Privacy Policy
Effective June 8, 2026
The short version: KatchT operates two kinds of products. Our browser extension — KatchT Links — runs entirely on your device and sends us nothing. KatchT HQ is a cloud-based service: when you create an account, it stores your account details, the marketing data you enter, and the lead records you capture on our infrastructure so your team can share them. This policy explains exactly what we hold for each, why, and the rights you have over it.
Who we are
Who this policy covers
Browser extension — data stays on your device
KatchT Links operates within your browser. We run no backend that receives, logs, or stores its activity.
- KatchT Links— Your templates and settings are saved with your browser's built-in sync storage, which lets them follow you across devices through your browser account. Your recent-link history is stored locally on the device only. KatchT never receives any of this. (If you choose to use the optional Send-to-HQ feature, the links you send are then governed by the KatchT HQ section below.)
KatchT HQ — what we collect and store
KatchT HQ is a multi-tenant cloud service. To provide it, we store the following categories of personal data on our infrastructure:
- Account records — When you sign up, our authentication provider stores your email address and a securely hashed password, along with account timestamps and your organization membership. We use this to authenticate you and to scope your data to your organization.
- Lead records you capture — When you or your team capture or import leads against a campaign or event, HQ stores the contact fields you enter for each lead: first name, last name, job title, company, email address, and the lead source, together with the event it was captured at and the capture timestamp. These records describe your contacts (for example, event attendees), not you. For this data you are the data controller and KatchT acts as your processor — see Our role for lead data below.
- Marketing link data — When links are sent from the KatchT Links extension into HQ, we store the destination URL, the event/campaign name, the UTM parameters (source, medium, campaign, term, content), and whether a QR code was downloaded. This is operational marketing metadata and does not normally identify a person.
- API keys — Business-plan users may generate API keys. We store an 8-character display prefix and the SHA-256 hash of the key only. The full plaintext key is shown once at creation and is never stored or recoverable by us.
- Product usage analytics — We collect pseudonymous in-product events (for example, "a board was created" or "a PDF was exported") to understand how HQ is used and to improve it. Each event is tagged with a random account identifier — not your email address. These events do not include the content of your campaigns, leads, or other data; only the action type, a count where relevant, and the timestamp.
We do not run third-party advertising or behavioral retargeting inside HQ, and we never sell or rent any of this data.
Why we process it, and our lawful basis (GDPR Article 6)
For users in the UK and European Economic Area, we rely on the following lawful bases under Article 6 of the GDPR:
| Data | Purpose | Lawful basis |
|---|---|---|
| Account records | Create and secure your account; provide the service you signed up for. | Performance of a contract — Art. 6(1)(b). |
| Lead records you capture | Store and organize the leads you collect at your events on your behalf. | Processed on behalf of you (the controller) under our customer agreement — Art. 6(1)(b) / Art. 28. You are responsible for the lawful basis for collecting these contacts. |
| Marketing link data | Aggregate your campaign and event link activity inside HQ. | Our legitimate interest in operating the service you requested — Art. 6(1)(f). |
| API key records | Authenticate programmatic access; attribute API usage to the generating user. | Performance of a contract — Art. 6(1)(b). |
| Product usage analytics | Understand aggregate feature usage to improve the product. | Legitimate interest in operating and improving the service — Art. 6(1)(f). |
| Support correspondence | Respond to your questions and requests. | Legitimate interest in supporting our users — Art. 6(1)(f). |
Our role for lead data (controller vs. processor)
Sub-processors
- Supabase — managed database, authentication, and backend hosting. Account records, lead records, and marketing link data are stored in our Supabase project. Supabase processes this data as our sub-processor under its own data protection terms.
- PostHog — product analytics platform. We send pseudonymous usage events (action type, a count where relevant, and timestamp) tied to a random account identifier to PostHog. No email addresses, lead contact records, campaign names, or other business content are sent to PostHog.
- Stripe — payment processing. Stripe handles subscription billing and stores your payment method. KatchT does not store your card details. Stripe is certified PCI DSS Level 1.
If we add or change a sub-processor, we will update this list and notify Business-plan customers by email with at least 10 days' notice. Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Third-party integrations (HubSpot, Zapier)
Business-plan subscribers may connect KatchT HQ to third-party services. When you enable an integration:
- HubSpot— When connected, KatchT pushes lead records you have captured (name, company, email, title, source, and event name) from HQ to your HubSpot CRM portal. This transfer is initiated by you, subject to your HubSpot account's terms and privacy settings. OAuth access tokens are encrypted at the application layer; we never store HubSpot tokens in plaintext.
- Zapier— When connected, KatchT sends webhook payloads to Zapier when certain events occur in your HQ workspace (for example, a new lead is created). The payload contains only the fields you have configured. Zapier's own privacy policy governs how it handles that data.
You can disconnect any integration at any time from your organization's settings. Disconnecting stops all future data transfers; it does not delete data already sent to the third-party service — contact that service directly to exercise rights over data it holds.
For GDPR purposes, you remain the data controller for lead records transferred to HubSpot or Zapier via these integrations. KatchT acts as your processor for the transfer itself.
Data retention
- Account records — kept for as long as your account is active. If you close your account, we delete or anonymize your account data within 90 days, except where we must retain limited records to meet a legal obligation.
- Lead and marketing link data— retained for as long as your organization keeps it in HQ. You can delete individual records at any time, and we delete your organization's data within 90 days of account closure or on your documented request.
- Extension data— lives on your device or in your browser's sync storage; its retention is fully in your control.
Your rights
If you are in the UK or EEA, you have the right to access, rectify, erase, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent where we rely on it. You also have the right to lodge a complaint with your local data protection authority.
Right to erasure. You can ask us to delete personal data we hold about you. For data in KatchT HQ, email privacy@katcht.com and we will action verified requests within 30 days. If KatchT is acting as a processor (lead records), we will forward your request to the relevant customer (the controller) or act on their instruction. For extension data, deleting it on your device or clearing your browser storage removes it immediately, since we never hold a copy.