KitTrail Privacy Policy
Controller: Liubov Leonidovna Demidova, self-employed taxpayer under Russia’s Tax on Professional Income (NPD), INN 250362444501. For privacy requests: hello@getkittrail.com. Seller details are available on the Seller & Contact page.
This Policy describes data processing when visiting getkittrail.com, downloading KitTrail, activating a license, or contacting support. The website displays prices and an interactive checkout preview, but public payment, order placement, issuance of new paid licenses, and public email-based license recovery are not currently enabled. Prodamus is not connected.
Data processed
When a page or file is requested, technical infrastructure may process an IP address, request time, requested page or file, browser and device type, referral source, and technical information needed to deliver, diagnose, and protect the service. Hosting and object-storage systems may create their own request logs; each provider determines their exact contents and retention periods.
Cloudflare Web Analytics is enabled on the website. Its browser beacon measures page-load performance. Cloudflare says it does not use cookies or browser storage for this analytics service; a network request to Cloudflare is made. Cloudflare’s own documentation and terms govern its processing details.
The selected language and currency are used by the page interface; currency and the selected plan are carried in the URL query and browser history. The website does not use cookies or localStorage/sessionStorage to retain the currency choice and does not select currency from IP address, geolocation, or device region. The checkout preview includes an email field for browser-side format validation and for previewing the future delivery step. The website code does not read its value for another purpose, send it to a server, put it in the URL, or store it; browser form-history behavior depends on the visitor’s settings. Continuing only displays the unavailable-payment message and does not create an order.
If you email hello@getkittrail.com, we process your sender address, message, and any information you choose to include. Incoming messages sent to hello@getkittrail.com and privacy@getkittrail.com are forwarded through Porkbun to the KitTrail mailbox at Yandex Mail (kittrail@yandex.com), according to the owner-confirmed current routing. Porkbun and Yandex Mail process message content and metadata; their storage locations and retention are governed by their terms and mailbox settings.
When an already-issued license is activated, the application sends the Licensing server the license key and a device pseudonym derived on the Mac from the system identifier and license identifier. The application does not send the Mac’s raw system UUID. Deactivation sends an activation identifier and management credential. The server response contains information needed to verify the license locally. The Licensing service runs in Yandex Cloud. Questionnaire answers, selected tasks, detected applications, and the Mac setup profile are not sent by the application to the KitTrail website. Separate Homebrew, Mac App Store, and third-party developer processes are governed by their own terms.
Commerce/YDB and Postbox components exist for staging tests. The public website does not use them to accept orders, purchaser email addresses, or payments. Staging test messages are not public purchases. This Policy will be updated before those public collection processes are enabled.
KitTrail does not receive or store full bank-card credentials or CVV/CVC. There is no payment form or active payment provider on the current website.
Purposes and legal grounds
Technical data is used to deliver the website and downloads, protect the service, diagnose faults, and measure page performance. Support-message data is used to respond and provide support. License data is used to activate, enforce the purchased concurrent-device limit, deactivate, and restore access under an existing license. Processing is carried out to provide a requested service or perform a contract, comply with legal duties, protect legitimate service-security interests, or on consent where required.
Providers and data transfers
The services currently used include Hostinger (website hosting), Cloudflare (DNS and Web Analytics), Yandex Cloud (object storage and licensing), Porkbun (email forwarding), and Yandex Mail (receiving support and privacy messages). Yandex Cloud Commerce/YDB and Postbox are used for staging tests. These providers may process technical data as part of their services. Their precise logs, backups, processing locations, and retention periods are not fully controlled by the Controller. This Policy therefore does not claim that all data is stored only in Russia.
Some providers may process data outside Russia. Before starting or expanding a cross-border transfer, the Controller must satisfy applicable notice and other legal requirements. Prodamus is not currently accepting KitTrail payments; details of any future payment provider will be published before orders are enabled. KitTrail does not sell personal data.
Retention and security
Data is retained to the extent and for the time needed for the stated purposes, mandatory legal requirements, and protection of the parties’ rights. Specific periods depend on the record type, applicable requirements, and provider configuration; the Controller does not state one unverified period for all systems. Organizational and technical measures are used in proportion to the data processed. No Internet transmission can be guaranteed to be entirely risk-free.
Your rights and requests
Subject to applicable law, you may request information about processing, correction of inaccurate data, restriction or deletion where grounds exist, and withdraw consent where processing is based on consent. To protect data, the Controller may reasonably ask you to verify your identity or connection to a license. Send requests to hello@getkittrail.com.
Deleting data does not always terminate a license, and license termination does not always require deletion of every record. Minimal records may be retained when needed to perform a contract, verify a license, protect service security, or meet mandatory legal requirements.
Changes
This Policy may be updated when the website, application, infrastructure, or legal requirements change. The current version is published on the website. Material new collection processes will be described before they are enabled.