This Privacy Policy explains what personal data Tinda ("Tinda", "we", "us", "our") collects when you use the Tinda app and website (together, the "Service"), why we collect it, who we share it with, and the choices you have. We built this policy to match what the app actually does — not generic boilerplate — so it describes the real data fields, features, and third-party processors behind Tinda.
We collect the following categories of information, either because you give it to us directly, because it's generated by using the Service, or because your device provides it with your permission.
Your email address and phone number are stored separately from your public profile and are never shown to other members — they're used only for sign-in, account recovery, and support.
If you choose to request a "Verified" badge, we collect a photo of your government ID/passport and a guided selfie capture. See Identity verification below for how this is handled.
Wallet top-ups and subscription payments are processed by Stripe. We store the resulting balance, currency, subscription tier, renewal date, and a transaction history (amount, status, type, and date) — we do not receive or store your full card number. See Payments & wallet below.
With your permission, we access your camera and photo library to let you take or choose profile photos, complete the guided face capture for identity verification, and align a payment card when reloading your wallet. We do not use your camera or photos for anything beyond the specific action you initiate.
We use the information above to:
We do not use your data to serve third-party advertising, and we do not sell your personal information.
If you grant location permission, we use your device's GPS to calculate distance between you and other members for the discovery deck. Before it's stored anywhere another member could read it, your location is rounded to roughly 100 meters of precision — we don't share your exact coordinates. You can decline or revoke location permission at any time from your device or browser settings; discovery will fall back to working without distance-based filtering.
Verification is optional. If you request it, you submit a photo of your government ID or passport and complete a guided selfie capture. Your device compares the selfie against your existing profile photo using an on-device geometric-similarity check — this is a supporting signal for our review team, not biometric identification, and it is never the sole basis for approving or rejecting a request. A human administrator reviews the submission before awarding the "Verified" badge.
Your ID document image is stored in a restricted, access-controlled location that only our review team can open — it is never visible to other members and is not included in the automatic deletion that runs when you delete your account (see Data retention & deletion), since we may need to retain it for a limited period for fraud-prevention and legal-compliance purposes.
Tinda offers a wallet you can top up to pay for features like Boost, and paid subscription tiers (Gold and Platinum). All card payments are handled directly by Stripe, our payment processor — we never receive or store your full card number. We do store the outcome: your wallet balance and currency, your subscription tier and renewal choices, and a ledger of top-up and spend transactions (amount, status, and date) so we can show you your own payment history and support billing questions.
We keep your information for as long as your account is active, so the Service can function. You can permanently delete your account at any time from within the app. Deleting your account immediately and permanently removes:
Your sign-in credentials are deleted as the final step, so the deletion can't leave you in a broken, half-deleted state.
We may also retain limited information where required to comply with a legal obligation, resolve disputes, enforce our agreements, or where content you sent is part of another member's own conversation history (e.g. a message you sent that the recipient hasn't deleted).
Depending on where you live, you may have additional rights under local law (for example, to object to or restrict certain processing). Contact us and we'll do our best to help.
We use industry-standard safeguards to protect your information, including encryption in transit, access-restricted storage for sensitive files like ID documents, server-side enforcement of who can read or write which data (so, for example, only you can ever read your own private contact details or wallet balance), rate-limited login attempts with account lockout, optional two-factor authentication, and bot/ abuse protection via Firebase App Check. No method of transmission or storage is 100% secure, but we work to protect your information using measures appropriate to its sensitivity.
Tinda is intended for adults 18 years of age and older only. We do not knowingly collect personal information from anyone under 18. If we become aware that an account belongs to someone under 18, we will take steps to remove that account and the associated data. If you believe a minor is using Tinda, please contact us at support@medtechs.my.
Tinda is operated using service providers — including Google Firebase and Stripe — that maintain infrastructure in multiple countries. As a result, your information may be processed and stored in countries other than the one you live in, which may have different data protection laws. Where required, we rely on appropriate safeguards for these transfers as offered by our service providers.
The Tinda web app doesn't use third-party advertising cookies or trackers. It does use your browser's local storage and on-device caching (for example, to keep your session signed in and to cache profile cards and chat messages so the app feels fast) — this data stays on your device and is used only to operate the app itself.
We may update this Privacy Policy from time to time to reflect changes to the Service or applicable law. If we make material changes, we'll notify you through the app or by other reasonable means before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.
If you have questions about this Privacy Policy or how we handle your information, reach out any time:
Email us at support@medtechs.my