When you sign up for and use Kesper, we may collect the following information about you (the merchant or operator):
When a Shopify merchant installs Kesper, we process a limited set of their customers' personal data on their behalf, as a data processor. The merchant remains the data controller; Kesper processes this data solely to provide the contracted Service.
Fields processed:
What we do not do: We do not sell, rent, or license this customer data. We do not use it for advertising, marketing to end customers, or personalization outside the merchant's operational brief. End-customer PII is never displayed to district managers or other merchant staff — only aggregate signals derived from it.
Retention: Customer data tied to a merchant is retained for the duration of their active subscription and purged within 30 days of uninstall, triggered by Shopify's shop/redact webhook. Individual customer deletion requests via customers/redact are honored immediately.
We use the information we collect to:
Kesper relies on the following sub-processors to operate the Service:
Your data is stored on Railway infrastructure located in the United States. The managed PostgreSQL database encrypts data and backups at rest using AES-256. Marketplace credentials and API keys receive an additional layer of app-level field encryption (AES-256-GCM). All data in transit is protected with HTTPS/TLS 1.2+. Passwords are hashed using scrypt with a 16-byte random salt. Sessions use server-revocable Bearer tokens. Access to merchant data within Kesper is restricted by role, with data-touching mutations recorded to an immutable audit log.
We do not sell your personal or business data, and we do not sell the personal data of your end customers. Data is shared only with the sub-processors listed above, and only to the extent necessary to operate the Service:
Kesper uses minimal tracking. We store a session token in your browser's localStorage to keep you signed in. We do not use third-party tracking cookies. We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and does not collect personal data. Plausible is fully compliant with GDPR, CCPA, and PECR.
You have the right to access, export, and delete your data at any time. To exercise these rights, contact us at support@kesper.io. We will respond to your request within 30 days. End customers of Shopify merchants should direct requests to the merchant; we will process verified deletion requests forwarded by the merchant or received through Shopify's customers/redact webhook.
If you are a California resident, you have the right to request deletion of your personal information, know what personal information is being collected, and opt out of the sale of your personal information. As stated above, we do not sell personal data. To submit a CCPA request, email support@kesper.io.
If you are located in the European Union, you have the right to access, rectify, erase, and restrict the processing of your personal data. You also have the right to data portability and the right to object to processing. To exercise any of these rights, contact support@kesper.io.
We retain your account data for as long as your account is active. If you cancel your account, your data will be available for export for 30 days. After that period, all account data is permanently deleted from our systems. Customer data processed on behalf of Shopify merchants follows the retention rules described in Section 2.
Kesper is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will delete it promptly.
We may update this Privacy Policy from time to time. Updated versions will be posted on this page with a revised effective date. We encourage you to review this page periodically.
If you have questions about this Privacy Policy, please contact us at support@kesper.io.