Skip to content
Home › Privacy

Privacy policy

Last updated: 26 August 2026

This policy explains how the operator of kitcompliance.com (“KitCompliance”, “we”, “us”) handles personal data. KitCompliance is workplace first-aid compliance software: organisations use it to record kits, inspections, equipment, first-aider certificates and accident-book entries.

This page is a factual description of the product as built. It is not a substitute for legal advice. If you need a contract that names a specific legal entity, registered office or DPO, contact us before processing special-category data at scale.

Who this applies to

What we collect

Account and organisation data

Name, email address, password hash (we do not store the password), organisation name, role, optional Google account identifier if you sign in with Google, plan and billing identifiers from Stripe, and product usage needed to enforce plan limits.

Workplace records the customer enters

Kit locations and contents, inspection results, equipment and servicing history, training certificates, and accident-book fields (including what happened, who was involved, and optional scene photos). Accident records can include health information. Customers must have a lawful basis under UK GDPR before they enter it.

Technical data

Server logs (path, method, time, coarse IP for rate limiting), and optional error reports sent to Sentry when that is configured. We do not run advertising cookies on the public site.

Why we use it

For our own account data the legal bases are typically contract (running the account you asked for) and legitimate interests (keeping the service secure). For accident-book content the customer determines the basis; that is often a legal obligation on the employer.

Where it is stored

Application data is stored in a SQLite database on the hosting volume, and uploaded accident photos live on the same persistent volume. Photo URLs are short-lived signed links; they are not meant to be indexed or cached publicly. Hosting is currently on Railway. Email is sent through Resend. Payments go through Stripe. Optional error monitoring uses Sentry. Optional SMS alerts use Twilio.

Those providers act as processors or independent controllers for payment. We do not sell personal data.

How long we keep it

Account and workplace records stay until the organisation deletes them or asks us to delete the account. Customers are responsible for accident-book retention periods under UK health and safety law (often years, not days). Server logs are kept only as long as needed for security and debugging. Signed upload links expire (default 12 hours).

Sharing

We share data with the subprocessors named above, and with someone you authorise (for example another user on the same organisation). We disclose information if required by law. We do not share data with advertisers.

Your rights (UK GDPR)

Depending on your role you can ask for access, correction, deletion, restriction, objection, or portability. Account holders can correct much of this in the app. People named only inside a customer’s accident book should contact that employer first — they are the controller. You can complain to the Information Commissioner’s Office.

Cookies and sign-in

After you log in we set an HttpOnly session cookie (kc_session) so the browser can call the API. It is essential to the service. A CSRF token is stored by the app so other sites cannot reuse that cookie. We do not use it for advertising.

Children

The product is for workplace compliance, not for children to open accounts. Early-years customers may record first-aid provision for a setting; they remain responsible for any data about children they enter.

Contact

Privacy questions: privacy@kitcompliance.com. Security disclosures: security@kitcompliance.com (see also security.txt).