Last updated 30 August 2026
This policy covers two things that are easy to confuse. First, information about you as a visitor or enquirer on this website. Second, the operational data inside a client instance of Kestrelay, where we act on behalf of the business that bought it.
We do not run advertising trackers, analytics profiles or session recording on kestrelay.com. There is no cookie banner because there are no cookies to consent to.
When you submit the contact, demo or affiliate form we store what you typed: your name, company, email, phone if you gave one, and your message. We use it to answer you and, if you become a client, to set your account up. We do not sell it, rent it or add you to a marketing list you did not ask for.
Our web server keeps standard request logs including IP addresses for a short period, for security and troubleshooting.
Where a business runs Kestrelay, that business decides what goes into it and we process it on their instructions. Each client has its own separate database, its own backups and its own export.
What a client instance typically holds:
Images uploaded as attachments are re-encoded on arrival, which removes embedded camera metadata including GPS coordinates. That happens before the file is stored, so location data from a staff member's phone is never written to disk.
Attachments are purged automatically on a schedule the client sets per category, which is typically between thirty days and a year. Messages, receipts and audit records are retained for the life of the client account, because a receipt that disappears makes the report it supports untrue.
Sites and users are archived rather than deleted. A manager who left in March still has to appear as the person who acknowledged a notice in February. When a client account ends, we provide a full export and then delete the database.
Website enquiries are kept for two years unless you ask us to remove them sooner.
Data is held on servers we control. We use a small number of third parties, each for one job:
We do not use client data to train machine learning models, ours or anybody else's.
We do not keep standing accounts inside client systems. When support requires it, a session is issued from our control plane with a stated reason. It is read only unless the client agrees otherwise, it expires within an hour, and it is written into the client's own audit log. The client can see every occasion we looked and why.
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. Email privacy@kestrelay.com and we will respond within thirty days.
If the data sits inside a client instance, the client is the controller and we are the processor. Direct the request to that business and we will support them in answering it. We will not act on their data without their instruction, which is the same protection that keeps anyone else from doing so either.
If this policy changes materially we will tell active clients by email rather than quietly updating the date at the top.
Kestrelay, privacy@kestrelay.com