Privacy Policy

This policy explains how Kordiva collects, processes, stores, and protects personal data.

Last updated: March 2026. This document is provided for transparency and operational guidance.

1. Controller and scope

Kordiva processes personal and business-related data required to provide e-commerce platform services, onboarding, payments, and legal compliance workflows.

2. Categories of data

  • Account and identity data (name, email, organization role, login activity).
  • Business data (legal entity details, trade name, tax/registration information, store settings).
  • Payment and payout metadata required for Stripe onboarding and account operations.
  • Operational and compliance records (orders, invoices, audit logs, support interactions).
  • Technical usage data (IP address, device/browser data, security and error logs).

3. Stripe and payment privacy

For card payments, connected account onboarding, and payouts, data is shared with Stripe according to Stripe's own privacy and compliance framework. Stripe may process KYC/verification data, beneficial ownership details, payout account information, and transaction metadata.

Only required data is transferred for lawful payment processing, fraud prevention, and regulatory checks. If Stripe requests additional verification documents, users must submit those documents directly in Stripe to complete activation and payouts.

4. Why we process data

  • To deliver core platform features (product categories, products, orders, store administration).
  • To enable billing, subscription management, and payment operations.
  • To support legal and tax workflows, including reporting and invoicing readiness where applicable.
  • To secure the platform, detect abuse, and provide customer support.

5. Retention and security

Data is retained for the period necessary to provide the service, meet legal obligations, resolve disputes, and maintain auditable records. We use technical and organizational controls to protect confidentiality, integrity, and availability of data.

6. International transfers and processors

Some processors (including payment infrastructure and cloud services) may process data outside your country. Where required, appropriate contractual and technical safeguards are applied.

7. Data subject rights

You can request access, correction, deletion (where permitted), restriction, and objection in accordance with applicable law.

8. Contact

contact@kordiva.com

9. Policy updates

We may update this policy when platform functionality, payment flows, or legal obligations change. Material changes are reflected on this page with an updated date.