Legal · Privacy

Privacy Policy

Effective: August 3, 2026Last updated: August 3, 2026

This Policy explains what information KPI360 collects, how we use and share it, and the choices and rights you have. We built KPI360 to keep your business data yours — isolated per company, encrypted, and never sold.

1.Scope and roles

This Privacy Policy applies to information processed through the KPI360 website and platform (the “Service”). For most business data your company connects (e.g., point-of-sale records), you are the controller and KPI360 acts as a processor on your behalf under our Data Processing Addendum. For information about your account and your use of our website, KPI360 is the controller and this Policy governs.

2.Information we collect

Information you provide

  • Account & contact: name, email, phone, company, role, and store/location assignment.
  • Billing: subscription and payment details, processed by our payment processor (we do not store full card numbers).
  • Support & communications: messages you send us.

Business data via Integrations

  • Point-of-sale & operations: sales, orders, product mix, labor hours and pay, and related figures ingested from systems you connect (e.g., Toast) or spreadsheets you link/upload.

Automatically collected

  • Usage & device: log data, IP address, browser/device type, pages viewed, and actions taken, used for security and to operate the Service.
  • Cookies: as described in the Cookies section below.

3.How we use information

We use information to: provide, secure, and maintain the Service; ingest and analyze your business data to produce dashboards, forecasts, and AI-generated insights; authenticate users and enforce access and usage limits; process billing; provide support; detect, prevent, and investigate fraud, abuse, and security incidents; comply with law; and improve the Service. We do not use your Customer Data to train third-party AI models, and we do not sell personal information.

4.AI processing

Certain features send relevant, minimized data to an AI provider (Anthropic) to generate summaries, forecasts, and suggestions. This processing is performed to provide the feature you request. AI outputs are informational and may be inaccurate; see the “No advice” disclaimer in our Terms. We choose providers that contractually commit not to train their models on data submitted through their business APIs.

6.How we share information

We share information only as follows:

  • Subprocessors & service providers who host and support the Service under contract (see Security for our subprocessor list), including cloud hosting (Vercel), database (Neon), payments (Stripe), and AI (Anthropic).
  • Integrations you connect, at your direction.
  • Legal & safety: to comply with law, enforce our terms, or protect rights, property, and safety.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

7.Cookies and similar technologies

We use strictly necessary cookies to run the Service (e.g., authentication and security) and, only with your consent, optional cookies for analytics to understand and improve usage. You can accept or decline non-essential cookies via our banner, and control cookies through your browser. Declining optional cookies does not affect access to the Service.

8.Data retention

We retain personal and business data for as long as your account is active or as needed to provide the Service, then for a limited period as required to comply with legal obligations, resolve disputes, and enforce agreements. On termination, and subject to the DPA, we delete or de-identify Customer Data within a reasonable period after any export window. You may request earlier deletion where legally permitted.

9.Security

We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, per-company data isolation, and access controls. See our Security & Compliance page for details. No method of transmission or storage is 100% secure.

10.Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to opt out of certain processing, and to withdraw consent. To exercise rights, contact privacy@kpi360.ai; we will verify and respond as required by law and will not discriminate against you for exercising rights.

California (CCPA/CPRA). We do not sell or share personal information as defined by the CPRA. California residents may request to know, delete, and correct personal information, and may designate an authorized agent. New York and other states. Residents may have similar rights under applicable state law. For business data we process on your company’s behalf, please direct requests to that company (the controller); we will assist as its processor.

11.International data transfers

We operate the Service using infrastructure primarily located in the United States. If you access the Service from outside the U.S., you understand your information may be processed in the U.S. Where required, we rely on appropriate transfer mechanisms.

12.Children’s privacy

The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child provided us information, contact us and we will delete it.

13.Changes to this Policy

We may update this Policy. Material changes will be posted here with a new effective date and, where appropriate, communicated to you. Your continued use after the effective date constitutes acceptance.

14.Contact us

Privacy questions or requests: privacy@kpi360.ai. KPI360, New York, NY.