Skip to content

International shipping — delays and options worked out for your country. See my country

Legal

What we know about you, and what we chose not to know.

This policy describes the data KONECT processes, the reason for each piece of it, and what you can demand about it. It is written to be read, not to be accepted unread.

Last updated:

The principle that governs everything else

A KONECT accessory — card, badge, key fob — contains no personal data. Its chip carries only a web address and an identifier that means nothing outside our servers. Your name, your number and your email are not written on it.

The practical consequence matters more than the principle: a lost accessory reveals nothing, and cutting the link from your dashboard is enough to stop it opening anything at all. No reprint, no data to recover.

Everything this policy describes therefore lives on our servers, under your control — never in the object you hand over.

Who processes your data

KONECT is a VeraUp product, headquartered in Ottawa, Ontario, Canada. That entity decides the purposes and the means of the processing described here, and is therefore accountable for it under the law.

The address to send any request about this policy is at the bottom of this page.

What we collect, item by item

Nothing is collected "just in case". Every item below matches a function you asked for.

  • Your account — email address and encrypted password, your name, your language. Without them there is no account to protect.
  • Your public profile — exactly what you write in it: display name, title, company, links, contact details, photo, sections. You decide field by field what is visible.
  • Your orders — recipient name, phone, delivery address and city, cart contents, requested customisation, amount and currency. An order without an address cannot be delivered.
  • Contacts exchanged — when someone leaves their details through your profile: name, phone, email, company, note and their explicit consent.
  • Usage measurement — for each profile opening: country, device type, where the link came from, timestamp. Never a name, never an IP address in the clear.
  • Technical logs — an irreversible, salted fingerprint of the IP address, to slow abuse on public forms. The address itself is not kept.

We buy no data from third parties and we enrich your profile from no external database.

What each piece of data is for

Data collected for one reason is not repurposed for another without telling you.

  • Running the service — displaying your profile, maintaining your account, applying your visibility settings.
  • Fulfilling your orders — manufacturing, customising, charging, shipping, handling a return.
  • Answering you — processing a message sent through the contact form and routing it to the right team.
  • Giving you your statistics — telling you how many times your profile was opened and from which country, without identifying who opened it.
  • Protecting the service — detecting abuse, rate-limiting public forms, diagnosing an outage.
  • Meeting our obligations — keeping the accounting records of a sale for as long as the law requires.

Depending on the case, processing rests on performing our contract with you, on your consent — which you may withdraw —, on our legitimate interest in protecting the service, or on a legal obligation.

The person who taps your card

They install nothing, create nothing, and we do not try to identify them. Opening a KONECT profile requires no account.

What gets recorded on that occasion is an event, not a person: approximate country, device type, where the link came from. Nothing that would reconstruct an individual journey, and no advertising identifier.

If they choose to leave you their details, that is a deliberate act: they fill in a form and tick their consent. Those details belong to you; we host them, we do not exploit them.

Who else has access

Running an online service means relying on providers. Here are ours, and what each of them sees.

  • Supabase — database, authentication and media storage.
  • Vercel — application hosting and delivery.
  • Cloudflare — media delivery when it is enabled.
  • Stripe and Flutterwave — payment processing. Your card number never passes through our servers and is never stored there.
  • Resend — sending transactional email (confirmations, notifications).
  • Sentry — reporting technical errors, so we can fix what breaks.

Each one accesses only what its function requires, and acts on our instructions. We sell no personal data and rent none of it for advertising. Data may be handed to an authority where the law compels us. Some of these providers operate outside Canada: such transfers are then governed by each provider's contractual commitments.

How long it is kept

Data that no longer serves a purpose has no reason to be kept.

  • Account and profiles — as long as your account exists. Deleting it erases the associated profiles and media.
  • Contacts exchanged — as long as you keep them. You can delete any of them at any time from your dashboard.
  • Orders and invoices — seven years after the sale, the accounting retention period applicable in Canada.
  • Usage measurement — twenty-four months, then aggregated with no detail retained.
  • Technical logs and IP fingerprints — twelve months at most.

What you can demand

These rights need no justification and cost nothing to exercise.

  • Access the data concerning you and obtain a copy of it.
  • Correct anything inaccurate — most fields can be edited directly from your dashboard.
  • Delete your account and what it contains, subject to records the law requires us to keep.
  • Withdraw your consent where processing relies on it, with no retroactive effect on what was already done.
  • Object to processing based on our legitimate interest, by explaining your situation.
  • File a complaint with the Office of the Privacy Commissioner of Canada if our answer does not satisfy you.

Write to us through the contact form: we acknowledge receipt and answer within thirty days.

How it is held

The security of this service does not rest on the discipline of whoever writes the code, but on rules the database enforces itself.

  • Isolation at the database level — every table enforces its own access rules. A query with no right to see a row does not see it, whatever route it took.
  • Encryption in transit — all communication goes over HTTPS.
  • No IP address in the clear — public forms keep only a salted, irreversible fingerprint.
  • Passwords never readable — they are stored only as a hash, including by us.
  • Restricted internal access — administrative keys never leave the server and are never exposed to the browser.

No system is infallible. Should an incident affect your data, we will inform you, and the competent authority where the law requires it.

Minors

KONECT is not intended for children under thirteen and we do not knowingly collect their data. If you are between thirteen and eighteen, use the service with the agreement of your parent or guardian.

If you find that an account was created by a child under thirteen, tell us: we will delete it.

When this document changes

This policy will evolve with the service. The date of the last update is at the top of the page, and that date governs.

A change affecting the nature of what we collect or who we pass it to is announced to you by email before it takes effect — not merely published here.