Kabi

Privacy policy

Last updated: 29 September 2026

Kabi runs advertising screens in vehicles: Android tablets in taxis and ride-hailing cars, and Android smart TVs, managed from the Kabi dashboard at kabi.ylcnetwork.com. This policy covers the Kabi Android app installed on those screens and the Kabi dashboard. It says what is collected, why, for how long, and who else sees it.

Who we are

Kabi is published by YLC NETWORK FZC, a free zone company incorporated under the laws of the United Arab Emirates, with its registered office at Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, holding commercial licence no. 300641 issued by the Sharjah Publishing City Free Zone Authority. Kabi is one of the apps of the YLC suite.

Contact: support@ylcnetwork.com. It reaches a person.

Screens belong to fleet companies (taxi companies, ride-hailing operators, advertising agencies) that use Kabi. For the data of its screens, the fleet company decides what its screens show and where they run, and Kabi processes that data on its behalf. For dashboard accounts, YLC NETWORK FZC is responsible.

What the screen app collects

An installation identifier: a random identifier the app creates for itself on first launch. It is not your phone number, not a hardware serial number and not an advertising identifier.

A screen key: when a company admin types the activation code shown on the screen into the dashboard, the screen receives its own key, once. On the device the key is stored encrypted by the Android Keystore; our servers keep only a SHA-256 hash of it. The key can be revoked at any time from the dashboard.

Technical details sent with each request: the app version, whether the device is a tablet or a TV, and whether it is a managed kiosk device. We also record when the screen was last seen online.

Location, on tablets only: the app reads the device location with Android's own location service, only while the app is open on screen (foreground). It never asks for background location, and it never reads location on a TV. A point is recorded about every 30 seconds or every 100 metres, so that ads can be targeted to zones and so that the company can see where its screens are. The detailed track is kept for 30 days and then deleted automatically every night; what remains are hourly counts per zone, without coordinates. The last known position of each screen is shown on its card in the dashboard.

Proof of play: each time an ad is played, the screen records which ad, when it started, how long it played, the zone and the location point where it was played. These records are what advertisers are shown and billed on; they are kept with the company's statistics for as long as the company uses Kabi, and are counted into hourly totals.

The app does not use the camera: it takes no picture, records no video or sound, and sends none. It collects no data about passengers or drivers. It has no advertising identifier, no advertising or analytics SDK, and no Google services.

What the screen shows, and who that reaches

Ad videos and images are downloaded from our storage (Supabase) through short-lived signed links, and kept on the device so that the screen keeps playing without a network.

Weather: the screen asks our server for the weather, and our server asks Open-Meteo for a square of about 0.1° (roughly 10 km) around the screen. Open-Meteo never receives the identity of the screen.

News feeds chosen by the company are fetched by our server, not by the screen; only titles and dates are shown.

Link and mini-game tiles open web pages chosen by the company, inside the app. Those websites see the screen's IP address, as any website does. Everything they store is erased when the page is closed.

QR codes: a passenger may scan the QR code of an ad with their own phone. The scan passes through our server, which counts it with the ad, the time and the country given by our host, then redirects to the advertiser. The IP address is never stored: only a daily keyed hash of it is used to limit abuse, and it is deleted within one day.

Dashboard accounts

You sign in to the dashboard with your YLC account (account.ylcnetwork.com). Kabi receives your YLC account identifier, your verified email address and your name. Kabi has no password of its own.

Within a company we keep your role (admin, content manager, read-only), the invitations you send or receive (the invitee's email address; the invitation email is sent by Resend), and a log of sensitive actions (activating, revoking or transferring a screen, role changes, prices).

Content you upload: ad videos and images, advertiser names, company logos and colours, zones drawn on the map, tile settings.

Payments by fleet companies are made through Whop (Whop Inc., United States), the merchant of record, on its own page. Card details never reach us; we receive payment events (identifiers, amounts, status).

YLC members may run a campaign on an open fleet and pay with YLC credits. The credits are held by YLC, the same company; Kabi records the campaign, its budget and the credits reserved, used and returned.

The dashboard map is drawn with tiles from OpenFreeMap, loaded by your browser: OpenFreeMap sees your IP address and which area is shown.

When AI image generation is offered in the dashboard and you use it, the text of your request is sent to OpenAI (United States) to create the image. Your email address is never sent.

Service providers

Supabase hosts the database, file storage and sign-in, in the European Union (Paris). Vercel hosts and serves the dashboard and the API. Resend sends emails. Whop takes payments. Open-Meteo provides weather. OpenFreeMap provides map tiles. OpenAI creates images when that feature is used. Each processes data on our instruction and for no other purpose. We do not sell data, and we do not share it with third parties for their own advertising.

Security

All traffic between the app, the dashboard and our servers is encrypted in transit (HTTPS). Each company's data is isolated from every other company's by database rules. Screens never talk to the database directly: they call our API with their own key.

Your rights and deletion

You may ask to access, correct, delete or receive a copy of your data, or object to its use. A company admin can release or deactivate a screen at any time, which revokes its key. Uninstalling the app erases everything stored on the device.

To delete a dashboard account, a screen's data or a company's data, write to support@ylcnetwork.com. We answer within 30 days. For data processed on behalf of a fleet company, we may forward your request to that company.

You may also complain to the data protection authority where you live.

Audience

Kabi is a professional service for companies. The dashboard is not meant for anyone under 18.

Changes

When what Kabi collects changes, this page changes first, and its date with it.