1. Scope and roles
This Privacy Policy applies to personal information processed by Kite Systems, Inc. through our websites, waitlist, accounts, dashboard, APIs, SDKs, CLI, cloud platform, support, and related services (the "Services"). It does not apply to third-party services governed by their own policies or to employee and applicant information.
Kite acts as a controller or business for account, billing, website, marketing, and business-contact information. Kite generally acts as a processor or service provider for Customer Data submitted to the Services by a customer. Our processing of Customer Data is governed by our agreement with that customer, including any data processing addendum. If you interact with a Kite customer and have questions about data it sent to Kite, contact that customer first.
2. Information we collect
- Account and profile data: name, email, profile image, organization, role, authentication method, verification status, and account preferences.
- Authentication and security data: encrypted credentials, session and access tokens, IP address, browser or device information, two-factor settings, security events, and audit records.
- Billing data: plan, subscription status, transaction and invoice details, usage, and payment-provider identifiers. Payment card details are collected and processed by our payment provider, not stored directly by Kite.
- Customer Data: product events, customer or user identifiers, traits, account attributes, configuration, lifecycle states, segments, journeys, health scores, logs, webhook data, and other content a customer chooses to submit.
- Usage and technical data: pages viewed, clicks, referring URLs, timestamps, API activity, feature usage, diagnostics, performance, errors, device type, operating system, browser, and approximate location inferred from IP address.
- Integration data: identifiers, permissions, tokens, installation details, repositories, projects, or events made available when you connect services such as GitHub or PostHog.
- Communications: support requests, feedback, survey responses, waitlist name and email, and correspondence with us.
Please do not submit sensitive personal information unless it is necessary, expressly supported by the Services, and covered by an appropriate written agreement with Kite.
3. Sources of information
We collect information:
- directly from you when you register, join the waitlist, pay, or contact us;
- from your employer, organization administrator, or another authorized user;
- automatically from your browser, device, and use of the Services;
- from customers that submit Customer Data through our APIs and integrations;
- from services you connect or use to sign in, including Google, GitHub, and PostHog, according to your settings and permissions; and
- from service providers, security partners, payment providers, and public sources.
4. How we use information
- provide, operate, configure, maintain, and improve the Services;
- create accounts, authenticate users, and manage organizations and permissions;
- process events and Customer Data according to customer instructions;
- process payments, subscriptions, usage limits, refunds, and invoices;
- provide support and send service, security, billing, and administrative messages;
- send product updates or marketing communications where permitted;
- measure performance, understand usage, and develop features;
- detect, investigate, and prevent fraud, abuse, security incidents, and illegal activity;
- enforce agreements, protect rights and safety, and resolve disputes; and
- comply with law, legal process, and regulatory obligations.
We may use aggregated or de-identified information that cannot reasonably identify an individual for analytics, security, research, and product improvement. We do not attempt to re-identify data maintained in de-identified form.
5. Legal bases
Where the GDPR, UK GDPR, or similar law applies, we process personal information as necessary to perform a contract or take requested pre-contract steps; pursue legitimate interests such as operating, securing, supporting, and improving our business; comply with legal obligations; and, where required, based on consent. You may withdraw consent at any time without affecting earlier processing. We balance legitimate interests against your rights and do not rely on them where your interests override ours.
6. How we disclose information
We may disclose information to:
- cloud hosting, database, analytics, communications, customer support, security, error monitoring, and other vendors that process data for us;
- payment providers such as Stripe, email providers such as Resend, analytics and hosting providers such as Google and Vercel, security providers such as Cloudflare and Sentry, and AI infrastructure providers such as Microsoft Azure;
- your organization, its administrators, and users authorized to access shared data;
- third-party integrations you choose to enable, according to your instructions;
- professional advisers, auditors, insurers, and financing counterparties subject to appropriate confidentiality obligations;
- authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate wrongdoing, or enforce our agreements; and
- a buyer, investor, successor, or adviser in connection with a merger, financing, reorganization, sale, or similar corporate transaction.
We do not sell personal information for money. We do not knowingly sell or share personal information for cross-context behavioral advertising. We may disclose data when you direct us to or consent to the disclosure.
7. Cookies and analytics
We and our providers use cookies, local storage, pixels, and similar technologies to keep you signed in, remember preferences, protect the Services, measure traffic, and understand use. Our website uses Google Analytics and Vercel Analytics, which may collect device, interaction, and approximate location information. Authentication, fraud prevention, and load-balancing technologies may be necessary for the Services to function.
You can control cookies through browser settings and available consent controls. Blocking necessary technologies may prevent features from working. Some browsers send Do Not Track signals, but there is no uniform response standard. Where legally required and technically supported, we honor applicable opt-out preference signals such as the Global Privacy Control for the browser or device sending the signal.
8. Customer Data
Customers determine what Customer Data they submit and why it is processed. Kite processes that data to provide the Services, secure them, comply with documented customer instructions, and meet legal obligations. Customers are responsible for providing required notices, establishing a lawful basis, respecting end-user choices, and avoiding unnecessary or prohibited data. We do not use Customer Data for our own advertising. A customer may request a data processing addendum where required.
If you seek access, deletion, correction, or another right concerning information a Kite customer submitted, contact that customer. If we receive your request directly, we may refer it to the customer and assist them as required by contract and law.
9. AI features
When you use an AI feature, we may process prompts, selected Customer Data, context, and generated outputs to provide and secure that feature. This information may be sent to our AI infrastructure providers. Unless we clearly disclose otherwise and obtain any required authorization, Kite does not use Customer Data to train third-party foundation models. Do not include sensitive or unnecessary personal information in prompts.
10. Data retention
We retain personal information only as long as reasonably necessary for the purposes described here, including to provide the Services, maintain security and backups, comply with tax, accounting, and legal obligations, enforce agreements, and resolve disputes. Retention depends on the type and sensitivity of data, customer configuration, plan, contractual commitments, legal requirements, and risk. Customer Data is retained according to the customer's plan and instructions and is deleted or returned after termination as provided in the applicable agreement, subject to backups and legal holds.
11. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authentication, encryption where appropriate, monitoring, and incident response practices. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. You are responsible for protecting credentials, managing permissions, and promptly reporting suspected compromise to us.
12. International transfers
Kite and its providers may process information in the United States and other countries that may have different data-protection laws. Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK Addendum, or another lawful mechanism. Contact us to request information about applicable transfer safeguards.
13. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- know whether we process your personal information and access or receive a copy;
- correct inaccurate information;
- delete information;
- restrict or object to processing;
- receive portable information you provided to us;
- withdraw consent and opt out of marketing;
- opt out of sale, sharing, or certain profiling where applicable;
- appeal our decision on a request; and
- complain to your local data-protection authority.
Submit a request to support@usekite.cloud. Describe your request and the Kite service involved. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted, but we may require proof of authorization and direct identity confirmation. We will not discriminate against you for exercising a privacy right.
14. Regional disclosures
United States
In the preceding 12 months, we may have collected the categories described above: identifiers; customer records; commercial and transaction information; internet or electronic activity; approximate geolocation; professional or employment-related information; authentication data; and inferences generated to provide customer-success features. We collect them from the sources and for the purposes described in Sections 3 and 4, and disclose them to the recipients in Section 6. We do not knowingly collect sensitive personal information for purposes of inferring characteristics about a person. We do not knowingly sell or share personal information of anyone under 16.
EEA, United Kingdom, and Switzerland
Kite Systems, Inc. is the responsible controller for information covered by this Policy unless we process Customer Data on behalf of a customer. You may contact your national supervisory authority, but we encourage you to contact us first so we can address your concern.
Other regions
Residents of Brazil, Canada, and other jurisdictions may exercise applicable access, correction, deletion, portability, objection, consent, and complaint rights by contacting us. We will respond according to the law that applies to your request.
15. Communications
We may send transactional messages needed to operate your account, including security, billing, support, and service notices. You cannot opt out of essential messages while maintaining an account. You may unsubscribe from marketing emails using the link in the message or by contacting us. We may retain a limited suppression record to honor your choice.
16. Children
The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child provided information to us, contact us so we can investigate and delete it where required.
17. Third-party services
The Services may contain links to or integrate with third-party websites and products. Their privacy practices are governed by their own notices, and Kite is not responsible for them. Review those notices before authorizing an integration or providing information.
18. Changes to this Policy
We may update this Policy to reflect changes in our Services, practices, or law. We will post the revised version and update the effective date. If changes are material, we will provide additional notice where required, such as by email or an in-product notice.
19. Contact us
For privacy questions, rights requests, or complaints, contact:
Kite Systems, Inc.Privacy Teamsupport@usekite.cloud