Privacy

Make a privacy request

Ask what we hold, have it corrected or deleted, take a copy, object, or withdraw consent. One form, every right, no account needed.

01Make a request

This form is for requests about data we hold about you — a waitlist entry, an account, an email you sent us, a visit to this site. It takes about a minute and needs no account.

Use the address you think we hold. It is how we find you and how we reply.

Only affects which deadline we hold ourselves to. We honour every right below for everyone regardless.

What would you like us to do?

02What you can ask for, and where it comes from

One list rather than a Californian one and a European one. We honour all of these for everyone — checking a postcode before granting a right would cost more than granting it.

RightWhere it comes fromWhat it means here
Know and accessCCPA §1798.100 · GDPR Art. 15A copy of what we hold about you, the categories, the sources, the purposes, and who we disclosed it to.
Delete / erasureCCPA §1798.105 · GDPR Art. 17Removal, apart from what we must keep — billing records for tax law, and security logs while an investigation is open.
Correct / rectifyCPRA §1798.106 · GDPR Art. 16Fix anything inaccurate. Most of it you can edit yourself in the product.
Opt out of sale or sharingCCPA §1798.120There is nothing to opt out of today — we do neither — but the control exists and we honour it, including the Global Privacy Control signal your browser may send.
Limit the use of sensitive personal informationCPRA §1798.121We collect none, so there is nothing to limit. The control exists for the same reason as the one above.
Non-discriminationCCPA §1798.125Exercising any of these changes nothing about your price, your plan or the service you get.
Restrict processingGDPR Art. 18Ask us to hold rather than use, while something is disputed.
PortabilityCCPA §1798.100(d) · GDPR Art. 20Machine-readable export. Every table in the product already exports as CSV, on every plan, without asking us.
ObjectGDPR Art. 21Object to processing we do on legitimate interests. Tell us what and we will stop or explain why we cannot.
Withdraw consentGDPR Art. 7(3)Where we rely on consent, withdraw it at any time. It does not undo what was lawful before you did.

03How we check it is really you

We will email the address on the request and ask you to confirm it, and for an account we will ask for something only the account holder would know. If what you have asked for is a large disclosure or a deletion, we ask for more than we would for a simple correction — the more there is to lose, the more certain we have to be.

This is a legal requirement as much as a courtesy. Acting on an unverified deletion request is how one person erases another’s data; acting on an unverified access request is how somebody’s data is handed to a stranger who happened to know their email address.

If we genuinely cannot verify you, we will say so and explain why, rather than going quiet. An agent acting on your behalf is fine — we will need your written authorisation and will still verify you directly.

04How long we take

California: 45 days, extendable once by a further 45 where the request is complex (§1798.130).

EU and UK: One month, extendable by two further months for complex requests (GDPR Art. 12(3)).

We aim to answer inside 30 days for everyone, whichever regime applies. If we need an extension we will tell you before the first deadline passes, not after it.

There is no charge. We may charge or refuse only where a request is manifestly unfounded or excessive — repetitive requests, in practice — and we will explain which and why if it ever happens.

05If your request is about an order you placed

If you bought something from a brand that runs its warehouse on Kinetel, your request belongs with that brand. They decide what happens to your data; we process it on their instructions, and answering you directly would mean acting outside them.

Write to the brand you ordered from. They have a tool inside Kinetel that exports or erases one person’s record, so the request is one they can actually answer. If you cannot reach them, tell us and we will pass it on.

You can also complain to a regulator. If you are in the EEA or the UK you can complain to your local supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, and it will not count against you either way.

Effective 30 September 2026. Prefer email? Write to support@kinetel.io — the form is faster only because it asks for the things we would have to ask for anyway. To opt out of sale or sharing, use Your Privacy Choices, which takes effect immediately.

Something here unclear, or does not cover your situation? Ask us — a policy you have to guess at is not doing its job.