Privacy

Notice at Collection

What we collect, why, how long we keep it, and whether we sell it. Given at the point of collection, as California requires.

01What we collect, and why

This is the short version, given at the point we ask for anything. The full Privacy Policy says the same things at greater length and adds the parts that do not belong on a notice this size.

CategoryWhat that means hereWhyHow long
A. IdentifiersName, work email address, company name, and the industry you pick on the form.Creating and running your account, signing you in, and answering you. For the waitlist: telling you when access opens.For the life of the account. Waitlist entries are deleted after 180 days.
B. Customer records (Cal. Civ. Code §1798.80)Billing contact details and the last four digits and brand of a payment card.Taking payment and issuing invoices.Kept for as long as tax and accounting law requires, which outlives the account.
F. Internet or network activityServer logs: the request path, the response status, how long it took, a request id, and the tenant it belonged to. Error reports carry a stack trace.Keeping the service up, finding faults, and investigating abuse. A business purpose under §1798.140(e).Log retention is set by the host. Error reports age out on the tracker's schedule.
A. Identifiers (attribution)The `ref` or `utm_source` on the link you arrived through, if there was one.Knowing which post or page actually brought people in. First-party only — it is never sent anywhere.Deleted with the waitlist entry, at 180 days.
A. Identifiers · C. Protected characteristics you volunteerWhatever you put in the contact form or an email to us: your name, email address, company, and the message itself.Answering you. The contact form is not stored in the database — it is delivered to our inbox, where it lives as long as the correspondence does.As long as the conversation is live, and our mail archive after that. Ask us and we will delete it.
A. Identifiers (privacy requests)The name, email, region and relationship you give when you make a privacy request, what you asked for, and the browser user-agent the request arrived with.Finding you, verifying you are who you say, answering the request, and being able to show a regulator that we did. The user-agent is kept because an abusive pattern is only visible across submissions.Kept after the request is answered. A request to be forgotten is itself the evidence we honoured it, and deleting the record would destroy the only proof that we did.
K. InferencesNone.We do not build profiles, score you, or infer characteristics, preferences or behaviour about any individual.—

The categories are the ones the CCPA names in §1798.140(v)(1). Where a category is listed as none, it is none — we have not left it out because it was inconvenient.

02Sensitive personal information

We do not collect sensitive personal information as the CPRA defines it — no government identifiers, no precise geolocation, no racial or ethnic origin, no religious beliefs, no union membership, no genetic or biometric data, no health data, and no contents of your mail, email or texts.

Your account password is a credential. It is stored only as a one-way hash, is used only to sign you in, and is never sold, shared, disclosed, or used to infer anything about you — which is the limited use the statute permits without a separate right to limit.

03Do we sell or share it?

No. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done either. There is no advertising pixel, analytics script or tag manager anywhere in this product — the only cookie it sets is the one that keeps you signed in.

We do not knowingly collect personal information from anyone under 16, and we have never sold or shared the personal information of a consumer we knew to be under 16.

The opt-out control exists anyway, and we honour the Global Privacy Control signal — Your Privacy Choices. A control that already exists is one nobody has to remember to build later.

04What you can ask for

  • To know what we hold about you, and get a copy.
  • To have it corrected, or deleted.
  • To opt out of sale or sharing, and to limit the use of sensitive information.
  • To object, to restrict, to take a portable copy, or to withdraw consent.
  • To be treated no differently for asking.

Ask through the privacy request form, or email support@kinetel.io. We aim to answer inside 30 days for everyone, whichever regime applies.

Effective 30 September 2026. The longer version is the Privacy Policy; your controls are at Your Privacy Choices.

Something here unclear, or does not cover your situation? Ask us — a policy you have to guess at is not doing its job.