Meenda Privacy Policy
Meenda (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data.
1. Information We Collect
- Username, email, password
- Linked social media accounts (Instagram, TikTok, X, Facebook, YouTube), including access tokens generated when you connect an account
- Wallet balance, transaction history, payment records
- Gift purchases and receipt records
- Your activity on the platform
- Pages visited and interactions
- Analytics data (via Umami or similar tools)
- Device data and login logs
2. How We Use Your Information
- Providing and improving Meenda's services
- Verifying and linking social media accounts
- Processing payments and managing wallets
- Displaying gifts and rankings
- Communicating with you via notifications and email
3. Sharing Your Data
- With payment service providers
- With technical service providers
- When legally required, or to prevent fraud
- We do not sell your personal data to third parties, and we do not use social media access tokens for any purpose beyond what is disclosed in this policy (Limited Use).
4. Protection of Sensitive Data & Security
We classify passwords, social media OAuth access tokens, and payment/transaction data as sensitive data, and apply the following protections:
- Encryption: Data is encrypted in transit using TLS/HTTPS, and sensitive data is encrypted at rest.
- Passwords: Passwords are never stored in plaintext; they are stored hashed using secure algorithms (e.g., bcrypt)
- Social media access tokens: Stored encrypted, used only to perform the function the user consented to (e.g., account verification or displaying stats), and can be revoked by the user at any time from their account settings or from the social platform itself.
- Access control: Employee access to sensitive data is limited to those who need it to perform their job (principle of least privilege), and access is logged.
- Payment providers: Card data is processed via approved third-party payment providers compliant with PCI DSS; full card numbers are never stored on our servers.
- Data retention & deletion: Sensitive data is retained only as long as necessary to provide the service or meet legal requirements, and is deleted or anonymized upon account deletion request.
- Incident response: In the event of a security breach affecting your data, we will notify you and relevant authorities as required by applicable law.
- We use industry-standard security measures; no system is 100% secure.
5. Payments and Financial Information
We do not store complete card data; payments are processed via third-party providers compliant with industry security standards (PCI DSS).
6. Your Rights
- Access your data
- Request data correction
- Request data deletion
- Revoke your consent to linked social media accounts at any time
7. Changes to This Policy
This privacy policy may be updated, with a new effective date.
8. Contact
support@meenda.com