¶ THE FINE PRINT
Privacy Policy
Last revised 3 July 2026
Who we are and what this covers
HEYSINI PTY LTD (ACN 699 859 455), trading as Hey Sini ("Hey Sini", "we", "us"), provides an adults-only online social discovery platform that helps compatible members connect around a small recurring table in their own neighbourhood, currently in Melbourne, Australia and Jakarta, Indonesia. We are based in Melbourne, Victoria, Australia and are the controller of the personal information described here.
Importantly, members decide whether, where, when and how to meet. We may suggest public venue ideas, but we do not host, arrange, run, supervise or attend offline meetings. This policy explains the information we handle when you use our website and app. It works alongside our Terms of Service.
Information we collect
You give us
- Account and identity: your name, email and sign-in, handled through our authentication provider.
- Profile and matching details: your neighbourhood, the night you can keep, your vibe and interests, a short intro, and optional details such as age, gender (used only to balance tables, never shown to others), and social links.
- Photos:your profile photo, the live verification selfie used before table matching, and any photos you add to your table's shared roll. See section 4.
- Messages and content: messages in your crew chat and direct messages, RSVPs, venue suggestions, feedback, and mood posts.
- Safety details: reports or blocks you make, and, only if you opt in, an emergency contact name and number.
We collect automatically
- Approximate location:the neighbourhood you choose, and an approximate city inferred from your IP address to set your language and market. If you tap a “use my location” or “near me” control, your browser asks your permission to share your device location for that one action; we use it only in that moment to suggest your closest neighbourhood or nearby places, and we do not store the coordinate or track your location in the background.
- Device and usage: IP address, basic device and log data, and product analytics events (for example sign-up, matched, RSVP) used to run and improve the service and to rate-limit abuse.
- On-device personalization:some pages (for example the public Table Radar) remember the filter choices you make on the page in your browser’s local storage, so the page feels tuned to you next time. This stays on your device, is not tied to your account, and is never sent to us. Clear it any time by clearing your browser storage.
Payments
Dues are processed by our payment provider. We receive a customer and subscription reference and your payment status. We never receive or store your full card number.
How we use your information
We use your information to:
- match you into a compatible table and run the online platform around it;
- operate safety and moderation features (verification, reporting, blocking);
- take dues and manage your membership;
- send service messages, and marketing only where you have opted in;
- understand and improve the product through aggregate analytics; and
- comply with our legal obligations and enforce our Terms.
Our lawful bases (where required) are performing our contract with you, your consent (for example for the verification selfie and marketing email), and our legitimate interests in running a safe, working club. We do not sell your personal information.
Verification selfies and liveness
Before recurring table matching, you take a live photo on the spot (no uploads) and perform a simple action, such as holding up a number of fingers, so we can tell a live person from a photo of a screen or a printout.
The image may be checked by an automated vision service purely to answer "is this a live person doing the requested action?" We do not create a faceprint or biometric template, and we do not match your face against any identity database or other members' photos to identify you. The photo you take becomes your profile photo unless you change it.
Because face images and face data can be sensitive, we treat verification images as sensitive information. We use them only for the verification process and your current profile photo, do not sell them, and do not use them to train our own AI models.
Safety, reporting and chat moderation
To keep the club safe we provide reporting and blocking, basic word filters on messages, and human review of messages that are reported to us. We are transparent about this: we are not running covert surveillance of private conversations, and we disclose this safety layer here and in our Terms.
We are not an emergency service. If you feel unsafe, contact your local emergency number (000 in Australia, 112 in Indonesia).
Who we share information with
We share information only as needed to run Hey Sini:
- Other members: your name, photo, verification status and the profile details you provide are shown to the four people seated at your table, and your first name and photo may appear in discovery features you enable.
- Service providers (sub-processors) who process data on our instructions: hosting and file storage, authentication, payments, our database, transactional email, static maps for the venue area, and the automated liveness check. Each receives only what it needs for its function.
- Authorities where we are legally required to, or to protect the safety of members or the public.
We maintain a current list of sub-processors and will provide it on request to hello@heysini.com.
Where your data is processed
Several of our service providers are based in or process data in the United States and other countries, so your information may be transferred and processed outside Australia and Indonesia. Where we disclose information overseas we take reasonable steps to ensure it is handled consistently with this policy and applicable law, including contractual protections with our providers.
If Hey Sini is offered to members in Indonesia, Indonesia-specific cross-border transfer, PSE and Personal Data Protection Law requirements need local legal confirmation before the Jakarta member launch is treated as compliance-complete.
How long we keep it, and deletion
We keep personal information for as long as you have an account and for a reasonable period afterwards where needed to meet legal, accounting and safety obligations. When you delete your account, we remove your profile, uploaded files, table membership, direct messages and first-party social edges from our app database where they are tied to your account. Some records may still be retained where we have a legal basis to keep them, such as payment records held by our payment provider, logs needed for security, or records another person or authority requires us to preserve.
You can delete your account from your account settings, or by emailing hello@heysini.com.
Your rights and choices
Subject to local law, you can:
- access the personal information we hold about you and ask us to correct it;
- delete your account and request deletion of your personal information;
- opt out of marketing email at any time; and
- object to or restrict certain processing.
To exercise any of these, email hello@heysini.com. If you are in Australia and are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC). If you are in Indonesia, you may contact the relevant data protection authority.
How we protect your information
We use reasonable technical and organisational measures to protect your information, including encryption in transit (HTTPS), validation of every uploaded file by its true content, rate limiting, access controls, and keeping payment card handling entirely with our PCI-compliant payment provider. No method of transmission or storage is completely secure, so we also maintain a process for detecting and responding to incidents (see section 12).
Minimum age
Hey Sini is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal information from anyone under 18; if you believe a minor has given us their information, contact us and we will delete it.
Data breaches
If we become aware of a data breach that is likely to result in serious harm, we will assess it and notify affected individuals and the relevant regulator as required by law. In Australia we follow the Notifiable Data Breaches scheme, which requires us to assess a suspected eligible breach within 30 days and notify as soon as practicable thereafter.
Indonesia-specific breach-notification requirements are being confirmed with local counsel and will be reflected here before Jakarta member operations are treated as launch-ready.
Changes to this policy
We may update this policy as the product and the law change. When we make material changes we will revise the date at the top and, where appropriate, notify you in the app or by email. The current version always lives at this address.
How to contact us
For any privacy question or request, email hello@heysini.com, or use our contact page. Responsible entity: HEYSINI PTY LTD (ACN 699 859 455), Melbourne, Victoria, Australia.