Kundan HQ legal
Privacy Policy
This Policy explains what Kundan HQ collects, why we use it, who receives it, how long we keep it, and the choices available to merchants and storefront shoppers.
Effective and last updated August 28, 2026 · Version 2.1Scope. This Privacy Policy applies to kundanhq.com, Kundan HQ merchant workspaces, merchant storefront technology, account and billing communications, and related support. A merchant’s own storefront policy also governs that merchant’s use of shopper information.
1. Who is responsible for personal information
Kundan HQ is responsible for personal information used to operate our website, merchant accounts, subscriptions, security, and direct business communications. When a merchant enters or collects customer, supplier, or order information through its private workspace or storefront, the merchant decides why and how that information is used. In that context, the merchant is generally the business or controller and Kundan HQ acts as its service provider or processor, except where we independently use limited information for security, billing, legal compliance, or operating the platform.
For a storefront purchase, the connected merchant is the seller and merchant of record. Stripe independently processes payment details under Stripe’s privacy terms. Storefront customers should contact the merchant first about the merchant’s product, order, return policy, and use of customer information.
2. Personal information we collect
A. Merchant account and onboarding information
- name, business name, owner email, phone number, website, social-media handles, time zone, onboarding date/time preferences, and communications;
- login information, a securely hashed password, authentication status, password-reset records, session identifiers, and account permissions; and
- plan, subscription status, Stripe customer and subscription identifiers, billing dates, payment status, and limited transaction records. Stripe—not Kundan HQ—collects full card numbers and card security codes.
B. Merchant business data
- supplier names and records; shipment dates, costs, currencies, notes, quantities, and payments;
- inventory codes, categories, cost, asking and claim prices, status, labels, photos, descriptions, accessibility text, and availability;
- customer names, social handles, phone numbers, email addresses, shipping addresses, notes, claims, payments, balances, order history, and communications entered by a merchant;
- live-sale details, offline claims, payment allocations, packing and shipping records, carriers, tracking numbers, refunds, disputes, and reports; and
- store name, logo, website copy, policies, shipping and tax settings, Stripe Connect status, and public catalog content.
C. Storefront shopper and transaction information
- claim name and the item claimed;
- cart contents and temporary reservation information;
- checkout name, email, phone number, billing and U.S. shipping address, order items, subtotal, shipping, tax, total, order status, refund status, carrier, and tracking number;
- Stripe checkout, payment-intent, refund, and dispute identifiers and status. We do not receive or store a shopper’s full payment-card number; and
- for public storefront analytics, a random first-party identifier stored in keyed-hash form, storefront or product viewed, timestamp, reduced referral-source label, and campaign tags. Storefront analytics do not record raw IP addresses, full referring URLs, precise location, cart, checkout, order, or policy page activity.
D. Photos, voice, AI, and device workflows
- product photographs and related item codes or text submitted for photo storage or AI-assisted title creation;
- spoken-command transcripts, typed commands, command previews, corrections, and structured results. Browser or device speech services may process audio to produce a transcript; Kundan HQ generally receives the transcript rather than a permanent raw-audio recording;
- temporary photo-handoff tokens and device status used to move a photo from a phone into a merchant workspace; and
- printer model/status and local connection results needed to work with supported DYMO label software. Kundan HQ does not intentionally collect unrelated files or local-network content.
E. Technical, security, and support information
- IP address, browser and device type, operating system, requested URL, referring page, timestamps, session cookie, and security or error logs;
- login attempts, rate-limit events, suspected fraud or abuse signals, webhook delivery records, and email delivery status; and
- support messages, feedback, screenshots or files you choose to send, and records of troubleshooting or onboarding assistance.
2A. Private-service inquiries
When a person requests Private Onsite Setup, we collect the submitted name, email address, phone number, and seller handle so Jaden can personally evaluate the request and respond by phone or email. Submitting the form does not create a merchant account, take payment, or reserve travel dates.
3. Sources of personal information
We collect information directly from merchants and shoppers; from a merchant’s authorized users; automatically from browsers, devices, and security systems; from Stripe, Resend, OpenAI, Render, and other service providers; from shipping carriers when tracking information is used; and from a person or business that asks us to create, support, investigate, or secure an account. We may derive totals, statuses, risk signals, and reports from information already held in the Service.
4. How we use personal information
- create, authenticate, configure, and support merchant workspaces;
- provide inventory, claims, customers, payments, reports, labels, website, cart, order, refund, dispute, and shipping features;
- create Stripe subscription and storefront checkout sessions, synchronize payment status, and prevent duplicate fulfillment;
- calculate or display shipping and Stripe-provided tax amounts when enabled by a merchant;
- send account, claim, order, refund, payment-dispute, security, and shipping communications;
- process product photos or commands through AI-assisted features and return requested output;
- maintain data isolation, backups, authentication, rate limits, auditability, fraud prevention, and incident response;
- diagnose errors, measure reliability, provide support, improve usability, and develop features using aggregated or de-identified insights where practical;
- enforce our agreements, protect rights and safety, resolve disputes, collect amounts due, and comply with law; and
- complete a merger, financing, restructuring, or sale, subject to appropriate protections.
We do not use merchant or shopper personal information for unrelated targeted advertising. We do not make decisions producing legal or similarly significant effects based solely on automated profiling.
5. Legal bases where applicable
Where a law requires a legal basis, we process information as needed to perform a contract; take requested pre-contract steps; pursue legitimate interests such as providing, securing, supporting, and improving the Service; comply with legal obligations; protect vital interests; or act with consent. A merchant is responsible for identifying its own lawful basis for customer and supplier information it controls. Consent may be withdrawn where consent is the basis, without affecting earlier lawful processing.
6. How personal information is disclosed
We disclose personal information only as reasonably necessary for the purposes above:
- Merchants and their authorized users. A merchant can access the customer, supplier, item, claim, payment, shipping, and order information in its workspace. Public catalog details and merchant policies are visible to storefront visitors.
- Stripe. Stripe processes subscriptions, connected-account onboarding, checkout, payment, tax, refund, dispute, and payout functions. Stripe receives transaction, contact, address, and technical information required for those services.
- Resend and email infrastructure. Resend receives recipient email addresses, message content, event tags, and delivery information to send transactional email.
- OpenAI and AI infrastructure. When an AI-assisted feature is used, OpenAI may receive the submitted product image, item code, prompt, typed instruction, or voice-command transcript needed to produce the requested result. Kundan HQ uses business/API services for which provider inputs and outputs are not used for model training by default unless the customer expressly opts in through the provider.
- Hosting and operations. Render and related database, network, storage, logging, security, and backup providers process information needed to host and protect the Service.
- Browsers, devices, carriers, and integrations. A browser, device speech service, DYMO software, shipping carrier, or other integration receives the limited information necessary for the feature the user chooses.
- Professional advisers and authorities. We may disclose information to lawyers, accountants, insurers, auditors, regulators, courts, law enforcement, or other parties when reasonably necessary to obtain advice, comply with valid process, prevent harm or fraud, enforce agreements, or protect legal rights.
- Corporate transactions. Information may be disclosed under confidentiality protections in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets.
We may disclose information at a user’s direction or with consent. Service providers are permitted to process personal information only for contracted services and related legal obligations.
7. No sale, targeted advertising, or cross-context behavioral advertising
Kundan HQ does not sell personal information for money, does not share personal information for cross-context behavioral advertising, and does not use personal information for targeted advertising as those terms are defined by U.S. state privacy laws. We do not knowingly sell or share the personal information of anyone under 16. Because we do not conduct these activities, there is currently no separate “Do Not Sell or Share” link. If our practices change, we will update this Policy and provide legally required controls, including recognition of applicable universal opt-out signals.
9. Merchant privacy responsibilities
Merchants must provide their customers any privacy notice required for the merchant’s own business, collect only information reasonably needed, use it only for disclosed lawful purposes, keep it accurate and secure, restrict employee access, honor applicable privacy rights, and instruct Kundan HQ when assistance is required. Merchants must not upload highly sensitive information that the Service does not request, including Social Security numbers, full card numbers, account passwords, medical records, or biometric templates.
If a storefront shopper contacts Kundan HQ about merchant-controlled information, we may direct the shopper to the merchant and notify or assist the merchant. We may independently handle requests concerning Kundan HQ account, security, or technical information.
10. Retention and deletion
We retain each category only as long as reasonably necessary for the purposes described, taking into account account status, the merchant’s instructions, transaction and dispute periods, tax and accounting rules, fraud and security needs, legal claims, provider requirements, and backup rotation.
- Active workspaces. Account and merchant business data is generally retained while the subscription or authorized account remains active so the merchant can use historical reports, customer ledgers, orders, and inventory records.
- Storefront analytics. Detailed public storefront analytics events are designed to be retained for no more than 400 days, after which they are deleted or reduced to non-identifying totals.
- After cancellation or a verified deletion request. We may retain workspace data for a limited post-termination period to permit recovery or export and then delete or de-identify it, unless a longer period is required for transactions, disputes, security, consent records, legal compliance, or establishment of legal claims.
- Financial and transaction records. Subscription invoices, order/payment/refund/dispute records, tax-related totals, and associated audit information may be retained for up to seven years or longer when law, litigation, or a continuing dispute requires.
- Security and support records. Authentication, security, error, email-delivery, and support records are retained for the period reasonably needed to prevent abuse, diagnose incidents, document requests, and enforce agreements.
- Temporary data. Cart reservations, password-reset links, photo-handoff tokens, and similar workflow data expire according to the feature, although limited audit or transaction records may remain.
- Backups. Deleted information may remain in encrypted or access-restricted backups until overwritten through the normal backup cycle and will not be restored except for continuity, security, or disaster recovery.
We may retain aggregated or de-identified information that cannot reasonably be linked to a person. A merchant may have independent legal duties to retain its own sale, customer, and tax records even after Kundan HQ deletes them.
11. Security
We use safeguards designed for the nature of the Service, including encrypted network connections, password hashing, secure session settings, CSRF protection, rate limiting, access controls, merchant data isolation, signed Stripe webhooks, idempotent transaction processing, backup procedures, and restricted provider credentials. We review and improve safeguards as risks change. No transmission, provider, database, or security measure is guaranteed to be completely secure. Notify security@kundanhq.com promptly if you suspect unauthorized access.
12. Privacy rights and choices
Depending on residence and applicable law, a person may have the right to:
- confirm whether personal information is processed and access it;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- receive a portable copy of information provided to us;
- opt out of sale, targeted advertising, or certain profiling (activities Kundan HQ does not currently perform);
- limit or withdraw consent for certain sensitive-information processing;
- use an authorized agent where permitted; and
- receive equal service and not be discriminated against for exercising a privacy right.
Submit a request to security@kundanhq.com with the subject “Privacy Request.” Describe whether the request concerns a merchant account, a particular storefront, or a Kundan HQ interaction. We will verify identity and authority before disclosing or deleting information and may request information reasonably necessary for verification. If we deny a request, you may appeal by replying with the subject “Privacy Appeal.” We will respond within the period required by applicable law.
Storefront shoppers should first submit merchant-controlled requests to the merchant shown on the storefront. Kundan HQ will reasonably assist a merchant with valid processor obligations. Rights are subject to exceptions for security, fraud, free expression, legal claims, transactions, tax records, and other lawful needs.
13. California privacy notice
For California residents, the categories described in Section 2 correspond to identifiers; customer records; commercial information; internet or electronic network activity; approximate location inferred from IP address; audio/transcript or visual information; professional or employment-related business information; and inferences drawn to provide reports, security, or workflow assistance. We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the recipient categories in Section 6 for business purposes.
In the preceding 12 months, Kundan HQ has not sold personal information or shared it for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about a person. California residents may request to know, access, correct, or delete covered information and may exercise rights through Section 12. We do not discriminate for exercising CCPA rights.
14. Children
The Service is intended for adults and businesses and is not directed to children under 13. We do not knowingly collect personal information directly from a child under 13. If you believe a child submitted information without legally sufficient parental permission, contact security@kundanhq.com so we can investigate and delete it where required. Merchants may not use Kundan HQ to circumvent children’s privacy laws.
15. United States operation and international users
Kundan HQ is operated in the United States and our providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. If a merchant offers products to people outside the United States, the merchant is responsible for determining whether additional notices, contracts, transfer mechanisms, representatives, or customer rights apply. The current storefront checkout is configured for U.S. shipping addresses.
16. Changes to this Policy
We may update this Policy to reflect new features, providers, laws, or practices. We will post the revised version, update the effective date, and provide additional notice when a change is material or consent is required. The version in effect when information is processed governs that processing, subject to applicable law.
17. Contact
Email privacy, security, access, correction, deletion, portability, or appeal requests to security@kundanhq.com. Include enough information to identify the relevant account or merchant storefront, but do not email passwords, full payment-card numbers, government identifiers, or other unnecessary sensitive information.