Privacy Policy
This policy explains what personal data Kindled collects, why, and the rights you have under UK data protection law. It is a working template — the items marked below must be confirmed before launch.
Last updated: Template — pending founder/legal review
[TODO — founder/legal to confirm] Confirm the legal entity (company name, number, registered address), the named data controller, and the Data Protection Officer / contact, then replace the placeholders throughout.
Who we are
Kindled ("we", "us") provides a group-gifting service that lets families and friends contribute towards shared gift wishes. For the purposes of UK GDPR, the data controller is the entity to be confirmed above.
What we collect
- Contact details you give us, e.g. your email address when you join the waitlist or create an account.
- Wish and contribution details: the wishes you create or contribute to, amounts, and any message or media you add.
- Payment data processed by our payment provider (see "Payments"). We do not store full card numbers.
- Technical data: essential cookies, device/browser information, and aggregated usage analytics (only with your consent).
How we use your data & our lawful bases
- To provide the service and process contributions — performance of a contract.
- To send you launch and early-access updates you asked for — consent (withdraw any time).
- To keep the service secure and prevent fraud — legitimate interests.
- To meet legal and financial-record obligations — legal obligation.
Cookies
We use strictly necessary cookies to make the site work. Optional analytics/marketing cookies are only set if you accept them in our consent banner, in line with PECR. You can change your choice at any time by clearing the "kindled-consent" preference in your browser.
Payments
Card and open-banking payments are handled by Stripe, our payment processor. Your card details are sent directly to Stripe and are not stored on our servers. See Stripe's own privacy notice for how they process payment data.
[TODO — founder/legal to confirm] Confirm the payment processor(s) actually used and link their privacy notice(s).
Children's data
Some features (e.g. star charts) relate to children but are set up and managed by a parent or guardian. We design these with the ICO's Age Appropriate Design Code ("Children's Code") in mind.
[TODO — founder/legal to confirm] Complete a Children's Code assessment: confirm what child data is processed, data-minimisation, default high-privacy settings, and that no child profiling or targeted marketing occurs. Legal to sign off.
Sharing & processors
We share data only with the processors needed to run the service (e.g. payment, email delivery, and hosting providers), under contract. We do not sell your personal data.
[TODO — founder/legal to confirm] List all sub-processors (hosting, email, payments, analytics) and the safeguards for any transfers outside the UK.
Video and voice messages
Messages recorded for a reveal are stored privately (never publicly listable) and exist to be seen once, by the recipient, at the reveal. Draft retention policy: sandbox recordings are deleted whenever the sandbox resets; in the live product we plan to delete reveal media 90 days after the reveal date, and you can ask us to delete yours at any time.
[TODO — founder/legal to confirm] Legal to confirm the 90-day retention window and the moderation process before launch.
How long we keep it
We keep personal data only as long as needed for the purposes above and to meet legal/financial-record requirements.
[TODO — founder/legal to confirm] Set concrete retention periods per data category.
Your rights
Under UK GDPR you can request access, correction, erasure, restriction, portability, or object to certain processing, and withdraw consent at any time. To exercise these, contact us via the contact page. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).