Privacy Policy
Last updated: 2026-05-14
Kandir, Inc. ("Kandir," "we," "us," or "our") is committed to protecting your privacy and the security of your information. This Privacy Policy describes how we collect, use, disclose, store, and safeguard your personal data, including data we receive from Google APIs when you connect a Google account. By using our services, you consent to the practices described in this policy.
1. Information We Collect
We may collect the following types of information:
- Personal Information: your name, email address, mailing address, phone number, and other contact details you provide.
- Account and Payment Information: account credentials, billing details, and payment information processed by our payment provider.
- Usage Information: information about your interactions with our website and product, including IP address, browser type, device information, and pages visited.
- Opt-in Integration Information: if you choose to connect a third-party service (e.g., Gmail, Google Calendar, Slack, Salesforce, HubSpot), we receive data from that service as needed to provide the integration's features. See Section 2 for the specific terms that apply to data received from Google APIs.
2. Google User Data
When you connect a Google account to Kandir, we request only the minimum scopes needed to provide the connected feature:
-
https://www.googleapis.com/auth/userinfo.emailandhttps://www.googleapis.com/auth/userinfo.profile— to identify the connected Google account and display your name and email in the Kandir UI. -
https://www.googleapis.com/auth/gmail.readonly— read-only access to your Gmail messages and metadata, used solely to extract account-planning signals (for example: meetings, mentions of accounts you are tracking, and key contacts) and surface them in your account-plan views inside Kandir. -
https://www.googleapis.com/auth/calendar.readonly— read-only access to your Google Calendar events, used solely to surface meetings related to accounts you are tracking and to extract attendee and meeting context for your account-plan views inside Kandir.
How Google user data is handled
- Storage: data retrieved from Google APIs is processed on Kandir-controlled servers, encrypted in transit (TLS) and at rest, and stored only to the extent needed to provide the features you have enabled.
- Access: access by Kandir personnel is restricted to authorized employees who need access to operate, secure, or support the service.
- No advertising: we do not use Google user data for advertising, and we do not transfer Google user data to third parties for advertising purposes.
- No sale: we do not sell Google user data.
- No generalized AI/ML training: we do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models. We may use AI/ML to process your Google user data on your behalf solely to produce features inside your own Kandir account (for example, generating signals or summaries you see in your account plans).
- No human review of message or event content except where: (a) you have given us explicit permission for specific messages or events; (b) it is necessary for security purposes such as investigating abuse; (c) it is necessary to comply with applicable law; or (d) the data is aggregated and de-identified and used for internal operations consistent with the Limited Use requirements.
- Sharing: we do not share Google user data with third parties except (i) sub-processors that host or operate our service under contractual obligations consistent with this policy and the Limited Use requirements, or (ii) where required by law.
Limited Use disclosure: Kandir's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
Disconnecting and deletion: you may disconnect a Google integration at any time from within Kandir's settings, which revokes Kandir's stored OAuth tokens and stops further data retrieval. You may also revoke Kandir's access at any time from your Google Account at https://myaccount.google.com/permissions . To request deletion of Google user data already retrieved by Kandir, contact us at support@kandir.io; we will delete the data from our production systems within 30 days, subject to backup-retention cycles described in Section 5.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and secure our services.
- Process transactions and send transaction notifications.
- Provide the features of any third-party integrations you have connected, subject to Section 2 for Google user data.
- Improve our website and services (excluding any use of Google user data prohibited by Section 2).
- Send service updates and, where you have opted in, promotional emails (you can opt out at any time).
- Respond to your inquiries and support requests.
4. Data Sharing
We may share your information with:
- Sub-processors and service providers who host, operate, or support our services under contractual obligations consistent with this policy.
- Law enforcement or government authorities when required by law or to protect the rights, property, or safety of Kandir, our users, or others.
We do not sell your personal information, and we do not transfer Google user data for advertising purposes.
5. Data Retention
We retain personal information for as long as your account is active or as needed to provide the services and to comply with our legal obligations. Google user data is retained only as long as necessary to provide the connected feature. When you disconnect an integration or close your account, we delete the associated data from our production systems within 30 days. Residual copies may persist in encrypted backups for up to 90 days before being overwritten in the normal course of backup rotation.
6. Cookies and Tracking Technologies
We use cookies and similar technologies to enable core functionality, remember your preferences, and analyze usage. You can manage cookie preferences in your browser settings.
7. Security
We implement administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
You may request access to, correction of, or deletion of your personal information, including any Google user data we hold on your behalf. Contact us at support@kandir.io to exercise these rights.
9. Children's Privacy
Kandir is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date and, where appropriate, notify you through the service.
11. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at support@kandir.io.