KimePush is a Kimevik product that provides push notification and email delivery infrastructure. This Privacy Policy explains how Kimevik ("Kimevik", "we", "us", "our") collects, uses, discloses, and protects information in connection with KimePush (the "Service"). It applies both to developers and organisations who create a KimePush account ("Customers") and to the end users of Customers' own apps and products whose device tokens, email addresses, and related data Customers send to us through the Service ("End Users"). By using the Service, you agree to the collection and use of information as described in this Policy.
1. Two Kinds of Data
Customers use our API and dashboard to send push notifications (via Firebase Cloud Messaging, Apple Push Notification service, and Web Push) and email (via Amazon SES) to their own End Users. Because of this, we handle two distinct categories of personal information, and our role is different for each:
- Customer Account Data — information about the Customer themselves.
- End User Data — information about a Customer's own users, submitted to us so we can deliver notifications and emails on the Customer's behalf.
We are a data controller for Customer Account Data, and a data processor (service provider) for End User Data. Section 4 explains this distinction.
2. Information We Collect
Customer Account Data
- Identity and contact details: name, email address, password (stored as a salted hash, never in plain text), or Google OAuth identifier.
- Organisation details: account and project names, team member roles and invitations.
- Billing information: billing address and payment details processed by our payment processor, Stripe — we do not store full card numbers.
- Authentication data: API keys (stored as SHA-256 hashes, never in plain text), session tokens, admin access records.
- Support communications you send to support-kimepush@kimevik.com.
- Technical and usage data: login timestamps, IP address, browser/device type, and API request metadata (endpoint, timestamp, response status, rate-limit counters).
End User Data (processed on behalf of Customers)
Customers may submit the following to our API to deliver notifications and emails to their own End Users:
- Device push tokens and platform identifiers (FCM registration tokens, APNs device tokens, Web Push subscriptions).
- Contact information the Customer chooses to provide: email address, mobile number, first/last name.
- Custom variables attached to a contact or send request (e.g. order IDs, personalisation fields).
- Topic and tag subscriptions, and unsubscribe/suppression records.
- Delivery and engagement telemetry: send/delivery/failure status, opens and clicks for email, and device platform/app version metadata submitted at registration.
We do not decide what End User Data a Customer submits and have no direct relationship with End Users. Customers are solely responsible for the accuracy and lawfulness of the End User Data they submit — see Section 5.
Automatically Collected Data
- A session cookie for the dashboard, and a Cloudflare Turnstile challenge token used to distinguish humans from bots at sign-up and login. We do not use advertising or cross-site tracking cookies.
- Aggregated, de-identified analytics about API and delivery volume, used to operate rate limiting, billing, and service reliability.
3. How We Use Information
We use Customer Account Data to provide and maintain the Service, authenticate accounts and enforce plan limits, process payments and manage billing, send service and security notifications, respond to support requests, detect and prevent fraud and abuse, and improve the Service.
We use End User Data solely to route and deliver the push notifications and emails a Customer requests; maintain delivery and suppression state, so we do not send to a token or address that has bounced, unsubscribed, or been removed; provide the Customer with delivery analytics; and enforce fair-usage and anti-abuse controls that protect deliverability for all Customers, including detecting compromised API keys or sending patterns that risk our reputation with Apple, Google, or Amazon.
We do not sell personal information, and we do not use End User Data for our own advertising or marketing purposes.
4. Our Role: Controller and Processor
For Customer Account Data, Kimevik is the data controller. For End User Data, Kimevik acts as a data processor / service provider on behalf of the Customer, who is the data controller. The Customer determines what End User Data is submitted, obtains any consents or provides any notices required for its own End Users, and instructs us — via the API — on how that data is used. Our Terms of Service, together with this Policy, form the data processing terms between Kimevik and the Customer for End User Data. If you are an End User with a question about how your data is used, please contact the organisation that sent you the message, as we do not hold an independent relationship with or verified identity for End Users.
5. How We Share Information
We share data with the following service providers ("subprocessors"), strictly to operate the Service:
- Cloudflare — hosting for our API, web, and admin applications, database (D1), key-value storage, message queues, object storage, bot protection (Turnstile), and analytics.
- Amazon Web Services (Amazon SES) — email delivery infrastructure.
- Google (Firebase Cloud Messaging, Google OAuth) — Android/web push delivery and optional "Sign in with Google" authentication.
- Apple (Apple Push Notification service) — iOS push delivery.
- Stripe — payment processing and subscription billing.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes. We may disclose information where required by law, to comply with legal process, to protect the rights, property, or safety of Kimevik, our Customers, or others, or in connection with a merger, acquisition, or sale of assets.
6. International Data Transfers
Kimevik and the subprocessors listed above operate infrastructure in multiple countries, including the United States. By using the Service, Customer Account Data and End User Data may be processed and stored outside Australia. We take reasonable steps to ensure recipients of data provide a comparable standard of protection, consistent with Australian Privacy Principle 8.
7. Data Retention
We retain Customer Account Data for as long as an account is active, and for a reasonable period afterward to meet legal, tax, billing, and dispute-resolution obligations. End User Data is retained according to the Customer's plan-configured log retention period, after which it is automatically pruned; Customers may also delete contacts, tokens, or projects directly at any time via the API or dashboard.
8. Security
We use safeguards appropriate to the sensitivity of the data we hold, including encryption in transit (TLS), encryption at rest for sensitive credentials, hashed storage of passwords and API keys, role-based admin access with a manual approval step, and rate limiting and anti-abuse controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
If you are a Customer, you may access, correct, export, or request deletion of your Customer Account Data at any time via the dashboard, or by contacting support-kimepush@kimevik.com.
If you are an Australian individual, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, including the right to access and correct your personal information and to make a complaint. Complaints may also be made to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
If you are located in the European Economic Area, the UK, or a jurisdiction with similar data protection laws, you may have additional rights, such as the right to object to or restrict certain processing — contact us to exercise these.
If you are an End User with questions about a specific message you received, please contact the Customer who sent it, as explained in Section 4.
10. Children's Privacy
The Service is intended for business and developer use and is not directed at children. We do not knowingly collect Customer Account Data from anyone under 16. Customers are responsible for ensuring their own use of the Service in relation to End Users, including any minors, complies with applicable law.
11. Data Breach Notification
In the event of a data breach likely to result in serious harm, we will notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme, and will notify affected Customers without undue delay so they can meet their own notification obligations.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by a new version date at the top of this page and, where required, additional notice will be provided to Customers. Continued use of the Service after an update constitutes acceptance of the revised Policy.
13. Contact Us
Questions about this Privacy Policy or our data practices can be sent to support-kimepush@kimevik.com.