Privacy Policy
Last updated: 7 October 2026
This policy explains how [COMPANY NAME] ([STREET AND NUMBER], [POSTCODE] [CITY], The Netherlands, Chamber of Commerce [KVK NUMBER]) handles personal data in connection with kaas. We are the controller for data about merchants who use our dashboard. For data about the customers who shop in a merchant's checkout, the merchant is the controller and we are their processor — see the Data Processing Agreement; the merchant's own privacy policy applies to those customers.
1. Data about merchants and their staff
- Account data: business name, email address and a hashed password (we never see or store the password itself).
- Store connection data: the Shopify store address and settings, and encrypted access credentials for connected services.
- Billing data: tariff, invoices, payment status and the bank details you pay from.
- Technical data: IP address, browser information and log entries when you use the dashboard.
2. Why we use it
- To provide the Service and your account (performance of our agreement).
- To invoice you and keep our accounts (legal obligation and performance of the agreement).
- To keep the Service secure, prevent abuse and fix errors (legitimate interest).
- To tell you about changes to the Service or these documents (legitimate interest).
We don't sell personal data and don't use it for advertising.
3. Who we share it with
Only with service providers we need to run the Service, bound by data processing agreements:
- Vercel Inc. — hosting of the application.
- Neon Inc. — database hosting (United States, AWS us-east-1).
- Shopify, Mollie, Whop and Meta — only the ones you connect, to do what you connected them for.
4. Transfers outside the EU
Some providers process data in the United States. Where that happens, the transfer is covered by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses.
5. How long we keep it
Account and store data for as long as your account exists, and up to 30 days after it ends so you can export it. Invoices and billing records for 7 years, as Dutch tax law requires. Logs for at most 90 days.
6. Security
Connections are encrypted, passwords are hashed, and access credentials for connected services are stored encrypted. Access to production data is limited to what's needed to run and support the Service.
7. Your rights
You can ask us to see, correct, delete or export your personal data, to restrict or object to its use, by emailing [CONTACT EMAIL]. We reply within one month. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Cookies
The dashboard uses one functional cookie to keep you signed in. The checkout itself sets no tracking cookies of its own; tracking tools a merchant connects (such as a Meta pixel) are the merchant's responsibility and covered by the merchant's own policies.
9. Changes
We may update this policy and will tell you about material changes. The date at the top shows the latest version.