This policy explains how Kapvel (“we”, “us”) — 353 Lexington Avenue, 4th Floor Ste 483, New York, NY 10016, United States — collects, uses, and protects personal information when you use kapvel.com and its subdomains (the “Service”).
In short: we collect what’s needed to run a team workspace, we don’t sell personal information, and we don’t use your workspace content for advertising.
1. Information we collect
Account information
Your name, email address, password (stored as a salted hash by our authentication provider), and optional profile details such as an avatar.
Workspace content
Content you and your teammates create in the Service: projects, issues, comments, documents, spreadsheets, whiteboards, attachments, service-desk requests, and data you choose to import from other tools. Import credentials (for example an API token) are used in memory for the transfer and are not stored.
Billing information
Payments are processed by Stripe. We receive subscription status, plan, seat counts, and invoice metadata — we never see or store full card numbers.
Usage and log data
Standard technical data: IP address, browser type, pages requested, and timestamps, plus in-product activity records (for example issue change history) that are part of the workspace itself. If an error occurs, our error-monitoring service collects a technical report of the failure.
2. How we use information
- To provide, maintain, and secure the Service.
- To send transactional email — invitations, notifications about activity in your workspaces, password resets, and billing receipts.
- To respond to support requests.
- To detect, investigate, and prevent abuse or security incidents.
- To comply with legal obligations.
We do not sell personal information and we do not use Customer Content to train machine-learning models or for advertising.
3. Who can see your content
Workspace content is visible to the members of that workspace according to the roles and permissions its admins configure. Service-desk customers see only their own requests and the help center content the workspace publishes. Our staff access customer data only when needed to operate the Service — for example to investigate an incident you report — and access is logged.
4. Service providers (subprocessors)
We rely on a small set of providers to run the Service:
- Supabase — database, authentication, file storage, and realtime infrastructure (hosted on AWS, US region).
- Vercel — application hosting and content delivery.
- Stripe — payment processing and subscription management.
- Resend — transactional email delivery.
Each provider processes data only as needed to provide its service to us and is bound by its own security and privacy commitments.
5. Cookies
We use cookies that are strictly necessary for the Service to work: authentication session cookies (scoped so one login works across your workspace subdomains) and small preference cookies such as your theme and last-visited workspace. We do not use advertising or cross-site tracking cookies.
6. Data retention and deletion
- Account information and workspace content are retained while your account or workspace is active.
- Content you delete in the product (issues, pages, attachments) is removed from the live database, with residual copies expiring from backups on a rolling basis.
- To delete your account or an entire workspace, reach us through our contact page and we will complete the deletion within 30 days, except for records we must keep for legal or accounting reasons.
7. Security
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure providers. Access to production systems is restricted and credential-protected, passwords are checked against known-breach corpora at signup, and workspace access is enforced by row-level security in the database. No system is perfectly secure — report vulnerabilities through our contact page.
8. International transfers
We are a US company and process data in the United States. If you use the Service from elsewhere, you consent to your information being transferred to and processed in the US.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal information. You can edit your profile in the product; for anything else, reach us through our contact page and we will respond within 30 days. If you interact with a workspace run by one of our customers (for example through their help center), that customer controls your data there — we will refer your request to them where appropriate.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. For material changes we will give reasonable notice by email or in the product before they take effect. The “Last updated” date above always reflects the current version.
12. Contact
Privacy questions or requests: reach us through our contact page or write to Kapvel, 353 Lexington Avenue, 4th Floor Ste 483, New York, NY 10016, United States. See also our Terms of Service.