Effective Date: 3rd September 2026
Last Updated: 7th September 2026
This Privacy Policy applies to the KampZ mobile application (the "Application" or "KampZ") for iOS and Android, provided by KampZ ("Service Provider", "we", "us", or "our"), as a Freemium service. KampZ helps content creators and influencers manage brand collaborations, deliverables, payments, and invoices. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have regarding your information. Please read it carefully. By downloading, accessing, or using the Application, you agree to the collection and use of information in accordance with this policy.
- Scope of This Policy
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing (EEA/UK Users)
- How We Share Information
- Third-Party Services
- Advertising & Rewarded Ads
- Data Security
- Data Retention
- International Data Transfers
- Your Privacy Rights
- Additional Disclosures for EEA/UK Users (GDPR)
- Additional Disclosures for California Residents (CCPA/CPRA)
- Children's Privacy
- Your Choices & Opt-Out Rights
- Data Breach Notification
- Changes to This Privacy Policy
- Contact Us
1. Scope of This Policy
This policy covers the personal information the Application collects and processes when you use KampZ on your mobile device. It does not apply to information collected by third parties through their own apps or websites (for example, the Apple App Store, Google Play, or a brand you communicate with outside the Application), even if those services are linked to or accessible from the Application. We encourage you to review the privacy policies of any third-party services you use in connection with KampZ.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account & profile information | Name, email address, profile photo (optional), content niche, platforms you create content on, home currency, and password (if you sign up with email — stored and verified by Firebase Authentication, never stored by us in plain text) |
| Sign-in identifiers | If you choose "Sign in with Google" or "Sign in with Apple," we receive a unique identifier, your name, and email address (or Apple's private relay email if you choose to hide your email) from that provider. We never receive or store your Google or Apple account password. |
| Brand & collaboration details | Brand names, logos, contact persons, emails, phone numbers, deal terms, deliverables, content briefs, notes, and deadlines you add |
| Payment & invoice records | Agreed rates, amounts received or outstanding, due dates, payment methods (as text labels you enter, e.g. "bank transfer"), your business/billing details, and invoice line items you generate. The Application only records this information for your own tracking and record-keeping purposes; it does not process, transmit, or collect payments on your behalf, and it never asks for or stores your bank account or card numbers. |
| Files you upload | Optional attachments such as brand logos or profile pictures you choose to upload, stored in Firebase Cloud Storage |
| E-signature agreement records | If you use the Application's e-signature feature to send or sign a brand agreement: the generated agreement document and its terms; the name and email address of each signing party (you and the brand contact you enter); each signer's IP address and browser/device user-agent string; timestamps for when the document was opened, consented to, and signed; the electronic-signature consent statement each signer accepts; and the signer's drawn or typed signature. Once all parties have signed, the finalized agreement is sealed into a tamper-evident PDF accompanied by a certificate of completion and an independent trusted timestamp. Some of this data relates to the brand's representative rather than to you; you are responsible for having a lawful basis to provide their details for this purpose. |
| Support & correspondence | Information you provide when you contact us for support, including your email address and the contents of your message |
2.2 Information Collected Automatically
| Category | Examples |
|---|---|
| Device & technical data | IP address, device model, operating system and version, app version, language and locale settings, time zone |
| Usage data | Screens and features viewed, actions taken within the Application (e.g., creating a collab, generating an invoice), session duration, and general usage patterns, collected via Google Analytics for Firebase |
| Diagnostic & crash data | Crash logs, stack traces, and performance data collected via Firebase Crashlytics to help us identify and fix bugs |
| Push notification token | A device-specific token used solely to deliver reminders about deadlines and overdue payments to your device via Firebase Cloud Messaging |
| Subscription status | Whether you hold a "KampZ Pro" plan, your entitlement status, and purchase/renewal events, managed through our subscription provider, RevenueCat (see Section 6) |
| App integrity signals | Device attestation signals collected by Firebase App Check, used only to verify that requests to our backend come from a genuine, unmodified copy of the Application, and to block automated abuse |
The Application does not access or collect your precise GPS location, your device's contacts, photo library (beyond an image you explicitly choose to upload), microphone, or camera roll without an explicit action from you.
2.3 Information We Do Not Collect
We do not collect government ID numbers, financial account numbers, payment card numbers, health information, biometric identifiers, or precise geolocation. A drawn or typed signature captured through the e-signature feature is stored only as an image of that signature for the purpose of executing your agreement; it is not processed to biometrically identify anyone and is not used as a biometric identifier. If a future version of the Application were to begin collecting any of these categories, we would update this Policy and, where required by law, obtain your consent first.
3. How We Use Your Information
We use the information we collect to:
- Create and maintain your account, and authenticate you when you sign in
- Provide the core functionality of the Application — storing and displaying your brands, collabs, deliverables, payments, and invoices
- Send you reminders about upcoming deadlines and overdue payments, via push notification and/or on-device local notification
- Process and manage your "KampZ Pro" subscription and entitlements
- Show a rewarded video ad when you choose to unlock a gated action as a free-tier user (see Section 7)
- Diagnose crashes, fix bugs, and improve the performance, stability, and usability of the Application
- Understand aggregate usage trends so we can prioritize and design new features
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Respond to your support requests and communicate with you about important service updates
- Generate, deliver, and finalize e-signature agreements you create, capture the audit trail that evidences who signed and when, and retain the completed agreement and that audit trail as a record of the transaction
- Comply with our legal obligations
We do not sell your personal information, and we do not use the contents of your brand, collab, payment, or invoice records to train machine learning or AI models.
4. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:
- Performance of a contract — to provide the Application's core features and your KampZ Pro subscription
- Legitimate interests — to secure the Application, diagnose and fix crashes, understand aggregate usage, and prevent fraud or abuse, balanced against your rights and interests
- Consent — for optional features such as push notifications and, where required by applicable law, for advertising identifiers used by our ad partner
- Legal obligation — where we must retain or disclose information to comply with the law
- Establishment, exercise, or defence of legal claims — to retain completed e-signature agreements and their audit trail as evidence of a concluded transaction between you and a brand, which is also a recognised exception to the right of erasure (GDPR Article 17(3)(e))
5. How We Share Information
We do not sell, rent, or trade your personal information. We share information only in the following circumstances:
- Service providers ("data processors") — with vetted third-party companies that perform services on our behalf (hosting, analytics, crash reporting, notifications, subscription management, advertising), as described in Section 6, and only to the extent necessary for them to perform those services under confidentiality and data-protection obligations
- Legal requirements — if required to do so by law, subpoena, or other legal process, or in the good-faith belief that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request
- Business transfers — if KampZ is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will notify you via the Application or email before your information becomes subject to a different privacy policy
- With your direction — for example, when you use the built-in export feature to generate a CSV or PDF and share it via your device's native share sheet (e.g., to email an invoice to a brand). That export happens on your device and is sent only to the recipient(s) you choose — we do not receive a copy
We never share the brand names, contact details, deal terms, or financial figures you record in KampZ with other users of the Application, or with brands themselves, unless you personally choose to export and send that information.
6. Third-Party Services
The Application relies on the following third-party service providers, each of which processes data under its own privacy policy and, where applicable, as our data processor under a data processing agreement:
- Google Play Services — underlying platform services on Android devices
- Google Analytics for Firebase — aggregate, event-based usage analytics
- Firebase Crashlytics — crash and diagnostic reporting
- Firebase Cloud Messaging — delivery of deadline and payment reminder push notifications
- Firebase Cloud Firestore & Cloud Storage — secure storage of your account, brand, collab, payment, and invoice data, and any files you upload
- Firebase Authentication — account creation and sign-in (email/password, Google, and Apple)
- Firebase App Check — verifies that requests to our backend originate from a genuine copy of the Application, to block bots and abuse; it does not identify you personally
- Firebase Remote Config — lets us safely roll out feature and configuration changes without collecting additional personal data about you
- Sign in with Google — optional authentication method
- Sign in with Apple — optional authentication method
- RevenueCat — manages subscriptions and in-app purchases and tells us your entitlement status. Card and payment details are handled entirely by Apple's App Store or Google Play and are never seen by the Service Provider or RevenueCat.
- Google AdMob — serves the optional rewarded video ads described in Section 7
Your data stored in Firebase Cloud Firestore and Cloud Storage is protected by server-side security rules that restrict access to your own signed-in account only — other users of the Application cannot see your brands, collabs, payments, or invoices, and our engineers do not routinely browse individual user records; access is limited to what is necessary to investigate a support request, bug, or legal obligation.
The Application also schedules on-device reminders for upcoming deliverables and payments using your device's local notification system. These local reminders are computed and stored on your device and are not transmitted to any external service. If you use the optional home screen widget, the small set of upcoming deadline/payment data shown on the widget is cached locally on your device (via platform APIs such as iOS App Groups or Android App Widgets) and is not sent to any additional third party beyond the services already listed above.
7. Advertising & Rewarded Ads
Free-tier users may unlock certain gated actions (such as generating an invoice, or adding a brand, payment, or collab) by choosing to watch an optional rewarded video ad, served through Google AdMob. This is entirely optional — free-tier users can decline to watch an ad, and KampZ Pro subscribers never see ads. If you choose to watch a rewarded ad:
- Google AdMob and its advertising partners may collect information such as your advertising identifier (IDFA on iOS or Advertising ID on Android, where permitted by your device settings), IP address, device type, and general engagement data (e.g., whether the ad was viewed to completion) to serve the ad, prevent fraud, and measure ad performance
- We do not pass any of your KampZ account data — your brands, collabs, payments, or invoices — to AdMob or its partners
- On iOS, where required, the Application requests App Tracking Transparency permission before any cross-app tracking occurs; you can allow or deny this at any time from your device's Settings
You can learn more about how Google uses data from apps that use its services at policies.google.com/technologies/partner-sites, and manage your ad personalization settings at adssettings.google.com.
8. Data Security
We take the security of your information seriously and apply industry-standard safeguards, including:
- Encryption in transit — all communication between the Application and our backend services uses TLS/HTTPS encryption
- Encryption at rest — data stored in Firebase Cloud Firestore and Cloud Storage is encrypted at rest by Google Cloud's infrastructure
- Per-account access control — authenticated, per-account Firestore and Storage security rules ensure only you can read or write your own data
- App integrity checks — Firebase App Check helps ensure requests to our backend come only from genuine copies of the Application
- Least-privilege internal access — access to production data by our own personnel is limited and logged
- No storage of card or bank credentials — the Application never collects or stores your payment card or bank account numbers; subscription payments are handled entirely by Apple and Google
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential and for using a strong, unique password if you sign up with email and password.
9. Data Retention
We retain your information for as long as your account is active, and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account data is retained for as long as you maintain a KampZ account
- Account deletion — you can permanently delete your account at any time from within the Application's Profile screen. Deleting your account permanently deletes your profile, brands, collabs, payments, and invoice data associated with that account from our production systems, typically within 30 days, except where we are legally required or permitted to retain certain records for longer (for example, financial or fraud-prevention records; completed e-signature agreements, as described below; or backups that are cycled out over a limited retention window)
- Completed e-signature agreements — once an agreement has been signed by all parties, the
sealed agreement PDF, its certificate of completion, and the associated audit trail (signer names and
email addresses, IP addresses, browser/device user-agent strings, and consent and signing timestamps) are
retained for approximately 11 months from completion, or longer where a law, tax rule, or
an actual or reasonably anticipated dispute requires, in tamper-evident, retention-protected storage.
Because a completed agreement is the record of a concluded transaction that both you and the other signing
party (and, if a dispute arises, KampZ) may need to rely on, these records are not deleted when you
delete your account or make an erasure request; they are deleted automatically once the applicable
retention period ends. The sealed PDF and its certificate are self-contained — their digital signature and
independent timestamp can be verified without KampZ — so they remain valid after we delete our copy; each
party is expected to keep their own copy, and the in-app download and the
verifylookup for an agreement stop working once its files are removed. If you need KampZ to retain a completed agreement for longer than the standard period, contact us before it ends. Agreements that are still in draft, that you send but that are never completed, and the unsigned working copy and raw signature images of such incomplete agreements, are deleted together with the rest of your collab data on account deletion - Crash and analytics data is retained by our providers (Google Analytics for Firebase, Firebase Crashlytics) according to their standard retention windows, and is not directly identifiable to you by name
- Support correspondence is retained for as long as necessary to resolve your request and for a reasonable period afterward for quality and record-keeping purposes
To request deletion of your data without deleting your account, or if you have any difficulty using the in-app deletion feature, contact us at contact@kampz.online.
10. International Data Transfers
KampZ and its service providers (including Google Firebase and RevenueCat) may process and store your information on servers located outside of your country of residence, including in the United States. Where we transfer personal data from the EEA, UK, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, such as Standard Contractual Clauses, as offered by our service providers, to protect your information.
11. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you
- Correction — request that we correct inaccurate or incomplete information (you can also edit most of your data directly within the Application)
- Deletion — request deletion of your personal information (you can also delete your account directly within the Application, as described in Section 9), except for records we are permitted or required to keep, such as completed e-signature agreements and their audit trail, which we retain for the limited period described in Section 9
- Portability — request an export of your data in a portable, machine-readable format. You can already export your brand, collab, payment, and invoice records to CSV at any time using the Application's built-in Export feature
- Restriction or objection — request that we restrict or stop certain processing of your information, subject to legal exceptions
- Withdraw consent — where processing is based on consent (e.g., push notifications), you may withdraw that consent at any time
- Non-discrimination — we will not discriminate against you for exercising any of these rights
To exercise any of these rights, contact us at contact@kampz.online. We will respond to verifiable requests within the timeframe required by applicable law (generally within 30 days). We may need to verify your identity before fulfilling certain requests.
12. Additional Disclosures for EEA/UK Users (GDPR)
If you are located in the European Economic Area or United Kingdom, in addition to the rights listed in Section 11, you have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data infringes applicable data protection law.
13. Additional Disclosures for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information. We do not sell your personal information for money. Depending on how California regulators interpret the term, our use of advertising identifiers for the optional rewarded ads described in Section 7 could be considered "sharing" for cross-context behavioral advertising; you can limit this by declining rewarded ads (they are entirely optional) and by adjusting your device's advertising ID settings. Your right to request deletion is subject to the exceptions permitted by the CCPA/CPRA, including our need to complete a transaction and to keep records reasonably necessary to exercise or defend legal claims; in particular, completed e-signature agreements and their audit trail are retained for the limited period described in Section 9 and are not deleted in response to a deletion request. To exercise your CCPA/CPRA rights, contact us at contact@kampz.online. We will not discriminate against you for exercising these rights.
14. Children's Privacy
The Application is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal information from a child under 16, we will take steps to delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@kampz.online so we can take appropriate action.
15. Your Choices & Opt-Out Rights
- Push notifications — you can disable deadline and payment reminder notifications at any time from the Application's Notification Settings, or from your device's system notification settings, without needing to uninstall the Application
- Advertising — rewarded ads are entirely optional; you can always decline to watch one. You can also reset or limit your device's advertising identifier, or opt out of personalized advertising, from your device's system privacy/ads settings
- Account & data deletion — you can delete your account and associated data at any time from the Profile screen, or by contacting us
- Full opt-out — you can stop all collection of information by the Application at any time by uninstalling it using your device's standard uninstall process. Note that uninstalling alone does not delete data already stored on our servers; use the in-app account deletion feature, or contact us, to request deletion of that data
16. Data Breach Notification
In the event of a data breach that compromises your personal information, we will notify affected users and the relevant regulatory authorities as required by applicable law, without undue delay.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Application's features, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, provide additional notice (such as an in-app notice or email). Your continued use of the Application after any changes take effect constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically.
18. Your Consent
By downloading, accessing, or using the Application, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at: contact@kampz.online