Privacy Policy
SoloKit is built with a privacy-first philosophy. This policy explains what data we collect, why we collect it, and how we protect your information across all jurisdictions.
1. Introduction and Jurisdictions
At SoloKit, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit and use our Service. Please read this policy carefully to understand our practices regarding your personal data.
This policy is designed to comply with the following data protection regulations and frameworks:
- EU General Data Protection Regulation (GDPR) — applicable to all users in the European Union and European Economic Area.
- US California Consumer Privacy Act (CCPA) — applicable to residents of California, United States.
- Nigeria Nigeria Data Protection Regulation (NDPR) — applicable to users in Nigeria.
- Australia Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) — applicable to users in Australia.
- UK UK General Data Protection Regulation (UK GDPR) — applicable to users in the United Kingdom.
- Global International Standards — including OECD Privacy Guidelines and APEC Privacy Framework principles.
By using SoloKit, you consent to the data practices described in this policy. If you do not agree with the terms of this policy, please do not use the Service.
SoloKit is designed to be privacy-first. Unlike most SaaS platforms that collect extensive user data for advertising or profiling, SoloKit collects only the bare minimum necessary to provide its core functionality.
Key Principle: SoloKit does not track, profile, or sell your data. We do not use analytics cookies, advertising trackers, or third-party monitoring tools without explicit user consent. Your information belongs to you.
2. Information We Collect
SoloKit collects very limited information. The specific data we collect depends on how you use the Service:
- Guest Users (No Account): When you use SoloKit without creating an account, we do not collect any personal information. Your interactions are anonymous. We may temporarily store session data, such as the short links you generate, in your browser's local storage or session storage. This data is not transmitted to our servers and is deleted when you close your browser.
- Registered Users (With Account): When you create an account using Magic Link authentication, we collect and store your email address. This is used solely for authentication — to send you a secure login link. We also store the history of invoices, contracts, short links, and other content you generate while logged in, so that you can access it later.
- Usage Data (Future Implementation): We may implement Google Analytics or similar analytics services in the future to understand how users interact with the Service. This will be done with explicit user consent and in compliance with applicable data protection regulations. Any analytics data collected will be anonymized and aggregated.
- Cookies: We use essential cookies to maintain your session (if you are logged in) and to remember your theme preferences. These cookies are minimal and do not contain any personal information.
What we don't collect: We do not collect your name, physical address, phone number, payment information, browsing history, device information, IP address (for tracking purposes), or any other personal data beyond your email address (if you create an account).
3. How We Use Information
The limited information we collect is used for the following purposes only:
- Authentication: Your email address is used exclusively to send Magic Link login emails. We do not use your email for marketing, promotional, or any other purpose.
- Service Delivery: Session data (such as temporary short links) is stored in your browser to enable the Service to function correctly. For registered users, we store generated content (invoices, contracts, links) to allow you to access them later.
- Preferences: We store your theme preference (light, dark, forest, ocean) in a cookie so that your chosen appearance persists across visits.
- Analytics (Future): If we implement analytics tools in the future, we will collect anonymized, aggregated data to improve the Service. This will only be done with your explicit consent.
We do not use your information for advertising, profiling, data mining, or any form of automated decision-making. We do not create user profiles or behavioral segments.
4. Data Storage and Security
SoloKit takes data security seriously. We implement industry-standard measures to protect the limited information we store:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). This ensures that your data cannot be intercepted or read by third parties during transmission.
- Database Security: Your email address and generated content are stored in a secure database with restricted access. Only essential personnel have access to the database, and only for maintenance or support purposes.
- Data Minimization: By design, SoloKit collects the absolute minimum data required to provide the Service. This reduces the risk associated with data breaches and ensures that there is little to no sensitive data to be compromised.
- Data Retention: If you create an account, your data is stored until you request deletion. Guest users have no data stored on our servers. Session data is stored only in your browser and is automatically cleared when you close your browser.
- Data Sovereignty: Your data is stored on servers located in secure data centers. We comply with applicable data sovereignty requirements and do not transfer your data to jurisdictions with inadequate data protection laws.
While we implement reasonable security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the best of our ability.
5. Third-Party Services
SoloKit integrates with a small number of third-party services to provide its functionality. These services are carefully selected and are used only when necessary:
- QR Code Generation: When you generate a QR code, the URL you provide is sent to a third-party QR code generation API. This API receives only the URL you supply and does not receive any personal information. The API is used solely to generate the QR code image, which is then returned to you.
- Magic Link Authentication: We use a secure email delivery service to send Magic Link login emails to your email address. This service receives your email address only to deliver the login link and does not store or use it for any other purpose.
- Fonts: SoloKit uses web fonts from Google Fonts and Fontshare. These services may collect limited information about your browser and device for font delivery purposes.
- Analytics (Future): If we implement Google Analytics or similar services in the future, we will ensure that all data collection is compliant with applicable regulations and that user consent is obtained before any data is collected.
We do not share your data with any third-party services for advertising, marketing, analytics, or any purpose other than the direct delivery of the Service. We do not use social media tracking pixels, retargeting scripts, or any form of third-party monitoring without explicit consent.
6. Cookies
SoloKit uses minimal cookies to provide essential functionality:
- Session Cookies: If you are logged in, we use a session cookie to authenticate your requests. This cookie is necessary for the Service to function correctly and does not contain any personal information beyond your session identifier.
- Preference Cookies: We use a cookie to store your theme preference (light, dark, forest, ocean). This allows us to display the correct appearance on subsequent visits without requiring you to select your preference again.
- Cookie Consent: We use a cookie to remember that you have accepted our cookie policy, so that we do not display the cookie consent banner on every visit.
- Analytics Cookies (Future): If we implement Google Analytics or similar services in the future, we will use analytics cookies only with your explicit consent. You will have the option to opt out of analytics tracking at any time.
We do not use tracking cookies, advertising cookies, or any third-party cookies without explicit consent. You can disable cookies in your browser settings, but please note that some features of the Service may not function correctly if cookies are disabled.
7. Your Rights
Depending on your location, you may have certain rights regarding your personal data. SoloKit respects and supports these rights:
- Right to Access: You have the right to request a copy of the personal data we hold about you. If you have an account, you can view your data in your dashboard. For guest users, we do not hold any personal data.
- Right to Correction: If you believe that the information we hold about you is inaccurate or incomplete, you have the right to request correction. You can update your email address and other account details through your dashboard.
- Right to Deletion (Right to be Forgotten): You have the right to request that we delete your personal data. If you have an account, you can request deletion by contacting us at support@solokit.sbs. We will delete your account and all associated data within a reasonable timeframe.
- Right to Withdraw Consent: If you have provided consent for any data processing activity, you have the right to withdraw that consent at any time.
- Right to Data Portability: You have the right to request that we export your data in a structured, machine-readable format. We can provide you with a CSV export of your account data upon request.
- Right to Object: You have the right to object to the processing of your personal data for direct marketing purposes or where processing is based on legitimate interests.
- Right to Restriction: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe that we have violated your privacy rights.
To exercise any of these rights, please contact us at support@solokit.sbs. We will respond to your request within a reasonable timeframe, typically within 30 days, as required by applicable regulations.
GDPR, CCPA, NDPR, and APP Compliance: SoloKit is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Nigeria Data Protection Regulation (NDPR), and the Australian Privacy Principles (APPs). We collect minimal data, and all data processing is conducted in accordance with these regulations.
8. Children's Privacy
SoloKit is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately. We will take steps to delete such information from our records.
We encourage parents and guardians to monitor their children's online activity and to help enforce this policy by instructing children never to provide personal information on the Service.
In compliance with the Children's Online Privacy Protection Act (COPPA) and similar regulations in other jurisdictions, we do not target or knowingly collect data from children.
9. International Data Transfers
SoloKit operates globally, and your data may be transferred to and processed in countries outside of your jurisdiction. We ensure that any such transfers are conducted in compliance with applicable data protection laws:
- EU/EEA: Data transfers from the EU/EEA are conducted in accordance with the GDPR, using appropriate safeguards such as Standard Contractual Clauses (SCCs).
- UK: Data transfers from the UK are conducted in accordance with the UK GDPR and UK adequacy regulations.
- Australia: Data transfers from Australia are conducted in accordance with the Privacy Act 1988 and the Australian Privacy Principles.
- Nigeria: Data transfers from Nigeria are conducted in accordance with the NDPR and applicable Nigerian data protection regulations.
- Other Jurisdictions: Data transfers to other jurisdictions are conducted in accordance with applicable local laws and international data protection standards.
We are committed to ensuring that your data is protected regardless of where it is processed. All data transfers are conducted with appropriate safeguards to maintain the confidentiality and integrity of your information.
10. Data Breach Notification
In the event of a data breach that affects your personal information, we will take the following steps:
- Investigation: We will promptly investigate the breach and take appropriate measures to contain and remediate the issue.
- Notification: We will notify affected users and relevant data protection authorities within 72 hours of becoming aware of a breach, as required by GDPR and other applicable regulations.
- Communication: We will communicate the nature of the breach, the data affected, the potential risks, and the steps we are taking to address the issue.
- Support: We will provide guidance to affected users on how to protect themselves from any potential harm.
We maintain robust security measures to minimize the risk of data breaches, but in the event that a breach does occur, we are committed to transparency and accountability.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this page.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Service after any changes to this policy constitutes your acceptance of the updated policy.
If we make any material changes to this policy, we will notify you by posting a prominent notice on the Service or by sending you an email notification (if you have an account).
12. Contact Us
If you have any questions about this Privacy Policy, our data practices, or your rights, please contact us:
- Email: support@solokit.sbs
- Website: solokit.sbs
- Data Protection Officer (DPO): For privacy-specific inquiries, you may contact our Data Protection Officer at dpo@solokit.sbs
- Response Time: We will respond to all inquiries within 2 business days.
Last updated: July 2026