Kampawng

Kampawng iOS Application

App Privacy Policy

Last updated:

Kampawng is a product of Keystone Lab and is operated by TZ APAC Pte. Ltd. (UEN: 202012283D) (“we”, “us”, or “our”). We are committed to protecting the personal data of people who interact with Kampawng.

This Privacy Policy explains what personal data we process when you use Kampawng, why we process it, who we share it with, how long we keep it, and the rights available to you. It applies to the Kampawng mobile application, the guest-care web application, our sharing service, our tag pages, and the Kampawng website and its sub-domains (together, the “Service”).

Where a particular section of this Privacy Policy applies only to the Website or only to the App, that is stated clearly. In all other respects, this Privacy Policy applies to your use of the Service in its entirety.

This Privacy Policy should be read alongside our Terms of Service, which governs your use of the Service. Capitalised terms used but not defined here have the meanings given to them in the Terms of Service.

By accessing or using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree, you must not use the Service.

Kampawng is designed to be local-first, and this shapes everything below. Your pets’ records are stored in encrypted form on your own device. There is no Kampawng account, no password, and no copy of your records on our servers — we do not receive them and we cannot read them. Information leaves your device only when you use an optional feature that requires it: sharing with a household member or caregiver, pairing a tag, publishing a Pet ID, enabling notifications, or joining the donor pilot. Other than a published Pet ID and the donor pilot (both explained below, and which we can read), your device encrypts anything you share for the recipients you chose before it reaches us.

We do not sell personal data, we do not serve advertising, and we do not track you across other companies’ apps or websites.

1. Our commitment to data protection principles

We are responsible for the processing of your personal data. In order to protect your personal data in connection with your use of the Service, we are committed to adhering to the principles below.

Every individual working for us must also adhere to these principles in performing his or her day-to-day duties. We will therefore make sure that your personal data is:

  • processed lawfully, fairly and in a transparent manner (lawfulness, fairness and transparency);
  • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (purpose limitation);
  • adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (data minimisation);
  • accurate and, where necessary, kept up to date; every reasonable step will be taken to ensure that your personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay (accuracy);
  • kept in a form which permits your identification for no longer than is necessary for the purposes for which personal data is processed (storage limitation); and
  • processed in a manner that ensures appropriate security of your personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).

The controller of your personal data is TZ APAC Pte. Ltd. If you have any questions, you can reach out to [email protected].

A note on pet data: A pet is not an identifiable natural person, so information about a pet on its own (for example, a breed, a vaccination date, or a microchip number) is not “personal data” under the PDPA, the GDPR, or similar laws. However, records about a pet frequently contain personal data about people such as the name and contact details of a veterinarian, clinic, breeder, shelter, previous owner, or co-carer referenced in a health record, a published Pet ID, or an emergency contact field (“Third-Party Individual Data”). If you record, share, or publish information about another person, you must have their consent or another lawful basis to do so — this applies particularly to a published Pet ID, which can be read by anyone holding the link. This Privacy Policy addresses the personal data of individuals that we or you process through the Service, including such Third-Party Individual Data.

2. Personal Data We Collect

“Personal data” means any information that relates to an identifiable natural person. The personal data we collect depends on how you interact with the Service.

2.1 Website visitors (Website only)

When you visit the Website, our web services keep no visitor access log: the Website application serves the requested page and does not persist your IP address, user-agent string, or referrer in its first-party quiz measurement log. A hosting provider, CDN, reverse proxy, operating system, or network operator may process ordinary request metadata needed to deliver and secure the Website. We may use such infrastructure data for security only where that processing actually occurs, and we may evaluate IP addresses together with other data in cases of suspected attacks on our infrastructure or unauthorised or abusive use of the Website, for the purpose of protection and, where appropriate, for use in legal proceedings against the relevant users. This is based on our legitimate interest in protecting the Website and our users.

2.2 Website Early Access Form (Website only)

The Website currently links to an early-access form hosted by Tally. If you submit that form, Tally and any service used to administer the form may process the information you provide under their own privacy notices. We will describe and use any information we actually receive for the stated early-access purpose.

2.3 Local pet records (App)

Held on your device, and not received by us: pet profiles and health records, care records and observations, routines, reminders, notes, photos, videos, imported documents and attachments, local backups, local diagnostic information, and your app preferences. As set out above, this information relates to your pet rather than to an identifiable natural person, except where it incidentally identifies a person. For example, a previous owner’s name in an adoption record, or a veterinarian’s or clinic’s contact details in a health record.

2.4 Sharing, households, guest care, and tags (App)

When you enable sharing, households, guest care, or tags, we process: technical identifiers for your device and its cryptographic keys; information about the authorisations you create, including the recipient, the role and scope you selected, and the relevant dates and status; the encrypted content and care records exchanged under those authorisations; and technical information associated with a paired tag. Your device encrypts this content for the recipients you chose before it reaches us, so we hold it without being able to read it. Your device identity is not an email address, and there is no password.

2.5 Notifications (App)

If you enable notifications, we process a device notification token issued by Apple. Notifications we send are silent prompts that carry no pet or care content; your device retrieves and decrypts the relevant item locally.

2.6 Published Pet ID (App)

If you publish a Pet ID, we process only the fields you explicitly select from a fixed list which may include your pet’s name, species, breed and photo, a medical-alert headline, and emergency contact and veterinary contact details, together with an optional photo and any expiry you set. Unlike the records described in Section 2.3, we can access a published Pet ID in full: it requires no sign-in, and anyone holding the link or scanning the code can read it for as long as it remains active. Access does not end for anyone who has already read or saved it.

2.7 Donor pilot (App, optional)

If you join the donor pilot, we process your pet’s species and blood type, a coarse Singapore region, your availability and alert preferences, the clinic name you enter, and only after you and a matched participant each explicitly agree, a phone or messaging number exchanged between you. Any abuse report you submit is also processed.

2.8 Device information and usage data (App, opt-in)

If you turn on “Share Anonymous Usage”, we receive aggregate usage events drawn from a fixed list of feature names and predefined values. Your IP address and device user agent are removed and not stored, and free text, contact details, health information, precise location, and persistent device identifiers are not accepted. This setting is off by default, and turning it off deletes anything queued. The App contains no third-party analytics or crash-reporting software.

2.9 Analytics data (Website only)

With your permission at https://kampawng.com, we use Google Analytics 4 to measure selected page visits and allowlisted link actions, drawn from a fixed list of page and action parameters (see Section 6). We do not send form answers, real pet or medical data, user IDs, user properties, cross-domain linker data, or advertising signals.

2.10 Support correspondence

Information you send us when you contact us.

We do not process location data, Apple’s advertising identifier, payment information, or information from a third-party sign-in provider, because the Service does not currently offer any of these features.

3. Why We Collect Your Personal Data

We process personal data collected through the Service for the following purposes:

  • to provide, operate, and maintain the Service, including local pet-record storage, sharing, households, guest care, tags, published Pet IDs, and the donor pilot;
  • to authorise, deliver, and revoke the access you grant to others;
  • to deliver notifications;
  • to operate the donor pilot and other optional features;
  • to understand, in aggregate, how the Service is used, only where you opt in to usage sharing or website analytics;
  • to detect, investigate, and prevent fraud, abuse, and unauthorised access;
  • to respond to support and privacy requests; and
  • to comply with applicable law.

4. Lawful basis for processing

We process your personal data on the following bases in accordance with the Personal Data Protection Act 2012 of Singapore (PDPA) and, where applicable, the General Data Protection Regulation (GDPR) and other applicable data protection laws:

Processing Activities and Lawful Bases
Processing Legal basis
Operating sharing, households, guest care, tags, and notifications you have enabled Performance of a contract
Publishing a Pet ID, joining the donor pilot, optional usage statistics, website analytics, and early-access communications Consent
Security, integrity, abuse prevention, and operating and protecting our website Legitimate interests
Responding to legal requests and meeting our legal obligations Legal obligation

Where we rely on consent, you may withdraw it at any time. Withdrawal applies to future processing and does not affect processing already carried out. Where we have no other lawful ground to continue holding personal data after you withdraw, we will delete it.

5. Disclosure and Transfer of Your Personal Data

We do not sell your personal data. We may share personal data with the following categories of third parties, each of whom is subject to strict confidentiality obligations and required to protect data privacy to a standard consistent with this Privacy Policy:

  • recipients you choose: household members, caregivers, and other people you authorise, and, for a published Pet ID, any person holding the link;
  • other pilot participants: where you take part in a pilot feature and the pilot’s rules provide for it;
  • service providers that support the Service: including hosting, network, and content-delivery providers, Apple (for notification delivery), our website analytics provider (where you have allowed analytics), and our early-access form provider;
  • our operating entity: TZ APAC Pte. Ltd., where necessary for operational or administrative purposes;
  • regulators, courts, and law-enforcement authorities: where disclosure is required by a binding legal obligation or is permitted to address fraud, abuse, or a security threat — we assess each request and comply only where it is legally binding and properly issued; and
  • an acquiring entity: in connection with a merger, acquisition, financing, reorganisation, or sale of all or a material part of our assets, subject to protections consistent with this Policy.

Where we engage a service provider as a processor, it acts only on our instructions under a written agreement requiring confidentiality and security measures appropriate to what it holds.

In the event of a merger, acquisition, or sale of all or a material part of our assets, your personal data may be transferred to the acquiring entity, provided that entity agrees to be bound by terms consistent with this Privacy Policy.

6. Google Analytics (Website only)

On the Website, we use Google Analytics 4, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Analytics cookies are only placed on your device after you provide consent through our cookie consent mechanism; before permission is given, after permission is denied, and on non-canonical or non-HTTPS hosts, the Website does not start the Google tag.

Our Google Analytics configuration is limited and fixed: the Website sends only predefined page and action parameters, and does not send form answers, real pet or medical data, user IDs, user properties, cross-domain linker data, or advertising signals. Google may process browser, device, and usage information under its current terms and may transfer that data to servers in the United States. You may withdraw consent at any time through your browser settings or the Google Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout. For further information on how Google processes data, see Google’s Privacy Policy at https://policies.google.com/privacy.

7. Cookies (Website only)

The mobile application uses no browser cookies. The guest-care web application sets no cookies; it stores its keys and any work pending submission in the caregiver’s own browser storage. Our website uses:

Website Cookies and Storage
Category Purpose Retention
Strictly necessary Records your analytics choice so we do not ask again Up to 180 days
Analytics Website usage measurement, set only after you allow analytics Up to 28 days
Local preference Remembers your light or dark display choice, stored in your browser only Until you clear it

You can change your choice at any time using “Cookie preferences” in the website footer, and you can manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Website.

8. Tracking

We do not track your activity across other companies’ apps or websites for advertising purposes, and we do not share your data with advertising networks or data brokers. The App does not access device-level advertising identifiers such as Apple’s IDFA, so no App Tracking Transparency prompt is required.

9. Securing your data

We use reasonable technical, organisational, and administrative safeguards designed to protect personal data processed through the Service. These include encryption of your records on your device, encryption of shared content before it leaves the sending device, encryption in transit and at rest on our servers, device authentication and app-lock controls, cryptographic verification of requests to our sharing service, access controls, restricted service exposure, rate limits and quotas, and operational monitoring.

Where information is held on your device or in a caregiver’s browser, its security also depends on the device passcode, biometric lock, operating system protections, and the security of any copy you export. The App can create a backup protected by a passphrase you choose; we cannot recover that passphrase or open the backup without it. Please secure the devices and files under your control, and contact us promptly at [email protected] if you suspect unauthorised access.

No service, device, network, or encryption method is completely secure, and we cannot guarantee that the Service will be immune from unauthorised access, data loss, or security incidents.

10. Data Breach Response

If we become aware of a personal data breach, we will take reasonable steps to investigate, contain, remediate, and mitigate its effects. Where the breach is notifiable under Singapore’s PDPA, we will notify the Personal Data Protection Commission (PDPC) within 3 calendar days of making that determination. Where the GDPR applies, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours. We will notify affected individuals where required by applicable law, using a channel available for the affected feature — for example, an in-app notice.

11. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, and then delete it or render it anonymous. Where we cannot state a fixed period, we determine retention by reference to how long the feature needs the data, any applicable legal or regulatory requirement, and our need to resolve disputes, prevent abuse, and enforce our terms.

In practice:

  • records and other content held on your device remain there until you delete them, and local diagnostic information is limited to a short rolling window;
  • content and care records shared under an authorisation are retained until the authorisation is revoked or expires, or your relay account is deleted, and care submissions and guest-care media are in any event deleted within approximately 30 days;
  • a published Pet ID is retained until it expires, you revoke it, or you delete your relay account;
  • notification tokens are retained until replaced, until you turn notifications off, or until your relay account is deleted;
  • donor pilot information is retained while you take part and for a short period afterwards for moderation and dispute-handling purposes, and contact details exchanged with a participant are cleared as soon as the exchange ends;
  • optional usage statistics are retained as aggregate counts, and the technical reference that groups a single day’s events is discarded once that day ends; and
  • after you delete your relay account we retain a limited record confirming the deletion, so that it can be evidenced and cannot be repeated in error.

Deleted information may persist briefly in backups and disaster-recovery systems until those systems complete their ordinary overwrite cycle.

11.1. Deleting your information

The App provides two separate controls, and it is important to understand the difference. “Delete All Data / Start Over” removes Kampawng’s data, key material, attachments, backups, reminders, tag state, diagnostics, and preferences from that device and returns the App to first run; it offers to create an encrypted backup first and asks you to confirm. “Delete Relay Account” permanently removes your registration with our sharing service, revokes the access you have granted to others, removes your household memberships and any published Pet ID, and removes your notification token; your records on your device are preserved. You can choose to do both at once. Neither control erases a physical tag, a file you have exported outside the App, or information a recipient has already received.

12. Cross-Border Data Transfers

Because the Service relies on cloud infrastructure, network providers, notification services, and other service providers, personal data may be transferred to, stored in, or processed in countries outside Singapore. Where required, we use safeguards recognised by applicable law: for transfers subject to the PDPA, arrangements requiring the recipient to provide a comparable standard of protection; and for transfers subject to the GDPR, an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. You may ask us which safeguard applies to a particular recipient.

13. Your rights in connection with your data

You have the following rights in connection with your personal data, subject to applicable law:

  • Access: confirmation of whether we hold personal data about you, and information about its use and disclosure;
  • Correction: correction of inaccurate or incomplete personal data we hold about you;
  • Erasure: deletion of your personal data;
  • Data portability: a copy of qualifying personal data in a structured, commonly used, and machine-readable format;
  • Objection: objection to, or restriction of, our processing of your personal data; and
  • Withdrawal of consent: where processing is based on consent, withdrawal of that consent at any time.

Because your records are held on your own device and we cannot read them, a request about that content is usually satisfied fastest by the App’s own export and deletion controls described in Section 11.1, rather than by contacting us.

To exercise a right that concerns information we do hold (see Section 2), contact us at [email protected] with “Privacy Request” in the subject line. We will respond within 30 days, or within any shorter period required by applicable law. We may need information to verify your identity. These rights may be limited by law, by the rights of others, by security requirements, and by our need to establish, exercise, or defend legal claims.

You may also lodge a complaint with a data protection authority. In Singapore this is the Personal Data Protection Commission (PDPC) at https://www.pdpc.gov.sg. We would appreciate the opportunity to address your concern first.

14. Children and Minors

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe we hold personal data relating to a person under 18, please contact us at [email protected] and we will assess the circumstances and take the steps required by applicable law.

If you record a minor as a co-carer, owner, or emergency contact, you are responsible for obtaining the authority and consent required by applicable law.

15. Changes to this Privacy Policy

We may update this Policy to reflect changes to the Service, our processing practices, or applicable law. We will post the updated version and revise the date above. For material changes we will provide the notice, or obtain the consent, required by applicable law through a channel available for the affected feature — for example, an in-app notice or a notice on the Website. We will not introduce external processing of your records, including any use of a third-party artificial intelligence service, without updating this Policy first and obtaining any permission required.

16. Contact

For questions about this Policy, or to make a privacy request, contact us at [email protected] with “Privacy Request” in the subject line. For product support, contact [email protected].

Kampawng
Developed by Keystone Lab and operated by TZ APAC Pte. Ltd. (UEN: 202012283D)
36 Robinson Road, #07/05-06 City House, Singapore 068877
Email: [email protected]

Where you are located in a jurisdiction with a designated data protection supervisory authority, you also have the right to lodge a complaint with that authority. In Singapore, complaints may be directed to the Personal Data Protection Commission (PDPC) at https://www.pdpc.gov.sg.