
PRIVACY POLICY
PRIVACY POLICY
Effective: 01 January 2026
Last updated: 25 July 2026
Version 1.0
This policy explains what data Togethër collects, why we collect it, who we share it with, and the control you have over it — across every product we run: the website, the mobile and web apps, the AI chat assistant, merchant tools, wallet features, token services and swaps.
1. WHO WE ARE
Togethër ("Togethër", "we", "us", "our") is operated by Together Inc. (BVI) Ltd. (Company No. [123467898803]), a company incorporated in British Virgin Islands with its registered address at Commerce House, Wickhams Cay 1, P.O. Box 3140, Road Town, Tortola, British Virgin Islands VG1110.
We are the data controller for personal data processed through our products. Where we act only as a data processor — for example, handling data on behalf of a merchant partner — the merchant's own privacy policy also applies.
We handle personal data in line with the Personal Data Protection Act 2010 (Malaysia) and its amendments, and, where applicable to you, the Singapore PDPA and the EU/UK GDPR.
2. WHAT THIS POLICY COVERS
This policy applies to:
- Our websites, including tgt.wtf and any subdomain or campaign page
- The Togethër mobile apps (iOS and Android) and the web app
- The Togethër merchant app, dashboard and partner tools
- Our AI assistant, chat, recommendation and itinerary features
- Community features: reviews, contributions, referrals, rewards and creator tools
- Wallet-linked features, $TGT token utility features, in-app redemptions and swap interfaces
- Our official channels on Telegram, X, Discord, Instagram and Facebook, to the extent we control them
What this policy does NOT cover:
Public blockchains, third-party wallets (such as Phantom or Solflare), decentralised exchanges, centralised exchanges, and any merchant, venue or partner you transact with. Those are run by other parties under their own terms and privacy practices. Read section 4 and section 16 carefully.
3. DATA WE COLLECT
3.1 Data you give us
Account — Name or display name, email, mobile number, password hash, profile photo, language, country. Collected at sign-up.
Profile and preferences — Interests, dietary needs, travel style, saved places, wishlists. Collected during ongoing use.
Content you post — Reviews, ratings, photos, tips, comments, and local knowledge you contribute to train our AI. Collected through community features.
Chat and support — Messages to our AI assistant, support tickets, attachments, call notes. Collected when you contact us.
Transactions — Bookings, orders, redemptions, receipts, refunds, points and reward balances. Collected on purchase.
Referrals — Referral codes used, who invited you, invites you send.
Verification — Government ID, selfie, proof of address, business registration. Collected only where legally required or for merchant onboarding.
3.2 Data collected automatically
- Device and technical: device model, OS version, app version, language, time zone, IP address, mobile network, crash logs, advertising identifier (where you allow it)
- Usage: screens viewed, features used, search terms, taps, session length, referring page, in-app performance data
- Approximate location derived from IP address
- Cookies and similar technologies — see section 8
3.3 Data from third parties
- Social or wallet sign-in providers (basic profile and the identifier they return)
- Payment processors and acquirers (payment status, last four digits, issuer country — we do not store full card numbers)
- Merchant and venue partners (booking confirmations, redemption status)
- Analytics, attribution, anti-fraud and blockchain analytics providers
- Public sources, including public blockchain data
3.4 Sensitive data
We do not ask for sensitive personal data such as health, religion, political views or biometric data, except where you volunteer it (for example, a dietary or accessibility preference) or where identity verification legally requires it. Please do not send us sensitive data you don't need us to have.
4. BLOCKCHAIN, WALLET AND SWAP DATA
4.1 We are non-custodial
When you connect a self-custody wallet, we receive your public wallet address and can read publicly available on-chain information associated with it. We never ask for, receive, or store your private key, seed phrase or recovery phrase. No Togethër employee, agent or support channel will ever request them. Anyone who does is attempting fraud.
4.2 On-chain data is public and permanent
Transactions involving $TGT or any other digital asset are recorded on a public, decentralised blockchain operated by an independent network — not by us. This means:
- Transaction details, wallet addresses, amounts and timestamps are visible to anyone, permanently
- Blockchain records are immutable. We cannot edit, anonymise, or delete them, and no right of erasure, correction or restriction can be exercised against them
- Third parties may be able to link a wallet address to a real person using publicly available analysis tools
If on-chain visibility is a concern for you, do not connect a wallet that you have linked to your identity elsewhere.
4.3 Swaps and token interfaces
Where our products display a swap, bridge or exchange interface, that function is provided by third-party protocols, liquidity venues or exchanges. We may show you routing and pricing information, but we do not execute, custody, guarantee or reverse those transactions. Your interaction is directly with the relevant protocol or exchange and is governed by their terms and privacy policies.
4.4 Token positioning
$TGT is a utility token used to unlock membership, features and redemptions within the Togethër ecosystem. Nothing in this policy is an offer, solicitation, or recommendation to acquire any digital asset, and nothing here constitutes financial, investment, tax or legal advice.
5. AI CHAT AND ASSISTANT FEATURES
- We store your prompts, our responses, and related context so the assistant has continuity and so we can debug and improve it.
- Conversations may be reviewed by a limited number of authorised staff and by automated systems for safety, abuse prevention and quality.
- We may use conversation data — de-identified or aggregated wherever practicable — to improve our models and recommendations. Where local law requires consent for this, we will ask for it and you can withdraw it.
- Some features rely on third-party AI providers. Content you submit may be transmitted to them for processing under contractual confidentiality and security terms.
- Do not enter passwords, seed phrases, private keys, full card numbers, ID numbers or other people's personal data into chat.
- AI output can be wrong. Do not rely on it for financial, legal, medical or safety-critical decisions.
6. LOCATION DATA
Nearby recommendations, routing and check-in features work better with location. We collect:
- Approximate location from your IP address, for language, currency, availability and security
- Precise location from GPS, Wi-Fi or Bluetooth signals, only with your permission
You can withdraw location permission at any time in your device settings. Some features will stop working when you do. We do not sell location data.
7. WHY WE USE YOUR DATA
Create and manage your account; deliver the features you ask for — Performance of contract
Process bookings, payments, redemptions, rewards and referrals — Performance of contract
Personalise recommendations, itineraries and content — Legitimate interests / consent
Operate community rewards and creator payouts — Performance of contract
Fraud prevention, abuse detection, wallet and account security — Legitimate interests / legal obligation
Customer support and dispute resolution — Performance of contract
Product analytics, testing, debugging and improvement — Legitimate interests
Marketing, newsletters and campaign messages — Consent (withdrawable any time)
Regulatory, tax, accounting and law-enforcement obligations — Legal obligation
We do not sell your personal data.
8. COOKIES AND TRACKING
Strictly necessary — Login, session, security, load balancing. Always on.
Preference — Language, currency, saved settings. Optional.
Analytics — Usage measurement and performance. Optional.
Marketing and attribution — Campaign measurement, referral tracking. Optional.
Manage your choices through our cookie banner, your browser settings, or your device's advertising-identifier controls. We honour Global Privacy Control signals where they apply.
9. WHO WE SHARE DATA WITH
- Merchants, venues and partners — only what is needed to fulfil your booking, order or redemption
- Payment processors and financial institutions — to take payment and process refunds
- Cloud, hosting, storage and CDN providers
- Analytics, attribution, crash-reporting and communications providers
- AI and machine-learning service providers, for the features in section 5
- Blockchain analytics, compliance and anti-fraud providers
- Exchanges and listing partners, where you use a service that requires it
- Professional advisers — lawyers, auditors, accountants — under confidentiality
- Regulators, courts and law enforcement, where legally compelled or to protect rights and safety
- An acquirer or successor in a merger, acquisition, financing or asset sale, subject to this policy
All service providers act on our instructions under written agreements. Public content you post — reviews, photos, contributions, public profile — is visible to other users and may be indexed by search engines.
10. CROSS-BORDER TRANSFERS
We operate across ASEAN and use global infrastructure, so your data may be stored or processed outside your country. Where we transfer personal data across borders, we rely on adequacy findings, standard contractual clauses, or other lawful transfer mechanisms, and we require comparable protection from recipients.
11. HOW LONG WE KEEP DATA
Account and profile — While active, then up to 24 months after closure
Transaction and tax records — 7 years, as required by law
Chat and support records — Up to 24 months
Marketing consent records — 3 years after withdrawal
Server and security logs — Up to 12 months
On-chain records — Permanent, outside our control
After these periods we delete or irreversibly anonymise the data.
12. YOUR RIGHTS
- Access a copy of the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data, where no legal obligation requires us to keep it
- Withdraw consent, including for marketing and location, at any time
- Limit processing or object to processing based on legitimate interests
- Portability — receive your data in a structured, machine-readable format
- Complain to your data protection authority. In Malaysia this is the Personal Data Protection Department (JPDP)
Email privacy@tgt.wtf to exercise any right. We respond within 30 days and may ask you to verify your identity first. Requests are free unless they are repetitive or excessive.
Limit: these rights cannot be applied to blockchain records — see section 4.2.
13. SECURITY
- Encryption in transit (TLS) and at rest for sensitive stores
- Role-based access control and least-privilege internal access
- Hashed passwords, optional two-factor authentication
- Logging, monitoring and periodic security review of our code and infrastructure
- Vendor due diligence and contractual security obligations
You are responsible for keeping your password, device and wallet credentials secure. Losing a seed phrase means losing access to your assets permanently — we cannot recover it.
14. DATA BREACHES
If a personal data breach occurs that is likely to cause significant harm, we will notify the relevant data protection authority within the timeframe required by law — 72 hours under the Malaysian PDPA and the GDPR — and notify affected users without undue delay, together with the steps you should take.
15. CHILDREN
Togethër is intended for users aged 18 and above. We do not knowingly collect data from children. If we learn that a minor has created an account, we will close it and delete the associated data. Parents or guardians who believe a child has provided us data should contact privacy@tgt.wtf.
16. THIRD-PARTY SERVICES AND LINKS
Our products link to and integrate with services we do not control, including wallets, decentralised and centralised exchanges, blockchain explorers, payment providers, map providers, merchant sites and social platforms. We are not responsible for their content, security or privacy practices. Review their policies before using them.
17. CHANGES TO THIS POLICY
We may update this policy as our products, partners or legal obligations change. The "Last updated" date at the top always reflects the current version. For material changes we will give notice in-app, by email, or through our official channels before the change takes effect. Continued use after that date means you accept the updated policy.
18. CONTACT US
Entity: Together Inc. (BVI) Ltd.
Privacy: privacy@tgt.wtf
Data Protection Officer: Pepper Romanoff — dpo@tgt.wtf
Support: support@tgt.wtf
Registered address: Commerce House, Wickhams Cay 1, P.O. Box 3140, Road Town, Tortola, British Virgin Islands VG1110.
Website: tgt.wtf
© 2026 Togethër. All rights reserved.
