Privacy Policy
How we protect and handle your data
Table of Contents
Kinect B2B LLC ("KinectMax," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the KinectMax software platform and related services (the "Service"). By using the Service, you agree to this Privacy Policy.
1. Who This Policy Covers
This policy covers two groups:
KinectMax Customers — businesses and individuals who create an account and subscribe to the Service. We are the "controller" of personal information about Customers, meaning we decide how and why we process that information.
End Users of our Customers — the customers, leads, vendors, and contacts whose information our Customers upload to the Service. For this information, we are a "processor" or "service provider" acting on behalf of our Customers, who are the controllers of that information. If you are an End User and want to know how your information is being used, contact the KinectMax Customer whose business you interact with.
2. Information We Collect
From KinectMax Customers
When you create an account or use the Service, we collect:
- Account information — name, email address, business name, business phone number, business address
- Billing information — billing address and payment-card metadata (such as card type and last four digits); your full card number is collected and stored by Stripe, not by us
- Authentication information — login credentials, including hashed passwords and, if you enable two-factor authentication, encrypted 2FA secrets
- Connected-service tokens — encrypted OAuth tokens for integrations you choose to connect, such as Google and QuickBooks Online
- Communications — messages you send to our support team, feedback you submit, and survey responses
Automatically Collected Information
When you use the Service, we automatically collect:
- Usage data — pages viewed, features used, actions taken, and timestamps
- Device and connection data — IP address, browser type, operating system, device identifiers, and referring URLs
- Cookies and similar technologies — see Section 7 for details
From Your Customers (End Users)
When you upload or sync data into the Service, that data may include personal information about your End Users, such as their names, email addresses, phone numbers, addresses, payment history, job records, and notes. We process this information solely to provide the Service to you, in accordance with your instructions and our agreement with you.
From Third Parties
If you connect a third-party integration, we may receive data from that provider as needed to operate the integration. For example, if you connect QuickBooks Online, we receive invoice and customer data necessary to keep your records in sync; if you sign in with Google, we receive a verified email address and a profile identifier.
3. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process payments and manage your subscription
- Send transactional communications related to your account, billing, security, and service updates
- Provide customer support and respond to inquiries
- Detect, prevent, and investigate fraud, security incidents, and violations of our Terms
- Comply with legal obligations and enforce our agreements
- With your consent, send marketing communications about KinectMax features and offerings (you may opt out at any time)
- Develop new features and analyze usage trends in aggregated, de-identified form
We do not sell personal information. We do not share personal information with third parties for their own independent marketing purposes.
4. Legal Bases for Processing (GDPR)
If you are in the European Economic Area or the United Kingdom, our legal bases for processing your information are:
- Performance of a contract — processing necessary to provide the Service you signed up for
- Legitimate interests — operating, securing, and improving our business, where those interests are not overridden by your rights
- Consent — for optional features such as marketing emails or non-essential cookies, where required
- Legal obligations — where we are required to process information by applicable law
6. Data Retention
We retain information for as long as you maintain an active account and for a reasonable period afterward to comply with legal obligations, resolve disputes, enforce agreements, and recover from data corruption.
When you cancel your account, we retain Your Data for 30 days to allow for export and recovery, after which it is deleted from our active systems. Backups containing your data may persist for an additional period (typically up to 90 days) before being overwritten on standard retention cycles.
Payment records, tax records, and certain transactional records may be retained for longer where required by law (typically up to seven years).
You may request earlier deletion as described in Section 8, subject to legal retention requirements.
8. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the information we hold about you
- Correction — ask us to correct inaccurate information
- Deletion — ask us to delete your information, subject to legal retention obligations
- Portability — request a copy of your information in a structured, machine-readable format
- Restriction or objection — ask us to limit or stop certain processing
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise these rights, contact us at support@kinectmax.com. We will respond within the time frame required by applicable law (generally within 30 days). We may need to verify your identity before fulfilling a request.
If you are an End User of one of our Customers, please contact that Customer directly with requests about your information. We will assist them in fulfilling your request as required by law.
9. California Privacy Rights (CCPA / CPRA)
California residents have specific rights under the California Consumer Privacy Act and California Privacy Rights Act, including the rights described in Section 8. In the past 12 months, we have collected the categories of personal information described in Section 2 for the purposes described in Section 3. We have not "sold" or "shared" personal information as those terms are defined under California law.
To exercise California rights, contact support@kinectmax.com.
10. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected such information, contact us at support@kinectmax.com and we will delete it.
11. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Where required by law, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
12. Security
We take reasonable technical and organizational measures to protect personal information, including:
- Encryption of data in transit (TLS) and encryption at rest for sensitive credentials (such as QuickBooks OAuth tokens, which are encrypted with AES-256-GCM)
- Role-based access controls and authentication for our team
- Row-Level Security policies that isolate each Customer's data
- Regular security reviews of our infrastructure and dependencies
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information, we will notify you in accordance with applicable law.
13. Email and Communication Tracking
Transactional emails sent from the Service (such as invoice notifications to your customers) may contain technical elements that allow us to confirm delivery and detect bounces. We use this information to ensure reliable email delivery and to troubleshoot problems. We do not use email tracking for advertising purposes.
If you, as a KinectMax Customer, send communications to your End Users through the Service, you are responsible for complying with applicable laws (such as CAN-SPAM, CASL, and GDPR) governing those communications.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
15. Contact Us
Questions, requests, or complaints about this Privacy Policy or your information?
If you are not satisfied with our response, you may have the right to lodge a complaint with a data protection authority in your jurisdiction.
Thank you for trusting KinectMax with your data. We are committed to protecting your privacy and providing a secure, reliable service. See also our Terms of Service.