Last updated: August 13, 2026
The short version. We collect the information we need to run your account, bill you, secure the Services, and support you — and nothing more. We don't retain the secret values held in your Azure Key Vaults; where a bulk operation requires us to handle them, they stay encrypted and are discarded when it finishes. We don't sell personal information, and we don't run advertising or third-party tracking on this site.
This Privacy Policy explains how KickCatch, LLC ("KickCatch", "we", "us", "our") collects, uses, shares, and protects personal information in connection with our website at kickcatch.com, our customer portal at portal.kickcatch.com, and our products — Secrets Manager, Integration Manager, and Release Manager (together, the "Services").
It does not apply to third-party services you connect to or reach from ours, including Microsoft Azure. Those are governed by their own privacy policies.
We act as a controller for the account, billing, support, and website information described below — we decide why and how it is processed.
We act as a processor for the cloud resource metadata we read from your Azure environment on your instruction. You decide what we may access and what we do with it; we process it to provide the Services and on your documented instructions. If you require a data processing agreement, contact [email protected].
We do not retain the secret values held in your Azure Key Vaults. Secrets Manager reads and writes those values through the Azure Key Vault API while carrying out a request you have made. They are not recorded in the secret catalogue we keep for your account, and are not written to our application logs, our telemetry, or our backups. What we keep is metadata — names, tags, identifiers, versions, and timestamps — which is what enables search, cross-vault views, and bulk editing. When you clone a key vault, only names and structure are copied; values are not.
Bulk operations are a limited, temporary exception. A bulk creation or bulk update has to apply the values you submitted across every target vault, so those values must be held for as long as the operation takes to complete. Throughout that window they are encrypted, and they are discarded once the operation finishes or fails. They are not retained afterwards, are not included in backups, and never become part of the metadata we hold about your environment.
We deliberately do not publish the specifics of this handling. A detailed description of the mechanism would be more useful to an attacker than to you. If you need that detail for a security review or vendor assessment, write to [email protected] and we can provide it under a confidentiality agreement.
Separately, we never receive or store your full payment card number or its security code, and we never receive the password you use with an external identity provider.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train machine learning models.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and equivalent laws:
We use a small number of cookies and browser storage entries, almost all of which are strictly necessary for sign-in, security, and multi-factor authentication. We do not run advertising cookies or third-party analytics trackers on our website. Our Cookie Policy lists every cookie we set, what it does, and how long it lasts, and explains how to change your choices.
We share personal information only in these circumstances:
We rely on the following providers to operate the Services:
| Provider | Purpose | Data involved |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, file storage, messaging, and identity | All hosted account and metadata records |
| Stripe, Inc. | Payment processing and subscription billing | Name, email, billing details, payment card data |
| Twilio SendGrid | Transactional email delivery | Name, email address, message content |
| Cloudflare, Inc. | Bot detection on public forms (Turnstile) | IP address, browser signals |
| Sumo Logic, Inc. | Application log management and monitoring | IP address, request URLs, diagnostic and error data |
| Microsoft, Google, GitHub | Optional single sign-on, if you choose to use it | Name, email address, provider account identifier |
We review this list as our infrastructure changes. To be notified of changes to our sub-processors, email [email protected].
We are based in the United States and our infrastructure and service providers are primarily located there. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, together with the technical and organizational measures described below.
We may retain information longer where required by law or where necessary to establish, exercise, or defend legal claims.
We apply technical and organizational measures appropriate to the risk, including:
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.
Depending on where you live, you may have the right to:
You can update much of your account information directly in the portal. For anything else, email [email protected]. We will verify your identity before acting and will respond within the time required by applicable law. If your information was submitted to us by an organization using the Services, we will refer your request to that organization and assist them in responding.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have the rights described above, including the right to know, delete, correct, and obtain a portable copy of their personal information.
In the twelve months preceding the date of this policy, we collected the categories of personal information described in section 3 — identifiers, commercial information, internet or network activity information, and professional information — for the business purposes described in section 5, and disclosed them only to the service providers listed in section 9.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly process sensitive personal information for the purpose of inferring characteristics about you. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" mechanism. We honour Global Privacy Control and similar browser signals where applicable.
You may designate an authorized agent to make a request on your behalf; we will ask for proof of authorization.
The Services are business tools intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
We may update this policy as our practices change. When we do, we will revise the "Last updated" date at the top of this page. If a change is material, we will give you notice by email or through the Services before it takes effect.
For any privacy question or to exercise your rights, email [email protected] or use the contact form on our website.
KickCatch, LLC
[email protected]