Privacy Policy
1. Introduction
At Kinmoot, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our property investment marketplace.
2. Information We Collect
2.1 Personal Information
- Name and contact information
- Profile information and preferences
- Payment and transaction details
- Communication history on our platform
2.2 Usage Information
- Device and browser information
- IP address and location data
- Platform usage patterns
- Cookies and similar tracking technologies
- When you open the deal form, or save or submit a deal, we keep a record of the attempt: when it happened, whether it succeeded, and if not, which parts of the form were incomplete or what went wrong. We use it to find and fix problems with the form. It never includes what you typed or uploaded, and it is deleted after twelve months.
- When you read a feasibility sheet or brochure through the importer (section 4.3), we keep a record of the reading: when it happened, which hub and account it was for, whether it worked, how many figures it found, and what it cost us to run. We use it to see how well the reader works over time. It never includes any of the text of your document, and we keep it for as long as we run the service.
3. How We Use Your Information
We use your information to:
- Provide and improve our services
- Process transactions and payments
- Communicate with you about our services
- Protect against fraudulent or illegal activity
- Comply with legal obligations
4. Information Sharing
We may share your information with:
- Other users as necessary for platform functionality
- The business running the site you joined through, where that business is not Kinmoot itself — see 4.1 below
- Service providers who assist in our operations
- Legal authorities when required by law
- Business partners with your consent
4.1 Sites run on Kinmoot by other businesses
Not every site built on Kinmoot is run by us. Some are run by our customers — a property educator or sourcing business with their own branded site and their own members. If you joined through one of those sites rather than through kinmoot.com, then that business, and anyone they have made an administrator of their site, can see the following about you from the dashboard we give them:
- Your email address, whether you hold member or administrator access, whether that access is invited, active or withdrawn, the date you were added and the date you were last active on their site. Your membership record holds your email address and no other contact details.
- For each email they send you through Kinmoot, whether it was delivered, whether it bounced and whether you opened it.
- Which of their lessons you have opened, and when. What they are shown is the lesson and the time, recorded against your account — not what you typed, not which pages you browsed, and not your device, IP address or location. No recording is made of your session on their site.
- If you register interest in one of their deals: the name and email address you gave on that form, how you said you intend to buy, your timescale, your buying history, how many of their deals you have registered on and when, along with a ranking we work out from those answers. They are also shown that you are one of their members.
- If you ask to be introduced to one of the professionals they list, the name you gave with that request. If you submit a deal to them, the name and photograph on your Kinmoot profile.
Where your name appears in that list it is the name you gave on the form in question, not a name taken from your account. What they can see is limited to their own site: they cannot see what you do on kinmoot.com, or on any other site run on Kinmoot that you belong to.
4.2 AI assistants connected to those sites
A business running a site on Kinmoot can connect an AI assistant — such as Claude, ChatGPT or a similar tool — so that they can ask questions about their own site rather than reading the dashboard themselves. Where they do:
- The assistant can read no more about you than the information described in 4.1 above. Connecting one does not give them anything further about you.
- The assistant can only read. It cannot change their site, contact you, or act on your record.
- Information the assistant reads is sent to the company providing that assistant, and is handled under that company's terms and privacy policy. We do not choose which assistant a business connects, and we do not control what that company does with what it receives.
- Access is limited to that one site, and the business can withdraw it at any time.
If you want to know whether the site you joined through has connected an AI assistant, and which one, ask the business running it. If you would rather they did not, that is a decision for them and not for us — but you can ask us to delete your data at any time under section 6 below.
4.3 Reading a feasibility sheet or brochure you upload
If you run a hub, you can upload your own feasibility spreadsheet or a property brochure and have the figures read out of it into a draft listing. When you do, the text of the sheets you select, and the text of the brochure, are sent to Anthropic PBC in the United States, which returns the figures it found. Email addresses and telephone numbers are removed before anything is sent to Anthropic.
Anthropic does not use this content to train its models, and deletes inputs and outputs within 30 days. We keep the text of the sheets and the brochure you upload — exactly as uploaded — together with what was read from them and what you changed while working on the draft, whether or not you go on to publish it, for twelve months, so that we can measure and improve the reader. That stored copy still includes any email addresses or telephone numbers in your original document; only the copy sent to Anthropic has them removed. The extracted figures we use so that re-opening the same sheet does not need a second reading are still deleted after 30 days. Nothing read this way is published: it becomes a draft that you review, edit and submit yourself. Ask us at the address in section 12 to delete any of this sooner.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to data processing
- Data portability
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint. We would appreciate the chance to address your concerns before you approach the ICO, so please do contact us first — by email at privacy@kinmoot.com or by phone on 07706 029772.
7. Cookies
We use cookies and similar tracking technologies to improve your browsing experience, analyze site traffic, and understand where our visitors come from.
7.1 What Are Cookies
Cookies are small text files that are stored on your device when you visit our website. They help us recognize your device and remember certain information about your visit.
7.2 Types of Cookies We Use
- Essential Cookies: Required for the website to function properly. These cannot be disabled.
- Functional Cookies: Help us remember your preferences and settings.
- Analytics Cookies: Allow us to understand how visitors interact with our website, helping us improve our services.
- Marketing Cookies: Used to track visitors across websites to display relevant advertisements.
7.3 Analytics and Session Recording
With your analytics consent, we use the following providers to understand how the site is used and to fix problems. Until you give that consent, none of them receive any information about your visit. PostHog stores only an empty record and a note of your choice on your device — no identifier is created.
- PostHog (EU region) — product analytics, and session recording on kinmoot.com only. On the sites described in section 4.1 there is no session recording at all: PostHog receives events and page views there and nothing else, whether or not you have given analytics consent. Where recording does apply it captures how pages are used: clicks, scrolling and navigation. Text you type into forms is masked before it leaves your browser, so we do not receive it. If you are signed in, events and any recording are linked to your account so we can help when something goes wrong.
- Microsoft Clarity — heatmaps and session recording.
- Google Analytics 4 — aggregate traffic and conversion reporting.
- Vercel Analytics and Speed Insights — page performance.
We also use Sentry to record technical errors. Error reports contain the page, browser and a technical stack trace, plus your account identifier if you are signed in. They do not include your email address, and error reporting is not used to track or profile you.
7.4 Managing Cookies
You can manage your cookie preferences through the cookie banner shown on your first visit to any site run on Kinmoot, including the sites described in section 4.1. You can change your choice at any time afterwards using the Cookie settings link in the footer of any page. Withdrawing analytics consent stops event collection immediately, and stops session recording wherever it applied.
8. The Member App
Members of a hub run on Kinmoot may be given a mobile app carrying their own organisation’s name. The app is a second way into the same hub, it holds no separate account, and this policy covers it as it covers the website. It has no cookies, so section 7 does not apply to it; what follows does instead.
8.1 What the App Collects
- Your email address, to send the six-digit code you sign in with.
- A notification token for your device, issued by Apple or Google, so we can tell you when your organisation adds something. It is stored with the device type and your notification preferences, and it is deleted when you sign out or uninstall the app.
- Your progress through lessons — how far into a video you watched and which lessons you have finished — so you can pick a course back up where you left it.
The app has nothing to buy in it and asks for no payment details. It does not use your location, your contacts, your photos, your microphone or your camera.
8.2 Crash Reports
The app sends crash and error reports to Sentry so that a fault reaches us without you having to report it. A report carries the error, the device model and operating system version, and your Kinmoot account identifier — never your email address, and never anything you were looking at.
8.3 App Analytics Are Off Unless You Turn Them On
Product analytics in the app go to PostHog (EU region), the same provider named in section 7.3, and they are switched off until you switch them on. A fresh install sends nothing. If you turn on “Help improve the app” in Settings, we record which screens and features you use — for example that a notification was opened, or that a lesson was started. You can turn it off again in the same place at any time, and collection stops immediately.
The app never records your screen. Session replay and screenshot capture are both disabled in the app deliberately and permanently, because the screens in it show live deal details and an organisation’s own course video. There are no advertising or ad-measurement services in the app, and nothing it collects is shared with a data broker or used to track you across other companies’ apps and websites.
9. Connecting Your Google Calendar
If you run a hub on Kinmoot, you can connect your Google Calendar so that members can book a call with you at a time you are genuinely free. This section applies only to the person who connects the calendar. Members who book a call never connect one, and nothing here applies to them.
9.1 What We Access, and What We Do Not
We ask for two permissions and no others:
- See when you are busy (
calendar.freebusy). This returns the start and end times of the things in your calendar, and nothing else. We use it to remove times you are already busy from the slots your members are offered. - Create and remove the bookings members make (
calendar.events). We add a booking to your calendar when someone books, and remove it if the call is cancelled.
We never read the contents of your calendar. Not the title of a meeting, not its description, not its location, not who else is attending. The narrower permission above returns busy periods only, which is why we ask for it instead of full calendar access. Events we did not create are, to us, an anonymous block of time.
9.2 What We Store
- An access token and a refresh token issued by Google, so that we can keep checking your availability without asking you to sign in again. These are held in a table that is unreachable by any browser and readable only by our own servers.
- The email address of the Google account you connected, so we can show you which calendar is attached.
- The bookings themselves, which are ours rather than Google’s: the member’s name, email address, the time, anything they wrote when booking, and the identifier of the calendar event we created.
We do not copy, mirror or store your calendar. Your availability is fetched from Google at the moment a member looks at your booking page and is not retained afterwards.
9.3 How to Disconnect
You can disconnect at any time from Book a call in your hub dashboard, which stops all access immediately. You can also revoke it directly from your Google Account under Security, Third-party apps with account access. Disconnecting does not delete bookings already made, so that neither you nor your members lose a record of them.
9.4 Limited Use
Kinmoot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to anyone except as needed to provide the booking feature, and no human reads it except where you ask us to help with a specific problem or where the law requires it.
10. Children’s Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect or maintain information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
12. Contact Us
The data controller for the personal data described in this policy is Kinmoot Ltd, a company registered in England and Wales under company number 17381326, whose registered office is 66 Paul Street, London, EC2A 4NA.
Kinmoot Ltd is registered with the Information Commissioner's Office under registration reference ZC223910.
If you have any questions about this Privacy Policy, please contact us at privacy@kinmoot.com or on 07706 029772.