Back to home
Kivio
Kivio

Privacy Policy

Last updated: August 31, 2026

1. Introduction

Kivio (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our interactive email widget platform (“the Service”).

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Password (stored securely using bcrypt hashing)
  • Organization and company details
  • Google account information (if using Google OAuth)

2.2 Usage Data

We automatically collect:

  • Widget interaction data (views, submissions, conversions)
  • Feature usage and interaction patterns
  • Browser type, device information, and IP address (anonymized)
  • Pages visited and actions taken within the Service

2.3 Integration Data

When you connect third-party services (Klaviyo, Shopify, WooCommerce), we store OAuth tokens and access credentials securely. We may access:

  • Klaviyo: profile data, list and segment memberships, email templates, campaign and flow metrics, and account-level settings required to send and track emails
  • Shopify / WooCommerce: product catalog data, order and transaction events, and customer data as required to power email personalization and automation

2.4 Widget Submission Data

When end users interact with your email widgets, we collect the data they submit (e.g., review ratings, survey responses, phone numbers for SMS signup). This data is stored on behalf of your organization.

2.5 Your Customers’ Data

To power personalization and automation, we process data about your customers on your behalf. For this data you are the controller and we act as your processor. It includes:

  • Email addresses, used to match a recipient to their history in your store
  • Order and purchase history, used for product recommendations and to attribute revenue to your emails
  • Storefront browsing activity, described in section 2.6
  • Abandoned cart contents, and orders placed from within an email

We do not use your customers’ data to build profiles across merchants, and we do not use it to advertise to them on our own behalf.

2.6 Storefront Tracking

On Shopify, Kivio installs a web pixel on your storefront. It records which products a visitor views and, when a visitor submits a form or completes a checkout, associates that browsing with their email address so we can send browse-abandonment emails on your behalf.

The pixel only runs when the visitor has granted consent for analytics and marketing. It declares those requirements to Shopify, and Shopify will not load it without permission. Visitors control this through your store’s cookie banner or privacy settings.

2.7 Saved Payment Methods

If you enable card on file, a customer can choose at checkout to save their payment method so they can buy directly from a future email. We never see or store card numbers. Shopify stores the payment method; we store a reference to it together with the customer’s email address, their store customer ID, and a record of the consent they gave and when.

That reference is used only to place an order the customer initiates from one of your emails. It is revoked automatically when a data deletion request is received for that customer.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process transactions and manage subscriptions
  • Send transactional emails (password resets, payment confirmations, usage alerts)
  • Generate analytics and reports for your organization
  • Sync data with connected third-party platforms at your direction
  • Monitor for abuse and enforce our Terms of Service
  • Respond to support inquiries

4. Data Sharing

We do not sell your personal information. We may share data with:

  • Infrastructure: Vercel (application hosting), Neon (database hosting, United States)
  • Service providers: Stripe (payments), Mailgun and Postmark (transactional email), Sentry (error monitoring), Upstash (rate limiting), PostHog (product analytics)
  • Third-party integrations: Only when you explicitly connect them (Klaviyo, Shopify, WooCommerce)
  • Legal requirements: When required by law, subpoena, or legal process

5. Data Security

We implement industry-standard security measures including:

  • Encrypted data transmission (TLS/HTTPS)
  • Secure password hashing (bcrypt)
  • OAuth 2.0 with PKCE for third-party integrations
  • Rate limiting to prevent abuse
  • Role-based access control for multi-tenant data isolation

6. Data Retention

We retain your account data for as long as your account is active. Widget submission data is retained for the duration of your subscription. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.

If you uninstall the Kivio app from your Shopify store, Shopify notifies us and we delete the data we hold for that store, including your customers’ browsing history, attributed orders, abandoned carts and any saved payment method references.

7. Customer Data Requests

When one of your customers asks you to access or delete their data, Shopify forwards that request to us and we act on it:

  • Access requests: we compile the data we hold for that customer and provide it to you, within the 30 days Shopify allows.
  • Deletion requests: we delete that customer’s browsing history, attributed orders and abandoned carts, and revoke any saved payment method reference.

You can also reach us directly at hello@kivio.io to make a request on a customer’s behalf.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your personal data
  • Object to or restrict certain processing of your data
  • Export your data in a portable format
  • Withdraw consent at any time

To exercise these rights, contact us at hello@kivio.io.

9. Cookies and Tracking

Within the Kivio application we use essential cookies for authentication and session management, and we use Sentry for error tracking and PostHog and Vercel Analytics for product usage metrics.

Separately, on your storefront, Kivio’s web pixel tracks browsing in order to send browse-abandonment emails on your behalf. This is marketing activity and it runs only with the visitor’s consent, as described in section 2.6. We do not operate advertising networks, and we do not sell or share this data.

10. Children's Privacy

The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children.

11. International Data Transfers

Your data may be processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place for any international data transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Continued use after changes constitutes acceptance.

13. Contact

For privacy-related questions or concerns, contact us at hello@kivio.io.

See also our Terms of Service.