This policy describes how Tink works today. Tink is a free app and it will keep changing — what we collect and how we use it can change with it. See Changes.
Who we are
Tink is operated by BT Vickers App Development Pty Ltd (ACN 699 645 184) of West Perth, Western Australia. Contact: support@tinkdate.com.
What Tink does
Two people connect their phones, swipe on food and activity ideas, and get matched suggestions of nearby venues they can book.
What we collect, and why
The table below describes current practice, at the date above.
| Data | Why | Where it lives, and for how long |
|---|---|---|
| Your sign-in identity | When you sign in, Apple or Google hands Tink a signed token proving your account. We verify it, take the account’s anonymous subject number, and scramble that with a secret key to produce your Tink user ID — a random-looking identifier that contains no personal information. On Android, your account’s first name is suggested on your device to prefill the editable name field — you can change it, and whichever name you end up with (suggested or typed) becomes your display name, handled as described in the next row. We do not currently request or store the email address attached to the account. (An email you enter into the website waitlist is separate — see the last row of this table.) | On our servers while you have data with us. Signing in with the same account produces the same ID — that is how people you’ve planned with can still invite you on a new phone. (Your saved partner list has its own row below.) |
| A device integrity check (optional) | Your device can prove it is a genuine iPhone (Apple App Attest) or a genuine Android device (Google Play Integrity). This is an anti-abuse signal — it unlocks higher daily usage limits and is not part of your identity. If the check is unavailable, Tink still works. | The fact and time of a successful check, inside your session credentials. On iPhone, the check’s key identifier also serves as the device identifier in those credentials. |
| Your first name (or nickname) | Shown to the person you are planning a date with, and restored on a new phone so you are not asked again. | On our servers, in your account’s own storage, until you change it or delete your account. It also travels with each running session, as before. |
| A search location | Finding restaurants and activities near you. You choose it, or grant one-time location access. Tink does not currently use background location. | Used precisely during the session; stored afterwards rounded to roughly 100 metres as part of the session record. |
| Swipes and results | Matching you with your partner, and improving which categories and venues Tink offers. | Processed live. The session record — matched categories, the suggested venues, and which options were booked — currently contains no user identifier at all, so nothing connects it back to you. It is kept as anonymous product statistics. |
| Chat messages and reactions | Coordinating the booking with your partner during the decide window. | Relayed live between participants. A short tail is briefly written to session storage so a disconnection doesn’t lose messages, and is deleted when the session ends (at most a couple of hours). Chat is not logged or analysed — with one exception: if a participant files a safety report, a snapshot of the recent chat is preserved as evidence (see “Safety reports” below). |
| A push token (optional) | Delivering date invites from people you have planned with before. | On our servers until replaced or your data is deleted. When you turn notifications off, your device reports that and the token is marked disabled — a disabled token is never used to send anything. |
| Your saved partners | Inviting people you have planned with before, naming those invites, and restoring your list when you get a new phone. | On our servers, in your account’s own storage: for each saved partner, their Tink user ID, the nickname you chose for them, and the technical key that lets you invite them (capped at 64 entries). When someone invites you, the notification names them using the nickname you saved — your words, never their self-chosen name. Deleted with your account. The entry a partner keeps about you lives in their account and is their data — like your name in someone else’s address book. |
| Invites and blocks | Letting a previous partner invite you, and letting you block that. | Pending invites are deleted within about 30 minutes. Blocks are stored as salted hashes; a blocked person cannot tell they are blocked. |
| Safety reports | Acting promptly on reports of harassment or abuse, and meeting our obligations under app-store rules and the Online Safety Act. | When someone in a session files a report, we preserve a snapshot as evidence: the reported message, the recent chat around it, and the names of who was in the session at that moment. This is the deliberate exception to chat being deleted — evidence has to outlive the session or nothing can be done about it. So a human sees it quickly, the report’s content (including the chat snapshot) is also sent by email to our access-controlled review inbox. Reports are kept while open, and deleted 90 days after being resolved. If you filed a report and delete your account, your identity is removed from it; reports about you are kept even if you delete your account (enforcement records), and the same applies to a suspension: deleting your account does not lift it. |
| Waitlist email (website only) | If you join the waitlist at tinkdate.com, we store the email address you enter so we can tell you when Tink launches. | On our servers until launch has been announced and the list is no longer needed, or sooner if you ask us to remove it at support@tinkdate.com. It is used for launch news, not linked to any app account. |
| Usage statistics | Understanding whether Tink works: sessions played, match rates, booking clicks, weekly retention. | Pseudonymous — identifiers are salted, truncated hashes that are not reversible by us. Event data ages out at our analytics provider after about 3 months. A weekly “was active” ledger, keyed only by hash, is kept until you delete your data. |
Bluetooth
“Tinking” phones together uses Bluetooth to exchange a short one-time session code with a nearby phone. No Bluetooth device information is collected or retained; our pseudonymous usage statistics do record which of the three ways of starting a session was used (phones touched, link, or invite).
How Tink is paid for
Tink is free to use. Today it earns nothing from you directly: some booking links are affiliate links, and if you book through one we may earn a commission from the venue or booking platform.
We may introduce other ways of funding the app — including advertising, sponsored or featured venues, paid placement, subscriptions, or commercial partnerships — and commercial relationships may be one of the things that influences which venues we suggest and in what order. If we introduce advertising or begin sharing personal information with partners, we will update this policy and our app-store disclosures first, and we will label paid placement where the law requires it.
Third parties
- Cloudflare hosts our backend at edge locations worldwide, so data is processed on Cloudflare infrastructure, including outside Australia. The waitlist form on this website also uses Cloudflare Turnstile to tell people from bots without showing a CAPTCHA: it evaluates limited technical signals from your browser for that one purpose, and is covered by the Cloudflare Turnstile privacy policy.
- Apple processes Sign in with Apple, device attestation, and push notifications on iPhone under Apple’s own policies. On iPhone, Tink’s identity and partner list are stored in the system Keychain, which is included in your encrypted device backups and phone-to-phone transfers — that is what lets a new phone restore them.
- Google processes Google sign-in, device attestation (Play Integrity), and push notification delivery (Firebase Cloud Messaging) on Android under Google’s own policies. On Android, the app’s data is included in Android’s app backup to your Google account (the same restore-on-a-new-phone mechanism every backed-up app uses). We also use Google’s Places service on our own servers to organise venue locations — no user data is involved in that.
- Viator, a Tripadvisor company, supplies much of our venue and activity data (details, photos, ratings, availability), and many booking links go to Viator. No personal information flows from Tink to Viator — attribution happens on their side when you open a booking link.
- Booking sites: when you tap a booking link, you leave Tink and the venue’s or booking platform’s privacy policy applies. Some links are affiliate links, and the platform may know the click came from Tink. Attribution happens on the booking site’s side: the link may carry a referral code, and that site may set cookies or use its own analytics under its own policy — that part of the journey is theirs, not ours.
Your rights
We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles. You can ask us what we hold, ask for correction, or ask for deletion at support@tinkdate.com. The fastest path is Settings → Delete my data inside the app, which erases your server-side data immediately (your sign-in proves which user ID is yours). A step-by-step guide — including what to do if you have already deleted the app — lives at tinkdate.com/delete-account. Deleting the app alone does not erase your data: your display name and partner list live in your account on our servers, and the device copy of your identity and partner list is designed to survive reinstalls (via the iPhone Keychain and its encrypted backups, or Android’s app backup) so a new phone can restore them. Use Settings → Delete my data — it erases the server copy and the device copy together.
Outside Australia (including the United States)
We are an Australian company and Tink is available in other countries, including the United States. Wherever you are, we extend the same rights — access, correction, and deletion — and the same practices described in this policy. For California residents: we do not currently sell or share personal information as those terms are defined in the CCPA/CPRA. If that changes, we will update this policy and provide the opt-out the law requires before doing so.
Complaints
If you believe we have mishandled your personal information, contact us at support@tinkdate.com and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Children
Tink is for adults planning dates — including at bars, breweries and wineries — and is not directed at anyone under 18. We do not knowingly collect information from children.
Changes
Tink is under active development and this policy describes how it works today, at the date shown above. We may change what we collect, how we use it, where it is stored, and how the app is funded — including storing on your behalf things that are currently kept only on your device, adding other ways to sign in, and introducing advertising or commercial partnerships. Where a change is material, we will update this policy, update our app-store disclosures, and tell you in the app before the change applies to you. The latest version always lives at this address.