Kiaveo

Legal

Privacy Policy

Last updated 27 August 2026

This policy explains how Kiaveo (kiaveo.com) collects and uses your personal data, and the rights you have. We keep the data we hold to what we genuinely need to sell you a licence, invoice it correctly, and support you.

1. Data controller

The data controller is meeco Servicios Globales S.L., VAT ESB42774703, with registered office at Avenida de Cataluña 16, 03540 Alicante, Spain. Email our privacy contact directly at privacy@kiaveo.com. Full registration details appear in our Legal Notice.

2. What we collect

  • Order and contact details — the email address you order with, and your name where you provide it.
  • Billing and tax details — billing address, company name and VAT identification number when you buy as a business, so we can issue a compliant invoice.
  • Order history — the products you bought, the licence keys issued to you, and your invoices.
  • Support content — the messages and any order references you send us when you open a case.
  • Optional marketing preferences — your email address, newsletter scope, locale, request/confirmation/withdrawal times, notice version, and pseudonymous HMAC evidence of a shortened IP prefix. We never retain the raw confirmation token or raw IP address in the marketing record.
  • Short-lived checkout intent — when abandoned-checkout capture is enabled and you enter a valid email, we may retain that address, a pseudonymous HMAC recipient key, product SKUs and quantities, locale, the server-assigned legal basis, notice/objection evidence, and timestamps. We do not put names, addresses, prices, discounts, availability claims or payment details in this record.
  • Technical data — basic, security-related information such as your IP address and the essential cookies needed to run your cart and session.

We do not store your full card number. Card and wallet payments are processed directly by our regulated payment providers (such as Revolut and PayPal), who handle your payment credentials under their own terms.

3. Why we use your data, and our legal bases

  • To perform our contract with you — to take payment, deliver your keys and invoice, and provide support.
  • To meet a legal obligation — to issue invoices and retain accounting records as required by Spanish and EU tax law.
  • For our legitimate interests — to keep the store secure, prevent fraud, and improve our service, balanced against your rights.
  • With your consent — for the optional newsletter. Entering an address only requests a confirmation email; marketing starts only after you use the double-opt-in confirmation and applies only to product news and offers.

Newsletter consent is optional, separate from buying a licence, and may be withdrawn at any time. Every marketing message includes both a visible unsubscribe route and an email-provider one-click unsubscribe mechanism. A browser GET only opens a confirmation page; it does not change your preference. A fresh double-opt-in confirmation is required to subscribe again after withdrawal.

Entering an email during checkout is never consent and never a legal basis for a reminder by itself. An abandoned-checkout reminder may be scheduled only if you separately confirmed the cart-reminder scope, or if a prior completed purchase made after this feature was introduced records that we gave you a simple opportunity to object and the message concerns our own similar products. Legacy orders do not contain that evidence and are excluded. The checkout objection control is separate from the optional, unchecked newsletter control, and global unsubscribe or objection stops optional marketing immediately.

4. Sharing your data

We share data only with providers needed to operate the service, and never sell it. The production configuration currently identifies the following processors or independent payment recipients:

  • StripeCard payment processing and fraud prevention. International-transfer position: Provider safeguards and applicable adequacy/SCC mechanisms.
  • PayPalPayPal payment processing. International-transfer position: Provider safeguards and applicable adequacy/SCC mechanisms.
  • RebillLocal payment-method processing. International-transfer position: Provider safeguards and applicable SCC mechanisms.
  • ResendTransactional email, newsletter confirmation, and consented marketing email delivery. International-transfer position: Applicable SCC mechanisms.
  • Hetzner Online GmbHApplication hosting, encrypted storage and backups. International-transfer position: Hosting region and safeguards stated in the provider agreement.
  • DeepSeekAdmin-approved translation and support/catalogue assistance. International-transfer position: Restricted transfer under the configured provider agreement.
  • OpenRouterAdmin-approved AI routing, image and catalogue assistance. International-transfer position: Applicable provider safeguards/SCC mechanisms.
  • GoogleConsent-controlled visit, purchase and advertising measurement, including hashed enhanced-conversion data when permitted. International-transfer position: Google contractual safeguards and applicable SCC mechanisms.

Payment providers generally act as independent controllers for the payment credentials and compliance data they collect. Processors acting on our behalf are covered by appropriate contractual terms. Where personal data leaves the EEA, we use an applicable adequacy decision or contractual safeguards such as the EU Standard Contractual Clauses, according to the provider and processing location.

5. How long we keep it

Our operational retention schedule is: invoices, order records and accounting evidence for six years from the last relevant accounting entry; closed support cases for 24 months; rate-limit/security request records for up to 24 hours; and reseller API-usage summaries for 30 days. A raw checkout intent expires and is purged within 72 hours of its last active capture. For optional marketing, the raw address is otherwise retained only while needed for an active consent request, subscription or send and is removed immediately after unsubscribe. Minimal HMAC-keyed consent and suppression evidence is retained for up to six years after the last marketing event so that a withdrawal remains effective and we can demonstrate compliance. An active account profile is kept while the account remains open. Closing an account removes the login and reusable profile immediately, while statutory financial records are restricted until their retention period expires. Data needed for an active dispute, fraud investigation or legal claim may be restricted for longer while that matter remains live.

The six-year accounting period reflects Article 30 of Spain's Commercial Code. Retention is also subject to any longer or more specific legal requirement that applies to a particular record.

6. Your rights

Under the GDPR you have the right to access the data we hold about you, correct inaccurate data, request erasure, restrict or object to certain processing, and receive portable data. Signed-in customers can export their data, update it, change marketing consent and close their account under Account → Profile & preferences. Newsletter recipients can withdraw immediately through the unsubscribe link in every marketing email, including supported one-click email controls. You can also email privacy@kiaveo.com. We respond within the legally required period and may need to verify identity. You may complain to your local supervisory authority; in Spain this is the Agencia Española de Protección de Datos.

7. AI-assisted processing

Authorised staff may use configured AI providers for catalogue translation, image quality checks, and explicitly approved support or operational assistance. Customer data is not used to train our own model, high-impact writes require human approval, and staff must minimise or redact personal data before it is sent. The processor list above shows which AI providers are enabled in production. You can object to optional AI-assisted handling of a support case by telling us in that case.

8. Cookies and measurement choices

We use the essential cookies required to keep you signed in, remember your cart and currency, and secure checkout. These are necessary for the store to function, so they do not require consent. We do not use analytics or advertising storage without your consent. Our Cookie Policy lists the cookies and browser storage used, their purposes and durations.

On the Kiaveo storefront, Google Analytics and Google Ads are configured in advanced consent mode. Before you choose, analytics and advertising storage, ad user data and ad personalisation remain denied. The Google tag still loads and Google may receive limited cookieless measurement signals. URL passthrough and ads-data redaction are enabled; page locations sent by our code contain only the origin and path, without query strings or fragments.

The Analytics category controls analytics storage for Google Analytics and is also the consent category reserved for any future Microsoft Clarity integration. The Marketing category separately controls Google Ads storage, ad-user-data and ad-personalisation signals. Optional categories are not preselected, and you may allow either, both or neither.

The host-only kiaveo_tracking_consent cookie stores only your versioned category choices for 12 months. To prevent the same purchase being counted repeatedly, your browser also stores an order ID and sent timestamp in local storage for up to 400 days, capped at 100 entries; it does not contain an order access token, licence key, email address or other customer details.

When advertising measurement is configured and you have granted ad-user-data consent, we normalise and SHA-256 hash the order email on the server and send only that pseudonymous hash with the Google Ads purchase conversion. The raw email is never placed in the browser tracking payload. The hash is omitted when consent is denied or undecided.

You can withdraw or change either category at any time through the Cookie settings button in the footer or on the Cookie Policy page. Rejecting a category updates Google consent immediately and removes its known first-party Google cookies. The necessary preference cookie and purchase-deduplication record remain so that your choice is remembered and a reload does not duplicate a conversion.

To preserve the source of a later paid order, Kiaveo stores bounded campaign touches and Google landing identifiers (gclid, gbraid or wbraid) in host-only, HttpOnly cookies for up to 400 and 90 days respectively, even before you make a measurement choice. Permitted identifiers and your category choices at checkout are snapshotted on the order even if conversion uploads are paused.

A paid purchase may be reported to Google Analytics only when the order snapshot records Analytics consent, using its transaction ID and a random per-order measurement ID; no email or licence data is included. A stored landing identifier is uploaded to Google Ads only when the order snapshot records Marketing consent. Undecided orders, and orders without the relevant category consent, are not uploaded for that measurement category.

9. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed; material changes will be made clear on this page.

Privacy Policy — Kiaveo