Skip to content
KezaroPay

Privacy notice

Where this release keeps your information.

This notice describes the KezaroPay site as it works today: server-backed account access and a browser-based financial testing workspace. These are different stores of information with different limits.

Account registration and sign-in

Registration sends your name, email address, business name and password to the application server. The server stores account records in its persistent SQLite database, including a password hash rather than the readable password.

Session records support sign-in, session expiry and account security. They can contain device information, timestamps and a hashed IP reference. Authentication and rate-limit records are separate from the financial examples in the workspace.

Cookies and appearance preferences

A session cookie keeps you signed in. Production session cookies use Secure and HttpOnly settings; the sign-in flow also uses a separate security cookie to check form requests.

Your Light, Dark or System appearance choice is stored in a browser preference and a cookie. This allows the same appearance to be applied when a page loads. Clearing site data can remove that preference.

Financial examples stay in this browser

Cards, Billing Profiles, simulated balances, payment records and test support tickets are currently saved in account-scoped browser storage. They are not an authoritative financial ledger on the server.

Signing in on a different device does not transfer that local testing state. Clearing browser storage can remove it. Do not enter real payment credentials, identity documents or sensitive customer data into these simulated workflows.

External services and messages

Live card, payment and advertising integrations are not enabled for this release. The sample checkout does not charge a payment method, and the workspace’s local support-ticket action does not deliver a message to a support inbox.

Password-reset email delivery is not connected. Provider-specific data disclosures must be published when live services are introduced; sample integration screens do not establish a provider relationship.

Information still awaiting owner review

The publisher’s legal identity, a verified privacy contact, formal retention periods and the process for access or deletion requests have not yet been published. Any applicable provider list and cross-border data handling also need review before live financial use.

This is a description of the current implementation, not a claim that every legal disclosure is complete. The Contact page states the present support limitation.