Data protection
Privacy notice
Last updated: 28 July 2026
This notice covers the public website, kit builder, purchase and recovery flow, enquiries and business outreach. The product does not connect to your Microsoft tenant, request Microsoft Graph permissions or install an application.
Who is responsible for the data?
Kinane Labs Ltd, operator of SetupPasskeys, is the controller for order administration, enquiries, service security, product measurement and its own business outreach. Contact: privacy@setuppasskeys.com.
For payment data, Stripe also acts under its own legal responsibilities. Where an organisation places personal data in editable kit content and instructs SetupPasskeys to render, store or deliver it solely for that organisation, the organisation is normally the controller and Kinane Labs Ltd acts as processor for that limited processing. The offered processor terms are in the Data Processing Addendum.
Data used to build a preview
The builder processes the organisation domain, name, colours, logo, selected passkey methods, example work-email format, helpdesk details, rollout date and custom notes that you enter. When a domain is supplied, the service may retrieve public DNS information, Microsoft Entra sign-in branding and public website/logo assets. This lookup uses public information; it does not authenticate to the organisation’s tenant.
Please use a synthetic example account and do not enter passwords, passkeys, device or security-key PINs, Temporary Access Pass values, recovery codes, authentication tokens, live enrolment QR codes, special-category data or confidential incident evidence.
Saved drafts, purchases and recovery
Before checkout, the kit configuration is stored with a random private token and recovery code so it can survive the Stripe redirect. Unpaid drafts expire seven days after the last save. After payment, the order record also holds the purchase email, Stripe Checkout session reference, payment and delivery state, package configuration and email-delivery timestamps.
The private token is an access credential. Anyone holding the private link may be able to restore and edit the associated kit. The shorter recovery code is used only with the purchase email to resend that link; it does not return the configuration directly.
Payments and transaction emails
Stripe collects and processes payment-card, billing and tax information. SetupPasskeys does not receive or store full card numbers. Resend processes the recipient address and message content needed to deliver purchase, recovery and support emails. The service records delivery status so a confirmed purchase is not silently left without its link.
Enquiries and support
An enquiry may include name, work email, company domain, organisation-size band, intended rollout date, product interests, message, form location, landing URL and campaign parameters. The request user-agent and referrer are stored for context and spam triage. A truncated daily hash of the request IP address is retained for rate limiting; the enquiry row does not store the raw address. Submitting an enquiry does not by itself subscribe the address to marketing.
Domain preview submissions
When you deliberately submit a valid domain, Kinane Labs Ltd records the normalised domain, submission time, whether it was the public example, the preview or checkout entry point, whether the browser was marked as an internal test and a random one-use request identifier that prevents a network retry creating a duplicate. This limited record is created for every deliberate submission so the requested preview can be operated, protected and counted.
The unlinked domain-submission record contains no analytics browser or visit identifier, email address, IP address or hash, user-agent, referrer, campaign label, device information or fingerprint. It cannot establish that someone returned, that one person tried multiple domains, which guides they viewed or how long they were active. A submission shows only that someone entered the domain; it does not prove that the organisation itself visited or expressed interest.
Temporary product and visitor measurement
While the new reporting system is being verified, first-party visitor measurement starts by default unless the browser sends Global Privacy Control or Do Not Track. It records a random browser identifier, a separate per-tab visit identifier, campaign labels, funnel stages, the guides and guide pages viewed, and cumulative time while the page is visible. A deliberately submitted domain is also attached to that visitor journey. This allows Kinane Labs Ltd to verify return visits, multi-domain evaluation and which product material is useful.
The random browser identifier expires after 90 days and is not made from an IP address,
browser characteristics or another fingerprint. These measurement rows do not contain an
email address, IP address or IP hash, raw referrer, user-agent, precise location, prospect
token, guide text, helpdesk details or Microsoft tenant credentials. Campaign source may
use a tagged value such as reddit; an untagged referral is reduced to a
hostname in the browser.
Business prospect and outreach data
Private sales tooling may store organisation domains, public DNS/Entra signals, public website branding and business contact details published on the organisation’s own website, together with source URLs and evidence. A personalised preview link can record a truncated hash of the visitor IP address, user-agent, referrer, visit timing and product progression. That particular visit hash is not daily-rotated and can associate repeat visits from the same address.
Outreach email records can include delivery, first-open, click/preview engagement, suppression and unsubscribe state. Open detection uses a small remote image; mail-client privacy features may block or proxy it, so it is not treated as proof that a person read an email. Every marketing message must provide a suppression or unsubscribe route.
Request metadata and service security
Hosting, database and email providers necessarily process network and diagnostic data such as IP address, request time, URL, response status and user-agent in their service logs. SetupPasskeys also uses a daily server-keyed IP hash to limit anonymous kit saves. The raw address is used only in memory for that calculation and the quota record is deleted after approximately 25 hours.
Cookies and browser storage
The public kit does not use an advertising cookie or a third-party analytics cookie. Stripe may use cookies or similar technology after you open its hosted checkout under Stripe’s own notice.
The kit uses browser storage for the following functional purposes:
- Local storage: builder choices, tour state, the most recent unpaid draft token, a paid private-link/unlock reference and an internal-testing marker. Unless a supported browser privacy signal disables measurement, local storage also holds the random first-party visitor identifier for no longer than 90 days.
- Session storage: unless a supported browser privacy signal disables measurement, a random per-tab visit identifier, one-time event flags and the cumulative visible-time counter for the current browser session. Enquiry campaign attribution is also retained for the session and is sent only if an enquiry is submitted.
Local-storage values remain on that browser until they are replaced or you clear site data. Session-storage values normally disappear when the tab or browser session ends. Blocking storage does not prevent viewing the site, but it can stop the builder remembering choices or a purchase on that device; use the emailed private link to restore a paid kit.
The analytics choice prompt is temporarily disabled while Kinane Labs Ltd verifies that reporting is received correctly. Global Privacy Control and Do Not Track remain respected. Email privacy@setuppasskeys.com to object or request erasure. Collected rows expire under the 90-day rule unless erased earlier following a valid request.
Purposes and lawful bases
| Purpose | Usual GDPR basis |
|---|---|
| Build, sell, deliver, recover and support an ordered kit | Contract; steps requested before contract |
| Invoices, tax records and responding to statutory rights | Legal obligation |
| Prevent abuse, secure private links and diagnose delivery failures | Legitimate interests in operating a safe and reliable service |
| Process a domain to build the preview requested by the visitor | Steps requested before contract, where applicable |
| Retain a limited, unlinked domain-submission record for 90 days | Legitimate interests in operating, protecting and evaluating the preview service, subject to the right to object |
| Temporary product measurement and reporting verification | Legitimate interests claimed for the limited test; the consent model must be restored and reviewed before this becomes the normal public configuration |
| Answer enquiries and manage relevant business outreach | Steps requested before contract and/or legitimate interests; consent where required |
Where processing relies on legitimate interests, you may object. Direct marketing will stop for the address when you unsubscribe or ask for suppression.
Retention and deletion
| Record | Retention approach |
|---|---|
| Anonymous save-quota events | Deleted after approximately 25 hours |
| Unpaid kit drafts | Seven days after the most recent save |
| Paid kit configuration and private-link record | Kept while edit and re-download are provided, or until a valid deletion request, subject to records that must be retained |
| Invoices and transaction records | Normally six years, or longer where a tax, audit, dispute or legal requirement requires it |
| Enquiries and support correspondence | Until the matter and any related claim period are complete, then deleted or minimised unless required for records |
| Rollout Kit domain submissions and temporary visitor measurement | A daily retention job deletes rows once they are older than 90 days; the admin reporting view normally displays the latest 30 days |
| Funnel, prospect and outreach records | Reviewed against the active business relationship and deleted or aggregated when no longer necessary; suppression records are retained to honour opt-outs |
Deletion from live systems may not immediately remove encrypted backup copies; those age out under the relevant provider’s backup cycle and are not restored except for disaster recovery. A deletion request does not require erasure of data that must be retained by law or for the establishment, exercise or defence of legal claims.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data; receive portable data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing. There is no solely automated decision that produces legal or similarly significant effects through the public kit.
Email privacy@setuppasskeys.com. Enough information may be requested to verify that the response is sent to the right person, but do not send identity documents unless specifically and securely requested. You may also complain to the Irish Data Protection Commission or your local supervisory authority.
Changes to this notice
Material changes are dated here. If a change materially affects an active paid order and contact is reasonably possible, an additional notice may be sent to the purchase email.