Privacy Policy
1. Who we are
KinLink is operated by Daniel Roizer, trading as KinLink, a sole trader based in Sutton-in-Ashfield, United Kingdom ("we", "us"). We are the data controller for the personal data described in this policy. KinLink is a UK-only service, we do not sell to, ship to, or offer this service outside the United Kingdom, so all our own processing relates to UK data subjects. Contact us at hello@kinl.ink with any privacy question or request.
2. What we collect, and why
2.1 Account holder (guardian) data
When you create an account: name, email address, phone number. Used to operate your account, process orders, and contact you about scans and renewals.
2.2 Child/dependant profile data
When you add a child or dependant to your account: their name and profile details, and the information below.
Emergency contacts (per child): name, relationship, phone number, email, notification preference (SMS/email), priority order. Used solely to route a scan alert or finder message to the right person.
Medical information (optional): allergies, conditions, medications, GP details. This is special category health data. It is only collected if you actively choose to add it, is encrypted at rest, and you separately control, field by field, whether it is visible to a finder on the scan page, given specifically for this feature, separate from your general account consent. You can remove this information at any time.
2.3 Order and payment data
Order history, items purchased, delivery address. Card payment details are handled entirely by our payment provider, Stripe, we do not receive or store your full card number.
2.4 Scan data
Every time a wristband is scanned: the time of the scan, a hashed version of the finder's IP address (we do not store the finder's IP address in readable form), and, if the finder chooses to provide them, a message and/or their own approximate location (rendered as a static map via our map provider, see Section 3).
3. Who we share data with
We use the following third-party services to operate KinLink. Each only receives the data it needs to perform its function, and each is bound by its own privacy terms as a data processor acting on our instructions:
| Service | What it's used for | What it receives | Where it's processed |
|---|---|---|---|
| Stripe | Payment processing, renewal subscriptions | Payment details, billing name/email, order amount | UK/EU and the United States. Stripe LLC is US-based; transfers from the UK are covered by the EU-US Data Privacy Framework and UK-approved Standard Contractual Clauses |
| The SMS Works | Sending scan alert and notification SMS messages | Recipient phone number, message content | United Kingdom only (their servers and data centres are UK-based, and they state SMS data does not leave the UK) |
| Geoapify | Generating the static map image on the finder-facing scan page | The location shown on the map (our server requests the map on your behalf, the map provider's key is never exposed to the finder's browser) | European Union (Geoapify is an EU company and hosts services in EU data centres by default). This is a transfer covered by the UK's adequacy decision for the EU, not a higher-risk transfer |
| Royal Mail (Click & Drop) | Creating shipping labels and dispatching orders | Delivery name and address, order reference | United Kingdom (Royal Mail Group is a UK company processing domestic shipping data) |
We do not sell personal data to third parties, and we do not share child or medical data with any service beyond what's listed above and what's needed to deliver the safety function itself.
4. International transfers
Because KinLink only sells to and serves customers within the United Kingdom, the personal data we hold about you and your family is, by default, UK data. The only transfer of note is Stripe, which processes payment data in the United States as well as the UK/EU, and which we rely on for card payments and renewal billing. That transfer is protected by Stripe's certification under the EU-US Data Privacy Framework and by UK-approved Standard Contractual Clauses, both recognised transfer safeguards under UK GDPR. Our other processors (The SMS Works, Royal Mail) keep data within the UK, and Geoapify's EU processing is covered by the UK's own adequacy decision for the European Union, which does not require additional safeguards.
5. How long we keep data
- Account and child profile data: for as long as your account is active, and for a reasonable period after closure in case you wish to reactivate, after which it is deleted unless we're required to keep it for a legal reason (e.g. financial records).
- Scan records: kept in a form that supports abuse detection (hashed IP, timestamp) for as long as the associated wristband is active. If you erase a child's data using the account tool described in Section 6, associated scan records are anonymised rather than fully deleted, so scan-count abuse patterns can still be detected without any personal data remaining attached to them.
- Order and payment records: kept for as long as required by UK tax and accounting law (normally 6 years).
6. Your rights, and the tools we give you to exercise them
Under UK GDPR you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. KinLink gives you direct, self-service tools for the most common of these rather than requiring you to submit a request and wait:
- Export your data: available directly from your account settings, produces a copy of your account, children, contacts, and scan history.
- Erase a child's data: available directly from your account, removes that child's profile, contacts, and medical information. Associated scan records are anonymised as described in Section 5, not fully deleted.
For anything not covered by these self-service tools (e.g. correcting an error you can't fix yourself, or a full account deletion request), contact us at hello@kinl.ink. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you believe we've mishandled your data.
7. Children's data specifically
KinLink is not designed for children to use or interact with directly. All child profile data is entered and controlled by the guardian's account. By adding a child's profile, you confirm you are their parent, guardian, or otherwise have the authority to provide their information for this purpose. If you believe a child has provided their own data to KinLink without appropriate authorisation, contact us at hello@kinl.ink so we can review and, if appropriate, remove it.
8. Security
Medical information is encrypted at rest. Access to personal data within our admin systems is restricted by role (only staff with an administrator role can access the back office), and administrative access to sensitive records is logged for audit purposes. Finder IP addresses on scan records are stored as a salted hash, not in readable form. No system is completely secure, and we can't guarantee absolute security, but we take reasonable technical and organisational measures appropriate to the sensitivity of the data involved.
9. Cookies and similar technologies
We use essential cookies needed to operate your account session and checkout (including cookies set by Stripe during payment).
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified to account holders in advance, in the same way described in our Terms and Conditions.
11. Contact
Questions about this policy or your data: hello@kinl.ink.