Privacy Policy
This Privacy Policy describes how KiwiDock collects, uses, and shares information in connection with the beta Service at kiwidock.com. It is written for beta transparency and should be reviewed by counsel before relying on it for production or regulated use.
1. Who we are
“KiwiDock,” “we,” “us,” and “our” refer to the operator of the Service. Contact for privacy requests: derek@kiwidock.com. We do not publish a separate registered agent street address in this beta policy; email is the designated contact channel.
2. Scope
This policy covers:
- Account and platform data — information about tenant owners, invited users, billing contacts, and site visitors on kiwidock.com
- Customer Data — CRM and business records tenants store in the Service (leads, customers, quotes, projects, files, etc.)
When a tenant uses KiwiDock to process their own customers’ or leads’ personal data, that tenant is typically the controller of that Customer Data. We act as a processor/service provider for Customer Data, processing it on the tenant’s instructions to provide the Service.
3. Information we collect
Account and usage
- Name, email, shop/company name, subdomain, password (hashed), and authentication factors (for example email codes or passkeys)
- Plan, billing-related identifiers, and payment status when you subscribe (payment card details are handled by the payment processor, not stored by us as full card numbers)
- Device/browser technical data, IP address, timestamps, and diagnostic/security logs needed to operate and secure the Service
- Content you submit through feedback or support channels
Customer Data (tenant-controlled)
- Business records tenants choose to enter or import (contacts, opportunities, documents, uploads, form submissions, and similar)
- Public form and customer-upload submissions directed to a tenant’s workspace
We do not intentionally collect
Special categories of data beyond what tenants choose to store. Please do not submit sensitive personal data unless necessary for your business process and lawfully permitted.
4. How we use information
- Provide, maintain, secure, and improve the Service
- Create and administer tenant accounts, roles, and authentication
- Process subscriptions and communicate about the Service (including beta notices and security messages)
- Prevent abuse, debug issues, and comply with law
- Process Customer Data solely to deliver the Service to the relevant tenant
We do not sell personal information.
5. How we share information
We share information only as needed to run the Service, including with:
- Hosting and infrastructure — for example DigitalOcean (application hosting and managed database) and object storage used for file attachments
- Email delivery — providers used to send transactional mail (signup, invites, password resets, document emails)
- Payment processors — Stripe (and/or similar) when platform billing or tenant payment features are enabled; Square when a tenant connects it
- Professional advisors or authorities — when required by law or to protect rights and safety
Subprocessors may change as the stack evolves; material changes will be reflected in updates to this policy or related notices. Tenant Customer Data is isolated by design; we do not use one tenant’s Customer Data to market to another tenant’s customers.
6. Cookies and similar technologies
We use essential cookies required for the Service to function — for example authentication/session cookies, antiforgery tokens, and user preference cookies (such as appearance/theme). We do not currently set third-party advertising or analytics cookies on the marketing site or app. Because we only use essential cookies, we do not show a separate cookie consent banner. If we later add non-essential analytics or marketing cookies, we will update this policy and provide an appropriate notice or choice.
7. Retention
We retain account and operational data for as long as your tenant is active and as needed for security, billing, and legal obligations. After account closure or tenant deletion, we delete or anonymize personal data within a reasonable period, except where we must retain it (for example backups, dispute resolution, or legal holds). Tenants control retention of Customer Data they store; deleted records may persist briefly in backups.
8. Security
We use administrative, technical, and organizational measures appropriate to a beta SaaS product (including tenant isolation, encrypted transport, and access controls). No method of transmission or storage is 100% secure; please use strong passwords and protect your credentials.
9. International transfers
The Service is operated with infrastructure that may be located in the United States. If you access the Service from elsewhere, you understand your information may be processed in the U.S. or other locations where our providers operate.
10. Your choices and rights
- Update profile and account settings in the app where available
- Request access, correction, or deletion of personal data we hold about you as an account holder by emailing derek@kiwidock.com
- If you are an end customer of a tenant, contact that tenant first — they control Customer Data in their workspace
Depending on where you live, you may have additional rights under applicable privacy laws. We will respond to verifiable requests as required by law.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children.
12. Changes
We may update this Privacy Policy. The “Last updated” date above will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.
13. Contact
Privacy questions: derek@kiwidock.com. Related: Terms of Service.