details
  • Bulk member exports or public phone directories

5. Why We Use Your Data

  • To authenticate your account and protect access to the community.
  • To enforce the acceptance gate (terms and privacy version check).
  • To enable moderation to keep the community safe.
  • To allow members to find each other by skill and area (if you opt into an approved profile).
  • To respond to privacy requests (hide, delete, correction).

6. Visibility Rules

  • Public (no login required): Home, About, Privacy, Terms, and Register pages only.
  • Members only (login required): Community walls, department walls, Kemunity (local community hub) pages and walls, approved profiles, member directory, and any contact details you chose to share.
  • Profile and contact details are visible according to the visibility setting you chose — either hidden or members-only. We do not offer public profile visibility.

7. Consent

You must accept the current community rules and privacy policy before accessing any member area. We record the version and timestamp of your acceptance. If we make a material change to either document, you will be asked to accept the new version before regaining access. Profile consent is recorded separately when you submit your profile.

8. Your Control

  • You can edit your profile at any time.
  • You can hide your profile so it is no longer visible to other members.
  • You can delete your profile.
  • You can ask an admin what data is stored about you.
  • You can ask for corrections to your data.
  • You can request full account deletion.

9. Admin Access

Admins can approve, reject, or hide profiles; remove posts and comments; and disable accounts. Admins access member data only as needed to operate and protect the community. All admin actions are logged.

10. Search and Indexing

Member pages, walls, profiles, and the admin area are excluded from search engine indexing via robots.txt and noindex meta tags. There is no public member directory, no map view, and no bulk export of member data.

11. Tracking

We do not use Google Analytics, Meta pixel, TikTok tracking, or any advertising trackers. We use server access logs only for basic operational monitoring.

12. Backups

We keep daily backups for up to 7 days for recovery purposes. Deleted profiles are removed from the live site promptly. Old backups expire naturally and are not retained indefinitely.

13. Data Sharing

We do not sell your data. We do not share data with advertisers. We do not create public exports of member information. The only third parties with any access are our infrastructure providers (hosting, DNS, backup storage) who process data under their own privacy terms.

14. Security

  • Passwords are hashed and never stored in plain text.
  • The site uses HTTPS.
  • All member routes require login.
  • Admin routes are further restricted to admin accounts.
  • Secrets are stored in environment variables, never in the codebase.
  • All user input is escaped in templates.
  • Packages are kept up to date.

15. Contact and Requests

To hide or delete your data, request a correction, ask what is stored about you, or report misuse, contact: admin@kempire.example.com (placeholder — to be updated).