Skip to legal content

Current policy

Privacy Policy

Last updated: September 5, 2026

1. Scope and our role

This Privacy Policy explains how Kpree (“Kpree,” “we,” “us,” or “our”) handles personal information when people use Kpree websites, applications, support channels, and related services (the “Services”). Kpree helps organizations understand appointment capacity and sales demand, identify revenue at risk, manage customer and operational data, run authorized communications and advertising workflows, and connect payment, billing, and accounting providers.

Organizations using Kpree control the customer and prospect information placed in their workspaces. For that information, Kpree generally acts as a service provider or processor on the organization’s instructions. Kpree is responsible for account, security, billing, and service-administration information that it handles for its own operational purposes.

2. Information we collect

  • Account and business information: names, business contact details, organization profile, locations, team roles, preferences, and authentication records.
  • Workspace and customer data: appointment, availability, service, minimized order, sale and refund facts, customer, prospect, consent, suppression, campaign, and communication information submitted by or for an organization. Sales-demand analysis does not require Kpree to store buyer names, phone numbers, email addresses, card details, or item-level order contents.
  • Integration data: provider account identifiers, authorization tokens, scopes, connection status, delivery events, and data needed to operate integrations selected by an organization.
  • Billing and accounting data: subscription, invoice, payment-status, reconciliation, and accounting-export information. Payment card and bank details are handled by the applicable payment provider rather than stored by Kpree as full payment credentials.
  • Usage, device, and security data: IP address, browser and device information, timestamps, audit events, error records, and diagnostic information used to operate and protect the Services.
  • Communications: information included in support, onboarding, security, or business communications with us.
  • Website inquiries and assistant interactions: the name, work email, business details, selections, and message you submit through our contact form, plus questions you choose to send to the Kpree Assistant. We ask visitors not to submit customer data, credentials, payment information, or other sensitive information through these tools.

3. How we use information

We use information to provide and maintain the Services; authenticate users; configure workspaces and integrations; analyze appointment capacity, sales demand, and business performance; identify short-term revenue gaps; measure verified recovery outcomes; carry out authorized communications, advertising, billing, and accounting workflows; provide support; prevent fraud and abuse; enforce permissions and suppression choices; monitor reliability and security; comply with law; and improve the Services.

Contact-form information is used to review and respond to the inquiry. Questions submitted to the Kpree Assistant may be sent to OpenAI, acting as an automated language-service provider, to generate a product-related answer and apply safety controls. Kpree configures these requests not to store generated responses as application state. OpenAI may retain limited API content in abuse-monitoring logs for up to 30 days unless a different approved retention control applies. Assistant responses may be incomplete and should not be treated as legal, tax, medical, or financial advice.

Kpree does not use an organization’s customer data to advertise unrelated products to those customers. Advertising and messaging integrations process information only when enabled and directed by the organization, subject to the organization’s settings, consent records, suppression lists, and provider requirements.

4. How information is disclosed

We may disclose information to the organization that controls the relevant workspace; authorized team members; infrastructure, security, communications, analytics, payment, advertising, scheduling, and accounting providers that support the Services; professional advisers; an acquirer or successor in a business transaction; and public authorities when required by law or necessary to protect rights, safety, and service integrity.

Third-party integrations may include services such as Amazon Web Services, Square, Twilio, SendGrid, Google Ads, Meta, Stripe, and Intuit QuickBooks. A provider receives information only when needed for the enabled integration and handles it under its own terms and privacy practices.

5. Google Ads data and Google API Limited Use

When an organization chooses to connect Google Ads, Kpree may receive and store the OAuth access and refresh credentials authorized by that organization; accessible Google Ads customer and manager account identifiers and descriptive names; account currency, time zone, and billing-readiness status; campaign and resource identifiers, configuration, status, targeting, creative supplied by the organization, and cost or spend information.

Kpree uses this Google Ads data only to connect and select an organization-authorized account; validate permissions and account readiness; prepare, edit, launch, pause, or stop organization-approved campaigns; monitor campaign status and spend; reconcile advertising activity with business outcomes; maintain security and audit evidence; and provide requested support. Kpree does not sell Google Ads data, use it for unrelated advertising, or transfer it to data brokers.

Provider credentials are stored server-side using safeguards designed for sensitive credentials and are not exposed in the browser. Google receives campaign actions and content as needed to provide Google Ads, and infrastructure or security providers may process limited data as needed to operate and protect Kpree. An authorized organization administrator can disconnect Google Ads. Kpree then revokes or deletes the active provider credentials where supported, while retaining limited security, audit, suppression, billing, or legal records for the periods described in this Policy.

Kpree's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Organization responsibilities

Each organization is responsible for determining that it may lawfully collect, upload, use, and instruct Kpree to process workspace data. Organizations must provide required notices, obtain required consents, honor opt-outs and suppression requests, restrict team access, and use communications and advertising features in accordance with applicable law and provider policies.

7. Cookies and similar technologies

Kpree uses cookies and similar technologies that are necessary to authenticate users, maintain sessions, remember preferences, protect accounts, and operate the Services. We may also use limited diagnostic measurements to understand performance and reliability. Browser controls can limit cookies, but blocking necessary cookies may prevent sign-in or other features from working.

8. Data retention

We retain information for as long as reasonably necessary to provide the Services, fulfill an organization’s instructions, maintain security and audit evidence, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, fraud-prevention, or suppression obligations. Retention periods vary by data type and configuration. When information is no longer needed, we delete, anonymize, or isolate it, subject to backups and lawful exceptions.

9. Security and international processing

We use administrative, technical, and physical safeguards designed to protect information, including access controls, encryption for sensitive credentials, tenant isolation, audit logging, and bounded provider permissions. No method of storage or transmission is completely secure. The Services are hosted in the United States, and information may be processed in the United States and other locations where our providers operate.

10. Privacy choices and requests

Users may update available account and organization information through the Services. Requests to access, correct, export, restrict, object to, or delete workspace customer data should first be directed to the organization that controls that workspace. Kpree will assist organizations with verified requests where required. We may need to verify identity, authority, and the applicable workspace before acting.

Communication recipients can use the opt-out method supplied with a message. Suppression choices take priority over later campaign or audience instructions within Kpree.

11. Children’s privacy

The Services are business tools and are not directed to children under 13. Kpree does not knowingly collect personal information directly from children under 13. Organizations must not submit children’s information unless they have a lawful basis and have configured their use of the Services appropriately.

12. Changes and contact

We may update this Policy as the Services or applicable requirements change. We will post the revised version here and update the date above. Material changes may also be communicated through the Services or the organization’s established contact channel.

Questions, privacy requests, or complaints may be submitted through the contact form on kpree.com, the Kpree support channel provided to your organization, or your Kpree workspace administrator. Please identify the relevant organization and do not include passwords, access tokens, payment credentials, customer records, or other secrets.