← Konnect home

Privacy Policy

Effective date: August 26, 2026 Last updated: August 26, 2026

This Privacy Policy explains how Ethan William White, doing business as Konnect ("Konnect", "we", "us"), collects, uses, shares and protects personal information in connection with kiddynaconnect.com, the Konnect Discord bot, the Konnect dashboard and API, and the Konnect beat storefront (together, the "Service").

This policy covers two different groups of people, and the difference matters:

If you are a Contact and want your information removed, jump to Section 6 or email privacy@kiddynaconnect.com. We will action it.


1. Who we are and how to reach us

Konnect is based in British Columbia, Canada. Our primary privacy obligations are under the federal *Personal Information Protection and Electronic Documents Act* ("PIPEDA") and, for our activities within the province, British Columbia's *Personal Information Protection Act* ("BC PIPA"). Sections 1a and 1b are our notice under those laws. We separately describe GDPR/UK GDPR obligations (Section 6, Section 9) and US state obligations (Section 7) because we also serve Users and Contacts there.

OrganizationEthan William White d/b/a Konnect
Postal address2931 Fifth Street, Victoria, BC V8T 4B4, Canada
Privacy Officer (PIPEDA requires one be designated)Ethan William White — privacy@kiddynaconnect.com
EU/UK representative (Art. 27 GDPR)Not appointed — we do not target the EU/UK market

1a. Your rights under PIPEDA and BC PIPA

Under PIPEDA's ten fair information principles (which BC PIPA mirrors) you have the right to: know why we collect your information (Section 3); access the personal information we hold about you; request that we correct it; withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; and challenge our compliance with this policy. Exercise any of these by emailing our Privacy Officer above — no charge, and we respond within 30 days.

If you are not satisfied with our response, you may complain to the **Office of the Privacy Commissioner of Canada** (priv.gc.ca) or, for matters specific to our activity as a BC-based organization, the **Office of the Information and Privacy Commissioner for British Columbia** (oipc.bc.ca).

1b. Consent, and where we rely on it

We collect, use and disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances, and only with your knowledge and consent where PIPEDA or BC PIPA require it. Where you create an account, your consent is express, recorded with a timestamp. Where information is collected about a Contact from a public source (Section 6), PIPEDA and BC PIPA both permit collection from a source other than the individual, without their prior consent, where the information is **already publicly available** and the collection is for a purpose related to that public availability — which is the basis we rely on, alongside the assessment in Section 6.2. You may still object at any time; see Section 6.4.


2. Information we collect about Users

2.1 You give it to us

DataWhy we have itLegal basis (GDPR)
Discord user IDIdentifies your account, tracks creditsContract
Email address (web signup)Account identifier and sign-inContract
Password, stored only as a salted scrypt hashWeb sign-in. We never store or can recover the plaintextContract
Consent flag and timestampRecords the agreement you gave at signupLegal obligation / consent
Storefront profile: display name, bio, artwork, licence terms, pricesOperates your public shopContract
Support messages you send usAnswering youLegitimate interests
Waitlist email address, and which unreleased feature you asked aboutEmailing you once when that feature opens up. Nothing else is sent to it, and it is not added to any other listConsent

2.2 Generated by your use

DataWhy we have itLegal basis (GDPR)
Credit balance, plan and entitlementsOperating the credit systemContract
Scrape history: hashtag, platform, timestamp, result countsYour activity feed, deduplication, abuse preventionContract / legitimate interests
Contacts pipeline state, notes, follow-up statusThe CRM feature you useContract
Outreach send logs: recipient, timestamp, template, send outcomeEnforcing sending caps, duplicate-send protection, abuse investigation, and your own send historyContract / legitimate interests
Uploaded beats, renders, and storefront listingsHosting, rendering, publishing and selling at your directionContract
Server logs: IP address, user agent, request paths, timestamps, error tracesSecurity, abuse and fraud prevention, debugging, rate limitingLegitimate interests
Storefront analytics: page views, preview plays, buy-click eventsShowing you how your shop performsLegitimate interests

2.3 From third parties

SourceDataWhy
StripePayment event IDs, product IDs, subscription status, payout and Connect account status, last four digits and card brand where shownGranting credits idempotently, billing, marketplace payouts. We never receive or store full card numbers or bank details
DiscordYour Discord user ID and display nameBot authentication and account linking
Google / YouTubeOAuth tokens and channel title (see Section 5)Publishing beat videos to your channel
Google / GmailOAuth token with gmail.send scope, where you connect it (see Section 5)Sending outreach that you compose, from your inbox

We do not collect government IDs, biometric data, precise geolocation, health data, or any other special-category / sensitive personal data as defined by the GDPR or CPRA.


3. How we use information

**We do not use your data for behavioural advertising, we do not sell User account data, and we do not train third-party AI models on your beats or your private contacts.**


4. Who we share information with

We share only what is needed, with the following categories of recipients. Our current processors and sub-processors:

ProviderRoleWhat it receives
PebbleHostHosting and infrastructureEverything stored or processed by the Service, at rest on their servers
StripePayments, subscriptions, marketplace payouts (Connect)Payment and identity data you give Stripe directly, plus transaction metadata
DiscordBot platformYour Discord ID and the messages the bot exchanges with you
Google LLC (YouTube Data API, Gmail API)Publishing and sending, at your directionThe video you publish, the message you send, and the OAuth token authorising it
*(no separate object-storage provider is in use)*Audio and video files are stored on the application host covered by the PebbleHost row above

We also disclose information:

We do not sell User account data to anyone. For how the contact-trading feature is treated under US state privacy law, see Section 7.3.


5. Google user data (Beat Tools and Gmail outreach)

Konnect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

ScopeWhat it allowsWhy we ask
youtube.uploadUploading videos to your channelTo publish the beat videos you ask us to publish, and nothing else
youtube.readonlyReading your channel titleSo the dashboard can show which channel is connected
gmail.sendSending mail as youTo send the outreach messages you compose and approve, from your own inbox. This scope cannot read, list, delete or modify anything in your mailbox

What we store: the OAuth refresh/access token (used only for the actions above) and your channel title. We never see or store your Google password.

What we never do with Google user data: we do not sell it; we do not use it for advertising; we do not use it to train generalised AI or ML models; we do not transfer it to third parties except as necessary to provide the feature you requested, to comply with law, or as part of a merger where we obtain your consent; and no human reads it except with your explicit consent, for security or abuse investigation, or where required by law.

Revoking access: disconnect the channel or inbox in the Konnect dashboard, which deletes the stored token, or revoke Konnect at any time at Google security settings.

Beat Tools uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service; the Google Privacy Policy governs Google's own handling of your data.


6. If you are a Contact: information we hold about you

**This section is for artists, producers and businesses whose contact details appear in the Service, and who never signed up for it.** It is our notice under Article 14 GDPR and the equivalent provisions of other privacy laws.

6.1 What we collect and where it comes from

We collect **business-contact information that you or your representative published in a public place** — a public profile bio, an "about" or business-email field, a public channel description, or a public web page — on Instagram, TikTok, YouTube, SoundCloud, Spotify, and linked public sites. Typically: **an email address, a display name or handle, and the public profile URL it came from.**

We do not collect data from private accounts, private messages, or anything behind a login belonging to you. We do not collect phone numbers, addresses, payment data, or any special-category data about Contacts.

6.2 Why, and on what legal basis

We process it for one purpose: **to let music professionals find and contact other music professionals about collaboration, licensing, booking and promotion.**

Under PIPEDA and BC PIPA (our primary obligation, as a British Columbia organization), we rely on the "publicly available information" basis: the information was already made public by you or on your behalf for a purpose consistent with this one, so PIPEDA and BC PIPA permit its collection and use without prior consent, subject to it being reasonable in the circumstances and to your right to object below.

Where the GDPR or UK GDPR also applies, our legal basis is legitimate interests (Article 6(1)(f)) — our interest and our Users' interest in business-to-business music-industry outreach — balanced against your rights. We have carried out and documented a legitimate interests assessment, and we limit the data to business-contact fields you published for exactly this purpose. You have an absolute right to object; see 6.4.

We do not make automated decisions about you that produce legal or similarly significant effects.

6.3 How long we keep it

Contact records are retained while they remain useful for outreach and are reviewed periodically. Records that fail validation (for example, an address that no longer accepts mail) are flagged and become eligible for deletion. On a valid removal request we delete promptly, and we keep a minimal suppression record — a one-way hash of the address — solely so that the same address is never re-collected or re-contacted. That suppression record is kept indefinitely for that purpose, which is itself a protection for you.

6.4 Your rights, and how to use them in one step

**Email privacy@kiddynaconnect.com from the address in question, or tell us which record to remove.** You do not need an account, you do not need to explain why, and there is no charge. You can ask us to:

We respond within 30 days (extendable where the law permits and we tell you why). We will not discriminate against you for exercising a right, and we do not require you to create an account to exercise one.

We also notify Users. Our Terms require every User to delete their copy of your information on request. We will pass a deletion request on to Users who received your record where we are reasonably able to identify them.

You also have the right to complain to your data protection authority — in the EU, your national supervisory authority; in the UK, the ICO.


7. US state privacy rights

7.1 California (CCPA/CPRA), and other US state laws

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to: know and access the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients; delete personal information; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information and of targeted advertising; limit the use of sensitive personal information (we collect none); and appeal a denial. **We will not discriminate against you for exercising any of these rights.**

Exercise any of them by emailing privacy@kiddynaconnect.com with the subject line of the right you want. An authorised agent may act for you with written permission and verification. We verify requests by matching the request to information we already hold — for example, by requiring the request to come from the email address concerned.

7.2 Categories collected in the last 12 months

CCPA categoryCollectedExamples
IdentifiersYesDiscord ID, email address, IP address, account ID, public profile URL
Commercial informationYesCredits purchased, subscription and plan, sales and payout records
Internet or network activityYesServer logs, page and preview-play events, feature usage
Professional or employment informationYesBusiness-contact records and storefront profiles
Audio/visual informationYesBeats and renders that Users upload
Sensitive personal informationNoWe do not collect it
Biometric, geolocation, education, inferences for profilingNoNot collected

We keep each category only as long as described in Section 8.

7.3 "Sale" and "sharing" — the honest answer

We do not sell or share User account data, and we do not engage in cross-context behavioural advertising.

However, the Service includes a feature that lets Users **trade contact records with each other**. When you trade, business-contact information moves from one User to another in exchange for other contact information. **Under the CCPA's broad definition, that exchange for "other valuable consideration" is likely a "sale" of personal information**, so we treat it as one.

**If you are a Contact and you do not want your information traded, disclosed to Users, or held at all, email privacy@kiddynaconnect.com with the subject "DO NOT SELL OR SHARE" and we will suppress and delete it.** Because we obtain this information from public sources rather than from you directly, this email channel is the opt-out mechanism, and no account is required to use it.

We do not knowingly sell or share the personal information of consumers under 16 years of age.


8. How long we keep information

DataRetention
Account record (User ID, email, credits, plan)While the account is active, then deleted or anonymised within 30 days of a verified closure request
Password hashDeleted with the account
Scrape and outreach logsUp to 24 months, then deleted or aggregated
Uploaded beats, renders, storefront listingsWhile the account is active, or until you delete them
Payment and tax recordsAs long as required by tax and accounting law, typically 7 years
Server and security logsUp to 12 months
Contact recordsSee Section 6.3
Suppression list (one-way hashes)Indefinitely, solely to keep removed contacts removed
BackupsRolling daily snapshots, the newest 14 retained, so a backup is overwritten within 14 days; deletions propagate as backups cycle

We may keep information longer where we must to comply with law, resolve a dispute, or enforce our agreements.


9. Where information is processed, and international transfers

The Service is hosted in Canada (Montréal, Quebec). If you are in the EEA, UK or Switzerland, your information will be transferred to and processed in a country that may not provide the same level of protection as your own.

Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) as incorporated into our agreements with our processors, together with the supplementary measures described in Section 10. Stripe and Google each maintain their own transfer mechanisms, including certification under the EU-US Data Privacy Framework where applicable. You may request a copy of the relevant safeguards at privacy@kiddynaconnect.com.


10. Security

We take reasonable and appropriate technical and organisational measures to protect personal information, including: transport encryption (HTTPS/TLS) for all traffic; storing passwords only as salted scrypt hashes; keeping credentials and API keys in server environment variables rather than in source control; signature verification on payment webhooks with idempotent event handling; server-side authorisation checks on every data access; rate limiting; and restricting production access to the smallest number of people necessary.

No system is perfectly secure. We cannot guarantee absolute security, and you send information to us at your own risk. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as and when required by law. Under PIPEDA, we notify the Office of the Privacy Commissioner of Canada and affected individuals as soon as feasible after determining the breach creates a real risk of significant harm, and we keep a record of every breach, whether or not it meets that threshold, for at least 24 months. Where the GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, where the breach is notifiable. Where a US state breach law applies, we follow its own timeline.

Report a suspected vulnerability to security@kiddynaconnect.com; see our vulnerability disclosure policy for our good-faith-researcher commitments.


11. Cookies and similar technologies

Konnect uses a strictly necessary set only:

PurposeTypeCan you refuse it?
Keeping you signed inFirst-party session cookieNot without losing the ability to sign in
Security and abuse prevention (CSRF, rate limiting)First-partyNo — required for the Service to be safe
Remembering interface preferencesFirst-party, local storageYes, by clearing site data

**We do not use advertising cookies, third-party trackers, cross-site pixels, or behavioural analytics, so we do not show a consent banner** — strictly necessary cookies do not require consent under the ePrivacy rules. If that ever changes, we will ask for consent before setting any non-essential cookie.

We do not respond to browser "Do Not Track" signals, because there is no common standard for them. We do honour Global Privacy Control (GPC) signals as an opt-out of sale or sharing where applicable law requires it.


12. Children's privacy

The Service is not directed to children under 13, and paid and selling features require that you be 18 or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, contact privacy@kiddynaconnect.com and we will delete it and close the account.


13. Your choices


14. Changes to this policy

We may update this policy. If a change is material, we will give reasonable advance notice by email or in-product notice before it takes effect, and we will always update the "Last updated" date above. Previous versions are available on request.


15. Contact

PurposeAddress
Privacy questions, access, deletion, opt-outprivacy@kiddynaconnect.com
Security vulnerabilitiessecurity@kiddynaconnect.com
Everything elsesupport@kiddynaconnect.com

Ethan William White d/b/a Konnect

2931 Fifth Street, Victoria, BC V8T 4B4, Canada