PricingOpen the demo

Privacy

What we collect, why, where it lives, and how to get rid of it. Written to be read.

Last updated August 2026 · Kepra is in private development

Who we are

Kepra is a profit-analytics service for e-commerce and subscription businesses, operated from Denmark and hosted in the European Union. For the purposes of the GDPR we are the data controller for your account details, and a data processor for the commerce and advertising data you connect.

What we collect, and why

  • Your account. Email address and organisation name. Used to sign you in and to contact you about the service. We do not store a password — sign-in is by emailed link.
  • Commerce data. Orders, amounts, currency, timestamps, refund status, and a pseudonymous customer identifier from Shopify or Stripe. Used to calculate profit and repeat-purchase behaviour. We do not import names, addresses, email addresses or payment details of your customers.
  • Advertising data. Spend, impressions, clicks and campaign structure from Meta and Google Ads, plus the click identifier attached to a landing URL. Used to attribute orders to the ad that caused them.
  • Product usage. Which pages you open and which actions you approve, so we can find and fix what is slow or confusing.

What we never do

  • Sell, rent or share your data with third parties for their own purposes.
  • Use your business data to train models that serve anyone but you.
  • Pool your numbers into benchmarks shown to other customers.
  • Store your platform passwords — integrations use OAuth tokens, which you can revoke at any time from the platform itself.
  • Push a change to an advertising platform without a human approving that specific change first.

Where it lives

In the European Union (Ireland), on infrastructure provided by Supabase and Vercel. Every table is protected by row-level security: an organisation can only read its own rows, enforced by the database rather than by application code. Integration secrets are stored separately and are not readable by any browser session, including yours.

How long we keep it

Commerce and advertising data for as long as your account is active, and for 30 days after you close it, so an accidental cancellation can be undone. Disconnecting an integration destroys its stored credentials immediately. You can request earlier deletion at any time and we will action it within 30 days.

Your rights

Under the GDPR you may request a copy of your data, correct it, have it deleted, restrict how it is processed, or object to processing. Email us and we will respond within one month. You may also complain to Datatilsynet, the Danish Data Protection Agency.

Sub-processors

Supabase (database and authentication, EU region), Vercel (application hosting), and the platforms you choose to connect — Shopify, Stripe, Meta and Google — which act as sources rather than recipients. We will publish any change to this list here before it takes effect.

Cookies

One cookie, to keep you signed in. No advertising cookies, no analytics that follow you off this site, and therefore no consent banner to dismiss.

Questions, or a request about your data? privacy@kepra.io. You can also read how the data layer is built or the terms.