• Home
  • Products
  • Contact
  • Sign In

Privacy Policy

Last updated: August 13, 2026

The short version. We collect the information we need to run your account, bill you, secure the Services, and support you — and nothing more. We don't retain the secret values held in your Azure Key Vaults; where a bulk operation requires us to handle them, they stay encrypted and are discarded when it finishes. We don't sell personal information, and we don't run advertising or third-party tracking on this site.

On this page
  1. Scope of this policy
  2. Our role: controller and processor
  3. Information we collect
  4. How we handle your secret values
  5. How we use information
  6. Legal bases for processing
  7. Cookies and similar technologies
  8. How we share information
  9. Service providers and sub-processors
  10. International data transfers
  11. How long we keep information
  12. How we protect information
  13. Your privacy rights
  14. Notice for U.S. state privacy laws
  15. Children's privacy
  16. Changes to this policy
  17. How to contact us

1. Scope of this policy

This Privacy Policy explains how KickCatch, LLC ("KickCatch", "we", "us", "our") collects, uses, shares, and protects personal information in connection with our website at kickcatch.com, our customer portal at portal.kickcatch.com, and our products — Secrets Manager, Integration Manager, and Release Manager (together, the "Services").

It does not apply to third-party services you connect to or reach from ours, including Microsoft Azure. Those are governed by their own privacy policies.

2. Our role: controller and processor

We act as a controller for the account, billing, support, and website information described below — we decide why and how it is processed.

We act as a processor for the cloud resource metadata we read from your Azure environment on your instruction. You decide what we may access and what we do with it; we process it to provide the Services and on your documented instructions. If you require a data processing agreement, contact [email protected].

3. Information we collect

Information you give us

  • Account information — first and last name, email address, and optionally a phone number, avatar image, and time zone.
  • Authentication information — a salted cryptographic hash of your password (never the password itself), multi-factor authentication settings, and, if you sign in with Microsoft, Google, or GitHub, the identifier and email address that provider returns to us.
  • Organization information — your organization's name, description, logo, time zone, and email domains used for invitations.
  • Billing information — your subscription plan, billing history, and a token-based reference to the payment method held by our payment processor.
  • Support and contact information — the name, email address, and message content you submit through our contact form or send to our support address.

Information we collect automatically

  • Activity records — a log of significant actions taken in your account (what was done, by whom, to which resource, when, the originating IP address, and whether it succeeded), retained so administrators can audit their organization's use of the Services.
  • Authentication events — last sign-in time, failed sign-in attempts, lockout status, and trusted-device records where you have chosen to remember a device for multi-factor authentication.
  • Technical and diagnostic data — IP address, browser and device type, requested URL, timestamps, and error details captured in application logs and telemetry.
  • Cookies — as described in our Cookie Policy.

Information we receive from third parties

  • Identity providers — if you sign in with Microsoft, Google, or GitHub, we receive your name, email address, and a unique identifier from them. We do not receive your password.
  • Payment processor — Stripe provides us with a customer and payment-method reference, the card brand and last four digits, the expiration date, and the status of each transaction.
  • Your cloud environment — where you connect an Azure subscription, we read resource metadata such as subscription, resource group, key vault, and secret names, tags, versions, and timestamps.

4. How we handle your secret values

We do not retain the secret values held in your Azure Key Vaults. Secrets Manager reads and writes those values through the Azure Key Vault API while carrying out a request you have made. They are not recorded in the secret catalogue we keep for your account, and are not written to our application logs, our telemetry, or our backups. What we keep is metadata — names, tags, identifiers, versions, and timestamps — which is what enables search, cross-vault views, and bulk editing. When you clone a key vault, only names and structure are copied; values are not.

Bulk operations are a limited, temporary exception. A bulk creation or bulk update has to apply the values you submitted across every target vault, so those values must be held for as long as the operation takes to complete. Throughout that window they are encrypted, and they are discarded once the operation finishes or fails. They are not retained afterwards, are not included in backups, and never become part of the metadata we hold about your environment.

We deliberately do not publish the specifics of this handling. A detailed description of the mechanism would be more useful to an attacker than to you. If you need that detail for a security review or vendor assessment, write to [email protected] and we can provide it under a confidentiality agreement.

Separately, we never receive or store your full payment card number or its security code, and we never receive the password you use with an external identity provider.

5. How we use information

  • To create and administer your account and your organization's Customer Account.
  • To provide the Services, including connecting to your cloud environment and performing the operations you request.
  • To authenticate you, enforce permissions, and operate multi-factor authentication.
  • To process payments, manage subscriptions and renewals, and send invoices and billing notices.
  • To send transactional and service messages — verification emails, password resets, invitations, security alerts, plan and billing notices, and material changes to our terms.
  • To provide support and respond to your enquiries.
  • To secure the Services — detecting and preventing fraud, abuse, credential stuffing, and automated attacks, including through bot-detection challenges.
  • To monitor performance, diagnose errors, and improve the Services.
  • To attribute referrals where you reached us through a partner or affiliate link.
  • To comply with legal obligations and enforce our Terms & Conditions.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train machine learning models.

6. Legal bases for processing

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and equivalent laws:

  • Performance of a contract — to provide the Services, administer your account, and process payments.
  • Legitimate interests — to secure the Services, prevent abuse, maintain audit records, diagnose faults, and improve our products, balanced against your rights.
  • Legal obligation — to retain financial records and respond to lawful requests.
  • Consent — for non-essential cookies and any optional marketing communications, which you may withdraw at any time.

7. Cookies and similar technologies

We use a small number of cookies and browser storage entries, almost all of which are strictly necessary for sign-in, security, and multi-factor authentication. We do not run advertising cookies or third-party analytics trackers on our website. Our Cookie Policy lists every cookie we set, what it does, and how long it lasts, and explains how to change your choices.

8. How we share information

We share personal information only in these circumstances:

  • Within your organization — administrators of your Customer Account can see the users in it and the activity performed within it.
  • With service providers — the sub-processors listed below, who process information on our behalf under contract and may not use it for their own purposes.
  • For legal reasons — where required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, safety, or property of KickCatch, our customers, or the public.
  • In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred information.
  • With your direction — where you ask us to share information with a third party.

9. Service providers and sub-processors

We rely on the following providers to operate the Services:

Provider Purpose Data involved
Microsoft Azure Cloud hosting, database, file storage, messaging, and identity All hosted account and metadata records
Stripe, Inc. Payment processing and subscription billing Name, email, billing details, payment card data
Twilio SendGrid Transactional email delivery Name, email address, message content
Cloudflare, Inc. Bot detection on public forms (Turnstile) IP address, browser signals
Sumo Logic, Inc. Application log management and monitoring IP address, request URLs, diagnostic and error data
Microsoft, Google, GitHub Optional single sign-on, if you choose to use it Name, email address, provider account identifier

We review this list as our infrastructure changes. To be notified of changes to our sub-processors, email [email protected].

10. International data transfers

We are based in the United States and our infrastructure and service providers are primarily located there. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, together with the technical and organizational measures described below.

11. How long we keep information

  • Account information — for as long as your account is active, and for up to 90 days after termination so it can be restored or exported, after which it is deleted or anonymized.
  • Cloud resource metadata — for as long as the connection exists; removing a connected subscription or vault removes its indexed metadata.
  • Secret values submitted with a bulk operation — held in encrypted form only for the duration of that operation, then discarded. Never carried into backups or long-term storage.
  • Activity and audit records — retained for the life of the Customer Account so administrators can audit past actions.
  • Billing records — retained for at least seven years to meet tax and accounting obligations.
  • Application logs and telemetry — retained on a rolling basis, typically no longer than 90 days.
  • Support correspondence — retained for up to three years after the enquiry is closed.

We may retain information longer where required by law or where necessary to establish, exercise, or defend legal claims.

12. How we protect information

We apply technical and organizational measures appropriate to the risk, including:

  • encryption in transit using TLS, and encryption at rest for hosted data;
  • storing passwords only as salted cryptographic hashes;
  • holding our own application credentials in Azure Key Vault rather than in configuration files;
  • multi-factor authentication, which organization administrators can require for all users;
  • role-based access control and customer-scoped data isolation, so one customer's data is not reachable from another's account;
  • account lockout after repeated failed sign-in attempts, and bot-detection challenges on public forms;
  • a design that avoids retaining secret values at all, and that keeps them encrypted throughout the limited bulk-operation window described in section 4; and
  • logging and monitoring of significant account activity.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.

13. Your privacy rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you and obtain a copy;
  • correct information that is inaccurate or incomplete;
  • delete your personal information, subject to our legal and contractual retention obligations;
  • receive your information in a portable, machine-readable format;
  • object to or restrict certain processing, including processing based on legitimate interests;
  • withdraw consent where we rely on it, without affecting processing already carried out; and
  • not be discriminated against for exercising any of these rights.

You can update much of your account information directly in the portal. For anything else, email [email protected]. We will verify your identity before acting and will respond within the time required by applicable law. If your information was submitted to us by an organization using the Services, we will refer your request to that organization and assist them in responding.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

14. Notice for U.S. state privacy laws

Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have the rights described above, including the right to know, delete, correct, and obtain a portable copy of their personal information.

In the twelve months preceding the date of this policy, we collected the categories of personal information described in section 3 — identifiers, commercial information, internet or network activity information, and professional information — for the business purposes described in section 5, and disclosed them only to the service providers listed in section 9.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly process sensitive personal information for the purpose of inferring characteristics about you. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" mechanism. We honour Global Privacy Control and similar browser signals where applicable.

You may designate an authorized agent to make a request on your behalf; we will ask for proof of authorization.

15. Children's privacy

The Services are business tools intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Changes to this policy

We may update this policy as our practices change. When we do, we will revise the "Last updated" date at the top of this page. If a change is material, we will give you notice by email or through the Services before it takes effect.

17. How to contact us

For any privacy question or to exercise your rights, email [email protected] or use the contact form on our website.

KickCatch, LLC
[email protected]

Products
  • Secrets Manager
  • Integration Manager
  • Release Manager
Company
  • Home
  • Contact
Legal
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

© KickCatch, LLC.

We use cookies to keep you signed in, secure your account, and credit referrals. We don't use advertising or third-party tracking cookies. Read our Cookie Policy for the full list.

Learn more