Privacy Policy
This policy explains what information Kane collects, why we collect it, who processes it, and the choices you have. It applies to the Kane storefront, checkout handoff, accounts, and support channels we operate.
Last updated August 15, 2026
Who we are
[Legal Business Name] (“Kane,” “we,” “us,” or “our”) operates Kane. This Privacy Policy describes how we handle personal information when you visit the site, create an account, place an order, contact support, or otherwise use the Service.
For privacy questions or requests, contact [support@example.com]. Postal correspondence may be sent to [Registered Business Address].
This policy is designed to be accurate for the storefront as built. If a listed provider is not enabled in our environment, we do not use that provider to process your data until it is configured.
Information we collect
We collect information in the following categories, depending on how you use the Service:
- Account and contact details: email address, display name if you provide one, authentication tokens or session identifiers, and optional profile fields you submit.
- Order information: products, variants, quantities, order identifiers, delivery email, order status, timestamps, and related customer-record data returned by our commerce provider.
- Payment status: whether a payment is pending, completed, failed, refunded, or disputed. We do not collect or store full payment-card numbers, CVV codes, or bank-account secrets on Kane.
- Device and browser data: IP address, user-agent, approximate location derived from IP where our providers supply it, language and currency preferences, pages viewed, and diagnostic logs needed to operate and secure the site.
- Support communications: messages you send through the Support page, email, or Crisp live chat, including attachments you choose to upload and metadata such as time and channel.
- Security and fraud data: signals used to detect abuse, such as repeated failed checkouts, chargeback notices from processors, unusual order patterns, and technical logs of suspected attacks.
- Local storefront data: cart lines (product and variant identifiers and quantities), language, and currency stored in your browser or cookies so the cart and preferences persist.
We do not require you to provide government ID in the ordinary checkout flow. If we ever request additional verification for fraud or legal reasons, we will say why and retain it only as long as needed for that purpose.
How we use information
We use personal information for these purposes:
- Providing orders: creating checkout sessions, confirming payment status, delivering digital products, and showing order history where accounts are connected.
- Authentication: sending one-time login codes, maintaining sessions, and protecting accounts.
- Support: answering delivery, setup, and billing-status questions, and keeping a record of the conversation so we can help consistently.
- Fraud prevention and security: blocking abusive checkouts, investigating chargebacks, protecting the Service, and enforcing our Terms.
- Analytics: understanding aggregate storefront usage (for example, which pages load or fail) so we can fix issues and improve the site. We do not use analytics to build a secret advertising profile of you on Kane.
- Legal compliance: keeping records required for tax, accounting, dispute handling, and responding to lawful requests.
We do not use your content to train public machine-learning models. We do not sell your personal information for money. We share information with service providers as needed to run the Service, as described below.
Payments and card data
Checkout is handed off to a hosted payment flow and the payment methods configured on the store. Card details, wallet credentials, and other sensitive payment data are entered on the processor’s pages, not on a Kane card form.
Kane may receive order identifiers, payment status, amounts, and limited billing metadata needed to fulfill the order and handle support. Kane does not store full card numbers or CVV codes. Payment processors’ privacy policies apply to data they collect directly from you.
Service providers
We use companies that process information on our instructions to operate Kane. The providers that may apply, depending on configuration, include:
- Store platform: catalog, customers, orders, checkout sessions, and digital delivery.
- Hosting and infrastructure: the platform that serves the Kane website and related logs.
- Email provider: transactional messages such as one-time login codes and operational notices (for example, Brevo when configured).
- Analytics: privacy-respecting or aggregated usage measurement if we enable an analytics tool. We will identify the tool in this policy or in a cookie notice when it is active.
- Crisp: live support chat, including message content you submit in the widget.
Optional sign-in or bot-protection tools (such as Google or Discord OAuth, or Cloudflare Turnstile) process data only if we enable them. Those providers act as independent controllers or processors according to their terms for the data you submit to them.
We require service providers to use personal information for the contracted purpose, not to sell it as a standalone product. They may have their own legal obligations, for example as payment institutions.
Retention
We keep information only as long as needed for the purposes above, including:
- Account data: until you request deletion, plus a short period to complete the request, unless we must retain it longer for disputes, security, or law.
- Order and payment-status records: for the period required for accounting, tax, chargeback, and fraud-prevention obligations. This is often several years.
- Support messages: for as long as reasonably needed to finish the request and document what we advised, then in backup or archive according to our provider’s retention.
- Security logs: for a limited period appropriate to investigating abuse, typically days to months unless an incident requires longer retention.
- Browser cart and preference data: until you clear it or it expires.
When we no longer need personal information, we delete it or irreversibly aggregate it, subject to backup cycles and legal holds.
Security
We use reasonable administrative, technical, and organizational measures appropriate to a digital storefront, including HTTPS, server-side handling of commerce API credentials, and access limited to people who need it for operations or support. Payment-card data is handled by the payment processor, not stored by Kane.
No website, chat tool, or transmission can be guaranteed secure. You should use a unique password where passwords are offered, keep delivery emails private, and contact us if you suspect unauthorized access. We will notify you of a personal-data incident when the law requires it.
International transfers
Kane and its providers may process information in countries other than the one where you live, including the United States and the European Economic Area, depending on where those providers operate. Those countries may have different data-protection laws.
Where required, we rely on appropriate transfer mechanisms used by our providers (such as standard contractual clauses) or on necessity to perform a contract with you, for example to deliver an order. Contact us if you need more detail about the providers relevant to your request.
Your rights and requests
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information we hold, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You may also have a right to lodge a complaint with a data-protection authority.
To make a request, email [support@example.com] from the address associated with your account or order and describe what you need. We may ask you to verify your identity before completing a request so we do not disclose data to the wrong person.
We will not honor a request if the law allows us to refuse it—for example, where we must keep order records, where the request is unfounded or excessive, or where completing it would adversely affect others’ rights. Account deletion does not automatically erase records we are required to keep.
Children and minors
The Service is intended for customers who can lawfully purchase digital products. It is not directed at children under 13, or under the higher age of digital consent in their country if that age is greater.
If you are a parent or guardian and believe a child provided personal information to us in violation of this policy, contact us. We will take reasonable steps to delete the information where required. Minors who are allowed to purchase in their location should do so only with parent or guardian permission, as described in the Terms of Service.
Changes to this policy
We may update this Privacy Policy to reflect operational, legal, or provider changes. The “Last updated” date at the top of this page will change when we do. Material changes may also be highlighted on the site or sent to your account email when we have it.
Continued use of the Service after an update means the updated policy applies to information we process thereafter. If you do not agree, stop using the Service and request deletion of your account where that right applies.
Contact
Privacy requests and questions: [support@example.com]
You can also use the Support page on Kane.
[Legal Business Name]
[Registered Business Address]