At Identity Forge, accessible from https://identityforge.io, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Kasayo and how we use it.
If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.
This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in Kasayo. This policy is not applicable to any information collected offline or via channels other than this website.
Depending on the processing activity, we process personal data to perform a contract with you, comply with legal obligations, pursue legitimate interests such as security and service reliability, or on the basis of consent where consent is required. You can withdraw consent at any time without affecting processing that occurred before the withdrawal.
The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.
If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.
When you register for an Account, we may ask for your contact information, including items such as name, company name, address, email address, and telephone number.
When you purchase a subscription, Lifetime access, or credit boosters, we process transaction identifiers, product and amount, subscription status, billing address, business name, and tax identification information where provided. Stripe collects and processes payment-card details directly. Identity Forge does not receive or store complete card numbers.
Stripe processes payments and calculates applicable sales tax or VAT for us. We share the information needed to create and administer a payment, prevent fraud, issue invoices, and meet accounting and tax obligations. Stripe may act as our processor for payment instructions and as an independent controller for its own regulatory, fraud prevention, and payment-network obligations. See the Stripe Privacy Policy.
Billing and tax records are retained for the statutory accounting and tax retention periods that apply to Kasayo e.K. Other account data is retained while your account is active and then only as long as needed for the purposes described here, legal claims, security, or applicable law.
We use the information we collect in various ways, including to:
Our web server keeps an access log of the requests it serves. Each entry records the internet protocol (IP) address the request came from, the browser's user-agent string, the date and time, the path requested, the response status, and the referring page when the browser sends one. We use it to tell real visitors from automated crawlers, to investigate abuse and outages, and to check that our analytics are not silently missing traffic. The log is stored on infrastructure we operate in Germany, is not shared, and entries are deleted after one year.
We use the open-source Umami and OpenPanel services on infrastructure we operate in Germany. They set no analytics cookie and do not track visitors across sites. They record page views, product events, coarse location, referrers, approved campaign attribution, device details, and Web Vitals. Secret brand-share paths are replaced with /p/[token], and URL fragments and arbitrary query parameters are removed before collection.
On our public marketing and catalogue pages only, we also collect aggregate click and scroll positions to build heatmaps. Every form input and every piece of text is masked before anything leaves your browser, so what is recorded is where people clicked, not what they read or typed. This never runs on a signed-in page, a brand workspace, or a shared brand link.
Session replay is not enabled. We do not record or replay your screen, your mouse movements, or your keystrokes.
If you are signed in, we attach a plan label, the month your account was created, and an irreversible pseudonym derived from your account identifier, so we can understand how different kinds of account use the product. That pseudonym cannot be turned back into your account, your name, or your email address by anyone who does not hold our server key, and none of those values are sent. OpenPanel uses a separate versioned pseudonym made with an analytics-only server key, so its profile remains pseudonymous rather than anonymous.
Requests to our public API arrive without an account, so to tell one caller from many we derive a day-scoped pseudonym from the requesting address and user-agent using the same analytics-only server key. It is not stored, it cannot be reversed into an address, and it changes every day, so it counts callers within a day and cannot follow one across days. Requests from a declared crawler are labelled as such and receive no pseudonym at all.
Events we record on our server carry two further pieces of context to our own analytics: your user-agent, and a shortened form of your address with the final part removed. The shortened address is enough to resolve a country and deliberately not enough to resolve a city, a street, or you. Your full address is never stored for analytics, the shortened form is discarded as soon as the event has been recorded, and neither is combined with your account.
Pseudonymous analytics events and profiles are retained for the maximum period supported by our self-hosted OpenPanel deployment. We impose no shorter product expiry on ordinary analytics records; aggregate scorecards may be retained indefinitely where permitted. You can opt out at any time with ?analytics=off; ?analytics=on re-enables tracking. Automated browsers are excluded by default. Session replay is not enabled in either service, and signing out clears the analytics profile from the browser.
Like any other website, Identity Forge uses 'cookies'. These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information.
One of them is worth naming. On your first visit we set a first-party cookie called if_ft, readable only by our server and never by scripts, which records how you first arrived: the campaign tags in the link you followed, the website that referred you, and the page you landed on. It lets us tell which of our own posts and links actually bring people here. It contains nothing that identifies you, secret share links are replaced with /p/[token] before it is written, and it expires after six months. If you later create an account, that arrival information is copied onto the account so we can see which channels bring us customers.
For more general information on cookies, please read "What Are Cookies" (https://www.privacypolicyonline.com/what-are-cookies/) .
If you separately allow Ads measurement, our server sends Google Ads only a verified signup and your first paid Pro purchase. We do not use this consent for personalized advertising or remarketing.
For matching, we send Google the SHA-256 hash of your normalized email address and advertising click identifiers where available. Each conversion includes an opaque transaction identifier. A purchase also includes the net amount excluding VAT and EUR as the currency. We do not include your name, postal address, payment-card details, plan, brand data, project contents, Google Analytics identifier, or a Google account pseudonym. No Google Ads tag runs in your browser.
After consent, a first-party cookie may retain a Google ad click identifier for up to 90 days. Your consent choice is retained for up to one year and can be changed at any time through privacy choices. Withdrawing consent removes the stored click identifiers from your account and prevents pending conversions from being sent. Processing already completed before withdrawal is unaffected.
Google processes conversion data under its customer data and privacy terms. See the Google Privacy Policy.
Under the CCPA, among other rights, California consumers have the right to:
Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers.
Request that a business delete any personal data about the consumer that a business has collected.
Request that a business that sells a consumer's personal data, not sell the consumer's personal data.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.
We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:
The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service.
The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.
Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.
Kasayo does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.