Back

Privacy

Kusini coordinates guest transfers between charter carriers and remote camps. Doing that means holding some information about people who never signed up to it themselves: a guest whose name is on a movement, a driver whose number is on a roster. This page says what is held, why it cannot be dropped, and how long it stays.

What is held, and why

What is not held

No payment details, no passport or identity document numbers, no location history, and no record of a guest beyond the transfer they are on. Kusini is not a booking system and does not receive what one holds.

Who can see it

A carrier sees its own day and nothing of another carrier's. A camp sees the movements coming to it. Every query and every write goes through that check on the server, not in the browser, so guessing an address does not get anybody past it.

A board can be put on a screen in a room using a link that carries an unguessable token. That board shows times, strips, camps and aircraft, and never a phone number or a note. Whoever holds the link can read that day, so the link is a password: it is made from the desk and can be replaced at any time, which stops the old one at once.

Analytics

Where product analytics is switched on, all text is masked and session replay is off. A movement carries a guest's surname and a camp's phone number, and neither belongs in an analytics product.

Where it is kept

In a managed database run by Convex, and behind a sign-in run by Clerk. Neither Kusini nor either of them sells this data, and it is not shared with advertisers or data brokers.

Asking for a copy, or a deletion

Write to dev.kusini@gmail.com and say which camp or carrier the request concerns. Kusini holds this data on behalf of the carrier or camp that entered it, so a request is answered together with them.

Changes

If what is held changes, this page changes with it and the date at the top moves. It is not rewritten quietly.