Kytbox

© Kytbox. All rights reserved.

TermsPrivacy
2026
Kytbox

Privacy Policy

Last updated: February 21, 2026

At Kytbox, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services ("Service").

1. Data Controller

Kytbox is operated by Mohd. Azmi Amirullah. A, based in Indonesia. For any data-related inquiries, you can reach us at support@kytbox.com.

2. Information We Collect

We collect information that you provide directly to us, such as when you create an account, update your profile, or communicate with us. This may include:

  • Name and contact information (email address).
  • Authentication data (managed securely by Supabase Auth).
  • Content you upload to the Service (bio links, cashflow data).

We also automatically collect certain technical information when you use the Service, including server access logs (IP address, browser type, timestamps) for security and operational purposes. We use privacy-friendly analytics (Vercel Web Analytics) which does not use cookies and does not collect personally identifiable information.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you signed up for (account management, content hosting, cashflow features).
  • Legitimate interest: Processing for security, fraud prevention, service improvement, and responding to support requests.
  • Consent: Where you have given explicit consent (e.g., subscribing to optional notifications).
  • Legal obligation: Processing required to comply with applicable laws (e.g., tax records for transactions).

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service.
  • Process transactions and send related information.
  • Send you technical notices, updates, security alerts, and support messages.
  • Respond to your comments, questions, and requests.

5. Data Sharing

We do not sell your personal data. We may share your information with third-party vendors and service providers who perform services on our behalf, such as:

  • Hosting and infrastructure (Vercel, Supabase).
  • Rate limiting and security (Upstash).
  • Analytics (Vercel Web Analytics — privacy-friendly, no PII).
  • Performance monitoring (Vercel Speed Insights — no PII).

6. International Data Transfers

Your data may be transferred to and processed in countries other than your own, including the United States (where Vercel operates). We rely on the following safeguards for these transfers:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission, incorporated into our agreements with sub-processors.
  • Adequacy decisions where applicable under the relevant data protection framework.

By using the Service, you acknowledge these transfers. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. You may request deletion of your account and personal data at any time by contacting us at support@kytbox.com. We will process deletion requests within 30 days, except where we are required to retain data for legal or compliance purposes.

Server access logs (including IP addresses) are retained for a reasonable period for security and operational purposes and are periodically purged.

8. Data Security

We implement appropriate technical and organizational measures to protect the security of your personal information, including encryption in transit (TLS) and at rest. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure.

In the event of a data breach that affects your personal data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law.

9. Your Rights

Depending on your location (including under the GDPR for EEA residents), you may have the right to:

  • Access and receive a copy of your personal data.
  • Correct inaccurate personal data.
  • Request deletion of your personal data.
  • Restrict or object to the processing of your data.
  • Data portability (receive your data in a structured format).
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with a supervisory authority if you believe your rights have been violated.

You can manage most of your data directly within your account settings. To exercise any other rights, contact us at support@kytbox.com. We will respond to your request within 30 days.

10. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies. You can instruct your browser to refuse all cookies, but this may affect your ability to use the Service.

11. Children's Privacy

Our Service is not addressed to anyone under the age of 13 (or 16 in the EEA). We do not knowingly collect personal identifiable information from children under these ages. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

12. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and, where practicable, sending you an email notification.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@kytbox.com.

© Kytbox. All rights reserved.

TermsPrivacy
2026