Kiwy

Legal · Effective

Privacy Policy

How Kiwy collects, uses, shares, and protects personal information — including GDPR legal bases, retention periods, international transfers, and your data rights.

This Privacy Policy explains how Kiwy Technologies, LLC ("Kiwy", "we", "us", or "our") collects, uses, discloses, and protects personal information when you access or use kiwy.ai, our APIs, dashboards, customer portal, checkout tools, and associated services (collectively, the "Service").

Data Protection Roles (Controller vs. Processor)

Under applicable data protection laws (including the EU/UK General Data Protection Regulation - GDPR):

  • Kiwy as Data Controller: Kiwy acts as an independent Data Controller for processing activities related to platform account management, payment processing, tax calculation and remittance, merchant onboarding, fraud prevention, trade sanctions compliance, system security, and direct marketing.
  • Kiwy as Data Processor: Kiwy acts as a Data Processor on behalf of Sellers when processing Buyer personal data strictly under the instructions of the Seller to provide Seller-configured features, host Seller support records, or facilitate Seller-initiated buyer communications. Sellers act as independent Data Controllers for the Buyer data they receive.

1. Information We Collect

A. Information Collected from Sellers

When you register, apply, or operate a store on Kiwy, we collect:

  • Account & Contact Data: Name, email address, password hash, store name, profile image, and authentication metadata (including single sign-on credentials if you authenticate via third-party identity providers).
  • Business & Compliance Details: Legal business name, business entity type, country of registration, business website, store descriptions, product listings, uploaded assets, tax identification numbers, and regulatory/sanctions attestations.
  • Verification & Payout Data: Identity verification status, government ID confirmation metadata, and Know-Your-Customer (KYC) / Know-Your-Business (KYB) status provided via our verification partners; bank account details, payout routing numbers, and tax documentation (stored securely and encrypted).
  • Financial & Operational History: Transaction records, sales volume, payout history, fee deductions, invoices, and dispute history.
  • Technical & Usage Logs: IP address (recorded at signup, login, store submission, and payout request), browser type, operating system, dashboard activity, and security logs.

B. Information Collected from Buyers

When you purchase a product or subscription through Kiwy, we collect:

  • Order & Contact Information: Email address, full name (if provided), billing address (required for accurate VAT/sales tax calculation and invoicing), order history, license keys, and product access entitlements.
  • Payment Information: Payment card type, expiration date, card brand, and the last four digits of the card. Kiwy never stores raw full credit card numbers or security codes (CVV); all payment card data is collected and processed directly by PCI-DSS compliant payment processing partners.
  • Portal & Subscription Data: One-time access credentials, active subscription status, renewal history, and customer portal session data.
  • Support & Dispute Evidence: Correspondence, refund requests, and support communications submitted to Kiwy regarding an order or billing dispute.

C. Information Collected from Visitors

When you visit our public website, documentation, or blog, we collect:

  • Device & Connection Data: IP address, HTTP header details, user-agent string, page views, referring URLs, and standard web server access logs used for system security and reliability.

We do not knowingly collect personal data from children under 16 years of age. The Service is strictly intended for business professionals and adult consumers.

We process personal data only where we have a valid legal basis under Article 6 of the GDPR:

Processing Purpose / ActivityCategories of DataPrimary GDPR Legal Basis (Art. 6)
Account Creation & Service Operation: Creating accounts, enabling dashboard access, facilitating seller payouts, delivering digital products, granting license keys, and operating subscriptions.Account Data, Order Data, Payout Data, Financial HistoryPerformance of Contract (Art. 6(1)(b))
Tax Calculation & Remittance: Calculating, collecting, invoicing, and remitting VAT, GST, and sales taxes; maintaining accounting ledgers.Order Data, Billing Address, Transaction HistoryLegal Obligation (Art. 6(1)(c))
Sanctions & Trade Compliance: Screening sellers, beneficial owners, and transaction details against restricted-party lists (including OFAC, BIS, EU, and UN lists). This screening is carried out by our payment and identity-verification partners as part of their regulated onboarding and transaction-monitoring obligations; we receive and act on the outcome.Verification Data, Account Data, IP Address, Business DetailsLegal Obligation (Art. 6(1)(c)) & Legitimate Interests (Art. 6(1)(f))
Fraud Prevention & Security: Conducting store reviews, analyzing transaction risk signals, handling chargebacks, and defending platform security.Technical Logs, Verification Data, Order Data, Device DataLegitimate Interests (Art. 6(1)(f)) — protecting platform security & preventing financial crime
Automated Advisory Risk Assessment: Evaluating store listings against risk rules to order internal review queues (final decisions remain human).Store Listings, Business DetailsLegitimate Interests (Art. 6(1)(f))
Transactional Service Communications: Delivering receipts, invoices, login links, payout notices, and security alerts.Contact Data, Order DataPerformance of Contract (Art. 6(1)(b))
Optional News & Product Marketing: Sending non-essential product updates or newsletters.Contact DataConsent (Art. 6(1)(a)) — opt-in / withdrawable

3. Cookies and Tracking Technologies

Kiwy uses only strictly necessary and functional cookies required to operate the platform securely:

  • Session & Auth Cookies: To maintain your authenticated state and secure your session.
  • Security & CSRF Tokens: To prevent cross-site request forgery and fraudulent form submissions.
  • Environment Preferences: To remember user settings (e.g., switching between sandbox and production environments).

We do not use third-party behavioral advertising cookies or cross-site tracking pixels on our platform.

4. How We Share Information & Sub-Processors

We do not sell personal data. We share personal information only with service provider categories necessary to operate our business, with Sellers (for Buyer order fulfillment), or when required by law.

Service Provider Categories & Sub-Processors

We engage trusted third-party service providers acting as data processors under strict confidentiality and data protection obligations:

  • Payment Processors & Acquiring Banking Partners: To process card payments, execute seller payouts, manage chargeback evidence, and comply with card network rules.
  • Identity & Compliance Verification Partners: To verify Seller identities, screen against government sanctions lists, and confirm KYB status.
  • Cloud Infrastructure & Database Providers: To host platform applications, databases, and digital files.
  • Content Delivery Networks (CDNs): To distribute digital files and assets globally.
  • Transactional Email Services: To deliver receipts, sign-in links, and transactional alerts.
  • Security & Error Logging Services: To monitor system health, track bugs, and mitigate cyber threats.

An up-to-date summary of our sub-processors and categories is available upon request by contacting legal@kiwy.ai.

Disclosures to Sellers & Downstream Restrictions

When a Buyer purchases a digital product, Kiwy shares relevant order details (Buyer email, billing address, purchase date, product identifier, and license key) with the Seller who created the product so the Seller can provide product support and fulfill warranty obligations. Sellers are contractually prohibited under our Terms of Service from using Buyer data for unsolicited marketing, selling Buyer data, or using it outside direct order fulfillment without separate, explicit opt-in consent from the Buyer.

We may disclose personal information if required by law, subpoena, court order, or governmental enforcement agency (including reporting mandated by financial crime and sanctions regulators).

5. Data Processing Addendum (DPA) for Sellers

Kiwy's Data Processing Addendum, which forms part of these Terms and governs Kiwy's processing of Buyer personal data as a processor on behalf of Sellers, is available at https://kiwy.ai/legal/dpa. Contact legal@kiwy.ai with questions.

6. International Data Transfers

Kiwy operates globally. Personal data may be transferred to, stored, and processed in servers located outside your country of residence, including in the United States. Where personal data originates from the EEA, UK, or Switzerland and is transferred to jurisdictions that have not received an adequacy decision, we ensure appropriate safeguards are implemented, such as Standard Contractual Clauses or equivalent cross-border data transfer mechanisms.

7. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, destruction, loss, alteration, or disclosure, including:

  • Encryption of data in transit using Transport Layer Security (TLS/HTTPS).
  • Encryption of sensitive data at rest (such as financial records, tax identifiers, and authentication tokens).
  • Role-based access controls restricting production environment access to authorized personnel.
  • System logging and monitoring of administrative actions.

8. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this policy:

  • Account Data: Retained for the active duration of your account and for up to 7 years following account closure to resolve disputes, comply with financial audits, or defend legal claims.
  • Financial, Invoicing & Tax Records: Retained for 7 years as mandated by applicable tax and accounting laws.
  • Verification & Screening Outcomes: The results we receive from our verification and payment partners are retained for the period mandated by anti-money laundering and trade compliance regulations.
  • Technical & Security Logs: Typically retained for 30 to 90 days before automated purging.
  • Sandbox Test Data: May be modified, reset, or deleted at any time without notice.

9. Your Data Rights (General / GDPR)

Depending on your location, you may have the following rights under applicable privacy laws:

  • Access, Correction, Erasure: Request access to, correction of, or deletion of your personal data (subject to legal/tax retention rules).
  • Restriction & Objection: Request restriction of processing or object to processing based on legitimate interests.
  • Data Portability & Consent Withdrawal: Request a portable copy of your data or withdraw consent at any time.

To exercise your rights, email legal@kiwy.ai.

10. California Privacy Rights (CCPA / CPRA Notice)

This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").

A. Collection & No Sale / Sharing Confirmation

In the preceding 12 months, we collected Identifiers, Commercial Information, Financial Metadata, Network Activity, and coarse Geolocation Data (inferred from IP addresses, used for fraud prevention and platform security). Transaction taxes are calculated from the billing address you provide at checkout, not from your IP address.
Kiwy does not sell personal information and does not share personal information for cross-context behavioral advertising.

B. Sensitive Personal Information (SPI) Statement

Kiwy collects sensitive personal information (such as financial account credentials for payouts and government ID metadata for verification) strictly to perform requested services and comply with financial/sanctions law. Kiwy does not use or disclose Sensitive Personal Information for any purpose other than those permitted under California Code of Regulations § 7027(m).

C. Exercising Rights

California residents may submit CCPA access, deletion, or correction requests by emailing legal@kiwy.ai with the subject line "California Privacy Request".

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be notified via email or dashboard alert prior to taking effect. Current versions will be accessible at https://kiwy.ai/privacy.

12. Contact Information

Kiwy Technologies, LLC
2810 North Church Street STE 88591
Wilmington, DE, 19802 US
Email: legal@kiwy.ai