KTeC is a platform that lets apparel and print businesses launch a branded online store, design products in 3D, and receive and manage orders. This Privacy Policy is our commitment to being clear about the personal information that flows through that platform: what we gather, why we gather it, how it is protected, who we rely on to help run the service, how long we keep it, and the choices and rights you have over it.
We have written this policy to be genuinely readable, but also complete enough to stand up to the privacy laws that may apply to you or to your customers, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), similar US state laws, and Canada's PIPEDA. Where a specific law gives you more rights than the general text, that law controls for you.
This policy is part of, and should be read together with, our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms.
This policy applies to personal information handled through:
It applies to three kinds of people:
It does not cover any third-party website, payment app, or service that we link to or that a store owner connects; those are governed by their own policies.
KTeC is a multi-tenant platform, so responsibility for a given piece of data depends on whose data it is. This distinction runs through the whole policy, so it is worth stating plainly.
For a store owner's own account data — the owner's name, email, business details, login, plan, and billing status — KTeC decides how that data is used to provide and improve the service. Here KTeC is the controller, and this policy governs directly.
For personal data that a shopper provides through a particular store — orders, customer accounts, loyalty balances, bookings, newsletter sign-ups, gift-card requests — the store owner is the controller and KTeC is the processor. We store and process that data on the owner's behalf, under the owner's instructions, to provide the features the owner enabled. Shoppers with questions about a specific store should contact that store owner first, since the owner decides what data to collect and why.
If you are a shopper, the store you bought from is primarily responsible for your data, and KTeC supports that store as its processor. If you are a store owner, you carry controller responsibilities toward your shoppers, described in section 30.
When you create and run a KTeC store, we collect the following, most of which you enter yourself:
| Category | Examples |
|---|---|
| Identity | First and last name, business name. |
| Contact | Email address; the city and state you enter at signup. |
| Store identity | The store link (slug) you choose, which becomes your public URL. |
| Credentials | Chosen username; password stored only as a bcrypt one-way hash. A device-saved login copy exists only if you opt in. |
| Commercial | Selected plan, trial start date, and subscription state. |
| Catalogue | Products, prices, descriptions, and images you add. |
| Brand | Logo, brand colours, font choice, and the design style assigned to your store. |
| Support | Anything you send us by email or through support. |
We ask for each of these for a specific, limited reason: identity and contact data let us open your account, address you correctly, and reach you about it; the store link becomes your public address; credentials let you sign in securely; commercial data lets us place you on the right plan and bill it; catalogue and brand data are what actually appear in your store; and support data lets us help you. We do not ask for more than the service needs, and we do not require special categories of data (such as health, race, religion, or precise geolocation) to run a store.
You do not have to give us data that is not requested. Some fields are optional and simply improve your store (for example a logo). If you choose not to provide the data needed to open or run a store (for example an email or a store link), we may be unable to provide the service or a particular feature.
You can view and update most of your account and store data yourself in the dashboard at any time. Please keep it accurate and current, especially your email, since that is how we reach you about your account and send important notices.
Before signup you can take a short "vibe quiz." The quiz is a small set of tap-only questions.
Your tapped answers, and a colour-mood choice, are used to select which of our design styles best fits your brand. The answers themselves are simple category selections, not free text about you.
The matching runs in your browser. The result — a structure, a primary colour, a secondary colour, a font, and a style name — is stored in your browser's local storage, and once you create a store it is saved to your store record so your storefront wears that look.
Quiz answers are not sold, are not used to build an advertising profile, and are not shared for marketing. They exist only to design your store, and you can change your store's look at any time in the dashboard.
To make your store yours, we store the brand assets you provide (logo, colours, font) and the catalogue you build (products, prices, descriptions, images).
Your storefront includes a 3D customizer where you or your shoppers place artwork and text onto a 3D garment (for example a tee, hoodie, hat, or tote). Designs created or uploaded through the customizer, and any resulting order, are stored so the order can be produced and fulfilled. Uploaded artwork may be an image file that you or a shopper choose to add. You are responsible for holding the rights to any artwork uploaded through your store; see the Terms.
The customizer includes a "remove background" tool. This runs entirely on your own device using an in-browser machine-learning model. The image you process for that step is not uploaded to KTeC or to any third party; the computation happens locally in your browser. The processed image only reaches our storage if you then choose to save it to a product or an order. Because processing is local, it may take a few seconds depending on your device and image size.
When a shopper interacts with a store built on KTeC, we process — on the store owner's behalf — whatever that interaction requires. This may include:
KTeC does not collect card numbers from shoppers. As described in the Terms, shopper payments are made directly to the store owner's own payment account; KTeC does not hold those funds and does not receive card data from the storefront.
A KTeC storefront is designed to ask a shopper only for what an order needs. We do not ask shoppers for government IDs, precise device geolocation, or sensitive categories of data, and we do not require a shopper to create an account to browse. A store owner may choose to collect additional details through their own forms; when they do, that owner is responsible for asking only for what they need and for telling shoppers why.
We build features to collect the minimum necessary. For example, the newsletter feature stores an email address; the bookings feature stores the details needed to schedule an appointment. We do not silently gather more than the feature requires.
Depending on which features a store owner turns on, the following data may be processed, always on the owner's behalf and under the owner's control:
| Feature | What is processed | Typical purpose |
|---|---|---|
| Orders & dashboard | Order contents, customizations, and any contact/pickup details a shopper supplies. | Receive, view, and fulfil orders. |
| Customer accounts | Shopper email/username, hashed password, order history. | Let shoppers sign in and see their orders. |
| Loyalty | Points earned and redeemed, voucher codes, tied to an account or order. | Run a rewards programme. |
| Bookings | Requested date/time and the contact details a shopper provides for an appointment. | Take appointment requests. |
| Newsletter | Email addresses of shoppers who subscribe. | Let the owner email subscribers. |
| Gift cards | Gift-card requests and the details needed to issue or redeem them. | Issue and redeem gift cards. |
| Shop / catalogue | Product data the owner enters and shopper selections. | Display and sell products. |
A store owner controls which of these features are active and is the controller of the resulting shopper data. KTeC does not enable these features for its own purposes.
To keep the platform working, we automatically collect a limited amount of technical data when a page loads or something goes wrong.
Our hosting provider processes basic request data needed to serve any website, such as IP address, approximate location derived from it, browser and device type, and timestamps. This is used for delivery, performance, security, and abuse prevention.
KTeC includes a platform-wide error monitor. When a script error happens on a store or in the dashboard, we may record technical details of that error — such as the error message, the page or component where it occurred, and browser information — so we can find and fix bugs across every store. These reports are used strictly for diagnostics and platform reliability. They are not used for advertising and are not sold.
We may produce aggregated or de-identified statistics (for example counts of stores or orders, or how often a feature is used) that do not identify any individual. We use such data to understand and improve the service, and we may share it. When we hold data in a de-identified form, we maintain it as de-identified, do not attempt to re-identify it, and commit to that treatment as required by law.
We get personal data from three sources: (a) directly from you, when you sign up, build your store, or contact us; (b) automatically, from your device and browser as you use the service, as described in section 11; and (c) from a store owner, when we process shopper data on that owner's behalf. We do not buy personal data from data brokers to build marketing profiles.
Occasionally we may also receive limited data from a provider that helps us run the service (for example a payment status from Stripe about your own subscription). We use such data only for the purpose it was shared, such as keeping your subscription current. We do not enrich your profile with data purchased from third parties.
KTeC does not use advertising cookies or cross-site tracking. We rely mainly on your browser's local storage — not third-party ad cookies — to run the product. The table below describes the main items; exact names may change as the product evolves.
| Item | Purpose | Roughly how long |
|---|---|---|
| Sign-in / session state | Keeps you logged into your dashboard. | Until you sign out or it expires. |
| Store branding & account summary | Loads your look and account quickly. | Until changed or cleared. |
| Vibe-quiz result & pending style | Carries your chosen design into signup. | Short-lived; cleared after signup. |
| Saved login (opt-in) | Fills in your email, username, password next time — only if you tick the box. | Until you sign out or clear it. |
| Storefront session | Keeps a shopper's cart/session and, if enabled, their signed-in state. | Session-based. |
You can clear local storage and cookies at any time through your browser settings, usually under "Privacy" or "Site data." In most browsers you can also block or delete storage for a specific site. Signing out of your dashboard clears your session and any saved login. Note that blocking strictly necessary storage may stop parts of the service from working, including staying signed in.
We do not embed third-party advertising or social-media tracking pixels on our pages. Loading web fonts from Google Fonts does not set an advertising cookie, but Google receives the request (including your IP address) to deliver the font, as noted in the sub-processor section.
Because we do not track you across other websites for advertising, there is nothing for a "Do Not Track" signal to stop. Where required by law, we treat a recognised opt-out preference signal (such as Global Privacy Control) as a valid request to opt out of "sale" or "sharing" — though, again, we do not sell or share personal information for advertising.
We use personal data only for these purposes:
We do not use your data, or your shoppers' data, for behavioural advertising, and we do not sell it.
We may send you service messages about your account, security, billing, and important changes; these are part of providing the service and are not marketing. If we ever send optional product-update or promotional emails, we will do so only where permitted, and every such email includes an easy way to unsubscribe. Unsubscribing from marketing does not stop essential service messages, which we must send to run your account. Any newsletter you run for your own shoppers is separate: you are the sender and controller of that, and you are responsible for consent and unsubscribes there.
We will not use personal data for a new, unrelated purpose without first updating this policy and, where the law requires it, obtaining your consent.
Where the GDPR applies, we rely on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Create your account, build/host your store, provide features | Performance of a contract |
| Logins and account/platform security | Contract; legitimate interests (security) |
| Billing and fraud prevention | Contract; legal obligation |
| Error monitoring and reliability | Legitimate interests (a working service) |
| Support and service communications | Contract; legitimate interests |
| Legal, tax, accounting compliance | Legal obligation |
| Any optional marketing emails | Consent, which you can withdraw |
Where we rely on legitimate interests, we have weighed those interests against your rights. You may object to that processing as described in your rights section.
When paid subscriptions are enabled, KTeC's own billing is handled by Stripe. Stripe collects and processes your card details directly and securely; KTeC does not store full card numbers and receives from Stripe only what it needs to manage your subscription (for example the last four digits, card brand, and payment status). Stripe processes card data as an independent controller under its own privacy policy.
Separately, on the storefront side, shopper payments for orders go directly to the store owner's own payment account (for example Cash App or PayPal). KTeC neither collects nor holds those funds and does not process shopper card data.
Because shopper payments happen on the store owner's own payment app, the card and financial details of a purchase are handled by that app under its own privacy policy, not by KTeC. KTeC records only the order information the store needs to fulfil it (items, options, and any contact/pickup details the shopper provides), not card numbers. If you are a shopper, review the payment app's privacy policy for how it handles your payment data.
For KTeC's own subscription billing, Stripe may use device and transaction signals to help detect and prevent fraudulent charges. This helps protect both you and us and is part of providing a secure billing service.
We rely on a small set of trusted providers to run KTeC. Each handles only the data needed for its role and is bound to protect it.
| Provider | Role | Data it may handle |
|---|---|---|
| Supabase | Database & authentication | Account data, store data, orders, shopper data |
| Cloudflare | Hosting, delivery & security | Request/technical data, IP addresses |
| Stripe | Subscription payments (when enabled) | Billing and card data |
| Google Fonts | Web fonts on our pages | Your IP address is seen by Google when fonts load |
Each provider is bound by its own agreement and privacy commitments and may process data only for the purpose of providing its service to us. The in-browser background-remover model runs locally on your device and is not a sub-processor, because your image is not sent to it over the network. We keep this list current as the service grows and will update it here when we add or change a key provider. If we add an AI model provider for an AI feature, we will list it here while that feature is live.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal data only in these situations:
We disclose data to authorities only when we believe in good faith that we are legally required to, or that disclosure is reasonably necessary to comply with a legal process, protect someone's safety, prevent fraud or abuse, or defend our legal rights. Where we are permitted to, and it is lawful and practical, we will try to notify an affected store owner of a request for their data so they can respond.
We do not sell, rent, or trade personal information to data brokers, advertisers, or marketing networks, and we do not build or sell profiles of you or your shoppers.
KTeC is operated by Kidus Digital Group, and our providers may process data on servers located in other countries, including the United States. If you are in the EEA, the UK, or another region with transfer rules, your data may be transferred to and processed in a country whose laws differ from yours. Where required, such transfers rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) entered into by our providers, or another lawful transfer mechanism. By using KTeC you understand your data may be processed in these locations. You can contact us for more information about the safeguards in place.
Our main infrastructure providers (Supabase, Cloudflare, Stripe) operate global networks and publish their own data-transfer terms and, where applicable, their standard contractual clauses. We choose providers that offer these protections so that data moved across borders on our behalf stays covered by appropriate safeguards.
We keep personal data only as long as we need it for the purposes in this policy, then delete or de-identify it. As a general guide:
| Data | Kept for |
|---|---|
| Account and store data | While your account is active. |
| Catalogue and brand assets | While your store exists. |
| Shopper and order data | As long as the store owner keeps their store, so orders can be serviced and referenced. |
| Error / diagnostic data | Only as long as useful for debugging, then cleared. |
| Billing records | As long as required for tax and accounting. |
| Support emails | As long as needed to handle and reference your request. |
| Backups | For a limited rolling period, after which older copies age out. |
When an account is closed, we delete the store and associated personal data after a reasonable wind-down period, except where we must keep records for legal or accounting reasons or to resolve disputes.
Where a fixed period is not set by law, we decide how long to keep data based on: how long we need it to provide the service; whether you or a store owner still needs it (for example to service past orders); our legal, tax, and accounting obligations; and whether we need it to resolve disputes or enforce our agreements. When data is no longer needed for any of these, we delete it or de-identify it so it can no longer be linked to you.
Deleting data from the live service does not instantly erase it from routine backups. Backup copies age out on a rolling schedule, after which the deleted data is gone from them too. While it remains in a backup, it is not used for any active purpose.
We take reasonable technical and organisational measures to protect personal data, including:
Access to systems that hold personal data is limited to people who need it to operate the service, and administrative actions run through defined, permission-checked paths rather than open access. We use reputable infrastructure providers that maintain their own security programs.
No system is perfectly secure, and we cannot guarantee absolute security. You also play a part: keep your login private, use a strong and unique password, sign out on shared devices, and only tick "Save my login on this device" on a private device you control, because anyone using that browser could then sign in as you. If you run a store, keeping your own login secure is the single biggest thing you can do to protect your shoppers' data.
If you believe you have found a security issue in KTeC, please report it to us at the contact address below so we can investigate and fix it. Please do not exploit it or access data that is not yours.
If we become aware of a security incident that affects personal data, we will investigate promptly, take steps to contain and remediate it, and, where the law requires, notify the relevant authorities and affected people within the applicable timeframes. Where KTeC acts as a processor for a store owner, we will notify the affected store owner so that owner can meet its own notification duties.
Depending on where you live, you may have some or all of these rights:
Email us at the address in section 35, describing the right you want to exercise. We will take reasonable steps to verify your identity before acting, to protect your data. We may ask for information that matches what we already hold.
We respond within the time the applicable law allows (commonly 30–45 days, extendable where permitted for complex requests). Requests are usually free; we may charge a reasonable fee or decline a request that is excessive or clearly unfounded, as the law permits.
Where the law allows, you may use an authorised agent to make a request on your behalf; we may require proof of the agent's authority and verification of your identity.
If your request concerns data we hold on behalf of a specific store (as a processor), we may direct you to that store owner as the controller, or coordinate with them to fulfil your request.
If we decline your request and the law that applies to you provides an appeal process, our written response will explain how to appeal. You may also have the right to complain to a data protection authority.
To protect your data, we act only on requests we can reasonably verify come from you (or your authorised agent). We will not disclose personal data to someone who cannot be verified, and we may decline or pause a request while we confirm identity.
If you are in the European Economic Area or the United Kingdom, the controller of your store-owner account data is Kidus Digital Group. Our lawful bases are set out in section 16. You have the GDPR rights listed above, including the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concern first, so please consider contacting us before you complain.
Where we act as a processor for a store owner (for shopper data), the store owner is the controller and is your first point of contact for those rights; we will support the owner in responding. We do not carry out large-scale profiling or automated decisions with legal effects, so those specific GDPR provisions do not generally apply. If you need details of the safeguards we use for international transfers, contact us and we will provide them.
This section applies to California residents and uses the categories defined by the CCPA/CPRA. In the past 12 months we have collected the categories below, from the sources in section 12, for the business purposes in section 15, and disclosed them only to the recipients in section 19 (our sub-processors and, for shopper data, the relevant store owner). We have not sold and have not shared (for cross-context behavioural advertising) any category.
| Category | Examples we collect | Retention |
|---|---|---|
| Identifiers | Name, email, business name, username, store link, IP address. | While your account/store is active; see section 21. |
| Customer records | Account and login information (password stored only as a hash). | While your account is active. |
| Commercial information | Plan, trial start, subscription status, catalogue, and orders. | While the store exists; billing records per law. |
| Internet/network activity | Device and browser data, pages viewed, and error/diagnostic data. | As long as useful for reliability, then cleared. |
| Geolocation | Approximate location derived from IP; the city/state you enter. | With the related record; not precise geolocation. |
| Visual/content | Logos, product images, and designs you or your shoppers upload. | While the store exists. |
| Inferences | The design style suggested from your quiz answers. | While the store exists; changeable anytime. |
We do not seek to collect "sensitive personal information" as defined by California law (such as government IDs, precise geolocation, race, religion, health, or account log-in combined with a password for another account). Passwords you set for KTeC are stored only as one-way hashes and are used solely to authenticate you. Because we do not use or disclose sensitive personal information for purposes that would trigger a right to limit, that right does not generally apply, but you may still contact us with any concern.
This policy, together with what we show you at the point you provide data, serves as our "notice at collection": it tells you the categories we collect, the purposes, and that we do not sell or share your data.
California residents have the right to know, delete, correct, and limit certain uses of sensitive personal information, and the right not to be discriminated against for exercising these rights. To exercise them, use the contact in section 35. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit.
Residents of states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others as they take effect) have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Because KTeC does not sell personal data, does not use it for targeted advertising, and does not conduct profiling that produces legal or similarly significant effects, those opt-outs generally do not apply, but we will honour access, correction, deletion, and portability requests as those laws require. Some of these laws offer an appeal process if we deny a request; if we deny yours, our response will explain how to appeal.
To exercise a right under any of these laws, use the contact in section 35 and tell us which state you reside in and which right you wish to use. We apply the same core protections to everyone: we do not sell your data, we do not advertise to you based on tracking, and we give you meaningful control over the data we hold. Where a state law grants a right not expressly listed here, we will honour it to the extent it applies to you.
If you are in Canada, we handle personal information in line with PIPEDA's principles: we are accountable for the data in our care; we identify the purposes for collection; we seek consent where appropriate; we limit collection, use, disclosure, and retention to those purposes; we keep data accurate; we safeguard it; we are open about our practices in this policy; we give you access to your data on request; and we provide a way to challenge our compliance. You may direct a privacy concern to us and, if it remains unresolved, to the Office of the Privacy Commissioner of Canada or your applicable provincial regulator.
As a store owner you are the controller of your shoppers' personal data, and KTeC is your processor for that data. You agree to:
KTeC processes shopper data solely to provide the store features you enable, does not use it for its own purposes, and does not sell it. The processing terms in our Terms of Service also apply.
You are responsible for the lawfulness of the data you collect through your store, for the notices and consents you owe your shoppers, and for using KTeC's features in a compliant way. You must not use the service to collect special-category or sensitive data you are not permitted to handle.
KTeC may offer optional AI-assisted features, such as a shopper assistant or a design generator. When such a feature is active and you use it, the text or prompt you enter is processed to produce a response. AI features may be turned off platform-wide at our discretion. We do not use your private account data to train third-party advertising models. Where an AI feature relies on a third-party model provider, that provider processes the input under its own terms, and we will identify such providers in the sub-processor list when a feature is live.
The vibe quiz automatically selects a design style from your answers. This is an automated process, but it has no legal or similarly significant effect on you: it only chooses a look, which you can change at any time. We do not use automated decision-making to deny you the service, set your price based on a profile, or make other decisions with a significant effect on you.
If we ever introduce a feature that would make an automated decision with a legal or similarly significant effect, we would first tell you, explain the logic in general terms, and provide the safeguards the law requires, such as a way to get human review. You can always reach a person by using the contact details below.
KTeC is a business tool intended for adults and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it. Store owners are responsible for ensuring their own stores are not directed to children in a way that violates the law, and for any additional consent that children's-privacy laws (such as COPPA or the UK Children's Code) may require of a store aimed at younger audiences.
Our site, stores, and dashboards may link to third-party websites or connect third-party services (for example a payment app a store owner uses). We do not control those services, and this policy does not apply to them. Review their privacy policies before providing them your data. In particular, when you pay a store through the owner's payment app, that app processes your payment under its own policy; when a store links to a social profile or external site, that destination has its own practices. We are not responsible for the content or privacy practices of any third party.
We may update this policy as KTeC grows and as we add features or as laws change. We will change the "Last updated" date above and, for significant changes, provide reasonable notice (for example a notice in the dashboard or by email). Continuing to use KTeC after a change means you accept the updated policy. We encourage you to review this page periodically.
Privacy questions, or a request to access, correct, export, or delete your data? Email [email protected]. KTeC is operated by Kidus Digital Group. If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data protection authority, though we would welcome the chance to resolve your concern first.
← Back to KTeC