Privacy Policy
Last updated: 9 June 2026
[TODO] must be completed before production use.This Privacy Policy explains how [TODO: legal entity name] (Business Registration No. [TODO: registration number]), the operator of Kirado (“Kirado”, “we”, “us”), collects, uses, and protects information when you use our accounting and mini-ERP service for small and medium businesses. Our registered address is [TODO: business address].
We aim to handle personal data in a manner generally consistent with applicable data protection laws in the jurisdictions where we operate. Depending on where you access Kirado, additional local laws may apply; the lawyer review noted above should confirm scope.
Information we collect
- Account data — your name, email address, and a securely hashed password when you register. If you sign in with Google, we receive your basic Google profile (name, email) to create and authenticate your account.
- Organization and user data — the business/organization you create or join, your role and membership, and team members you invite. Every business record is scoped to your organization.
- Business records you enter — accounting and ERP data such as invoices, bills, ledgers, inventory, and transactions. This is your data; we process it to provide the service.
- Security and operational logs — technical logs needed to operate the service, investigate problems, and protect against abuse.
How we use information
- To provide, secure, and maintain the Kirado service and your account.
- To authenticate you and keep you signed in.
- To respond to support requests and communicate service notices.
- With your consent, to understand product usage so we can improve Kirado (see Cookies and analytics).
Our role: when we control data, and when we only process it
Data protection laws distinguish the party that decides why and how data is processed (a “controller”, or “data user” under some laws) from the party that processes it on that party’s behalf (a “processor”). Kirado plays both roles depending on the data:
- Your account and usage data — for the personal data of the person who signs up (your name, email, and consent-based analytics), we are the controller, and this policy is our notice to you.
- The business records you enter — invoices, bills, ledgers, and the customer, supplier, and staff details you put into Kirado, including any personal data about other people. For this, you are the controller and we act as your processor: we process it only to provide the service and on your instructions. You are responsible for having a lawful basis (such as consent or a notice) for the personal data you enter about other people, and for honouring their rights. We make a data processing agreement available to support this.
Google sign-in (OAuth)
If you choose “Continue with Google”, Google authenticates you and shares your basic profile with us so we can create or access your account. We do not receive your Google password. Google’s handling of your data is governed by Google’s own privacy policy.
Cookies and analytics
We use a small number of cookies and local storage entries, grouped as follows:
Strictly necessary (always on)
- Authentication session — Auth.js sets a secure, HTTP-only session cookie so you stay signed in. The service cannot function without it, so it is exempt from consent.
Preferences (functional)
- Theme preference — a
kirado-themecookie remembers your chosen appearance. It stores only the theme name, contains no personal data, and is unrelated to analytics. We treat it as a functional preference that you set by using the app.
Analytics (optional — off by default)
We use PostHog for privacy-masked product analytics to understand how Kirado is used so we can improve it. Our legal basis is your consent. Analytics is disabled by default and only runs after you click Accept on the cookie banner. If you click Reject, browser analytics is never enabled and request-side server events are not forwarded to PostHog. You can change or withdraw your choice at any time via ; withdrawing stops collection and clears the analytics identifier on your device.
When enabled, analytics may collect:
- Pages you view and basic navigation — including time on page. Web addresses are scrubbed before they leave your browser: query strings are dropped and identifier-like parts of the path (such as an organization id or document number) are replaced with
:id, so a page is recorded as e.g./invoices/:id, never the real reference. - Approximate location — a coarse country / region / city estimate that PostHog derives from your IP address on our behalf. We do not request precise device geolocation, and we do not store your full IP for our own profiling.
- Device and environment — browser, operating system, screen size, timezone, and language/locale. This helps us support the devices and regions our users actually use.
- Key product events — a defined, allow-listed set of actions (for example completing onboarding, creating a company, or posting an invoice) together with a small set of non-sensitive descriptors (such as a step name or a report type). Properties are filtered against a strict allow-list, so anything not explicitly permitted is dropped before sending.
- Autocapture (automatic clickstream) is off, and session replay, where used, masks all inputs and on-screen text. Sensitive visual regions, such as uploaded OCR documents, logos, and rendered document-template previews, are blocked from replay. We identify activity using an opaque internal ID only — never your name or email.
- We do not intentionally send your financial records, invoice data, ERP transaction contents, passwords, or payment details to analytics.
- PostHog acts as our processor. Analytics data is sent to PostHog’s EU infrastructure (
eu.i.posthog.com) and retained for as long as needed to analyse and improve the product, after which it is deleted or aggregated. [TODO: confirm PostHog data-processing terms and retention window with a lawyer.]
Telegram integration
Kirado offers an optional Telegram bot integration. This is a server-to-server connection with Telegram’s Bot API; it does not place cookies or tracking in your browser. If you use it, messages you send to the bot are processed to deliver the feature. Telegram’s own privacy policy governs the Telegram side.
Sharing
We do not sell your personal data. We share data only with service providers that help us run Kirado (such as our hosting provider and PostHog, the analytics processor described above), and where required by law. [TODO: list all sub-processors / hosting provider and confirm any cross-border-transfer safeguards.]
Data retention and security
We retain your data for as long as your account is active or as needed to provide the service and meet legal obligations. Posted accounting records are immutable by design and are corrected via reversal rather than deletion. We apply reasonable technical and organizational safeguards to protect your data.
Your rights
Subject to applicable law, you may request access to or correction of your personal data, and withdraw analytics consent at any time. To make a request, contact us at the address below.
Contact
Questions about this policy or your data: support@kirado.io.
See also our Terms of Service.