Privacy Policy

Last updated:

1. Who we are

DeliveryKit is operated by Femke Design Limited, a company registered in Canada (“DeliveryKit,” “we,” “us,” or “our”).

This policy explains how we collect, use and disclose personal information through our website, merchant dashboard, Stripe app, checkout links, delivery emails and buyer download portals.

For privacy questions or requests, contact [email protected].

2. Merchants and buyers

We use merchant account information to operate DeliveryKit, manage subscriptions, provide support and protect the Service.

When a merchant uses DeliveryKit to deliver a purchase, we also process buyer information on the merchant’s behalf. The merchant determines which products they sell, who receives them and how their customer relationship is managed. We use that information to provide delivery, access management and related services.

The merchant’s privacy policy applies to their own collection and use of buyer information. This policy explains DeliveryKit’s involvement.

DeliveryKit is not the merchant of record. Buyers purchase directly from merchants, with payments processed by Stripe through the merchant’s connected Stripe account. We nevertheless receive certain transaction and customer information needed to deliver purchases and support the Service.

3. Information we collect

Merchant accounts and workspaces

We collect information you provide when registering, joining a workspace, configuring the Service or contacting us. This may include:

  • Your name, email address, profile image and timezone.
  • Your business or workspace name, branding, support details and preferences.
  • Workspace membership, roles and account activity.
  • Information you submit when requesting access or describing your business.
  • Support messages and other communications.

We use WorkOS to support authentication and account management. Depending on your sign-in method, we receive account identifiers and profile information such as your name, email address and profile image from WorkOS or your authentication provider.

Connected Stripe accounts and transactions

Depending on the permissions granted and features used, we receive information from Stripe such as:

  • Connected-account identifiers and business profile information.
  • Products, prices, payment links and checkout sessions.
  • Buyer names, email addresses and Stripe customer identifiers.
  • Purchased products, payment amounts, currencies and transaction dates.
  • Payment, refund, dispute and delivery status.
  • Invoice and receipt information, links and transaction-related metadata.
  • DeliveryKit subscription, billing and application-fee information.

Stripe event notifications may contain additional billing, contact or payment-method details associated with those transactions.

Full payment-card numbers and card security codes are collected by Stripe through its payment interfaces, rather than by DeliveryKit’s own forms.

Files and published content

We store the files, resource links, product descriptions, images and branding merchants provide. These materials may contain personal information.

Merchants should only provide information they are authorised to share and should avoid including sensitive personal information that is unnecessary for the Service.

Content configured for public product pages is publicly accessible. Purchased files and resource links are made available through the merchant’s configured delivery and access features.

Delivery and technical information

We collect information needed to operate and protect the Service, including:

  • IP addresses and browser or device information.
  • Requests, timestamps, errors and security-related logs.
  • Delivery-email attempts and their status.
  • Download and access events, including timestamps and usage counts.
  • Session identifiers, access tokens and stored preferences.

Some of this information is linked to a particular account, order or buyer.

4. How we use information

We use personal information to:

  • Create accounts, authenticate users and manage workspace access.
  • Connect Stripe accounts and synchronise relevant information.
  • Create checkout sessions at a merchant’s request.
  • Associate purchases with digital products and deliver access to buyers.
  • Send purchase, account, billing and service-related communications.
  • Manage downloads, access recovery, refunds and related order updates.
  • Process DeliveryKit subscriptions and transaction fees.
  • Provide support and investigate delivery or payment problems.
  • Understand usage and improve reliability and usability.
  • Prevent fraud, abuse and unauthorised access.
  • Meet legal obligations and establish, exercise or defend legal claims.

We do not sell personal information or Stripe account data. We do not use buyer purchase information to build advertising audiences or market unrelated products to buyers.

We do not obtain permission to sell or independently exploit merchants’ uploaded files simply because they use DeliveryKit.

5. When we share information

We share information only where needed for the purposes described in this policy.

Merchants and workspace members. Authorised members of a merchant’s workspace can access customer, order and delivery information associated with that workspace.

Service providers. We use providers for hosting, storage, authentication, payment processing, email delivery and analytics. These include Laravel Cloud, WorkOS, Stripe, Resend and Google Analytics. Resend processes recipient details and message content to send purchase-delivery, account and billing emails. Hosting and storage services may involve infrastructure providers such as Cloudflare.

Providers receive information relevant to the services they perform. Where they process information on our behalf, we require appropriate privacy and security protections.

Some providers, including Stripe and authentication providers, also process information for their own purposes under their respective privacy policies.

Your instructions. We share information when you configure a feature that requires it, such as sending a delivery email, publishing a product page or connecting your Stripe account.

Legal and security reasons. We may disclose information where required or permitted by law, to respond to valid legal process, protect people and systems, investigate abuse or defend legal claims.

Business changes. Information may be disclosed as part of a proposed or completed merger, acquisition or sale of the business, subject to appropriate confidentiality protections and applicable law.

6. Cookies and analytics

We use cookies and browser storage to maintain sessions, support security and remember preferences such as appearance settings.

We also use Google Analytics on selected marketing and merchant-dashboard pages to understand visits and usage. Google Analytics uses cookies and receives technical information about visitors and their interactions. Google explains its data collection here.

Our page-view integration uses general page names and route patterns to avoid intentionally sending customer names, order identifiers, download tokens or URL query parameters in page-view metadata.

Buyer checkout and download-portal pages are excluded from this page-view integration.

You can manage cookies through your browser settings. Blocking essential cookies may prevent sign-in or other features from working. Google also provides an Analytics opt-out browser add-on.

7. International processing

Our application is hosted through Laravel Cloud in the United States. We operate from Canada, and our providers may process information in the United States and other countries where they operate.

These countries may have different privacy laws, and information may be accessible to courts, law enforcement or other authorities under applicable local law.

Where applicable law requires safeguards for international transfers, we will use appropriate contractual or other recognised safeguards. You can contact us for information about the safeguards applicable to your information.

8. How long we retain information

We retain information for the purposes described in this policy, considering the nature of the information, account activity, merchant instructions, security needs and legal obligations.

Our standard retention periods for hosted merchant files are:

  • Unconverted trials: files are scheduled for deletion 30 days after the trial ends.
  • Ended paid access: files are scheduled for deletion 60 days after paid access ends.

These periods concern hosted files. They do not mean that all customer, order, billing or support records are deleted at the same time.

We may retain transaction and account records where needed for accounting, disputes, fraud prevention or other legal and operational requirements. Backup copies may remain until they are removed through the applicable backup lifecycle.

Disconnecting Stripe or uninstalling the app stops the connected integration; it does not automatically delete previously collected records or cancel a DeliveryKit subscription.

Contact us to request deletion or information about retention. We will assess the request under applicable law and, where relevant, coordinate with the merchant responsible for the information.

9. Security

We use technical and organisational measures intended to protect personal information, including access controls and protections for authentication and download access.

No online service can guarantee absolute security. You should protect your login credentials and avoid sharing private download or account-access links.

If you suspect a security issue involving your information, contact [email protected] promptly.

10. Your rights and choices

Depending on the laws that apply, you may have rights to:

  • Request access to your personal information and information about its use or disclosure.
  • Correct inaccurate or incomplete information.
  • Request deletion, restriction of processing or a portable copy.
  • Object to certain processing.
  • Withdraw consent where processing relies on consent.
  • Make a complaint to a privacy regulator.

These rights may be subject to legal exceptions. Withdrawing consent does not affect processing that was lawful before withdrawal, and may affect our ability to provide features that require the information.

You can update certain account details in your settings. For other requests, email [email protected]. No special request form is required.

We may request proportionate information to verify your identity. If you are a buyer requesting changes to information managed for a merchant, we may direct your request to that merchant or assist them in responding.

We will respond within the periods required by applicable law.

11. Children

DeliveryKit’s merchant accounts are intended for adults who are legally able to enter into our Terms of Service.

The Service is not directed to children under 13, and we do not knowingly seek their personal information. Merchants must comply with applicable requirements when selling to or collecting information from minors.

If you believe a child has provided personal information inappropriately, contact us so we can investigate and take appropriate action.

12. Changes to this policy

We may update this policy as the Service or our practices change. The date at the top identifies the latest revision.

For material changes, we will provide a prominent notice in the Service or notify affected account holders where appropriate. Where a change requires consent under applicable law, we will obtain that consent before using information for the new purpose.

13. Contact and complaints

For questions, requests or complaints, contact:

Privacy contact — DeliveryKit

Femke Design Limited

202 - 3750 Shelbourne Street

Victoria, British Columbia V9C 0R2

Canada

Email: [email protected]

You may also contact the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, or the relevant privacy authority where you live.