Privacy Policy
Effective date: August 26, 2026 Last updated: August 26, 2026
This Privacy Policy explains how Ethan William White, doing business as Konnect ("Konnect", "we", "us"), collects, uses, shares and protects personal information in connection with kiddynaconnect.com, the Konnect Discord bot, the Konnect dashboard and API, and the Konnect beat storefront (together, the "Service").
This policy covers two different groups of people, and the difference matters:
- Users — producers and buyers who sign up for and use Konnect. We are the controller of your account data.
- Contacts — artists and businesses whose publicly posted business-contact information the Service surfaces. Section 6 is written specifically for you, including how to have your information removed.
If you are a Contact and want your information removed, jump to Section 6 or email privacy@kiddynaconnect.com. We will action it.
1. Who we are and how to reach us
Konnect is based in British Columbia, Canada. Our primary privacy obligations are under the federal *Personal Information Protection and Electronic Documents Act* ("PIPEDA") and, for our activities within the province, British Columbia's *Personal Information Protection Act* ("BC PIPA"). Sections 1a and 1b are our notice under those laws. We separately describe GDPR/UK GDPR obligations (Section 6, Section 9) and US state obligations (Section 7) because we also serve Users and Contacts there.
| Organization | Ethan William White d/b/a Konnect |
| Postal address | 2931 Fifth Street, Victoria, BC V8T 4B4, Canada |
| Privacy Officer (PIPEDA requires one be designated) | Ethan William White — privacy@kiddynaconnect.com |
| EU/UK representative (Art. 27 GDPR) | Not appointed — we do not target the EU/UK market |
1a. Your rights under PIPEDA and BC PIPA
Under PIPEDA's ten fair information principles (which BC PIPA mirrors) you have the right to: know why we collect your information (Section 3); access the personal information we hold about you; request that we correct it; withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; and challenge our compliance with this policy. Exercise any of these by emailing our Privacy Officer above — no charge, and we respond within 30 days.
If you are not satisfied with our response, you may complain to the **Office of the Privacy Commissioner of Canada** (priv.gc.ca) or, for matters specific to our activity as a BC-based organization, the **Office of the Information and Privacy Commissioner for British Columbia** (oipc.bc.ca).
1b. Consent, and where we rely on it
We collect, use and disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances, and only with your knowledge and consent where PIPEDA or BC PIPA require it. Where you create an account, your consent is express, recorded with a timestamp. Where information is collected about a Contact from a public source (Section 6), PIPEDA and BC PIPA both permit collection from a source other than the individual, without their prior consent, where the information is **already publicly available** and the collection is for a purpose related to that public availability — which is the basis we rely on, alongside the assessment in Section 6.2. You may still object at any time; see Section 6.4.
2. Information we collect about Users
2.1 You give it to us
| Data | Why we have it | Legal basis (GDPR) |
|---|---|---|
| Discord user ID | Identifies your account, tracks credits | Contract |
| Email address (web signup) | Account identifier and sign-in | Contract |
Password, stored only as a salted scrypt hash | Web sign-in. We never store or can recover the plaintext | Contract |
| Consent flag and timestamp | Records the agreement you gave at signup | Legal obligation / consent |
| Storefront profile: display name, bio, artwork, licence terms, prices | Operates your public shop | Contract |
| Support messages you send us | Answering you | Legitimate interests |
| Waitlist email address, and which unreleased feature you asked about | Emailing you once when that feature opens up. Nothing else is sent to it, and it is not added to any other list | Consent |
2.2 Generated by your use
| Data | Why we have it | Legal basis (GDPR) |
|---|---|---|
| Credit balance, plan and entitlements | Operating the credit system | Contract |
| Scrape history: hashtag, platform, timestamp, result counts | Your activity feed, deduplication, abuse prevention | Contract / legitimate interests |
| Contacts pipeline state, notes, follow-up status | The CRM feature you use | Contract |
| Outreach send logs: recipient, timestamp, template, send outcome | Enforcing sending caps, duplicate-send protection, abuse investigation, and your own send history | Contract / legitimate interests |
| Uploaded beats, renders, and storefront listings | Hosting, rendering, publishing and selling at your direction | Contract |
| Server logs: IP address, user agent, request paths, timestamps, error traces | Security, abuse and fraud prevention, debugging, rate limiting | Legitimate interests |
| Storefront analytics: page views, preview plays, buy-click events | Showing you how your shop performs | Legitimate interests |
2.3 From third parties
| Source | Data | Why |
|---|---|---|
| Stripe | Payment event IDs, product IDs, subscription status, payout and Connect account status, last four digits and card brand where shown | Granting credits idempotently, billing, marketplace payouts. We never receive or store full card numbers or bank details |
| Discord | Your Discord user ID and display name | Bot authentication and account linking |
| Google / YouTube | OAuth tokens and channel title (see Section 5) | Publishing beat videos to your channel |
| Google / Gmail | OAuth token with gmail.send scope, where you connect it (see Section 5) | Sending outreach that you compose, from your inbox |
We do not collect government IDs, biometric data, precise geolocation, health data, or any other special-category / sensitive personal data as defined by the GDPR or CPRA.
3. How we use information
- To create and operate your account and deliver the features you ask for.
- To process payments, grant credits, and run the marketplace.
- To render, publish, host, and deliver your beats and storefront.
- To send outreach at your instruction, from your own connected inbox.
- To enforce credit limits, sending caps, and the Acceptable Use rules in our Terms.
- To detect, investigate and prevent fraud, abuse, spam and security incidents.
- To debug, monitor, measure and improve the Service.
- To send service and transactional messages (billing, security, changes to terms). You cannot opt out of these while you have an account.
- To send product or marketing email, only where you have opted in or where permitted by law, with an unsubscribe link in every message.
- To comply with law, respond to lawful requests, and establish, exercise or defend legal claims.
**We do not use your data for behavioural advertising, we do not sell User account data, and we do not train third-party AI models on your beats or your private contacts.**
4. Who we share information with
We share only what is needed, with the following categories of recipients. Our current processors and sub-processors:
| Provider | Role | What it receives |
|---|---|---|
| PebbleHost | Hosting and infrastructure | Everything stored or processed by the Service, at rest on their servers |
| Stripe | Payments, subscriptions, marketplace payouts (Connect) | Payment and identity data you give Stripe directly, plus transaction metadata |
| Discord | Bot platform | Your Discord ID and the messages the bot exchanges with you |
| Google LLC (YouTube Data API, Gmail API) | Publishing and sending, at your direction | The video you publish, the message you send, and the OAuth token authorising it |
| *(no separate object-storage provider is in use)* | Audio and video files are stored on the application host covered by the PebbleHost row above | — |
We also disclose information:
- To other Users, where you direct it — your public storefront is public by design, and the contact-trading feature discloses contact records to the User you trade with. See Section 7.
- For legal reasons — to comply with law, a subpoena, court order, or other valid legal process; to enforce our Terms; or to protect the rights, property, or safety of Konnect, our Users, or the public. We will notify you of a legal demand for your data unless we are legally prohibited or it would be futile or dangerous.
- In a business transfer — if Konnect is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will give notice and any transferee remains bound by this policy or gives comparable protection.
We do not sell User account data to anyone. For how the contact-trading feature is treated under US state privacy law, see Section 7.3.
5. Google user data (Beat Tools and Gmail outreach)
Konnect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
| Scope | What it allows | Why we ask |
|---|---|---|
youtube.upload | Uploading videos to your channel | To publish the beat videos you ask us to publish, and nothing else |
youtube.readonly | Reading your channel title | So the dashboard can show which channel is connected |
gmail.send | Sending mail as you | To send the outreach messages you compose and approve, from your own inbox. This scope cannot read, list, delete or modify anything in your mailbox |
What we store: the OAuth refresh/access token (used only for the actions above) and your channel title. We never see or store your Google password.
What we never do with Google user data: we do not sell it; we do not use it for advertising; we do not use it to train generalised AI or ML models; we do not transfer it to third parties except as necessary to provide the feature you requested, to comply with law, or as part of a merger where we obtain your consent; and no human reads it except with your explicit consent, for security or abuse investigation, or where required by law.
Revoking access: disconnect the channel or inbox in the Konnect dashboard, which deletes the stored token, or revoke Konnect at any time at Google security settings.
Beat Tools uses YouTube API Services. By connecting a channel you also agree to the YouTube Terms of Service; the Google Privacy Policy governs Google's own handling of your data.
6. If you are a Contact: information we hold about you
**This section is for artists, producers and businesses whose contact details appear in the Service, and who never signed up for it.** It is our notice under Article 14 GDPR and the equivalent provisions of other privacy laws.
6.1 What we collect and where it comes from
We collect **business-contact information that you or your representative published in a public place** — a public profile bio, an "about" or business-email field, a public channel description, or a public web page — on Instagram, TikTok, YouTube, SoundCloud, Spotify, and linked public sites. Typically: **an email address, a display name or handle, and the public profile URL it came from.**
We do not collect data from private accounts, private messages, or anything behind a login belonging to you. We do not collect phone numbers, addresses, payment data, or any special-category data about Contacts.
6.2 Why, and on what legal basis
We process it for one purpose: **to let music professionals find and contact other music professionals about collaboration, licensing, booking and promotion.**
Under PIPEDA and BC PIPA (our primary obligation, as a British Columbia organization), we rely on the "publicly available information" basis: the information was already made public by you or on your behalf for a purpose consistent with this one, so PIPEDA and BC PIPA permit its collection and use without prior consent, subject to it being reasonable in the circumstances and to your right to object below.
Where the GDPR or UK GDPR also applies, our legal basis is legitimate interests (Article 6(1)(f)) — our interest and our Users' interest in business-to-business music-industry outreach — balanced against your rights. We have carried out and documented a legitimate interests assessment, and we limit the data to business-contact fields you published for exactly this purpose. You have an absolute right to object; see 6.4.
We do not make automated decisions about you that produce legal or similarly significant effects.
6.3 How long we keep it
Contact records are retained while they remain useful for outreach and are reviewed periodically. Records that fail validation (for example, an address that no longer accepts mail) are flagged and become eligible for deletion. On a valid removal request we delete promptly, and we keep a minimal suppression record — a one-way hash of the address — solely so that the same address is never re-collected or re-contacted. That suppression record is kept indefinitely for that purpose, which is itself a protection for you.
6.4 Your rights, and how to use them in one step
**Email privacy@kiddynaconnect.com from the address in question, or tell us which record to remove.** You do not need an account, you do not need to explain why, and there is no charge. You can ask us to:
- delete your information (right to erasure);
- object to processing, which we honour by deleting and suppressing;
- access a copy of what we hold about you;
- correct anything inaccurate;
- restrict processing while a request is considered;
- opt out of any "sale" or "sharing" of your information under US state law (see 7.3).
We respond within 30 days (extendable where the law permits and we tell you why). We will not discriminate against you for exercising a right, and we do not require you to create an account to exercise one.
We also notify Users. Our Terms require every User to delete their copy of your information on request. We will pass a deletion request on to Users who received your record where we are reasonably able to identify them.
You also have the right to complain to your data protection authority — in the EU, your national supervisory authority; in the UK, the ICO.
7. US state privacy rights
7.1 California (CCPA/CPRA), and other US state laws
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to: know and access the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients; delete personal information; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information and of targeted advertising; limit the use of sensitive personal information (we collect none); and appeal a denial. **We will not discriminate against you for exercising any of these rights.**
Exercise any of them by emailing privacy@kiddynaconnect.com with the subject line of the right you want. An authorised agent may act for you with written permission and verification. We verify requests by matching the request to information we already hold — for example, by requiring the request to come from the email address concerned.
7.2 Categories collected in the last 12 months
| CCPA category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Discord ID, email address, IP address, account ID, public profile URL |
| Commercial information | Yes | Credits purchased, subscription and plan, sales and payout records |
| Internet or network activity | Yes | Server logs, page and preview-play events, feature usage |
| Professional or employment information | Yes | Business-contact records and storefront profiles |
| Audio/visual information | Yes | Beats and renders that Users upload |
| Sensitive personal information | No | We do not collect it |
| Biometric, geolocation, education, inferences for profiling | No | Not collected |
We keep each category only as long as described in Section 8.
7.3 "Sale" and "sharing" — the honest answer
We do not sell or share User account data, and we do not engage in cross-context behavioural advertising.
However, the Service includes a feature that lets Users **trade contact records with each other**. When you trade, business-contact information moves from one User to another in exchange for other contact information. **Under the CCPA's broad definition, that exchange for "other valuable consideration" is likely a "sale" of personal information**, so we treat it as one.
**If you are a Contact and you do not want your information traded, disclosed to Users, or held at all, email privacy@kiddynaconnect.com with the subject "DO NOT SELL OR SHARE" and we will suppress and delete it.** Because we obtain this information from public sources rather than from you directly, this email channel is the opt-out mechanism, and no account is required to use it.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
8. How long we keep information
| Data | Retention |
|---|---|
| Account record (User ID, email, credits, plan) | While the account is active, then deleted or anonymised within 30 days of a verified closure request |
| Password hash | Deleted with the account |
| Scrape and outreach logs | Up to 24 months, then deleted or aggregated |
| Uploaded beats, renders, storefront listings | While the account is active, or until you delete them |
| Payment and tax records | As long as required by tax and accounting law, typically 7 years |
| Server and security logs | Up to 12 months |
| Contact records | See Section 6.3 |
| Suppression list (one-way hashes) | Indefinitely, solely to keep removed contacts removed |
| Backups | Rolling daily snapshots, the newest 14 retained, so a backup is overwritten within 14 days; deletions propagate as backups cycle |
We may keep information longer where we must to comply with law, resolve a dispute, or enforce our agreements.
9. Where information is processed, and international transfers
The Service is hosted in Canada (Montréal, Quebec). If you are in the EEA, UK or Switzerland, your information will be transferred to and processed in a country that may not provide the same level of protection as your own.
Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) as incorporated into our agreements with our processors, together with the supplementary measures described in Section 10. Stripe and Google each maintain their own transfer mechanisms, including certification under the EU-US Data Privacy Framework where applicable. You may request a copy of the relevant safeguards at privacy@kiddynaconnect.com.
10. Security
We take reasonable and appropriate technical and organisational measures to protect personal information, including: transport encryption (HTTPS/TLS) for all traffic; storing passwords only as salted scrypt hashes; keeping credentials and API keys in server environment variables rather than in source control; signature verification on payment webhooks with idempotent event handling; server-side authorisation checks on every data access; rate limiting; and restricting production access to the smallest number of people necessary.
No system is perfectly secure. We cannot guarantee absolute security, and you send information to us at your own risk. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as and when required by law. Under PIPEDA, we notify the Office of the Privacy Commissioner of Canada and affected individuals as soon as feasible after determining the breach creates a real risk of significant harm, and we keep a record of every breach, whether or not it meets that threshold, for at least 24 months. Where the GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, where the breach is notifiable. Where a US state breach law applies, we follow its own timeline.
Report a suspected vulnerability to security@kiddynaconnect.com; see our vulnerability disclosure policy for our good-faith-researcher commitments.
11. Cookies and similar technologies
Konnect uses a strictly necessary set only:
| Purpose | Type | Can you refuse it? |
|---|---|---|
| Keeping you signed in | First-party session cookie | Not without losing the ability to sign in |
| Security and abuse prevention (CSRF, rate limiting) | First-party | No — required for the Service to be safe |
| Remembering interface preferences | First-party, local storage | Yes, by clearing site data |
**We do not use advertising cookies, third-party trackers, cross-site pixels, or behavioural analytics, so we do not show a consent banner** — strictly necessary cookies do not require consent under the ePrivacy rules. If that ever changes, we will ask for consent before setting any non-essential cookie.
We do not respond to browser "Do Not Track" signals, because there is no common standard for them. We do honour Global Privacy Control (GPC) signals as an opt-out of sale or sharing where applicable law requires it.
12. Children's privacy
The Service is not directed to children under 13, and paid and selling features require that you be 18 or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, contact privacy@kiddynaconnect.com and we will delete it and close the account.
13. Your choices
- Marketing email — unsubscribe from any marketing message, or email us. Transactional and service messages continue while your account exists.
- Disconnect an integration — revoke Google, Discord, or Stripe access from the Konnect dashboard or from that provider's own settings.
- Export your data — request a copy at privacy@kiddynaconnect.com.
- Delete your account — request closure at the same address. We delete or anonymise within 30 days, subject to Section 8.
14. Changes to this policy
We may update this policy. If a change is material, we will give reasonable advance notice by email or in-product notice before it takes effect, and we will always update the "Last updated" date above. Previous versions are available on request.
15. Contact
| Purpose | Address |
|---|---|
| Privacy questions, access, deletion, opt-out | privacy@kiddynaconnect.com |
| Security vulnerabilities | security@kiddynaconnect.com |
| Everything else | support@kiddynaconnect.com |
Ethan William White d/b/a Konnect
2931 Fifth Street, Victoria, BC V8T 4B4, Canada