Privacy Policy
This Privacy Policy describes how Kymac (“Kymac,” “Shelf Co,” “we,” “us,” or “our”) collects, uses, and shares information in connection with our websites and products, including Shelf Co services such as shelf-smoke (prepaid API credits for automated URL smoke checks), available at https://shelf.kymac.co and related machine-readable endpoints.
1. Information we collect
- Account and contact details you provide (for example name, email) when you create an account, request an API key, or contact us.
- Payment information processed by our payment provider, Stripe. We do not store full card numbers on our servers. Stripe may collect billing details under its own privacy policy.
- API credentials and usage such as API keys you receive from us, request metadata, timestamps, endpoints called, credit balance and debit events, and similar operational logs needed to run the service.
- Technical data such as IP address, user agent, and approximate location derived from IP, collected automatically when you or an automated client access our services.
- Communications you send us (support requests, email).
2. How we use information
- Provide, operate, secure, and improve our services (including authenticating API calls and metering prepaid credits).
- Process payments and prevent fraud.
- Respond to support requests and service notices.
- Comply with law and enforce our terms.
3. How we share information
We share information only as needed to run the service:
- Stripe — payment processing and related fraud prevention.
- Infrastructure providers (for example cloud hosting) that process data on our behalf under contractual obligations.
- Legal — when required by law, legal process, or to protect rights, safety, and security.
We do not sell personal information.
4. Retention
We retain information for as long as needed to provide the service, meet legal and accounting obligations, resolve disputes, and enforce agreements. API usage and billing records are typically kept for a reasonable business period after an account becomes inactive.
5. Security
We use reasonable technical and organizational measures to protect information (including HTTPS on service endpoints where enabled, access controls, and keyed API authentication). No method of transmission or storage is 100% secure.
6. Automated clients and bots
Our products are designed for use by software agents as well as humans. The same privacy practices apply to data submitted by automated clients using your API keys. You are responsible for the data those clients send to our APIs (for example target URLs in smoke requests).
7. Children’s privacy
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
8. International transfers
We may process information in the United States and other countries where we or our processors operate. By using the services, you understand information may be transferred to those locations.
9. Your choices
- You may request access, correction, or deletion of personal information we hold about you by contacting us.
- You may revoke or rotate API keys to cut off further authenticated access.
- Depending on your location, you may have additional rights under applicable privacy laws. We will respond to verified requests as required by law.
10. Third-party links and processors
Stripe’s processing of payment data is governed by Stripe’s privacy policy at https://stripe.com/privacy. Other third-party sites linked from our services have their own policies.
11. Changes
We may update this Privacy Policy from time to time. We will post the updated version at this URL and revise the “Last updated” date above. Continued use of the services after changes means you accept the updated policy.
12. Contact
Questions about this Privacy Policy or our data practices:
Kymac · Shelf Co
Email: privacy@kymac.co
Web: https://kymac.co · Product: https://shelf.kymac.co