Legal
Privacy Policy
Version 2026-09-20
This Privacy Policy explains how Kelp collects, uses, protects, and discloses personal data when you use the Kelp Market website (kelp.market), the Kelp Market platform services, and the Kelp Market desktop application (together, the "Services"). It applies together with the Uploader Terms of Service, which govern the content you submit through the Services.
1. Who we are
- The Services are operated by KELP DIGITAL OÜ, an Estonian company (registry code 16239967) with a registered office at Pärnu mnt. 139c, Tallinn, Harju maakond 11317, Estonia ("Kelp", "we", "us").
- For the purposes of applicable European Union data protection legislation, Kelp is the data controller for the personal data described in this Policy.
- You can reach us at daniel@kelp.market for any privacy question or request.
2. What personal data we collect
- Account data. Your email address, collected when you register an account or sign in (by magic-link email, or optionally through a Google account). We keep a record of your sign-in sessions for security.
- Application data. If you apply to become a partner, we collect the email address and applicant type (creator or company) you submit with the application form.
- Content and proof data. If you upload media, we process the files, their metadata, and the verification artifacts generated from them — including gear proofs, capture-time proofs, and sensor fingerprints. This material is product content processed under the Uploader Terms of Service; it is personal data only to the extent you include personal data in it.
- Payment data. If you buy a dataset, your email address is passed to our payment provider to create the checkout, and we record the purchase, settlement, and delivery status. If you sell as a creator, payout onboarding is handled by our payment provider, which may require identity and tax verification. We do not collect, store, or process credit card information.
- API usage data. If you access the Services programmatically (MCP or API keys), we log requests and key identity to enforce license terms and detect abuse.
- Usage analytics. We operate first-party, self-hosted analytics (Umami) on our own servers in the EU. It records page paths, referrers, browser/OS/device class, coarse location (country/city), and an anonymized session identifier derived from request attributes. It sets no cookies, stores no IP addresses, and the identifier rotates so it cannot be linked back to you or across websites.
- Operational logs. We keep server logs including IP address, user agent, and request timing for security and reliability.
3. What we do not do
- Our analytics are first-party and self-hosted (Umami): no third-party analytics scripts, no ad pixels, no cross-site profiling, no cookies.
- We use only strictly necessary cookies (session, login, and security cookies). We set no advertising or preference cookies and therefore show no cookie-consent banner.
- We do not sell personal data.
- We do not collect credit card information; payments are handled entirely by Stripe.
4. Why we process personal data
- To provide the Services (performance of a contract): create and authenticate accounts, deliver sign-in emails, evaluate and fulfill dataset purchases and licenses, pay creator earnings, and operate upload, verification, and distribution.
- For our legitimate interests: keep the Services secure and reliable, prevent fraud and abuse, enforce our terms, respond to your messages, and maintain records of licenses sold.
- To comply with legal obligations: accounting, tax, and other mandatory record-keeping.
- We do not send marketing email; the only emails we send are transactional (sign-in links, account, order, and payout communication).
5. Who we share personal data with
- Stripe (payments): processes dataset purchases and creator payout onboarding. Stripe acts as controller for the payment and payout data it collects.
- Mailjet (email delivery): delivers transactional email such as sign-in links.
- Hetzner (hosting and object storage, EU): hosts the Services and stores uploaded content and databases.
- GitHub (desktop distribution): serves desktop application downloads and update checks.
- We share personal data with these providers only as needed to operate the Services, and we may disclose personal data where required by law or to protect the rights, property, or safety of Kelp, our users, or others.
- We may publish aggregated, non-identifying statistics about the Services.
6. Where data is processed
- Hosting, storage, and primary databases are located in the European Union.
- Some providers, notably our payment provider, process data outside the EU. Where personal data is transferred outside the EEA, we rely on the safeguards required by EU data protection law, such as the European Commission's standard contractual clauses.
7. How long we keep personal data
- Account and license records: for as long as your account is active, and thereafter as required for legal, accounting, and audit purposes.
- Partner applications: until a decision is made on the application, and longer only if the application leads to an account.
- Operational logs: for a limited period consistent with security and reliability needs.
- Usage analytics: kept on our own servers for aggregate statistics; individual event data is deleted on request.
- Uploaded content and verification artifacts are retained as described in the Uploader Terms of Service, including archival copies retained for legal, security, or audit purposes.
8. Your rights
- Under EU data protection law you have the rights to access, rectify, and erase your personal data, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on consent.
- To exercise any right, email daniel@kelp.market. We respond within the statutory period.
- You have the right to lodge a complaint with a supervisory authority. For Estonia this is the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate); you may also complain to the authority of your habitual residence.
9. Children
- The Services are not directed at children, and we do not knowingly collect personal data from children below the age required by applicable law. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this Policy
- We may update this Privacy Policy from time to time. The version in force is the one published on this page; material changes are identified by a new version marker, and where required by law we will notify you before they take effect.