KIKIT Privacy Notice

How KIKIT handles information across Product Requests, landed-cost estimates, account and campaign access, communications, and visitor analytics.

Last updated: August 20, 2026Version 2026-08-20
1

Who is responsible and contact

Allkmag, Inc. operates the KIKIT website and is responsible for the personal information handling described in this notice.

This notice applies to the public website, Product Requests, landed-cost estimates, optional email capture, customer account and campaign access, service communications, and related operator workflows.

For privacy questions or requests, contact hello@kikit.it.

2

Information collected by flow

Product Request

  • A Product Request may include contact details, product and request data, recipient name, phone, contact email, optional company or store name, address lines, postal code, city, optional state/province, optional state tax identifier, country, and other destination, shipping, or invoice details that you provide.
  • Its browser-local draft and one-time browser handoff are separate from submitted server operational records.
  • After a successful Product Request, a minimal request summary may remain in sessionStorage in the same tab for up to 24 hours.

Estimate browser draft

  • Entered product and destination data may be retained as text in sessionStorage, and a reduced screenshot may be retained in IndexedDB, in the same browser for up to 2 hours.
  • This browser-local state is separate from Estimate records submitted to KIKIT's servers.

Estimate analysis

  • An Estimate may use a product screenshot, entered product and price values, quantity, destination and postal details, the analysis result, and the resulting estimate.
  • AI analysis runs only when you choose Analyze. It estimates product and measurement details from the submitted screenshot and optional product-name hint; it is not physical verification of the product.
  • A postal lookup uses the postal code and supported country code you enter.

Optional estimate email capture

  • When the optional configured email action is used, KIKIT stores the normalized email, source and capture data, server-owned estimate payload, and subscription and unsubscribe material.
  • The source screenshot is not sent in the estimate email.

Private order tracking

  • Order tracking records may include the order number, customer and destination details, item and quantity information, customer-facing amounts, status history, shipment and invoice details, payment timing, and customer-facing notes.
  • The private order-tracking page shows only allowlisted customer-facing fields and attachments selected for public sharing. Internal operator notes, seller product links, audit records, and private attachments are excluded.

Visitor, account, campaign, and communication records

  • First-party pseudonymous visitor logs may include page, referral, campaign, CTA, device, and coarse request context. Quote field values are excluded from general visitor analytics.
  • Where the relevant feature is enabled or used, KIKIT keeps configured email, account and campaign access records, seller-verification details, service communications, and operator audit records needed to run those workflows.
3

How information is used

  • Review and answer Product Requests, prepare estimates, confirm destination and shipping assumptions, and operate quote or order follow-up.
  • Provide customer account access, email verification, saved or unlocked campaign estimates, seller verification, and reviewed-quote handoff where those features are used.
  • Protect the service, apply rate limits, diagnose errors, maintain operator accountability, and understand first-party page and conversion activity.
  • Send service email needed for a requested workflow. Service email is operational; marketing or briefing consent is optional and can be withdrawn.
4

Where and with whom it is processed

KIKIT operations

Depending on the flow and configuration, information is processed in KIKIT's private operational database, Google Sheet quote intake, configured email or communication tools, and customer account or campaign systems. Authorized operators use these records to handle the requested service.

Kikit Co., Ltd. receives the product, order, recipient, and shipping information needed to perform Korea-side sourcing, purchasing, inspection, storage, packing, and international dispatch.

This operational processing takes place in the Republic of Korea.

Hosted card payment

When a customer uses an Allkmag, Inc. Stripe Payment Link, payment information is processed on Stripe’s hosted payment page.

The KIKIT website does not store full card numbers or card security codes.

Estimate analysis and postal lookup

OpenAI is invoked only when you choose Analyze. KIKIT may send OpenAI up to two processing requests. The first receives the product screenshot and an optional product-name hint. When the first analysis produces three measurement candidates, a separate independent consistency review receives the same screenshot and limited structured first-pass product and measurement fields. These outputs are estimates, not physical verification.

Postal lookup sends only the entered postal code and supported country code to the configured postal lookup provider.

Optional marketing measurement

Optional marketing pixels are used only when configured and only after consent. They are not required to submit a Product Request or calculate an Estimate.

5

Retention and security boundaries

Browser-local records

  • A Product Request browser-local draft, including recipient name, phone, contact email, optional company or store name, address lines, postal code, city, optional state/province, and country, is eligible for automatic restoration for 30 days. The optional state tax identifier is not stored in the browser-local draft or one-time browser handoff. The browser record may remain until you clear it, a successful submission clears it, or browser storage is otherwise cleared or overwritten. Its one-time browser handoff is eligible for restoration for up to 24 hours and is cleared after use or successful submission.
  • Estimate draft text in sessionStorage and its reduced screenshot in IndexedDB use the same 2-hour browser-local lifetime.

Estimate server records

  • A private calculation and image handoff expires after 24 hours when it remains unlinked.
  • An immutable saved Estimate's source screenshot is a 30-day deletion candidate. An active review or operations hold can delay deletion.
  • Image-free calculator activity may be retained for up to 180 days for operational review.
  • Saved or shared public estimates may display the destination country and city. They exclude postal code, contact details, product link, and the source screenshot. General visitor analytics use a separate allowlist and exclude form field values.

Pseudonymous and operational records

  • The raw IP address is replaced by a pseudonymous hash for first-party visitor logs. The resulting identifier is pseudonymous, not anonymous.
  • Operational and business records are retained only for the period needed for quote and order operations and applicable recordkeeping obligations. Different records can therefore have different lifecycles rather than one fixed retention period.
  • KIKIT limits private workflow data to the relevant server and operator paths. Saved or shared public estimate output uses allowlisted fields: it may display the destination country and city, while excluding postal code, contact details, product link, and the source screenshot. General visitor analytics use a separate allowlist and exclude form field values.

Order tracking records

  • Order records are retained by default for 5 years for order operations, accounting, tax, dispute, and recordkeeping needs, subject to applicable law.
  • Order attachment originals are retained by default for 2 years unless a shorter period is required by an approved deletion or legal process. Removing an attachment from public view does not by itself erase the underlying business record.
  • A revoked tracking token becomes invalid immediately. KIKIT stores a token hash and version for access control rather than storing the public tracking token as readable plaintext.
6

Customer rights and choices

  • You may ask for access, correction, or deletion of personal information, or withdraw marketing or briefing consent, through the central privacy contact below.
  • Requests remain subject to applicable law and necessary operational and business recordkeeping. A deletion request does not require KIKIT to remove records that must still be kept for those purposes.
  • On a shared device, clear a Product Request draft when you finish. You can also decline optional marketing pixels without losing access to Product Request or Estimate functions.

Send a privacy or consent request to hello@kikit.it.