Skip to content
Driftr

Effective 2026-08-10 · Updated 2026-08-10

Privacy Policy

Substantive draft for counsel sign-off. Not binding until approved and this notice is removed.

1. Who we are

This Privacy Policy explains how the operator of the Driftr platform ("Driftr", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our websites (including driftr.asia), mobile applications, and related services (together, the "Services").

[Counsel: insert full legal entity name, jurisdiction of incorporation, and registered office address.]

Driftr is a verified social, dating, and lifestyle platform designed primarily for foreigners living, working, studying, or traveling in our launch cities across Asia. Identity and nationality verification are core to the product.

Privacy contact: privacy@driftr.asia. General contact: hello@driftr.asia. Operations / safety escalation: operations@driftr.asia.

2. Scope and roles

This Policy applies to personal data we process as a controller (or equivalent) for the Services. It does not cover third-party websites, apps, or services that we do not control, even if linked from Driftr.

Where we use processors (for example cloud hosting, identity verification, messaging infrastructure, analytics, or app-store billing), they process data on our instructions under appropriate contracts.

3. Personal data we collect

We collect the following categories of personal data, depending on how you use the Services:

  • Account identifiers: email address and/or phone number; account status; authentication tokens; device identifiers associated with your sessions.
  • Authentication data: password hashes (if you use password signup); one-time passcodes; Apple or Google OAuth subject identifiers and associated email when provided by the provider.
  • Profile data: display name, photos and short videos you upload, bio, city, stay duration, occupation, languages, intents (e.g. dating/friendship), prompts, interests, location settings you enable (e.g. approximate distance), and similar profile fields.
  • Verification data: verification status, verified level, provider name, provider reference IDs, document country / nationality confirmation flags, liveness and identity check outcomes, retry counts, manual-review case references, and timestamps. We design the product so that raw passport or government-ID images are processed by our verification provider and are not stored by Driftr as ordinary profile media, unless we are legally required to retain them or counsel directs otherwise.
  • Safety and trust data: reports, blocks, appeals, emergency contacts you save, panic/safety events (including optional location and notes you submit), moderation decisions, and related audit metadata.
  • Usage and communications: discovery views, likes/passes, matches, conversations and message content, notifications, support requests, and in-product feedback.
  • Payments and entitlements: subscription status, product identifiers, purchase tokens / transaction IDs from Apple or Google, coin/wallet balances where applicable, and related billing metadata. Card numbers are processed by the app stores / payment processors, not stored by Driftr.
  • Device and technical data: IP address, approximate location derived from IP or device permission, device model, OS version, app version, language/locale, crash/diagnostic logs, and security signals (e.g. VPN detection heuristics used to protect eligibility integrity).
  • Cookies and similar technologies on the website: essential cookies for security and preferences; analytics/marketing cookies only where required consent is obtained.
  • Marketing waitlist data: email addresses submitted for city launch notifications.

Sensitive data. Depending on jurisdiction, photos, biometric-related verification signals processed by our provider, precise location, message content, and dating-related profile attributes may be treated as sensitive. We process such data only as needed to operate the Services, for safety, or with appropriate legal bases / consents.

4. How we obtain data

  • Directly from you (account creation, profile, uploads, messages, reports, settings).
  • Automatically from your device and our systems when you use the Services.
  • From identity providers (Apple, Google) when you choose those sign-in methods.
  • From our identity-verification provider (currently Persona or a successor we designate) when you complete Level 2 verification.
  • From app stores / billing platforms when you purchase Premium or related products.
  • From other users (e.g. reports about you, messages they send you).

5. Why we use personal data

We use personal data to:

  • Provide, operate, and improve the Services (accounts, profiles, discovery, matching, messaging, notifications, Premium features).
  • Run identity, liveness, and nationality verification and maintain eligibility decisions (including soft-admit access while verification is pending, and locking discovery/matching until eligible).
  • Keep the community safer: detect fraud, impersonation, underage use, scams, abuse, and policy violations; moderate content; handle reports, blocks, appeals, and emergency features.
  • Communicate with you about the Services, security alerts, verification status, and (with consent where required) product updates or marketing.
  • Process payments and manage entitlements through Apple App Store and Google Play Billing.
  • Comply with law, enforce our Terms, protect rights and safety, and respond to lawful requests.
  • Analyse aggregated or de-identified trends to improve product quality and city launch planning.
  • Honour data-subject requests (access, export, deletion, correction) and maintain required records.

7. Identity verification (important)

To keep Driftr a foreigners-focused, high-trust network, we require Level 2 identity verification (liveness plus identity/nationality validation via our verification partner) before full discovery, matching, and messaging eligibility. You may be allowed into parts of the app while verification is pending (“soft-admit”), but critical social actions remain locked until our systems mark you eligible.

  • What we store: verification status, level, provider reference, country/nationality confirmation outcomes, retry metadata, manual-review identifiers, and timestamps.
  • What the provider processes: government ID images, selfie/liveness media, and related biometric signals as described in the provider’s own privacy notice.
  • Expedite requests: if you ask us to prioritise a stuck review, we may email our operations team with your user ID and verification metadata so humans can assist.
  • Consequences of failure or refusal: you may be unable to unlock matching/messaging; repeated abuse of verification may lead to limits or enforcement under our Terms.

Verification partners act as processors or independent controllers for certain steps of the check. Review their notices (e.g. Persona) in addition to this Policy.

8. How we share personal data

We do not sell your personal data. We share data only as follows:

  • Other users: profile information you choose to show; discovery cards; messages you send; verification badges/levels where the product surfaces them.
  • Service providers: hosting (e.g. AWS), databases, email/SMS, push notifications, identity verification, content moderation/scanning, analytics, customer support, and similar vendors under contracts.
  • App stores / payment processors: Apple and Google for purchases and subscription lifecycle.
  • Safety and legal: if we believe disclosure is necessary to protect users, investigate abuse, comply with law, or respond to valid legal process.
  • Corporate events: merger, acquisition, financing, or sale of assets, subject to appropriate safeguards and notice where required.
  • With your direction: when you export data or ask us to send information to someone else.

9. International transfers

We operate across Asia and may process data in regions where our infrastructure, vendors, or team members are located (including outside your home country). Where required, we use appropriate transfer mechanisms (for example contractual clauses, vendor certifications, or other lawful tools) and apply security controls described below.

10. Retention

We retain personal data only as long as needed for the purposes above, including:

  • Account and profile data: for the life of the account, then deleted or anonymised within a commercially reasonable period after deletion (subject to backups and legal holds).
  • Messages and matches: while your account is active and as needed for safety/dispute handling after deletion requests.
  • Verification metadata: for as long as needed to maintain trust decisions, prevent fraud, and meet audit/legal needs.
  • Safety reports, blocks, and enforcement records: retained as needed for safety, appeals, and legal compliance — often longer than ordinary profile data.
  • Billing records: as required by tax and accounting rules.
  • Logs and security telemetry: typically shorter rolling windows unless needed for investigations.

[Counsel: confirm numeric retention schedules per data class before public launch.]

11. Security

We use administrative, technical, and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege admin roles, audit logging for sensitive admin actions, secrets management, and monitoring. No method of transmission or storage is perfectly secure; you are responsible for protecting your devices and login factors.

12. Your rights and choices

Subject to local law, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent. In-product tools (where available) include profile editing, settings, data export, and account deletion. You may also email privacy@driftr.asia.

  • Access / export: request a copy of personal data we hold about you.
  • Correction: update inaccurate profile fields in-app or contact us.
  • Deletion: request account deletion; some records may be retained where law or safety requires.
  • Marketing opt-out: unsubscribe links or settings where marketing is offered.
  • Cookie choices: manage non-essential cookies via our banner/preferences (where deployed).
  • Device permissions: revoke camera, photos, location, or notifications in OS settings (some features will stop working).

We may need to verify your identity before fulfilling requests. You may lodge a complaint with a supervisory authority in your country; we encourage you to contact us first so we can help.

13. Children

The Services are for adults only. You must be at least 18 years old (or the higher age of majority in your place of residence). We do not knowingly collect personal data from children. If we learn that a user is under 18, we will take steps to suspend or delete the account and related data.

14. Automated decision-making

Eligibility, discovery ranking, content moderation, rate limits, and fraud/safety signals may be applied automatically, sometimes with human review (including manual verification review). These systems are used to operate a safe verified community. You can contact us about an eligibility or enforcement decision that materially affects you.

15. Additional US state notices (including California)

If you are a California resident, the CCPA/CPRA may grant rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information for cross-context behavioural advertising. We do not sell personal information for money. If we use advertising cookies or similar technologies that constitute “sharing,” we will provide an opt-out mechanism. Categories of data we collect and disclose are described in Sections 3 and 8. We do not knowingly sell or share personal information of consumers under 16.

16. AI and automated tools

We may use automated tools (including machine-learning based moderation, translation features, or vendor AI services) to help detect unsafe content, improve matching quality, or provide optional features. We do not use your private messages to train public foundation models. Where a feature uses third-party AI processing, we apply vendor controls appropriate to the sensitivity of the data.

17. Third-party services

Your use of Apple, Google, Persona (or successor verification providers), payment platforms, and other third parties is also governed by their terms and privacy policies. We are not responsible for their independent practices.

18. Changes to this Policy

We may update this Policy from time to time. We will change the “Last updated” date and, for material changes, provide additional notice (for example in-app notice or email) where required. Continued use of the Services after the effective date of an update constitutes acceptance of the revised Policy to the extent permitted by law.

19. Contact

Privacy questions and data-subject requests: privacy@driftr.asia. General support: hello@driftr.asia. Safety / operations escalations: operations@driftr.asia.

[Counsel: add postal address for privacy correspondence if required by local law.]

Questions? privacy@driftr.asia