Privacy Policy
Last updated: August 2026
Draft — not yet reviewed by counsel. This document describes how Kestrant actually works today and is structured for a lawyer to review and finalize. It is not legal advice and should not be published as final terms before that review.
Kestrant is financial planning and analysis software for businesses. This policy explains what we collect, why, and what we do not do with it. It is written to describe the system as it actually behaves.
What we collect
Account data. Name, work email, company name and role. This is what identifies a user and controls what they can see.
Financial data you upload. The spreadsheets you import and the figures derived from them. This is your company's data — we process it to render your reports and for nothing else.
Operational records. Audit events (who imported, approved, adjusted or exported what, and when), import provenance (file name, sheet, row and column behind each figure), and technical logs.
What we do not do
We do not sell your data. We do not use your financial figures to train models offered to other customers. We do not show advertising. We do not share your data with third parties except the infrastructure providers listed below, which process it on our instruction to run the service.
Sub-processors
Supabase — database, authentication and file storage. Vercel — application hosting. Resend — transactional email (invitations, notifications). Stripe — payment processing; Stripe receives billing details, never your financial reports. Each is bound by its own data processing terms.
Where data lives and how long we keep it
Data is stored in our provider's managed infrastructure. While your subscription is active we retain your data so your history stays intact — a reporting system whose past disappears is not useful. After termination we retain data for 30 days so you can export it, then delete it. Audit records are retained for seven years, because they exist precisely to survive the events they describe; they contain who did what and when, not the content of your statements.
Your rights
You can export your data at any time from within the product, in spreadsheet form. You can request correction or deletion by writing to us; we will confirm the request with an authorized administrator of your company before acting on it, because a deletion request is irreversible and affects everyone on your team.
Depending on where you are, you may have rights under GDPR, CCPA/CPRA or PIPEDA to access, correct, port or delete personal data, and to object to processing. We honour those rights regardless of jurisdiction.
Security
Access to company data is enforced at the database level, not only in the interface, so one company can never read another's figures. Passwords are hashed by our authentication provider and are never visible to us. See the security page for detail.
Children
Kestrant is a business product and is not directed to anyone under 18.
Changes and contact
Material changes will be announced in the product and by email before they take effect. Questions, requests or complaints: privacy@kestrant.com.