All legal documents

Trust and legal · Version 2026-08-20

Privacy Policy

Effective 20 August 2026

This policy explains who controls personal data, why it is processed, who receives it, how long it is kept, and how to exercise privacy rights.

Data we process

We process account and profile details, user-selected market, age declaration and verification status, content, device and security signals, support records, consent history, and transaction records.

Identity providers return a reference and verification result. CatchMate does not retain identity-document photographs in its application database.

In the local development email sign-in exception, CatchMate and Resend process the normalized email address and authentication message. CatchMate stores only a code HMAC and challenge metadata for up to 24 hours, not the verification code.

Purposes and legal bases

Contract performance supports accounts, profiles, messaging, orders, payment records, Credits, provider services, support, exports, and deletion requests. Legitimate interests support security, fraud prevention, service reliability, moderation, and product improvement after balancing user rights.

Legal obligations support tax, accounting, payment, sanctions, law-enforcement, and safety records. Consent supports optional analytics and other optional storage, and may be withdrawn at any time without affecting earlier lawful processing.

Recipients and processors

Data may be disclosed to identity and authentication providers, Stripe and applicable app stores, cloud hosting and storage providers, monitoring and security providers, customer-support processors, professional advisers, and authorities where legally required.

Resend processes development-only email authentication in the ap-northeast-1 region. This path is disabled in staging and production until separate privacy, legal, security, and deliverability approval.

Providers receive only the booking and account information reasonably needed to deliver a purchased service. CatchMate does not sell personal data.

Your rights

Depending on your location, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may opt out of sale or sharing through GPC.

Requests are tracked to the applicable deadline. Identity is verified proportionately before protected data is released or changed.

Retention and transfers

Active account and profile data is retained while the account is open. Login sessions expire after at most 14 days. Security events are retained for 90 days. Support and moderation records are normally retained for 24 months after closure; transaction, tax, ledger, refund, and payout records are retained for seven years unless a longer legal hold applies.

Development email authentication challenges, including the temporary normalized email address and delivery metadata, are deleted after 24 hours.

Deleted public content and closed account identifiers are removed or anonymised after operational backup rotation, normally within 90 days, unless a legal, safety, fraud, or dispute hold applies.

Data may be processed outside Hong Kong. CatchMate uses contractual safeguards, processor due diligence, access controls, and any transfer mechanism required by the destination or originating jurisdiction.

Security and incidents

CatchMate uses access controls, device-bound sessions or tokens, encryption, audit trails, and monitoring. Suspected personal-data incidents use a 72-hour internal escalation threshold so regional notification duties can be assessed in time.

Complaints

Contact the legal and privacy channel shown on this page first. You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, or the supervisory authority that applies where you live, without affecting other remedies.

Version 2026-08-20 · Effective 20 August 2026

Confirm action

Are you sure?

Report

What happened?

Choose the reason that best describes the issue.

Report category