Privacy
Updated August 2026
Short version: we keep what we need to run your shop. Card numbers never sit with us. We don’t sell a list of you or your buyers.
What this covers
This page is how kickbck handles personal information on kickbck.com: shops, checkout, downloads, and the emails we send about an order. It applies to creators and to buyers. Using the site means you’re okay with this. The terms are the rest of the rules.
What we have on creators
An email and a password, so you can log in. The username, name, bio, photo, location, site, and social handles you put on your shop. The products you add: title, price, files, covers. Which Stripe account you connected, and whether checkout is ready. Orders after someone pays, so we can show you the sale and let the buyer download.
What we have on buyers
When you pay on kickbck, we keep the email you used at checkout, what you bought, what you paid, and whether the order is paid, refunded, or disputed. That’s how we send the file and how /orders can send the links again, or a cancel link for a drop. The creator you bought from can see the purchase and the email on the order. They need it to deliver and to refund. We don’t give them your card.
If you only browse, we may still see a technical trace (IP, browser) in logs we use to keep the site up. We don’t build a marketing profile from that.
What Stripe has
Checkout runs on Stripe. They see the card, the charge, the billing details you type into their form, and the connected account a creator uses to get paid. We get back whether the payment succeeded, an id for the charge, and the email on the session, not the card number. Their privacy policy covers that side.
Who else sees anything
We don’t run this on a laptop. A few processors sit in the path so the shop works:
- Supabase: accounts, the database, and file storage.
- Vercel: the website itself.
- Logo.dev: brand logos on shops and links, looked up by domain.
- Resend: receipts and download mail.
- Stripe: cards and payouts, as above.
They only get what they need to do that job. We don’t sell your data to them, and we don’t let them use it to advertise back at you.
We may also share what we have if the law requires it, if we have to enforce the terms, or if the project is sold, in which case the buyer has to treat this page as the rules, or tell you otherwise.
How we use it
To run the shop you asked for:
- create and secure the account
- show the public page and take payment
- deliver the drop or the file after a paid order
- show creators their sales, and let them refund
- stop fraud, abuse, and people breaking in
- email you about the account or the order, not a newsletter we never asked to send
We may use counts and patterns with names stripped off (how many shops, how a page is holding up) to keep the product working. That is not a dossier on you.
What we don’t do
We don’t sell your data. We don’t sell your buyers’ emails. We don’t run ads against this, on the site or off it. We don’t buy lists. We don’t use what you upload to train a public model.
Cookies
Session cookies keep you logged in. That is the cookie we set on purpose. Stripe’s checkout may set its own when you pay. That’s them. We don’t use analytics cookies, ad cookies, or a pixel that follows you around the web.
Turn cookies off and the shop still reads; you just can’t stay logged in. We don’t respond to a Do Not Track signal because we aren’t tracking you for ads in the first place.
How long
Account data stays while the shop is open. Hide a product and it leaves the public page; the file stays in storage until you delete it or close the account. Delete the account and we remove what we can.
Paid orders we keep long enough to prove a download was owed, to handle a refund or a dispute, and to do our taxes. Logs age out. Mail in the outbox is there to send the receipt, then it’s done.
Your choices
You can edit the photo, name, bio, location, site, and socials on the shop from settings. You can hide or delete a product. You can ask what we have on you, and you can ask us to delete it. Creators do that from the account; buyers from the address they paid with.
We may have to keep an order record even after that: a refund, a dispute, or the law. If we can’t delete something, we’ll say why. Closing a creator account takes the public shop down; it doesn’t unwind money already paid out through Stripe.
Children
kickbck isn’t for anyone under 18. We don’t knowingly collect information from children. If we learn we have, we’ll delete it.
Security
Passwords are handled by our auth provider, not stored in a form we can read. Product files sit in private storage and come out as a signed link after a paid order. Card numbers never touch our servers.
No one can promise a site is unbreakable. If we learn of a breach that affects you, we’ll say so.
Where it lives
The processors above may keep data in the United States or in other countries. If you’re outside that, your information crosses a border so the shop can run. We only send what those processors need, under their terms.
Changes
We can update this page. The date at the top will move. If we start collecting more, selling data, or running ads (we won’t, but if we did) that would be a material change and we’d say so in the product, not only here.
Questions
Use the account if you’re a creator. Buyers can use /orders from the address they paid with. That’s how we know it’s you.