Privacy Policy

What we hold, who can see it, and how to get it back.

Written so that every sentence can be checked against what the software actually does. If any of it turns out not to be true, that is a bug and we want to hear about it.

01Who this covers

This policy covers Kinetel and the Kinetel service. It took effect on 10 August 2026.

There are two kinds of people in it, and the distinction matters. You are our customer — you have an account. Your customers are the people whose orders and delivery addresses you put into the product. For their data we are a processor acting on your instructions: you decide what goes in and what comes out, and we handle it for you.

02What we hold

Three categories, and nothing outside them.

Your account. Names and email addresses of your team, hashed passwords, roles, your company name and industry, and your billing contact. We never see your password, and card numbers go to Stripe directly without touching our servers.

Your warehouse. Everything you put in: products, costs, inventory, lots and expiry dates, purchase orders, vendors, orders, and your customers' names and delivery addresses. Photographs you upload for shipment verification.

How the service is used. An audit trail of who did what and when, error reports when something breaks, and request logs. These carry identifiers and actions rather than the contents of your inventory.

We do not use tracking cookies or third-party advertising or analytics on the product. The only cookie the application sets is the one that keeps you logged in.

03Why we hold it

  • To run the service you are paying for — that is what almost all of it is for.
  • To bill you, and to keep the invoice records that tax law requires.
  • To send you the mail the service needs to send: verification, password resets, low-stock alerts, payment failures.
  • To keep the service secure and working — rate limiting, audit trails, error alerting.
  • To answer you when you get in touch.

We do not sell your data. We do not share it for anyone else's marketing. We do not build a profile of you for advertising, and there is nowhere in the product where that would even be useful.

04The AI features, specifically

This is the question people ask first, so it gets its own section rather than a clause buried in the one above. Text and photographs are handled differently, so it is worth taking them in turn.

Text goes to a commercial AI provider. When you paste an order, match a product name, ask the copilot a question or generate a forecast narrative, the text of that request is sent to our AI provider over their commercial API — along with the catalogue rows needed to answer it, and nothing else. We hold a commercial agreement with terms that prohibit training on our traffic and provide no retention beyond answering the request. It is not a consumer chat service, where the data terms are entirely different.

Photographs are checked here first. When a packer photographs a box, the barcode reading, the label text and the image-quality scoring all run on a computer-vision service hosted alongside your warehouse data. None of that leaves, and it settles the large majority of parcels — a clean barcode read never goes anywhere.

Only a frame those checks cannot decide is escalated to our AI provider's vision model, under the same zero-retention terms as the text above. That escalation is deliberate and infrequent: it is the exception the deterministic checks could not resolve, not the routine path.

In no case is your data used to train a model — not ours, and not the provider's. It is not shared between tenants, and no model has a connection to your database or the ability to browse it.

A warehouse can require the photograph without the checking. Some do: the picture is what answers a customer who says the box arrived empty, and that works whether or not anything analysed it. Where a warehouse has switched the automated checking off, the photograph is stored and nothing reads it — no computer-vision service, no AI provider, no model of any kind. It is kept, and deleted, on exactly the same terms as the paragraph below.

A warehouse can choose to send a packing photograph to the supplier whose goods are in the box. It is off unless they switch it on, per supplier, and it is narrow when they do: the photograph goes only with orders assigned to that supplier, never with an order that mixes several, because the picture is of the open box and would otherwise show one supplier another's products alongside the customer's label. The image is resized for email and stripped of its camera metadata, including the location a phone records, before it leaves. This is the warehouse's decision about its own evidence and its own supply chain; we do not send these anywhere on our own account, and switching it off stops it from the next night.

Photographs are deleted after 30 days by default. A scheduled sweep removes the image itself — escalated or not — while the evidence drawn from it stays with the order: the barcodes read, the label text, the verdict, and any override a supervisor made. So an old decision remains reviewable, and the picture of somebody's parcel does not sit on a disk indefinitely.

The warehouse can set that window itself, between 7 and 365 days, because a business that has to answer a payment dispute months later needs longer than one that does not. Thirty days is what applies unless they change it, and the ceiling is deliberate: a warehouse wanting these images for years should be keeping its own copy rather than making us the long-term custodian of its customers' doorsteps.

The results — a parsed draft, a forecast, a verification verdict — are stored in your account like any other record, so you can review them later and see what was decided.

05Who else can see it

These are the services we rely on to run Kinetel. Everything marked optional only applies if you choose to connect it.

ServiceWhat forWhat it can see
Venice AIEvery AI feature: reading a pasted order into line items, matching a written product name to a SKU, answering questions about your own data, and the visual check on a packed box when the barcode and label cannot settle it.The text of the specific request — an order email you paste, one product name being matched, one question you ask, and the catalogue rows needed to answer it — and, on an escalated fulfilment check, the photograph of the packed parcel. Venice states zero retention of request contents and does not train on them; that commitment is the reason they are the provider rather than a cheaper one.
StripeSubscription billing and payment processing.Billing contact and payment details. Card numbers go to Stripe directly and never reach our servers.
Email delivery providerAccount, alert and billing email.Recipient address and the contents of the message being sent — a verification link, a low-stock alert, an invoice notice.
Hosting and databaseRunning the application and storing your data.Everything you put into the product. Hosted on infrastructure we operate.
Sentry (or a compatible error tracker)Only if you connect itAlerting us that something broke.Error messages, stack traces and the tenant an error happened in. Not your inventory or order contents.
ShopifyOnly if you connect itSyncing orders and products from your store.Orders, products and inventory levels for the store you connect.
Amazon Selling Partner APIOnly if you connect itSyncing orders and products from your Amazon account.Orders, products and inventory levels for the account you connect.
WooCommerce storeOnly if you connect itSyncing orders and products from your store.Orders, products and inventory levels for the store you connect.
EasyPostOnly if you connect itCarrier rates, label purchase and tracking.Delivery addresses and parcel details for the shipments you create, passed on to the carrier you choose.
Shipping carriersOnly if you connect itCarrying the parcel, and the tracking it generates.Delivery addresses and parcel details for the shipments you create.
SlackOnly if you connect itDelivering event notifications to a channel, when you configure a Slack rule.A one-line summary of the event, which for order events includes the customer name and order number.

We will update this list before adding anyone new to it. If you want to be told when that happens, ask and we will add you to the notice.

06How long we keep it

The short version: we do not delete your warehouse because you stopped paying, and we do delete it when you ask.

While your account is active
We keep your data for as long as you have an account, because it is the record of your warehouse and deleting it on a schedule would be deleting your books.
After a trial ends without a subscription
Nothing is deleted. The account goes read-only and you can still read and export everything. We hold it for at least 90 days so you have time to decide or to get your data out.
After you cancel
Same: read-only, exportable, retained for at least 90 days. Ask us to delete it sooner and we will.
When you ask us to delete
We remove the tenant and everything belonging to it — products, inventory, orders, customers, users and audit history — within 30 days. Encrypted backups age out on their own cycle within 90 days.
Fulfilment photographs
Deleted 30 days after they are taken, by a nightly sweep. Only the picture goes — the barcodes read from it, the label text, the verdict and any override stay with the order, because those are the audit trail and the photograph is not. Nobody reviews a frame from three months ago; keeping one forever was a cost with no benefit.
Order drafts, and the text they were parsed from
A draft you rejected is deleted 30 days later; an approved one 90 days after it was created. This matters more than it sounds: a draft holds the first few thousand characters of whatever was pasted in, which for an emailed order is the customer's own message — their signature, their phone number, whatever else they wrote. The order that came out of it is the record worth keeping; the email is not.
Webhook deliveries
The body of each event sent to your endpoints is kept for 30 days after it settles, then deleted. Long enough to answer “we never received that one”, short enough that we are not the long-term custodian of your order contents in a second place. Deliveries still being retried are never swept, however old.
Waitlist sign-ups
Deleted after 180 days if they never became an account. Somebody who gave us an address once and then went quiet should not be on our disk indefinitely.
Billing records
Invoices and payment records are kept for as long as tax and accounting law requires, which is longer than the rest. That is the one category we cannot delete on request.

07Your customers' data

Your customers' data is yours, and the requests about it come to you. For the data you put into Kinetel about your own customers, you are the controller and we are the processor: you decide what is collected and why, and we hold and process it on your instructions. If one of your customers asks what you hold about them, or asks you to erase it, the request is yours to answer — and the product gives you the means to. Every customer record can be exported in full, with their order history, as a single file you can send them; and any customer can be erased, which removes their name, email, phone and street address from their record and from the shipping details of every order they placed, while leaving the order, its contents and its lot history intact so your traceability and your books still work. Both actions are recorded in your audit log.

08What you can ask us for

Depending on where you are, you may have rights under the GDPR, the UK GDPR, the CCPA or similar law. We apply the following to everyone rather than checking your postcode first.

  • Get a copy. Every table is exportable as CSV and through the REST API, on every plan, without asking us. If you want it in another form, ask.
  • Correct it. Nearly everything is editable in the product. Anything that is not, we will change for you.
  • Delete it. Ask and we will remove your tenant and everything in it within 30 days, apart from billing records we are required to keep.
  • Object or restrict. Tell us what you object to and we will either stop or explain why we cannot.
  • Complain. To us first, please — but you can go to your data protection authority, and we will not hold it against you.

Write to support@kinetel.io and we will answer within 30 days. If you are asking about data belonging to your customers, come to us and we will help you action it.

09How it is protected

Tenant isolation is enforced in the code and checked by the test suite. Connected store credentials are encrypted at rest. Passwords are hashed. Roles limit what each person can do, and privileged actions are checked on the server. Backups are restored on a drill rather than assumed to work.

The detail is on the security page, written for the person filling in a vendor questionnaire.

If there is ever a breach affecting your data, we will tell you what happened, what was affected and what we did — without waiting to have a comfortable version of the story.

10Where it lives

Your data is stored on infrastructure we operate. Some of the services in the table above — payment processing, email delivery — may process data in other countries. Where that happens we rely on the standard contractual protections those providers offer.

If you have a requirement that your data stay in a particular jurisdiction, tell us before you sign up rather than after.

11Changes to this policy

If we change anything that materially affects you, we will email you before it takes effect. Minor corrections get a new effective date at the top. We will not quietly edit this page and hope nobody notices, because the only value a policy has is that it can be relied on.

Something here unclear, or does not cover your situation? Ask us — a policy you have to guess at is not doing its job.