1. Introduction
Pro-Motion Lab Limited (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access and use our website, platforms (including Rainure, Kizuna, and Onto Something), and related services (collectively, “Services”).
We process personal data lawfully, fairly, and transparently. We minimize data collection, separate consent-based processing from legitimate business needs, and give you meaningful control.
Please read this Privacy Policy carefully. If you do not agree with our data practices, please do not use our Services.
2. Definitions
3. Information We Collect
3.1 Information You Provide Directly
Account Registration
- •Name, email address, phone number
- •Company name and industry
- •Billing address and payment information
- •Username and password
Service Usage
- •Content you upload, create, or input
- •Messages, communications, and support requests
- •Feedback, surveys, and preferences
Rainure (Events)
- •Event registrations: name, email, ticket type
- •Ticket purchases and transaction history
- •Communication preferences
Kizuna (Insurance)
- •Policy details and claims information
- •Underwriting data
- •Agent and broker information
Onto Something (Local Discovery & Habit App)
- •Account: email address, phone number (optional), display handle. You may sign up with email/password, or sign in with your Google or Apple account; in either case we receive only your name/email as shared by that provider, never your Google or Apple password.
- •Content you create: recommendations you send ("put-ons"), check-ins and notes, saved-place collections, habit goals, and any photos you choose to add (profile avatar, check-in photos, or place photos).
- •Social graph: who you follow, and (kept private to keep the safety features meaningful) who you block, mute, or report, and any report you file or that is filed about you.
- •Location: your general city (for local discovery) always; precise device location only if you grant permission, used solely for "near me" sorting and distance display. We do not track your location in the background, and check-ins are honour-system: we do not require or verify GPS proximity to a place to log a visit.
- •Subscription tier (Free/Pro/Premium), handled through Apple App Store or Google Play in-app purchases and RevenueCat as our subscription-management processor (not yet active while in-app billing is being finalized).
- •A device push-notification token, if you enable notifications, used only to deliver notifications you'd expect (habit reminders, activity related to your account) via Expo's push notification relay.
3.2 Information Collected Automatically (Minimized)
We limit automatic collection to what is strictly necessary. We collect:
- IP address (for security only, not tracking)
- Browser type and operating system
- Pages visited (landing page, checkout page only)
- Referral sources (for marketing attribution only)
- Session cookies (for security and functionality)
- General location derived from IP (not precise; deleted after 30 days)
We do NOT collect:
- ✕Unique device identifiers or fingerprinting
- ✕Precise GPS location (unless you explicitly opt in)
- ✕Individual session behavior for profiling
- ✕Search queries (deleted after 24 hours)
3.3 Information from Third Parties
We receive Personal Data from payment processors (for transaction verification only) and analytics providers (anonymized usage insights). We do not buy, sell, or receive data from data brokers.
3.4 Sensitive Data (Strict Handling)
Rainure: Events Platform
- Health/disability: Only if voluntarily provided for accessibility accommodations
- Dietary preferences: Only if provided for event catering
- Retention: Deleted 1 year post-event
- Deletion: You can request deletion anytime
Kizuna: Insurance Platform
- Health information: Medical history, health claims (inherent to insurance underwriting)
- Financial information: Income, credit history (insurance underwriting)
- Retention: Per insurance regulations (typically 10+ years); cannot be deleted due to legal requirements
- Safeguards: Enhanced encryption, access restrictions, full audit logging
Onto Something: Local Discovery & Habit App
Onto Something does not require or knowingly collect health, financial, biometric, or other special-category data as defined under GDPR Article 9. Any photo you choose to upload (avatar, check-in, or place photo) is entirely optional and under your control; we do not run facial recognition or biometric analysis on any photo.
We strictly prohibit:
- ✕Using sensitive data for marketing, analytics, or profiling
- ✕Sharing sensitive data with non-essential third parties
- ✕Retaining sensitive data longer than legally required
- ✕Training AI/ML models on sensitive data
4. Legal Basis for Processing
- •Promotional emails about products and offers
- •Google Analytics, Hotjar, Mixpanel tracking
- •Facebook Pixel, Google Ads retargeting
- •Behavioural profiling and personalisation
- •SMS/Text message marketing
You can withdraw consent at any time. We stop processing within 2 business days.
- •Account creation and management
- •Processing transactions and payments
- •Delivering platform features (Rainure, Kizuna)
- •Transactional emails (order confirmations, security alerts)
- •Technical support and troubleshooting
You cannot opt out of these without closing your account, as they are essential to the service.
- •Retaining transaction records for 7 years (tax law)
- •Insurance claims retention 10+ years (insurance regulations)
- •Responding to court orders, subpoenas, and legal processes
- •PCI DSS compliance for payment data
Required by law. We cannot avoid these obligations.
4.4 Legitimate Interests (Narrowly Defined)
We only claim legitimate interest after a balancing test and only for narrow technical purposes:
- Fraud prevention and security monitoring (security logs deleted after 90 days)
- Platform stability and bug identification (aggregate metrics only; anonymized after 30 days)
- Enforcing Terms of Service and protecting legal rights
We do NOT claim legitimate interest for:
- ✕Marketing (requires explicit consent)
- ✕Behavioural profiling (requires explicit consent)
- ✕AI/ML training (requires explicit consent)
- ✕Selling data or insights
- ✕Cross-site tracking (requires explicit consent)
- ✕Predictive modeling (requires explicit consent)
5. How We Use Your Information
5.1 Service Delivery (No Choice Required)
- Creating and managing your Account
- Processing transactions and payments
- Delivering platform features and functionality
- Providing customer support
- Sending transactional emails and service announcements
5.2 Service Improvement (Limited & Transparent)
- Analysing aggregate usage patterns (how many users access a feature, not individual behaviour)
- Identifying technical bugs (error rates, crashes, timeouts)
- Measuring platform performance (page load times, uptime)
What we do NOT do:
- ✕Train AI/ML models on user data without separate consent
- ✕Create detailed user behaviour profiles
- ✕Track individual users across sessions
- ✕Combine data across platforms to understand behaviour
- ✕Sell insights to third parties
5.3 Communication
Transactional (No consent required)
- • Order confirmations and receipts
- • Account security alerts
- • Password reset requests
- • Service updates and notices
- • Support responses
Promotional (Consent-based)
- • Product updates and new features
- • Special offers and discounts
- • Newsletter and insights
- • Requires explicit opt-in (not pre-checked)
- • Unsubscribe anytime
6. Data Sharing & Disclosure
We do not sell, rent, or share your Personal Data with third parties for marketing, advertising, or profit. Period.
6.1 Service Providers We Use
All service providers are bound by Data Processing Agreements (DPAs) that restrict how they use your data. They cannot use it for their own purposes.
DigitalOcean
Application and website hosting
Account data, content you create
Supabase
Database, authentication, and file storage
Account data, content, and encrypted credentials
Payment provider
Secure payment processing
Billing details entered on the provider's own secure page; we store no full card numbers
Resend
Transactional emails
Email address and message content only
Google Analytics
Website traffic analytics (anonymized), planned, not yet active
Page views, click patterns; data deleted after 26 months
Hotjar
Session recording and heatmaps (with consent), planned, not yet active
Recordings deleted after 90 days
Supabase (Onto Something)
Onto Something's database, authentication, file storage, and backend functions, hosted in the EU (Ireland)
Account data, content you create, photos, and location as described above; not routed through US infrastructure by default
Expo / EAS
Builds Onto Something and relays push notifications to Apple and Google
Push notification token and notification content
Apple / Google
Native sign-in (Sign in with Apple / Google) and in-app purchase processing for subscriptions
Sign-in identity token (name/email only), and purchase and subscription status
RevenueCat
Subscription management between Onto Something and the app stores, not yet active
Subscription tier and purchase status only, once live
6.2 Legal Compliance & Government Requests
We disclose Personal Data only when required by valid court orders, subpoenas, or legal processes. We disclose only the minimum data required, challenge overbroad requests, and will notify you unless legally prohibited.
6.3 Business Transfers
If Pro-Motion Lab is involved in a merger, acquisition, or asset sale, we will provide 30 days' notice, allow you to request data deletion, and require the acquiring entity to honour this Privacy Policy.
6.4 We Do NOT Share With:
- ✕Advertising networks (Facebook, Google, etc.) for ad targeting
- ✕Data brokers or data aggregators
- ✕Marketing automation platforms (without your explicit consent)
- ✕Competitors or third-party analytics firms
- ✕Any party for their own marketing purposes
7. Data Retention
We retain Personal Data only as long as necessary to provide Services or comply with specific legal requirements. We delete data once these purposes expire.
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account Data | 3 years after account closure | Dispute resolution, tax law |
| Transactional Data | 7 years | Tax and accounting requirements |
| Payment/Card Data | 3 years | PCI DSS compliance, fraud prevention |
| Support Tickets/Emails | 3 years | Dispute resolution, customer service |
| Login/Security Logs | 90 days | Security and intrusion detection |
| Website Analytics | 26 months (anonymized after 13 months) | Service improvement |
| Marketing Lists | Until unsubscribe (then permanent suppression) | Compliance with opt-out |
| Event Data (Rainure) | 2 years post-event | Event history and attendee records |
| Insurance Data (Kizuna) | 10+ years | Insurance regulatory requirements |
| Onto Something Account & Content | Until you delete your account | Kept only while the account is active; deleted on request |
| Onto Something Photos | Until you delete the photo or your account | User-controlled; deletable individually or via account deletion. A community photo shared publicly may stay visible after deletion (with your name removed); see the Onto Something Account Deletion page |
| Onto Something Push Token | Until notifications are off or the account is deleted | No longer needed once notifications are disabled |
| Backup Data | 30 days after deletion | Disaster recovery only |
| Session Cookies | Until browser closes | Security and authentication |
| Preference Cookies | 1 year | User preference storage |
7.1 Deletion Upon Your Request
We delete your data within 30 days of a valid deletion request. If legal obligations require us to retain specific data, we will:
- Inform you of the specific legal requirement (tax law, insurance regulation, etc.)
- Provide an estimated deletion date
- Restrict processing to that legal obligation only
- Delete data immediately when the obligation expires
- Confirm deletion in writing within 30 days
Onto Something users: see our dedicated Account Deletion page for how to request deletion in-app or without the app installed.
8. Your Rights & Choices
8.1 GDPR Rights (EU/EEA Residents)
Right of Access
Request a copy of all Personal Data we hold about you in portable, machine-readable format (CSV/JSON).
Right to Rectification
Correct inaccurate or incomplete Personal Data directly in your account or by emailing us.
Right to Erasure
Request deletion of your Personal Data. Exceptions apply for legal retention obligations, which we will specify.
Right to Restrict Processing
Request we limit how we use your data while a dispute is under investigation.
Right to Data Portability
Receive your data in portable format (CSV or JSON). Covers all data you have provided.
Right to Object
Object to processing based on legitimate interests. We stop within 7 days unless compelling legal reasons override.
Right to Withdraw Consent
Withdraw consent for any permission-based processing (marketing, analytics, profiling). We stop within 2 business days.
Automated Decision Review
Request human review of any automated decision that affects you. No penalty for requesting.
Onto Something: exercising these rights in-app. Export and deletion requests can be made directly from Settings → Your Data, free for every user regardless of subscription tier. Deletion completes within 30 days of your request; if you no longer have the app installed, see our Account Deletion page for how to request it by email instead. One narrow, deliberate exclusion applies to your data export: we do not include who has blocked, muted, or reported you, because disclosing that would defeat the safety purpose of those actions for the other person. This is permitted under GDPR Article 15(4), which states the right of access “shall not adversely affect the rights and freedoms of others.” Your own blocks, mutes, and reports that you filed are always included in your export, since those are your data.
8.2 California Rights (CCPA/CPRA)
Right to Know
Request all Personal Data collected in the past 12 months. Response within 45 days.
Right to Delete
Request deletion of Personal Data, subject to legal exceptions. Response within 45 days.
Right to Opt-Out
We do NOT sell Personal Data under CCPA. You can opt out of analytics data sharing.
Non-Discrimination
We do not discriminate against California residents for exercising their rights.
8.3 Exercising Your Rights
9. Cookies & Tracking Technologies
Essential Cookies
Always ActiveStrictly necessary for basic website functionality. Disabling these breaks the service.
| Cookie | Purpose | Duration |
|---|---|---|
| Session ID | Maintains login state | Session |
| CSRF Token | Prevents cross-site attacks | Session |
| Security Flag | Detects suspicious access | 30 days |
| Language Preference | Stores your language choice | 1 year |
Analytics Cookies
Requires ConsentNot currently active. We plan to deploy analytics tools in the future to track aggregate usage. These will only be activated with your consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Google Analytics | Page views and traffic patterns (anonymized), planned, not yet active | 26 months |
| Hotjar | Session recording and heatmaps (click/scroll only), planned, not yet active | 90 days |
| Mixpanel | Feature usage analytics (anonymized), planned, not yet active | 13 months |
Marketing Cookies
Requires ConsentNot currently active. We plan to deploy retargeting tools in the future. These will only be activated with your explicit consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Facebook Pixel | Ad retargeting on Facebook/Instagram, planned, not yet active | Until opt-out |
| Google Ads | Ad retargeting across Google properties, planned, not yet active | Until opt-out |
How consent works
A cookie banner appears before any non-essential cookies are set. No boxes are pre-checked. You choose exactly which categories to enable. You can update or withdraw your preferences at any time via the Manage Preferences link in the footer.
10. Data Security & Breach Notification
Encryption
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- All backups encrypted
Access Controls
- Role-based access control
- Multi-factor authentication for all staff
- VPN required for remote access
Monitoring
- Real-time security monitoring
- Automated anomaly detection
- Regular penetration testing
Compliance
- PCI DSS for payment data
- Annual security audits
- Employee privacy training
10.1 Data Breach Notification Timelines
High-Risk Breach
(Payment data, credentials, health info, >1,000 records)
You: Notified within 24 hours
Regulators: Notified within 72 hours
Via: Email or phone call
Low-Risk Breach
(Non-sensitive data, small number of records)
You: Notified within 7 days
Regulators: Notified within 72 hours
Via: Email
11. International Data Transfers
Our infrastructure providers, DigitalOcean (application hosting) and Supabase (database, authentication, and storage), may process data in data centres outside your country. Onto Something is handled differently: its user data is hosted in the EU (Ireland) via Supabase, so Onto Something user data does not leave the EU by default. Where a processor does require a transfer (for example, sign-in verification with Apple or Google, or push notification relay through Expo), we use legally approved mechanisms to transfer EU personal data, including Standard Contractual Clauses (SCCs) with Schrems II supplementary safeguards executed with all processors handling EU data.
All EU data is encrypted in transit (TLS 1.3) and at rest (AES-256). If transfer rules change, we will assess compliance within 30 days and cease transfers immediately if they become prohibited, offering EU-only data storage where feasible.
You can request restriction of processing in non-EU locations or request EU-only data storage by contacting [email protected].
12. Sensitive Data & Industry-Specific Use Cases
Sensitive data is handled with strict additional controls depending on the platform and the nature of the data.
Rainure: Events
Health/disability and dietary information may be collected if voluntarily provided for accessibility or catering. This data is encrypted, restricted to event organizers, never used for marketing, and deleted 1 year after the event. You can request deletion at any time.
Kizuna: Insurance
Health information, financial data, and (where applicable) genetic data are inherent to insurance underwriting and claims processing. This data is retained per insurance regulations (typically 10+ years), subject to enhanced encryption and access restrictions, and cannot be deleted due to legal requirements. You have the right to access, correct, and request portability.
Onto Something: Local Discovery & Habit App
Location and photos are the two areas needing the most care here. Your precise location is only read with your explicit device permission, only to sort places by distance, and is never stored as a location history; we don't build a trail of where you've been. Check-ins are honour-system: we don't verify your GPS position against the place you check in to, and the app tells you this plainly rather than implying a verification that doesn't exist.
Community place photos go through a two-layer moderation model: if two or more independent users report the same photo (or one user reports it for a severe reason, such as appearing in it without consent), it is automatically hidden pending review. This is a distinct-reporter threshold, not a raw report count, so one person cannot hide a photo alone. A human moderator then makes the final call on removal. We do not run AI content-scanning on uploaded photos.
Reporter and blocker identity is never disclosed to the person being reported or blocked. This is a deliberate safety design, not an oversight, and it's why our data-export process (Section 8) excludes this specific category of information about other people's protective actions.
Custom Development Projects
Projects involving sensitive data require a separate Data Processing Agreement (DPA), explicit written consent from the authorized data controller, and project-specific security measures in a fully isolated environment.
13. Automated Decision-Making & Profiling
We use automated systems in four areas:
Fraud Detection
Impact: Low-MediumAnalyses login and transaction patterns to flag suspicious activity. May temporarily restrict account access.
Your Rights: Request human review within 48 hours. Account restored immediately if wrongly flagged.
Content Moderation (Rainure)
Impact: LowFlags potential spam, harassment, or Terms of Service violations in event listings.
Your Rights: Request human review within 7 days. Content restored within 48 hours if wrongly flagged.
Insurance Underwriting (Kizuna)
Impact: HighRisk model analyses health, financial, and lifestyle data for insurance approval, premium, and coverage decisions.
Your Rights: Right to request human review, explanation of algorithmic logic, and reconsideration with additional information. Human review within 5 business days. Cannot be subject to purely automated decision without human oversight.
Community Photo Auto-Hide (Onto Something)
Impact: LowA place photo is automatically hidden from public view once two or more independent users report it (or one user, for a small set of severe reasons). This is a visibility hold, not a deletion; the photo is not removed from our systems by this step alone.
Your Rights: Request human review; a moderator reviews every auto-hidden photo. Photos wrongly hidden are restored.
14. Children's Privacy
Our Services, including Onto Something, are not intended for children under 13 (or the applicable age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect Personal Data from children, market to children, or use profiling directed at children.
If we discover a child has provided data, we delete it immediately and notify the parent or guardian. If you believe your child has provided data, contact [email protected] immediately.
15. Third-Party Links & Services
Our Services may contain links to third-party websites and services. We are not responsible for the availability, accuracy, or privacy practices of third-party content or services. Use of third-party services is at your own risk and subject to their own terms and privacy policies.
16. Modifications to This Privacy Policy
We may modify this Privacy Policy by posting the updated version with an updated “Last Updated” date. For material changes, we will provide notice via email or a prominent banner and request reaffirmation of consent where required.
We will NOT:
- ✕Weaken your privacy protections without consent
- ✕Expand sensitive data collection without notification
- ✕Change how we share your data without opt-in
17. Contact Us & Your Rights
Privacy Requests
Email: [email protected]
Acknowledged: Within 24 hours
Resolved: Within 30 days (GDPR) / 45 days (CCPA)
Data Controller
Pro-Motion Lab Limited
Company No.: 120251036414
Plot 13462 Meanwood Ibex, Lusaka, Zambia
17.1 Complaints & Appeals
Contact Us First
Email [email protected]. We investigate and respond within 30 days.
Escalate Your Request
If unsatisfied with our initial response, email [email protected] to have your request reviewed and escalated.
Lodge a Complaint
You have the right to complain to your local data protection authority (e.g., ICO in UK, CNIL in France, California AG, ANPD in Brazil). We cannot restrict this right.
Pro-Motion Lab Limited · Privacy Policy v2.1 · Last Updated August 2026