Pipoka
Pipoka Privacy Policy
This policy explains what Pipoka collects, why we use it, who processes it, how long it is kept, and the choices available to you.
1. Scope and controller
Nexfood Limited operates Pipoka. This policy covers the Pipoka mobile apps, public legal pages, account services, content playback, community features, purchases, notifications, and first-party product analytics.
2. Information we process
- Account data: phone number or enabled sign-in provider identifier, nickname, avatar, language, region, account status, and preferences.
- Device and security data: install/device identifier, platform, operating-system version, model, locale, app version, network class, push token, IP address, user agent, session and security signals.
- Use and content data: feed impressions and actions, searches, playback progress and quality, likes, favorites, follows, comments, reports, check-ins, tasks, notification interactions, and app settings.
- Transaction data: product, order, subscription and entitlement identifiers, price, currency, status, provider transaction/receipt references, refunds and wallet entries. Apple, Google, or Xendit processes the payment method; Pipoka does not need your full card number.
- Support and rights-request data: messages and the minimum information needed to verify and respond to a request.
3. Why we use information
Depending on your location and the activity, processing is based on performing our service contract, your consent, our legitimate interests in operating and securing the service, or a legal obligation. You may disable product analytics in Settings without losing core playback functionality.
- Provide sign-in, playback, personalization, community, customer support, purchases, subscriptions and account security.
- Remember preferences, synchronize progress, deliver requested notifications, prevent fraud and enforce community rules.
- Measure reliability, retention and feature performance, improve recommendations and content decisions, and run controlled product experiments when analytics is enabled.
- Meet payment, tax, accounting, legal, safety and store-policy obligations.
4. Service providers and disclosures
We do not sell personal data and do not use it for cross-company advertising tracking. We disclose only what is needed to providers that help run the service, such as AWS and CloudFront, PostgreSQL/ClickHouse hosting, Apple and Google billing, Xendit web payments where available, Twilio verification, FCM/APNs notifications, and first-party analytics providers configured for the release.
We may disclose information when required by law, to protect users and the service, or in a corporate transaction subject to appropriate safeguards. Each provider processes data under its own terms and our applicable agreements.
5. International transfers
Pipoka serves users across countries. Information may be processed in Hong Kong, Singapore, the United States, or another location where our contracted providers operate. We use contractual, technical and organizational safeguards required for the transfer.
6. Retention and deletion
- Account information is kept while the account is active and is anonymized or deleted when the account is deleted.
- Raw product-analytics events are designed for a rolling 30-day retention window; aggregated, non-identifying statistics may be retained longer.
- On account deletion, sign-in identities, sessions, device/push tokens, playback and feed history, notifications, social relationships, check-in/task history, analytics identity links and interactive state are removed. Authored comment text is erased and replaced with a non-identifying “[deleted]” placeholder so other people’s replies are not destroyed.
- Payment, refund, subscription, wallet and reward ledgers may be retained for the period required for tax, accounting, chargeback, fraud-prevention and legal obligations, linked only to the anonymized account record.
- Backups and provider systems may take a limited period to expire securely. We do not use retained records to restore a deleted account.
7. Your choices and rights
Depending on local law, you may request access, correction, deletion, portability, restriction or objection, and may withdraw consent. You can change analytics and notification choices in the app. You may delete your account in Settings or use the external deletion page.
We may verify your identity before acting on a request. You may also complain to your local data-protection authority.
8. Security, children and updates
We use access controls, encryption in transit, secret isolation, least-privilege service access, audit trails and deletion controls. No system is perfectly secure, so contact us if you believe your account or data is at risk.
Pipoka is not directed to children under 13 or a higher minimum age required in their country. If we learn that a child’s data was collected without required authorization, we will delete it.
We may update this policy when the service or law changes. Material changes will be presented through the app or this page, and the effective date will be updated.