Transparency information
Privacy at Kindly Sites
This page explains in plain language how the platform handles information. It does not replace each business’s own legal notice or, by itself, guarantee compliance with applicable law.
Updated:
Who does what
Each independent business that publishes a site decides why it uses messages, orders, and other information received from its customers. That business must publish its own privacy notice and contact details.
Kindly Sites provides the technical processing used to receive, store, and deliver that information to the authorized business. Separately, Kindly Sites determines how its own manager-account, access, security, abuse-prevention, and platform-maintenance operations work.
Information that may be handled
Storefront contact and orders
The name, email address or telephone number, message, requested service, products, quantities, and contact preference a person chooses to submit. The business uses this information to respond, confirm availability, and handle the order or inquiry.
Platform account and security
Account identifiers, site membership, settings and recorded changes, together with limited technical signals needed to authenticate, protect the service, enforce limits, and diagnose failures.
First-party statistics, when enabled
Page paths and bounded events such as visits, product or category views, add-to-cart actions, checkout starts, contacts, and order requests. In countries where the regional policy does not require a prior banner, a first-party pseudonymous identifier limited to 30 days associates the same browser’s journey with approximate city and region. They do not store the IP address or exact coordinates. These statistics belong to the site being visited: they are not advertising trackers and are not used to follow a person across unrelated sites or build cross-site advertising profiles.
Statistics choices by region
Visitor statistics remain off unless the site owner enables them and every platform safety gate allows collection.
The current regional policy asks first in the European Union, European Economic Area, United Kingdom, and Switzerland, and also when location is unknown or untrusted. Other recognized countries, including Colombia and the United States, use banner-free first-party analytics and a pseudonymous identifier limited to 30 days to associate the same browser’s journey.
Minimal counts of submitted messages or confirmed order requests may continue as business-operation records without form contents. When a site shows the “Privacy choices” control, a person can turn analytics off.
Configured retention
The application is configured with the following periods for these specific categories:
- 365 days
- Contact-form submissions are configured to be retained for up to 365 days.
- 30 days
- Raw statistics events, when collected, are retained for no more than 30 days.
- 400 days
- Aggregated daily statistics counts are configured for 400 days.
No single period is claimed here for every order, account, security record, backup, or record a business may need to keep. The business notice or an authenticated response should explain the period that applies to that information.
Technical services that may be involved
They are involved only when configured and needed for the relevant function:
- Google Cloud and Firebasehosting, authentication, database, files, rendering, and platform operations
- Cloudinaryoptimized delivery or controlled mirroring of public images, when enabled
- Resenddelivery of operational contact or order email, when configured
- Upstashusage limits and temporary acceleration of public data, when configured
- Cloudflarea trusted country and approximate-location signal for statistics, only when that layer is configured
How to make a request
Depending on where a person lives, they may have rights to inquire, access, correct, delete, restrict, object, or complain to a local authority.
For information submitted to a storefront — such as a message or order — the first route is the business’s contact details published on that same site. The business knows the relevant purpose and order.
For manager-account or platform-security information, begin with the authenticated manager access. Include the site, account, and action requested, but never send passwords or secrets. The existing support relationship can verify identity before action is taken.
Open manager access