Privacy Policy
What we hold, who can see it, and how to get it back.
Written so that every sentence can be checked against what the software actually does. If any of it turns out not to be true, that is a bug and we want to hear about it.
01Who this covers
This policy covers Kinetel and the Kinetel service. It took effect on 10 August 2026.
There are two kinds of people in it, and the distinction matters. You are our customer — you have an account. Your customers are the people whose orders and delivery addresses you put into the product. For their data we are a processor acting on your instructions: you decide what goes in and what comes out, and we handle it for you.
02What we hold
Three categories, and nothing outside them.
Your account. Names and email addresses of your team, hashed passwords, roles, your company name and industry, and your billing contact. We never see your password, and card numbers go to Stripe directly without touching our servers.
Your warehouse. Everything you put in: products, costs, inventory, lots and expiry dates, purchase orders, vendors, orders, and your customers' names and delivery addresses. Photographs you upload for shipment verification.
How the service is used. An audit trail of who did what and when, error reports when something breaks, and request logs. These carry identifiers and actions rather than the contents of your inventory.
We do not use tracking cookies or third-party advertising or analytics on the product. The only cookie the application sets is the one that keeps you logged in.
03Why we hold it
- To run the service you are paying for — that is what almost all of it is for.
- To bill you, and to keep the invoice records that tax law requires.
- To send you the mail the service needs to send: verification, password resets, low-stock alerts, payment failures.
- To keep the service secure and working — rate limiting, audit trails, error alerting.
- To answer you when you get in touch.
We do not sell your data. We do not share it for anyone else's marketing. We do not build a profile of you for advertising, and there is nowhere in the product where that would even be useful.
04The AI features, specifically
This is the question people ask first, so it gets its own section rather than a clause buried in the one above. Text and photographs are handled differently, so it is worth taking them in turn.
Text goes to a commercial AI provider. When you paste an order, match a product name, ask the copilot a question or generate a forecast narrative, the text of that request is sent to our AI provider over their commercial API — along with the catalogue rows needed to answer it, and nothing else. We hold a commercial agreement with terms that prohibit training on our traffic and provide no retention beyond answering the request. It is not a consumer chat service, where the data terms are entirely different.
Photographs are checked here first. When a packer photographs a box, the barcode reading, the label text and the image-quality scoring all run on a computer-vision service hosted alongside your warehouse data. None of that leaves, and it settles the large majority of parcels — a clean barcode read never goes anywhere.
Only a frame those checks cannot decide is escalated to our AI provider's vision model, under the same zero-retention terms as the text above. That escalation is deliberate and infrequent: it is the exception the deterministic checks could not resolve, not the routine path.
In no case is your data used to train a model — not ours, and not the provider's. It is not shared between tenants, and no model has a connection to your database or the ability to browse it.
A warehouse can require the photograph without the checking. Some do: the picture is what answers a customer who says the box arrived empty, and that works whether or not anything analysed it. Where a warehouse has switched the automated checking off, the photograph is stored and nothing reads it — no computer-vision service, no AI provider, no model of any kind. It is kept, and deleted, on exactly the same terms as the paragraph below.
A warehouse can choose to send a packing photograph to the supplier whose goods are in the box. It is off unless they switch it on, per supplier, and it is narrow when they do: the photograph goes only with orders assigned to that supplier, never with an order that mixes several, because the picture is of the open box and would otherwise show one supplier another's products alongside the customer's label. The image is resized for email and stripped of its camera metadata, including the location a phone records, before it leaves. This is the warehouse's decision about its own evidence and its own supply chain; we do not send these anywhere on our own account, and switching it off stops it from the next night.
Photographs are deleted after 30 days by default. A scheduled sweep removes the image itself — escalated or not — while the evidence drawn from it stays with the order: the barcodes read, the label text, the verdict, and any override a supervisor made. So an old decision remains reviewable, and the picture of somebody's parcel does not sit on a disk indefinitely.
The warehouse can set that window itself, between 7 and 365 days, because a business that has to answer a payment dispute months later needs longer than one that does not. Thirty days is what applies unless they change it, and the ceiling is deliberate: a warehouse wanting these images for years should be keeping its own copy rather than making us the long-term custodian of its customers' doorsteps.
The results — a parsed draft, a forecast, a verification verdict — are stored in your account like any other record, so you can review them later and see what was decided.
05Who else can see it
These are the services we rely on to run Kinetel. Everything marked optional only applies if you choose to connect it.
| Service | What for | What it can see |
|---|---|---|
| Venice AI | Every AI feature: reading a pasted order into line items, matching a written product name to a SKU, answering questions about your own data, and the visual check on a packed box when the barcode and label cannot settle it. | The text of the specific request — an order email you paste, one product name being matched, one question you ask, and the catalogue rows needed to answer it — and, on an escalated fulfilment check, the photograph of the packed parcel. Venice states zero retention of request contents and does not train on them; that commitment is the reason they are the provider rather than a cheaper one. |
| Stripe | Subscription billing and payment processing. | Billing contact and payment details. Card numbers go to Stripe directly and never reach our servers. |
| Email delivery provider | Account, alert and billing email. | Recipient address and the contents of the message being sent — a verification link, a low-stock alert, an invoice notice. |
| Hosting and database | Running the application and storing your data. | Everything you put into the product. Hosted on infrastructure we operate. |
| Sentry (or a compatible error tracker)Only if you connect it | Alerting us that something broke. | Error messages, stack traces and the tenant an error happened in. Not your inventory or order contents. |
| ShopifyOnly if you connect it | Syncing orders and products from your store. | Orders, products and inventory levels for the store you connect. |
| Amazon Selling Partner APIOnly if you connect it | Syncing orders and products from your Amazon account. | Orders, products and inventory levels for the account you connect. |
| WooCommerce storeOnly if you connect it | Syncing orders and products from your store. | Orders, products and inventory levels for the store you connect. |
| EasyPostOnly if you connect it | Carrier rates, label purchase and tracking. | Delivery addresses and parcel details for the shipments you create, passed on to the carrier you choose. |
| Shipping carriersOnly if you connect it | Carrying the parcel, and the tracking it generates. | Delivery addresses and parcel details for the shipments you create. |
| SlackOnly if you connect it | Delivering event notifications to a channel, when you configure a Slack rule. | A one-line summary of the event, which for order events includes the customer name and order number. |
We will update this list before adding anyone new to it. If you want to be told when that happens, ask and we will add you to the notice.
06How long we keep it
The short version: we do not delete your warehouse because you stopped paying, and we do delete it when you ask.
- While your account is active
- We keep your data for as long as you have an account, because it is the record of your warehouse and deleting it on a schedule would be deleting your books.
- After a trial ends without a subscription
- Nothing is deleted. The account goes read-only and you can still read and export everything. We hold it for at least 90 days so you have time to decide or to get your data out.
- After you cancel
- Same: read-only, exportable, retained for at least 90 days. Ask us to delete it sooner and we will.
- When you ask us to delete
- We remove the tenant and everything belonging to it — products, inventory, orders, customers, users and audit history — within 30 days. Encrypted backups age out on their own cycle within 90 days.
- Fulfilment photographs
- Deleted 30 days after they are taken, by a nightly sweep. Only the picture goes — the barcodes read from it, the label text, the verdict and any override stay with the order, because those are the audit trail and the photograph is not. Nobody reviews a frame from three months ago; keeping one forever was a cost with no benefit.
- Order drafts, and the text they were parsed from
- A draft you rejected is deleted 30 days later; an approved one 90 days after it was created. This matters more than it sounds: a draft holds the first few thousand characters of whatever was pasted in, which for an emailed order is the customer's own message — their signature, their phone number, whatever else they wrote. The order that came out of it is the record worth keeping; the email is not.
- Webhook deliveries
- The body of each event sent to your endpoints is kept for 30 days after it settles, then deleted. Long enough to answer “we never received that one”, short enough that we are not the long-term custodian of your order contents in a second place. Deliveries still being retried are never swept, however old.
- Waitlist sign-ups
- Deleted after 180 days if they never became an account. Somebody who gave us an address once and then went quiet should not be on our disk indefinitely.
- Billing records
- Invoices and payment records are kept for as long as tax and accounting law requires, which is longer than the rest. That is the one category we cannot delete on request.
07Your customers' data
Your customers' data is yours, and the requests about it come to you. For the data you put into Kinetel about your own customers, you are the controller and we are the processor: you decide what is collected and why, and we hold and process it on your instructions. If one of your customers asks what you hold about them, or asks you to erase it, the request is yours to answer — and the product gives you the means to. Every customer record can be exported in full, with their order history, as a single file you can send them; and any customer can be erased, which removes their name, email, phone and street address from their record and from the shipping details of every order they placed, while leaving the order, its contents and its lot history intact so your traceability and your books still work. Both actions are recorded in your audit log.
08What you can ask us for
Depending on where you are, you may have rights under the GDPR, the UK GDPR, the CCPA or similar law. We apply the following to everyone rather than checking your postcode first.
- Get a copy. Every table is exportable as CSV and through the REST API, on every plan, without asking us. If you want it in another form, ask.
- Correct it. Nearly everything is editable in the product. Anything that is not, we will change for you.
- Delete it. Ask and we will remove your tenant and everything in it within 30 days, apart from billing records we are required to keep.
- Object or restrict. Tell us what you object to and we will either stop or explain why we cannot.
- Complain. To us first, please — but you can go to your data protection authority, and we will not hold it against you.
Write to support@kinetel.io and we will answer within 30 days. If you are asking about data belonging to your customers, come to us and we will help you action it.
09How it is protected
Tenant isolation is enforced in the code and checked by the test suite. Connected store credentials are encrypted at rest. Passwords are hashed. Roles limit what each person can do, and privileged actions are checked on the server. Backups are restored on a drill rather than assumed to work.
The detail is on the security page, written for the person filling in a vendor questionnaire.
If there is ever a breach affecting your data, we will tell you what happened, what was affected and what we did — without waiting to have a comfortable version of the story.
10Where it lives
Your data is stored on infrastructure we operate. Some of the services in the table above — payment processing, email delivery — may process data in other countries. Where that happens we rely on the standard contractual protections those providers offer.
If you have a requirement that your data stay in a particular jurisdiction, tell us before you sign up rather than after.
11Changes to this policy
If we change anything that materially affects you, we will email you before it takes effect. Minor corrections get a new effective date at the top. We will not quietly edit this page and hope nobody notices, because the only value a policy has is that it can be relied on.
Something here unclear, or does not cover your situation? Ask us — a policy you have to guess at is not doing its job.