K3KEWBED

Privacy Policy

Effective Date: February 19, 2026 · Last Updated: February 19, 2026

This Privacy Policy describes how Kewbed ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our resource allocation planning platform ("Service"). We are committed to protecting your privacy and complying with applicable data protection laws, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union's General Data Protection Regulation (GDPR), and US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA).


1. Information We Collect

1.1 Account Information

1.2 Organization Data (Customer Data)

Important: Customer Data belongs to you. We process it solely to provide the Service. See our Terms of Service for data ownership details.

1.3 Technical and Usage Data

1.4 What We Do NOT Collect

2. How We Use Your Information

PurposeData UsedLegal Basis (GDPR)
Provide the ServiceAccount info, Customer DataContract performance
Authenticate your identityEmail, password, OAuth tokensContract performance
Fix bugs and maintain reliabilityError reports (Sentry)Legitimate interest
Respond to support requestsEmail, account infoContract performance
Send service notificationsEmailContract performance
Comply with legal obligationsAs requiredLegal obligation

3. Cookies and Tracking

The Service uses only essential cookies required for authentication and session management (set by Supabase Auth). We do not use:

Because we use only strictly necessary cookies, no cookie consent banner is required under GDPR or ePrivacy Directive.

4. Data Storage and Security

4.1 Where Your Data Is Stored

Customer Data and account information are stored on Supabase, which uses Amazon Web Services (AWS) infrastructure. Data may be stored in the following regions depending on Supabase project configuration:

4.2 Security Measures

5. Third-Party Service Providers

We use the following third-party processors to operate the Service:

ProviderPurposeData SharedLocation
SupabaseDatabase, authentication, real-time syncAll Customer Data, account infoAWS (US)
VercelWeb hosting and CDNServer logs (IP, request data)Global CDN
SentryError trackingError reports, browser infoUS
GoogleOAuth login, Drive file accessEmail, name (via OAuth); file access tokensUS
ResendTransactional email (password reset)Email addressUS
CloudflareDNS and DDoS protectionServer logs (IP, request data)Global

Each provider maintains their own privacy and security practices. We select providers that maintain appropriate security certifications (SOC 2 Type II for Supabase and Vercel).

6. Data Retention

7. Your Privacy Rights

7.1 Rights Under PIPEDA (Canada)

Under Canada's Personal Information Protection and Electronic Documents Act, you have the right to:

7.2 Rights Under GDPR (European Union)

If you are located in the European Economic Area (EEA), you have the right to:

For GDPR purposes, Kewbed is the data controller for account information and the data processor for Customer Data uploaded by your organization.

7.3 Rights Under US State Privacy Laws (CCPA/CPRA)

If you are a California resident, you have the right to:

We do not sell or share your personal information as defined under CCPA/CPRA. We do not use personal information for targeted advertising.

8. International Data Transfers

Your data may be transferred to and processed in the United States through our infrastructure providers. For transfers from the EEA, we rely on:

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will promptly delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice within the Service at least 15 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was last revised.

11. Contact Us

For privacy inquiries, data access requests, or to exercise any of your rights described above, contact us at:

We will respond to all privacy requests within 30 days (or within the timeframe required by applicable law).


Terms of Service