Skip to content
Keelstar

Legal

Privacy Policy

Effective date: July 7, 2026

This Privacy Policy describes how information is collected, used, disclosed, and safeguarded when you access or use this website and related online services (collectively, the “Service”). By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1. Roles and scope

For account, billing, and platform operation data, we act as a controller or business, as applicable under privacy law. For documents, vendor records, workflow content, and other materials you or your organization upload or generate through the Service (“Customer Content”), we generally act as a processor or service provider on your instructions. You are responsible for providing any required notices and obtaining any required consents from your users, vendors, employees, and other individuals whose data you submit.

2. Information we collect

  • Account and profile data: name, email address, authentication credentials, organization affiliation, role assignments, and preferences you provide.
  • Customer Content: files, metadata, form responses, signatures, comments, audit events, and workflow records you or your invitees submit.
  • Billing data: subscription status, plan selections, and payment-related identifiers processed by our payment provider. We do not store full payment card numbers on our servers.
  • Technical and usage data: IP address, device and browser type, log files, timestamps, pages viewed, feature usage, error reports, and security signals.
  • Communications: support requests, feedback, and messages you send to us.
  • Information from third parties: identity verification, fraud prevention, email delivery, analytics, hosting, and integration partners, as configured for the Service.

3. How we use information

We use information to:

  • provide, operate, maintain, secure, and improve the Service;
  • authenticate users, enforce access controls, and prevent abuse;
  • process transactions and manage subscriptions;
  • send transactional, security, and service-related communications;
  • generate logs, audit trails, and operational metrics;
  • comply with law, respond to lawful requests, and protect rights and safety;
  • develop new features and fix defects, including through automated processing of uploaded content where enabled.

We do not sell personal information. We do not use Customer Content to train generalized public machine learning models unless you separately opt in to a feature that expressly states otherwise.

4. Legal bases (where applicable)

Where required, we rely on contract performance, legitimate interests (such as security, fraud prevention, and product improvement), legal obligation, and consent where appropriate.

5. How we share information

We may share information with:

  • Service providers and subprocessors that host infrastructure, deliver email, process payments, provide analytics, or otherwise support the Service under contractual confidentiality and security obligations;
  • Your organization and authorized users according to your workspace permissions;
  • External recipients you direct through magic links, vendor portals, signature requests, or similar workflow features;
  • Professional advisers, auditors, and potential transaction parties under confidentiality obligations;
  • Law enforcement or regulators when required by law or when we believe disclosure is necessary to protect rights, safety, or the integrity of the Service.

We may also share aggregated or de-identified information that cannot reasonably identify you.

6. International transfers

Information may be processed in countries other than your own. Where required, we implement appropriate safeguards for cross-border transfers.

7. Retention

We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. Retention periods may vary by data category and your organization's settings. You may request deletion subject to applicable law and technical limitations.

8. Security

We implement administrative, technical, and organizational measures designed to protect information. However, no method of transmission or storage is completely secure. You are responsible for safeguarding your credentials and configuring access within your organization appropriately.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal information, and to withdraw consent where processing is consent-based. Organization administrators may control much of the data in a workspace. To exercise rights, contact us using the details below. We may need to verify your request and may deny requests where permitted by law.

10. Cookies and similar technologies

We use cookies, local storage, and similar technologies for authentication, security, preferences, and analytics. You can control cookies through browser settings; disabling some cookies may impair functionality.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.

12. Third-party sites and integrations

The Service may link to or integrate with third-party services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use after changes become effective constitutes acceptance of the revised Policy.

14. Contact

Privacy questions or requests: contact@keelstar.com.

This Policy is provided for operational transparency. It is not legal advice. Consider independent counsel review for your jurisdiction and use case.