Privacy Policy
Effective Date: 10/02/2026
HIFFI (“we,” “our,” or “us”) values your privacy and is committed to safeguarding the personal information of our users, including both audience members and artists/creators. This Privacy Policy describes in detail the types of information we collect, how we use and share it, the measures we take to secure it, and the rights available to you under applicable laws.
By accessing or using our website, mobile application, or any other services that form part of the HIFFI platform (collectively, the “Platform”), you agree to the terms of this Privacy Policy. If you do not agree with this Policy, you should refrain from using the Platform.
This Privacy Policy was last updated on 12/02/2026 and is effective as of 14th February 2026. For users in California, this Policy serves as our Notice at Collection under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). For users in other US states with comprehensive privacy laws, this Policy fulfills our transparency obligations under applicable state privacy statutes.
About Kinimi Corporation and Hiffi
Kinimi Corporation operates a global online platform under the name Hiffi, designed to support and promote artists, with a particular focus on live streaming performances, uploading pre-recorded content, and enabling real-time audience interaction. The Platform allows artists to monetize their work through voluntary support payments, tips, and subscriptions from audiences worldwide. We facilitate secure payment processing, deduct a platform service fee, and disburse the remaining amount to the respective artist. In doing so, we process certain personal information from both artists and audience members in accordance with applicable privacy laws.
Scope and Applicability
This Privacy Policy applies to all users of the Platform, regardless of location. For users in the United States, we operate in compliance with:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents
- Virginia Consumer Data Protection Act (VCDPA) for Virginia residents
- Colorado Privacy Act (CPA) for Colorado residents
- Connecticut Data Privacy Act (CTDPA) for Connecticut residents
- Utah Consumer Privacy Act (UCPA) for Utah residents
- Children's Online Privacy Protection Act (COPPA) for users under 13 years of age
- Federal Trade Commission Act Section 5 prohibiting unfair or deceptive practices
- Other applicable state privacy laws as they come into effect
For users outside the United States, we operate in compliance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 in India, as well as other applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union and United Kingdom, and other applicable laws in jurisdictions where we operate. Where local laws grant additional rights or impose stricter obligations, we will comply with those requirements.
Information We Collect
3.1 We collect personal information from you in various ways, depending on whether you are an audience member, an artist, or another type of user.
3.2 When you use the Platform as an audience member, we may collect your full name, email address, phone number (if applicable), payment information (processed through third-party payment providers), and your interactions with the Platform, such as the content you view, the artists you support, and your participation in chat or interactive features. We may also collect technical information, including your IP address, device identifiers, browser type, and platform usage statistics. For California residents, we collect the following categories of personal information under CCPA/CPRA: identifiers (name, email, IP address, device ID), commercial information (payment history, content viewed, artists supported), internet/network activity (browsing history, interactions with Platform), geolocation data, and inferences drawn from the above to create user profiles for personalization.
3.3 When you use the Platform as an artist or creator, we may collect your full name, email address, phone number, bank account details, government-issued identification documents for Know Your Customer (KYC) compliance (such as driver's license, state ID, passport, or for non-US artists, equivalent government-issued identification), as well as the content you upload or stream, and any optional information you choose to provide, such as your social media handles. For US-based artists receiving payments exceeding $600 annually, we collect taxpayer identification numbers (Social Security Number or Employer Identification Number) as required by IRS reporting obligations.
3.4 In addition, we automatically collect certain technical information from all users through cookies and other tracking technologies, including device information, IP address, geolocation data, and information about your use of the Platform.
3.5 We do not knowingly collect sensitive personal information as defined under CCPA/CPRA, including precise geolocation (within 1,850 feet), racial or ethnic origin, religious beliefs, genetic data, or biometric data processed for identification purposes, unless explicitly authorized by you for specific purposes. If we process sensitive personal information, you have the right to limit such processing under applicable state laws.
How We Collect Information
4.1 We collect information directly from you when you register an account, upload or stream content, make or receive payments, or communicate with us. Some information is collected automatically when you use the Platform, through cookies, analytics tools, and other technologies that help us understand and improve how our services are used.
4.2 We may also receive limited personal information from third-party services when you choose to log in using an integrated account, such as Google. Additionally, we may obtain information from our analytics service providers, including Google Analytics, MsClarity, and PostHog, which collect aggregated data on how users interact with the Platform. We do not purchase personal information from data brokers or third-party data aggregators. Information from third parties is limited to authentication services (e.g., Google OAuth), payment processors (transaction confirmation), and analytics providers (aggregated usage data).
4.3 Do Not Track Signals: Our Platform currently does not respond to "Do Not Track" (DNT) browser signals or similar mechanisms. However, California residents may exercise opt-out rights under CCPA/CPRA through our designated privacy controls, including the "Limit the Use of My Sensitive Personal Information" and "Do Not Sell or Share My Personal Information" options available in account settings.
Purpose of Data Use
5.1 We use the personal information we collect for the following purposes:
- To provide, operate, and maintain the Platform’s functionality.
- To process payments from audience members and make payouts to artists.
- To personalise recommendations and improve the quality of our services.
- To communicate with you, including sending updates, promotional messages, and important notices.
- To comply with applicable legal and regulatory requirements, including tax, KYC, and anti-fraud obligations.
- To monitor for fraudulent or suspicious activity and protect the integrity of the Platform.
- To conduct data security audits, risk assessments, and cybersecurity testing as required by applicable privacy laws;
- To comply with legal obligations including responding to lawful requests from law enforcement, regulatory agencies, and courts;
- To protect against, identify, and prevent fraud, unauthorized access, illegal activity, and claims or liabilities;
- To perform analytics and generate insights about Platform usage, user preferences, and content performance for business intelligence purposes.
5.2 We will not use your personal information for purposes unrelated to those described in this Privacy Policy unless we have your consent.
5.3 Automated Decision-Making: We use automated systems to personalize content recommendations, detect fraudulent transactions, and moderate user-generated content. California residents have the right to opt out of automated decision-making technology that produces legal or similarly significant effects under CCPA/CPRA regulations effective January 1, 2026. To exercise this right, contact us using the information in Section 16.
Legal Basis for Processing
6.1 Where required by law, we process your personal information on one or more of the following legal bases:
- Consent: where you have given clear consent for us to process your personal information for a specific purpose, such as receiving marketing communications.
- Performance of a contract: where processing is necessary to deliver the services you have requested.
- Compliance with a legal obligation: where we are required to process your data to meet our legal responsibilities.
- Legitimate interests: where processing is necessary for our legitimate business purposes, provided these are not overridden by your fundamental rights and freedoms.
- Public Interest: where processing is necessary to comply with legal obligations, protect public safety, or cooperate with law enforcement; and
- Vital Interests: where processing is necessary to protect the life or physical safety of individuals.
6.2 For US residents: We process personal information based on your consent (where required), to perform our contract with you (to provide Platform services), to comply with legal obligations (tax, KYC, AML requirements), and for our legitimate business interests (fraud prevention, analytics, service improvement) where not overridden by your privacy rights.
Sharing of Information
7.1 We may share your personal information with trusted third parties in the following circumstances:
- Payment processors for processing transactions securely. We are not a bank and do not provide banking services.
- Analytics providers (including Google Analytics, MsClarity, and PostHog) for performance monitoring and service optimization.
- Cloud hosting providers (such as Amazon Web Services or Google Cloud) that store our data securely.
- Regulatory authorities or law enforcement agencies when required by law or to protect our legal rights.
- Business partners with whom we collaborate for promotional activities, only where you have given consent.
- In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal information may be transferred to the acquiring entity.
7.2 We do not sell your personal information to third parties for monetary consideration. However, we may "share" personal information for cross-context behavioral advertising as described in our California-specific disclosures.
International Data Transfers
8.1 As a global platform, your personal information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws that are different from those in your jurisdiction and, in some cases, may not provide the same level of protection. Whenever we transfer your personal information to another country, we ensure that appropriate legal, technical, and organisational safeguards are in place to protect it in accordance with applicable laws.
8.2 Such safeguards may include implementing data transfer agreements incorporating standard contractual clauses approved by relevant regulatory authorities, ensuring the recipient is located in a jurisdiction that has been recognised as providing an adequate level of data protection, or relying on other legally recognised transfer mechanisms. Additionally, we require all third parties that process personal information on our behalf to comply with strict contractual obligations, including security and confidentiality requirements, regardless of the country in which they are located.
8.3 By using the Platform, you acknowledge and agree to the transfer of your personal information to countries outside your country of residence, subject to the protections outlined in this Privacy Policy.
Cookies and Tracking Technologies
The Platform uses cookies and similar technologies to enhance user experience, perform analytics, and ensure security. These may include essential cookies (necessary for the functioning of the Platform), performance cookies (to measure and improve performance), and analytics cookies (to help us understand user behaviour). Where required by law, you will be prompted to give consent to non-essential cookies on your first visit to the Platform. You can manage your cookie preferences through your browser settings or our designated privacy controls.
Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. For most users, we retain account information for the duration of your active relationship with us plus up to seven (7) years for legal, tax, and compliance purposes. Upon request, we will delete your personal information within thirty (30) days, except where we are legally required to retain it for a longer period, such as for tax or accounting purposes.
Your Rights
11.1 Depending on your location, you may have certain rights in relation to your personal information, including the right to access, correct, delete, or restrict processing, the right to object to processing, the right to withdraw consent, and the right to data portability.
11.2 California Rights: Residents have the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the "sale" or "sharing" of personal information, and the right to non-discrimination for exercising these rights.
11.3 Exercising Your Rights: To exercise these rights, please contact us at care@hiffi.com. We will verify your identity before processing your request.
11.4 Verification Process: To protect your privacy, we will take steps to verify your identity before fulfilling your request. This may include asking you to provide:
- Confirmation of the email address associated with your account
- Account username or user ID
- Answers to security questions or confirmation codes sent to your email/phone
For deletion requests involving sensitive information, we may require additional verification such as government-issued ID or notarized affidavit.
11.5 Authorized Agents - California residents may designate an authorized agent to submit privacy requests on their behalf. Authorized agents must provide:
- Signed written authorization from the consumer
- Proof of the agent's identity
We may require the consumer to verify their identity directly and confirm they authorized the agent
11.6 Response Timeframes: We will respond to verified requests within 45 days of receipt. If we require additional time (up to 90 days total), we will inform you of the reason and extension period.
11.7 Appeals Process: If we deny your privacy request in whole or in part, you have the right to appeal our decision. To appeal, email care@hiffi.com within 30 days of receiving our denial. We will respond to appeals within 45 days. Virginia, Colorado, Connecticut, and Utah residents may also contact their state Attorney General to submit complaints.
Data Security
12.1 We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. We also maintain strict internal policies on data handling, require our employees and contractors to sign confidentiality agreements, and ensure that any third-party service providers processing data on our behalf adhere to equally robust security standards.
12.2 However, no security system is impervious to all threats. In the event of a data breach affecting personal information, we will notify affected users and relevant regulatory authorities as required by applicable law:
- California residents: Within the timeframe required by California Civil Code § 1798.82 and CPRA breach notification requirements
- Other state residents: As required by applicable state data breach notification laws
- All users: Via email to the address on file and/or prominent notice on the Platform
12.3 Notification will include the nature of the breach, types of information compromised, steps taken to address the breach, and recommendations for protecting affected individuals. Where required by law, we will offer credit monitoring or identity theft protection services at no cost to affected individuals.
12.4 We conduct regular security audits and risk assessments in compliance with CCPA/CPRA cybersecurity audit requirements effective January 1, 2026.
Children’s Privacy
13.1 Age Restrictions: The Platform is not directed to children under the age of thirteen (13) in the United States or under the applicable age of majority in other jurisdictions. We do not knowingly collect, solicit, or process personal information from children under 13 without verifiable parental consent as required by the Children's Online Privacy Protection Act (COPPA).
13.2 Parental Consent Requirements: If we learn that we have collected personal information from a child under 13, or if we intend to offer services to children under 13 in the future, we will:
- Obtain verifiable parental consent before collecting personal information
- Provide clear notice to parents about what information we collect, how we use it, and our disclosure practices
- Obtain separate consent for internal use and disclosure to third parties
- Allow parents to review, delete, and refuse further collection of their child's information
- Limit collection to information reasonably necessary for participation in Platform activities
- Establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of children's personal information.
13.3 Enhanced Privacy Protections: In accordance with COPPA Rule amendments effective April 22, 2026:
- We will not condition a child's participation in any activity on the disclosure of more personal information than is reasonably necessary.
- We will clearly distinguish between consent for internal use and consent for disclosure to third parties.
- Our privacy notices will include specific identities of third parties receiving children's information and the purposes for such disclosures.
- We will implement heightened data security measures for any children's information collected.
- We will retain children's personal information only as long as necessary to fulfill the purpose for which it was collected.
- Biometric identifiers (fingerprints, voice prints, facial recognition) will not be collected from children.
13.4 Reporting Suspected Underage Accounts: If you are under 18, you should not attempt to register an account, use payment features, or provide personal information to us through the Platform without parental supervision. Parents or legal guardians who believe their child has provided personal information to us without consent should contact us immediately at care@hiffi.com so that we can investigate and take appropriate action, including account deletion and information purging, in accordance with COPPA and other applicable laws.
13.5 Third-Party Content: We take reasonable measures to ensure that third-party services integrated with the Platform comply with COPPA requirements. However, parents should review the privacy policies of third-party services their children may access through external links.
Grievance Redressal
We have appointed a Grievance Officer whose contact details are provided below. The Grievance Officer will acknowledge complaints within twenty-four (24) hours and resolve them within fifteen (15) days.
For US Residents - State Privacy Complaints:
If you are a US resident and believe we have violated your privacy rights under applicable state law, you may file a complaint with:
- California residents: California Privacy Protection Agency (CPPA) at https://cppa.ca.gov or California Attorney General at https://oag.ca.gov
- Virginia residents: Virginia Attorney General at https://oag.state.va.us/
- Colorado residents: Colorado Attorney General at https://coag.gov/office-sections/consumer-protection/
- Connecticut residents: Connecticut Attorney General at https://portal.ct.gov/AG/Sections/Consumer-Protection
- Utah residents: Utah Attorney General at https://dcp.utah.gov/
Federal Privacy Complaints:
You may also file complaints with:
Federal Trade Commission (FTC): For COPPA violations or unfair/deceptive practices at https://reportfraud.ftc.gov
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, technology, or legal requirements. Where required, we will notify you of significant changes by email or via the Platform before they take effect.
For California residents, if changes materially impact the processing of sensitive personal information or introduce new automated decision-making practices, we will provide at least 30 days' advance notice before the changes take effect, and you will have the opportunity to opt out of such new practices. Previous versions of this Privacy Policy will be archived and made available upon request.
California-Specific Disclosures
16.1 Categories of Personal Information Collected (Last 12 Months):
| Category | Examples | Collected? | Business Purpose | Disclosed to Third Parties? |
|---|---|---|---|---|
| Identifiers | Name, email, IP address, device ID | Yes | Platform functionality, account management, fraud prevention | Yes - service providers, payment processors, analytics providers |
| Commercial Information | Payment history, content viewed, subscription status | Yes | Service delivery, billing, recommendations | Yes - payment processors, analytics providers |
| Internet/Network Activity | Browsing history, search history, interactions with Platform | Yes | Analytics, service improvement, security | Yes - analytics providers |
| Geolocation Data | General location (city/state level) | Yes | Content recommendations, compliance | Yes - analytics providers |
| Audio/Visual Information | Uploaded content, profile pictures | Yes | Service delivery, content hosting | No |
| Inferences | User preferences, content interests | Yes | Personalization, recommendations | Yes - analytics providers |
16.2 Categories of Sensitive Personal Information: We do not intentionally collect sensitive personal information as defined under CPRA (precise geolocation, racial/ethnic origin, religious beliefs, genetic data, biometric identifiers for identification purposes, health information, sex life/sexual orientation). If such information is inadvertently provided, you may request deletion.
16.3 Financial Incentives: We do not currently offer financial incentives or price differences based on collection, sale, or deletion of personal information. If we introduce such programs in the future, we will provide separate terms and opt-in consent mechanisms as required by CCPA/CPRA.
Your Right to Opt Out of Sale/Sharing
17.1 We do not sell personal information for monetary consideration. However, under CCPA/CPRA definitions, "sharing" personal information with analytics providers for cross-context behavioral advertising may constitute a "sale" or "share."
17.2 To opt out:
- Click "Do Not Sell or Share My Personal Information" in the footer of our website
- Adjust privacy settings in your account dashboard
- Email care@hiffi.com with subject line "Opt Out Request"
17.3 We honor Global Privacy Control (GPC) signals as an opt-out mechanism for California residents. When we detect a GPC signal from your browser, we will apply opt-out preferences to that browser on our Platform. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age
Contact Us
If you have any questions about this Privacy Policy or our data handling practices, you may contact us at:
For Privacy Rights Requests:
Email: care@hiffi.com
Mail: Kinimi Corporation, ATTN: Privacy Rights, 8 The Green STE A, Dover, Kent County, 19901
For General Privacy Questions:
Email: care@hiffi.com
For COPPA-Related Inquiries:
Email: care@hiffi.com