KwikNest ("we", "us") operates a multi-tenant commerce platform serving merchants, suppliers, and the customers who shop on merchant storefronts. This policy explains what data we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it. It applies to kwiknest.dev and every storefront we host.
1. Who is the controller?
For data we collect about KwikNest accounts (merchants, suppliers, platform admins), KwikNest is the controller. For data collected by a storefront about its shoppers, the operating merchant is the controller and KwikNest is a processor acting on their instructions.
2. Information we collect
- Account data — name, email, organisation name, role, and Clerk-issued user ID.
- Commercial data — orders, quotes, RFQs, messages, payouts, refund requests.
- Payment metadata — Stripe customer ID, last 4 digits, billing address. Full card data is collected and stored by Stripe directly; we never see or store it.
- Technical data — IP address, user-agent, request path, and timestamps. We log these for security and abuse investigation only.
- Cookies / local storage — see the Cookies Policy.
3. Why we use it (lawful basis under GDPR Art. 6)
- Contract (Art. 6(1)(b)) — to provide the platform you signed up for, route orders, process payouts.
- Legal obligation (Art. 6(1)(c)) — tax records, fraud reporting, accounting retention.
- Legitimate interest (Art. 6(1)(f)) — security logging, abuse detection, product improvement on aggregated telemetry. Balanced against your rights and never used for third-party advertising.
- Consent (Art. 6(1)(a)) — non-essential cookies and marketing email. Withdrawable at any time via the cookie banner or email unsubscribe link.
4. Sub-processors
We share data with the following sub-processors strictly as needed to deliver the service. None of them sell your data.
- Clerk — authentication and session management.
- Neon (Postgres) — primary database hosting.
- Stripe — payment processing, payouts, optional Stripe Tax for sales-tax calculation.
- Resend (or comparable transactional email provider) — transactional and account-recovery email.
- Upstash — rate-limit state. Stores only request counts keyed on hashed IP, never personal content.
- Sentry (when enabled) — error monitoring with PII scrubbing on by default.
A current sub-processor list is published on our Sub-processors page. We give 30 days' notice before adding a new sub-processor that handles personal data.
5. International transfers
Our infrastructure runs in the United States. Where we transfer data out of the EU/UK we rely on the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, executed with each sub-processor.
6. Retention
- Account data — kept while your account is active and for 90 days after deletion to allow recovery, then purged.
- Order & payout records — kept for 7 years to satisfy tax / accounting law in most jurisdictions.
- Security logs — kept for 90 days, then anonymised (IPs truncated to /24 / /48).
- Marketing email opt-in records — kept until you opt out, then for 3 years to evidence your prior consent.
7. Your rights
Under GDPR and CCPA you may request: access, correction, deletion, portability, restriction of processing, objection to processing, and the right to withdraw consent. Email us at privacy@kwiknest.com and we will respond within 30 days. We will never charge a fee for a first request.
If you are not satisfied with our response, you may complain to your local data-protection authority. EU residents may also contact our EU representative when one is appointed (see that page for current status).
8. Children
KwikNest is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you become aware that a child has provided us data, contact us and we will delete it.
9. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is scoped per organisation and per role. Stripe handles all card data in PCI-DSS Level 1 environments. Webhook events are signed and idempotently processed. A full security overview will be published before public launch.
10. Changes
We notify you of material changes by email and on next sign-in. The "Last reviewed" date at the top of this page reflects the most recent counsel-reviewed revision.
Questions or requests? Contact privacy@kwiknest.com.