HomePrivacy Policy

PRIVACY POLICY

Last updated: April 17, 2026·GDPR Compliant

GDPR Art. 6 compliantNo data sold to 3rd partiesRight to erasureEncrypted in transit

KickPulse ("we", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use our Service at kickpulse.dev. It also explains your rights under the General Data Protection Regulation (GDPR) and other applicable data protection law.

01

Data Controller

The data controller responsible for your personal data is:

KickPulse

Service website: kickpulse.dev

Contact: [email protected]

For data protection enquiries, including exercising your GDPR rights, please contact us at the email above with the subject line "Data Protection Request".

02

Data We Collect

We collect the following categories of personal data:

Account Data

  • Username
  • Email address
  • Hashed password (bcrypt — never stored in plaintext)
  • Account creation date
  • Admin/user role

Subscription & Usage Data

  • Target Kick.com channel username
  • Subscription package purchased
  • Active viewer count setting
  • Subscription start/expiry dates
  • Bot activity status

Payment Data

  • Payment status and amount
  • Currency
  • Stripe session and payment intent IDs (reference only)
  • Dry-run / real payment flag

Full card details are processed exclusively by Stripe and never stored by KickPulse.

Support Data

  • Support ticket content and messages
  • Ticket status and timestamps

Technical Data

  • IP address (for rate limiting and security)
  • Browser user agent (from HTTP requests)
  • Authentication tokens (JWT, stored client-side in localStorage)
04

How We Use Your Data

We use your personal data to:

  • Create and manage your account
  • Process payments and activate bot subscriptions
  • Operate and manage bot instances on your behalf
  • Send transactional emails (welcome, subscription confirmation, password reset, support replies)
  • Respond to support tickets
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Improve the Service through anonymised analytics (if consent given)

We do not use your data for automated decision-making or profiling that produces legal or significant effects.

05

Data Sharing & Third Parties

We do not sell your personal data to third parties. We share data only where necessary:

Stripe Inc.

Payment processing. Stripe is PCI DSS compliant and GDPR compliant. Your full card data is processed directly by Stripe and never touches our servers.

stripe.com/privacy

SMTP Email Provider

Sending transactional emails (your email address is passed to the configured mail server for delivery).

Legal / Law Enforcement

We may disclose your data where required by law, court order, or to protect the rights, property, or safety of KickPulse, our users, or others.

06

Data Retention

We retain your data for the following periods:

Account data: Until you request account deletion, or 2 years after your last login if the account is inactive
Payment records: 7 years from the transaction date (legal/tax obligation)
Support ticket data: 3 years from ticket creation
Bot activity logs: 90 days
Security logs (IP, rate limit): 30 days
07

Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data. To exercise any of these rights, please contact us at [email protected] with the subject "Data Protection Request". We will respond within 30 days.

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your data ('right to be forgotten'), subject to legal retention requirements.

Right to Restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

Right to Withdraw Consent (Art. 7)

Withdraw consent for cookie-based processing at any time.

Right to Lodge a Complaint

File a complaint with your national supervisory authority (e.g. UODO in Poland, ICO in the UK).

08

Cookies & Local Storage

Our Service uses localStorage (browser-side storage) and may set cookies. We distinguish between:

Strictly Necessary

  • JWT authentication tokens (stored in localStorage to keep you logged in)
  • Cookie consent preference (stored in localStorage)

No consent required — necessary for the Service to function.

Analytics (optional)

  • Usage statistics, page views, feature interactions

Only if you provide consent via our cookie banner.

Marketing (optional)

  • Personalised content and advertising

Only if you provide consent via our cookie banner.

You can manage or withdraw your cookie consent at any time by clearing the "kp_cookie_consent" key from your browser's localStorage, or by reloading the page after clearing site data. This will show the cookie banner again.

09

Third-Party Links & Services

The Service may contain links to third-party websites or integrate with third-party platforms (e.g. Kick.com). These third parties have their own privacy policies, and we are not responsible for their practices. We encourage you to review the privacy policies of any third-party services you interact with.

Kick.com is an independent platform. Your interactions with Kick.com are governed by Kick.com's own Terms of Service and Privacy Policy.

10

Security Measures

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Passwords stored using bcrypt hashing (never in plaintext)
  • Authentication via short-lived JWT tokens (access + refresh)
  • All data transmitted over HTTPS/TLS
  • Rate limiting on authentication and API endpoints
  • Database access restricted to application layer only

No system is 100% secure. We cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately.

11

Children's Privacy

The Service is not directed at persons under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18 without verifiable parental consent, we will take steps to delete that data promptly.

If you believe we have inadvertently collected data from a child, please contact us immediately.

12

Contact & Complaints

For any privacy-related questions, to exercise your rights, or to file a complaint, contact us:

KickPulse Data Protection Contact

[email protected]

Subject: "Data Protection Request"

Response time: up to 30 days (GDPR Art. 12)

You also have the right to lodge a complaint with your national data protection supervisory authority. In the EU, a list of supervisory authorities is available at edpb.europa.eu.