Legal
Privacy Policy
Plain terms for how we handle your store data, your cost inputs and your personal details. Last updated 7 September 2026.
01
What we collect
- Account details you give us: name, work email, company and store URL.
- Store data we read through your authorised connections: orders, line items, products, customers, refunds, discount codes and subscription records.
- Cost inputs you upload: per-product COGS, shipping cost rules and fee rates.
- Product usage data: which analyses you open, so we know what to improve.
02
What we do with it
- Run the analyses you asked for and show them to your team.
- Support your account and answer your questions.
- Aggregate, non-identifying benchmarks only where you have opted in.
- We do not sell data, and we do not use your store data to train models sold to anyone else.
03
Where it lives and how long
- Store data is held in an encrypted database and encrypted in transit.
- Access tokens for connected platforms are encrypted at rest.
- You can disconnect a source at any time; we delete its imported data within 30 days.
- On account closure, all store data is deleted within 30 days and backups expire within 90.
04
Sub-processors
- Cloud hosting and database infrastructure.
- Payment processing for your subscription.
- Transactional email for account notifications.
- Product analytics limited to in-app usage events. A current list is available on request.
05
Your rights
- Request a copy of your personal data or ask us to correct it.
- Ask for deletion, subject to any records we must keep for tax and accounting.
- Object to processing or withdraw a connection's authorisation.
- Write to hello@kpiprism.com and we will respond within 30 days.
06
Cookies
- We use a session cookie required to keep you signed in to the application.
- The marketing site uses no advertising or cross-site tracking cookies.
Questions about this policy: hello@kpiprism.com