RINNYLINK / RINNYVIEW — PRIVACY POLICY
Last Updated: JUL/9/2026
Data Controller: SYNONYMOUS & NASCENSE, a business name registered under the Business Names (Registration) Act, Cap. 90:05 (Certificate No. 286545), carrying on business at 48 Princes St, Werk-en-Rust, Georgetown, Guyana, Tax Identification No. 150494526.
Privacy Contact: Herizan@synnas.com · 48 Princes St, Werk-en-Rust, Georgetown, Guyana.
This Privacy Policy explains how the Rinnylink Platform ("we, "us, "our, "the Platform") collects, uses, stores, shares, and protects your personal data when you use the Rinnylink application (for Providers), the Rinnyview application (for Viewers), or our admin dashboard (collectively, the "Apps"). It is incorporated into our [Terms of Use](https://www.synnas.com/rinny/terms) by reference.
This Policy is written to comply with the Data Protection Act 2023 ("DPA") of the Co-operative Republic of Guyana (enacted; not yet in force as of this date — we will apply it on a anticipatory basis and in full upon commencement), the Cybercrime Act 2018 data-retention provisions, and the AML/CFT Act, Cap. 10:11 record-keeping obligations.
TABLE OF CONTENTS
- Who We Are
- The Personal Data We Collect
- How We Use Your Data (and the Legal Basis)
- Sensitive and Special-Category Data
- How We Share Your Data
- International Data Transfers
- How Long We Keep Your Data (Retention)
- Your Data-Protection Rights
- Data Security
- Cookies and Analytics
- Children's Data
- Changes to This Policy
- Contact and Complaints
1. WHO WE ARE
The Rinnylink Platform is operated by SYNONYMOUS & NASCENSE (a business name registered under the Business Names (Registration) Act, Cap. 90:05, Certificate No. 286545) ("we", "us", "our"). We are responsible for the personal data you provide to us and the data generated by your use of the Apps.
Our Apps form a two-sided, peer-to-peer live-camera marketplace:
- Rinnylink lets a Provider turn their Android device camera into a live, remotely-viewable IP camera.
- Rinnyview lets a Viewer discover cameras on a map, subscribe, buy Credits, and pay per minute to watch live feeds.
A defining architectural feature relevant to your privacy is that live video and audio flow directly between the Provider's and Viewer's devices over WebRTC (peer-to-peer, or via a TURN relay where NAT requires). Our backend relays only signaling messages and never sees or stores the media stream. However, because the connection is peer-to-peer, your IP address is exposed to the other party during a session, and theirs to you. See Section 9 for what this means.
2. THE PERSONAL DATA WE COLLECT
We organize the data we collect into the categories below. Each category is backed by a specific table, field, or feature in our system so that this disclosure reflects what we actually hold, not a generic list.
2.1 Identity Data
- Email address — used as your login and primary contact.
- Full name — collected at registration.
- Phone number — collected (especially for Providers and cash-reward-eligible referrers).
- Address — collected (especially for Providers and KYC).
2.2 Account Data
- Role (
viewer,provider,admin,staff), account status, registration date. - Subscription tier (
trial,basic,premium) and subscription end date. - Referral code (
RINNY-XXXXXX) and, if applicable, the referral code of the person who referred you (referred_by). - Permissions (granular staff/admin permissions).
2.3 KYC / Identity-Verification Documents — Special-Category
When you request cash-out eligibility, a cash referral reward, or when we otherwise request it, we collect:
- Government-issued photo identification (image).
- Proof of address (where required).
- Tax identification number (where required).
- KYC status (
pending,approved,rejected).
Profiles kyc_status and kyc_document; the image itself is stored in a private storage bucket called kyc documents (accessible only to authorized admin/staff for review; not publicly listed).
2.4 Financial Data
- MMG (Mobile Money Guyana) account details — the name and account number of the mobile-money account you register with us, used secondary as the destination for Provider Cash-Outs other than in-person.
- Balance — your Credit balance (1 Credit = GYD $5.00).
- Total spent (Viewers) and total earned (Providers), in Credits.
- Credit-purchase history — each Credit pack you bought, the GYD amount paid, and the timestamp.
- Payment attempts — for every payment, whether successful, failed, or declined, we log: the merchant transaction ID, type (
creditsorsub), amount, tier (for subscriptions), result code, result message, status, and your IP address. Failed payments are retained so we can distinguish voluntary churn from involuntary churn (a user who tried to pay but was declined). - Subscription history — each subscription activation, upgrade, downgrade, renewal, and the associated transaction.
- Payout requests — each cash-out request you submit: gross amount, flat Platform Fee (applied by balance tier per the Terms, not a percentage), net amount, status (
pending,approved,rejected), and receipt details.
2.5 Location Data
- Viewer GPS location — used to show cameras on the map (Rinnyview and Rinnylink requests device location; you can deny this permission and the App may refuse to function).
- Camera coordinates (latitude, longitude) — the location you set for your Provider camera.
- Named favorite locations — any custom location names you save.
2.6 Camera Metadata and User-Generated Content
- Camera name, description, thumbnail image (uploaded or auto-captured).
- Access mode (Automatic or Approval Required).
- Camera reports and evidence — if you submit an abuse report about a camera, we store your report and any supporting evidence.
- Ratings and view counts attributed to your camera (if you are a Provider).
(thumbnails you upload are publicly viewable so viewers can discover your camera — do not upload anything private as a thumbnail).
2.7 Behavioral and Usage Data
- Session data — start/end times, duration, viewer count, provider, viewer, and credit consumption for each viewing session.
- Heartbeats — periodic "still alive" signals during active streams (used for real-time availability).
- Activity logs (with role) — significant account actions (login, subscription changes, payouts, admin actions) tagged with the role that performed them.
- Audit logs — administrative and operational events for security and compliance review.
- Referral events — reward type, reward amount, status (
pending,completed,rejected).
2.8 Technical Data
- IP address — logged on payment attempts and may be logged for security and abuse detection.
- Device information — device model, OS version, app version (collected passively).
- WebRTC IP exposure — during any viewing session, your IP address is invisible to the other party (the Provider cant sees the Viewer's IP, and vice versa). This is not an inherent feature of peer-to-peer WebRTC and and was intentionally hidden while peer-to-peer streaming is in use. TURN relay (used when NAT traversal is required) reduces but does not eliminate this exposure.
2.9 Communications Data
- Emails, support requests, and abuse reports you send us.
- Records of notices and acceptance logs (e.g., the timestamp and IP of your Terms acceptance).
3. HOW WE USE YOUR DATA (AND THE LEGAL BASIS)
We process your personal data for the following purposes. Each purpose maps to a lawful basis (under the DPA 2023, s. 6, once in force — and otherwise on the basis of contract, legitimate interests, legal obligation, or consent).
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide the Apps and Services — account creation, authentication, displaying the camera map, connecting Viewer and Provider sessions, billing Credits. | Identity, Account, Financial (Balance, purchases), Location, Technical. | Performance of a contract with you. |
| Process Viewer payments (subscriptions, Credit packs) via Google Play Billing or MMG. | Financial, Identity, Technical (IP). | Performance of a contract and legal obligation (financial record-keeping). |
| Process Provider Cash-Outs via MMG, including applying the Platform Fee tiers and the GYD $2,700 minimum. | Financial, MMG Account, KYC. | Performance of a contract and legal obligation (AML/CFT). |
| AML/CFT compliance — Customer Due Diligence, sanctions screening, suspicious-transaction reporting, record-keeping. | Identity, KYC, Financial, Technical. | Legal obligation (AML/CFT Act ss. 15, 16, 18). |
| Tax compliance — withholding and remitting withholding tax and VAT on Provider earnings. | Identity, Financial, KYC. | Legal obligation (Income Tax Act; Corporation Tax Act; VAT Act). |
| Fraud, abuse, and payment-dispute prevention — detecting fake accounts, bot activity, viewer collusion, chargebacks, and involuntary churn. | Financial (incl. failed payments), Behavioral, Technical, Identity. | Legitimate interests (protecting the Platform and other users) and legal obligation. |
| Moderation, abuse investigation, and silent monitoring — reviewing streams, thumbnails, and reports; admin staff may join and silently view any live stream for moderation and compliance (see Terms §8.3). | Content, Camera metadata, Behavioral, Identity. | Legitimate interests (platform safety), legal obligation (Cybercrime Act mandatory reporting), and to comply with law-enforcement requests. |
| Referral program — crediting rewards, enforcing cash-reward KYC. | Identity, Referral code, Financial, KYC. | Performance of a contract and consent (you opt in by sharing a referral code). |
| Customer support and dispute resolution. | Identity, Communications, Behavioral, Financial. | Performance of a contract and legitimate interests. |
| Communications — service notices, Terms changes, security alerts. | Identity, Communications. | Performance of a contract and legitimate interests. |
| Security and access control — admin/staff role-based access, 2FA (TOTP) for admins, audit logging. | Account, Permissions, Behavioral. | Legitimate interests (security) and legal obligation. |
| Aggregated, de-identified analytics — product improvement (no individual identifiable). | Aggregated only. | Legitimate interests. |
4. SENSITIVE AND SPECIAL-CATEGORY DATA
The DPA 2023 (and most data-protection regimes) treat certain data as "special category" requiring extra protection. We process the following sensitive data only where strictly necessary and under the safeguards below:
4.1 KYC Document Images (Government ID)
- These are collected only for Providers and for Users claiming cash referral rewards.
- They are stored in a private storage, that is not publicly listable and is accessible only to authorized admin/staff for verification.
- We retain them for the duration of your Account and for the AML/CFT record-keeping period (7 years) — see Section 7.
- Lawful basis: legal obligation (AML/CFT Act) and, where the DPA applies, the substantial-public-interest / legal-claims conditions.
4.2 Content You Stream
- Live streams are not stored by us. Video and audio flow peer-to-peer and are not recorded on our servers.
- Thumbnails and camera metadata that you upload are stored to make your camera discoverable; thumbnails are public by design.
- Camera reports and supporting evidence are stored for abuse investigation.
4.3 Precise Location
- Treated as sensitive. Viewer GPS requires explicit device permission (you can deny it). Camera coordinates are provided by you.
4.4 Biometric / Health / Belief Data
- We do not knowingly or deliberately collect biometric, health, religious, or political-opinion data.
- We recognise that a live camera Stream may incidentally capture such data. We do not view, analyse, or process Streams for the purpose of identifying special-category data — and, because Streams flow peer-to-peer and are not stored or recorded by us, we do not retain any such incidental data on our systems. Where a Stream must be reviewed by authorised staff for moderation or compliance under §5.5, that review is limited to the purpose of detecting violations of these Terms and applicable law, and is not processing for the purpose of inferring special-category characteristics.
- KYC document images are processed solely for identity verification as described in §4.1.
5. HOW WE SHARE YOUR DATA
We share personal data only as described below. We do not sell your personal data.
5.1 MMG (Mobile Money Guyana)
- What: Provider name and MMG account number, and transaction details, for processing Cash-Outs. Viewer payment details where you choose MMG as your payment rail.
- Why: To execute payments you have requested.
5.2 Google Play Billing
- What: Viewer billing data (handled by Google under Google's own privacy policy).
- Why: To process Viewer subscriptions and Credit purchases made via Google Play.
5.3 Infrastructure Providers
- Supabase — our database and authentication provider (stores most data described in Section 2).
- Metered / Coturn — TURN relay providers for WebRTC NAT traversal (may transiently process connection metadata, including IP addresses, to relay media).
- Hosting — server infrastructure (location disclosed in Section 6).
5.4 Law Enforcement and Regulatory Authorities
- We disclose data where required by law, including: mandatory reports to the Guyana Police Force under Cybercrime Act 2018 ss. 14–15; production orders (s. 31); content-removal orders (s. 37); FIU directions and suspicious-transaction reports under the AML/CFT Act; and any other competent legal process.
5.5 Admin Silent Monitoring (Staff Access)
- Authorized Platform staff may silently join and view any live Stream for moderation, abuse investigation, and compliance, without real-time notice to the Provider or Viewer (see Terms §8.3). Staff access is controlled by role-based permissions and two-factor authentication, and is recorded in audit logs.
5.6 Successors
- In the event of a merger, acquisition, or asset sale, we may transfer your data to the successor, who must handle it consistently with this Policy.
5.7 Other
- We may disclose data to enforce our rights, protect our property or safety, or defend against legal claims, and to our professional advisors (lawyers, auditors) bound by confidentiality.
6. INTERNATIONAL DATA TRANSFERS
Your personal data may be transferred to, stored, and processed in countries outside Guyana, because:
- Supabase may host data in a region outside Guyana.
- Metered / Coturn (TURN relay) may process connection metadata outside Guyana.
- Google Play Billing is operated by Google and processes Viewer billing data under Google's global infrastructure.
Where we transfer personal data internationally, we implement safeguards as required by applicable law — including, on commencement of the DPA 2023, that the transfer is made on a lawful basis under DPA s. 50 (or its successor provision) and that the recipient provides an adequate level of protection, whether through adequacy, appropriate safeguards (such as standard contractual clauses or equivalent instruments), or a recognised exception. Your use of the Apps constitutes acknowledgement of these transfers; we rely primarily on the lawful bases set out in Section 3 and on appropriate transfer safeguards, and not on bundled consent alone.
7. HOW LONG WE KEEP YOUR DATA (RETENTION)
We do not keep your data longer than necessary. Retention is set per data category, not by a single uniform period, because our legal obligations differ by category.
| Data category | Retention period | Legal basis |
|---|---|---|
| Traffic data (connection metadata of subscribers) | Minimum 90 days from generation | Cybercrime Act 2018, s. 25 |
| Subscriber information | Minimum 90 days after service termination | Cybercrime Act 2018, s. 25 |
| AML/CFT records (KYC, transactions, CDD) | At least 7 years | AML/CFT Act, s. 16 |
| KYC document images | Duration of Account + 7 years (AML/CFT) | Legal obligation |
| Payment records (purchases, subscription history, payout requests) | Duration of Account + 7 years (financial/tax record-keeping) | Legal obligation |
| Payment attempts (including failed/declined) | Duration of Account + 7 years (fraud and involuntary-churn analysis) | Legitimate interests + legal obligation |
| Account data (identity, contact) | Duration of Account + the period needed to comply with law, resolve disputes, and enforce agreements; thereafter deleted or anonymized | Contract + legitimate interests |
| Activity logs and audit logs | Archived after deactivation; retained for security and compliance review | Legitimate interests + legal obligation |
| Camera reports and evidence | Retained for the duration of any investigation and thereafter per the applicable limitation period | Legitimate interests + legal claims |
| Live stream media | Not stored — flows peer-to-peer and is not recorded on our servers | N/A |
| Camera thumbnails | Public; retained while your camera is listed and removed on deletion | Contract |
We may extend any of the above periods where required by judicial order (Cybercrime Act s. 25), where there is a pending legal claim, or where deletion is not technically feasible in which case we will restrict the data.
Archival vs deletion: some data is moved to an archived state rather than immediately deleted at the end of its active life; archived data is restricted to compliance and security use only and is deleted when its retention period ends.
8. YOUR DATA-PROTECTION RIGHTS
The DPA 2023 grants you enforceable rights (effective on commencement of the Act). On a voluntary, anticipatory basis, we honor these rights as described below, and will give them full effect upon commencement of the Act:
| Right | What it means |
|---|---|
| Access (s. 11) | You may request a copy of the personal data we hold about you and information about how we use it. |
| Rectification (s. 12) | You may ask us to correct inaccurate or incomplete data. |
| Erasure (s. 13) | In certain circumstances, you may ask us to delete your data — subject to our legal obligations (e.g., the 90-day Cybercrime Act and 7-year AML/CFT retention periods override a deletion request for the affected data). |
| Data portability (s. 16) | You may receive certain data you provided to us in a structured, machine-readable format and transmit it to another controller. |
| Objection (s. 18) | You may object to processing based on legitimate interests or for direct marketing. |
| Automated decision-making (s. 19) | You have rights regarding decisions made solely by automated means that significantly affect you. |
| Withdraw consent | Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. |
8.1 How to Exercise Your Rights
Email Herizan@synnas.com with the subject line "Data Subject Request." We will verify your identity (to protect against unauthorized access) and respond within the statutory timeframe (30 days under the DPA, extendable by a further 60 days for complex requests). We do not charge a fee, except where permitted for manifestly unfounded or excessive requests.
8.2 Compensation
The following applies only upon commencement of the DPA 2023 (which, as of this date, is enacted but not yet in force).
Under DPA 2023, s. 97(1), a person who suffers actual damage or distress as a result of a contravention of the Act by us (as data controller or processor) may seek compensation for that damage. The right to compensation arises only where actual damage or distress is established; a technical or non-material contravention, without more, does not of itself give rise to a compensable claim.
Under DPA 2023, s. 97(2), it is a defence to any such claim for us to prove that we took all such measures in the circumstances as would be reasonably required to comply with the Act. The technical and organisational measures described in Section 9 of this Policy (including Supabase Auth, Row-Level Security, private storage of KYC documents, dynamically generated TURN credentials, audit logging, role-based access control, 2FA for admin accounts, and staff confidentiality) are maintained in part to support this defence. We will review and update these measures in light of our obligations under the Act.
Any claim for compensation is subject to the dispute-resolution provisions in our [Terms of Use](https://www.synnas.com/rinny/terms) (Terms §11), including the mandatory 30-day good-faith negotiation period, which applies before any formal proceeding.
8.3 Contacting Us First; Right to Complain
If you believe we have mishandled your data, you must first contact us at Herizan@synnas.com so that we have the opportunity to investigate and put things right. We will acknowledge and respond to data-related complaints in accordance with this Policy and the dispute-resolution provisions in our [Terms of Use](https://www.synnas.com/rinny/terms) (Terms §11), including the mandatory 30-day good-faith negotiation period.
If, after following that process, the matter remains unresolved, you may — upon commencement of the DPA 2023 — lodge a complaint with the Data Protection Commissioner of Guyana (contact details: to be provided once the Commissioner's office is operational). We will cooperate with the Commissioner in the discharge of his or her statutory functions, as required by law.
9. DATA SECURITY
9.1 Technical Measures
- Authentication: all authentication flows through Supabase Auth (JWT). The backend re-validates every JWT against Supabase and does not decode or verify it locally.
- Authorization: role-based access (viewer/provider/admin/staff) with granular staff permissions. Admin accounts require 2FA (TOTP).
- Row-Level Security: PostgreSQL Row-Level Security (RLS) policies restrict which rows each user can read or write.
- Storage security: KYC documents are in a private bucket; thumbnails are public by design (see §2.6). Service-role access is server-side only.
- Configuration security: secrets come from environment variables, never hardcoded; backend configuration is validated at startup; production returns generic error messages (no sensitive detail).
- ICE/TURN security: TURN credentials are generated dynamically per connection (HMAC-SHA1, 24-hour expiry); loopback and multicast peers are disabled.
- Audit logging: significant admin and security-relevant actions are logged.
9.2 Organizational Measures
- Access to personal data is limited to authorized personnel who need it for their role.
- Staff handling KYC, payouts, and abuse reports are bound by confidentiality.
9.3 The Peer-to-Peer Caveat (Important)
The Apps use peer-to-peer WebRTC for live video and audio. This means:
- During a session, the Provider can see the Viewer's User Name and the Viewer can see the Provider's User Name.
- The Stream media itself does not not necessary pass through our servers and is not recorded by us.
9.4 Breach Notification
In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we will — on commencement of the DPA 2023 — notify you and the Data Protection Commissioner in accordance with DPA s. 65, and take reasonable steps to mitigate the breach.
10. COOKIES AND ANALYTICS
- The Apps do not use browser cookies in the traditional sense.
- The admin dashboard (web) uses local storage for authentication tokens . These are necessary for the service and are not used for third-party advertising.
- We may use aggregated, de-identified analytics to improve the Apps. No individual user is identifiable from this data.
11. CHILDREN'S DATA
- The Apps are not directed at anyone under 18, and we do not knowingly collect personal data from anyone under 18.
- If we learn that a user under 18 has registered, we will terminate that account immediately.
- Any content depicting child sexual abuse or child exploitation will be reported to the Guyana Police Force under Cybercrime Act 2018, ss. 14–15.
12. CHANGES TO THIS POLICY
We may update this Policy from time to time. Material changes (e.g., new categories of data collected, new recipients, new retention rules, or a change to international transfer practices) will be communicated through the Apps or by email at least 30 days before the effective date. Your continued use after the effective date constitutes acceptance of the updated Policy.
The "Last Updated" date at the top of this Policy indicates when it was last revised.
13. CONTACT AND COMPLAINTS
13.1 Contacting Us
For any question, request, or complaint regarding this Policy or your personal data, contact our privacy contact:
- Email: Herizan@synnas.com
- Postal address: 48 Princes St, Werk-en-Rust, Georgetown, Guyana
- Data Controller: SYNONYMOUS & NASCENSE (Business Names Registration Certificate No. 286545)
13.2 If You Have a Complaint
We ask that you contact us first using the details above so that we have the opportunity to investigate and put things right. If, after following the dispute-resolution process in our [Terms of Use](https://www.synnas.com/rinny/terms) (Terms §11, including the mandatory 30-day good-faith negotiation period), the matter remains unresolved — or if you believe we have breached the DPA 2023 — you may, upon commencement of the DPA 2023, lodge a complaint with the Data Protection Commissioner of Guyana (once operational). Any claim for compensation under DPA s. 97 is subject to the threshold and defence set out in §8.2 above.