Privacy Policy

Last updated August 12, 2026

KaBoon's approach to your privacy is straightforward: do the right thing. You should never be surprised by the information we hold about you or how we contact you. Every interaction should be valuable to both you and KaBoon.

We will not use your information without your permission. We strive to collect the least amount of data necessary to operate the Service.

If you disagree with this Privacy Policy, please do not use our Service. Our “Service” refers to everything KaBoon creates and operates, including the KaBoon website and Slack application.

Who You Are

If you use KaBoon, you are either a Workspace Admin or a Member. Workspace Admins install KaBoon into a Slack workspace, manage configuration, and have access to all workspace data. Members are the teammates participating in recognition within the workspace.

If you are a Member with data questions or concerns, please contact your Workspace Admin first. If you cannot reach your Admin or have a dispute, contact us directly at support@kaboon.io.

What We Collect and Why

When a Workspace Admin connects KaBoon to their Slack workspace, we collect information necessary for the Service to function. We also collect information you voluntarily provide. We use the data we collect to:

  • Personalise your experience and display recognition activity.
  • Operate, maintain, and improve the Service.
  • Respond to support requests and communicate with Workspace Admins.
  • Process billing and subscription management.

Here is what we collect and why:

  • Slack workspace name, ID, and metadata, used to identify your workspace, display names in the product, and associate data within your workspace.
  • Number of members in your workspace, used for seat-based billing and internal reporting.
  • Your name and display name, to identify you within the product and to other members of your workspace.
  • Your profile picture (avatar), collected from your Slack profile and displayed alongside recognition activity.
  • Email address, used to relate your account to billing records (for Workspace Admins) and to contact you about your subscription or support requests. Members will not be emailed unless their Admin or they themselves permit it.
  • Recognition messages and awards, we collect /award commands and related activity (message, timestamp, giver, receiver, values tagged, channel) to power leaderboards, seasons, and profile history. We only capture recognition-related interactions directed at the KaBoon Slack application, not all messages in your workspace.
  • Team, season, and leaderboard data, configuration you set up as an Admin (team groupings, season dates, values/categories) is stored to operate the Service.
  • Security logs, we keep an append-only record of security-relevant actions: signing in and out, changes to who is an admin, members being added or removed, reward claims, and data exports or deletions. Each entry records who acted, when, the workspace involved, and the IP address and browser the request came from. We keep these for 12 months so we can investigate suspicious activity and establish what happened if there is ever a security incident. Our legal basis is legitimate interest in keeping the Service secure, and these records are not used for analytics, profiling, or marketing.

If you have questions about the data we collect, contact us at support@kaboon.io.

Our Role and Legal Basis

Which role we play depends on the data, and it determines who decides why it is processed.

  • For your workspace's member data, including recognition, teams, seasons, and member profiles, your employer is the controller and we act as their processor. They decide why recognition happens and on what basis, and we process it on their instructions. If you are a Member asking why your employer runs a recognition programme, they are the right people to ask.
  • For account and billing data, including the Workspace Admin's contact details and subscription records, we are the controller. Our basis is performance of our contract with you (Article 6(1)(b)), and for invoice retention, compliance with a legal obligation (Article 6(1)(c)).
  • For security logs, we are the controller and our basis is legitimate interest in keeping the Service secure (Article 6(1)(f)). We consider this proportionate because the records hold actions and identifiers rather than content, and are used only to investigate suspicious activity.
  • For website analytics, our basis is your consent (Article 6(1)(a)), which you can withdraw at any time using the Cookie preferences link in the footer.

Workspace Admins who need this set out contractually, as their own compliance generally requires, can request a data processing agreement from us at support@kaboon.io.

Where Your Data Is Stored

We use Supabase (backed by Amazon Web Services) and Vercel as our hosting and infrastructure providers in the United States. Your data is encrypted at rest and in transit. We implement security measures to maintain the safety of your information.

If your data is exposed to an unknown third party due to a breach, we will notify you within 72 hours of the incident being confirmed.

KaBoon is established in the Netherlands, while the hosting providers above process data in the United States. Those transfers out of the European Economic Area rely on appropriate safeguards under Chapter V of the GDPR, such as Standard Contractual Clauses, together with the supplementary measures described in this section.

How Long We Retain Your Data

We retain data about your workspace for as long as you are an active customer, and for a reasonable period thereafter to allow for account recovery or disputes.

When a Workspace Admin removes KaBoon from Slack, we disconnect the workspace and invalidate its Slack access token immediately. Recognition history and member data are kept after that, so a workspace that reinstalls does not lose its history.

A Workspace Admin can ask us to erase that data at any time, and we will action the request within 30 days. Erasure removes every member record, all recognition, seasons, teams, rewards, and uploaded images. Admins are responsible for the data of Members in their workspace.

What we keep regardless: Invoices and the payment records needed to reconcile them are retained for seven years, because Dutch tax law requires it. The GDPR provides for this: the right to erasure does not extend to data we are legally obliged to keep (Article 17(3)(b)). These records contain billing details rather than recognition activity or member profiles.

Security logs are kept for 12 months and survive an erasure request for the same reason: a record of who changed access or deleted data is only meaningful if it cannot be removed by the person who acted. These entries hold an actor, a timestamp, an IP address, and what was done, not recognition content.

Cookies and Browser Storage

Cookies are small files a website stores in your browser. Some features use your browser's local storage instead, which works similarly. We use very few of either, and every one is listed below. We do not set advertising cookies, and we do not track you across other websites.

Cookies we set. Both are strictly necessary, meaning the Service cannot work without them.

NamePurposeDuration
kb_sessionKeeps you signed in to the KaBoon web app.7 days
kb_tv_displayKeeps a paired KaBoon TV display signed in to its workspace. Only set on displays paired through the activation flow.45 days

Both are HttpOnly, so JavaScript running in your browser cannot read them, are restricted to same-site navigations, and are sent only over HTTPS.

Browser storage we use.We store one value in your browser's local storage, kaboon-cookie-consent, which records whether you accepted or declined analytics. It stays until you clear your browser storage, and it is never sent to our servers.

Analytics. We measure aggregate website traffic, including page views, referring site, country, and browser and device type, to understand which pages are useful. Our analytics provider sets no cookies and stores nothing on your device. Visitors are counted using a temporary value derived from the request, which is discarded within 24 hours, and the results cannot be traced back to an individual. We ask for your consent before enabling analytics and do not load it at all unless you accept.

Third-party cookies. When a Workspace Admin opens the billing checkout, Stripe sets its own cookies for payment processing and fraud prevention. These are set by Stripe rather than by us, and only on pages where checkout is shown. See Stripe's privacy policy for details.

Your choices. The first time you visit, we ask whether to enable analytics. Declining means analytics is never loaded. You can change your answer at any time using the Cookie preferences link in the footer of any page, and withdrawing consent takes effect immediately. The two cookies above cannot be switched off, because without them we cannot keep you signed in. Your browser settings also let you block or delete cookies, though blocking the necessary ones will prevent you from signing in. For general guidance, see allaboutcookies.org.

If you have questions or feedback about the cookies we use, contact us at support@kaboon.io.

Who Has Access to Your Data

Your information will not be sold, traded, or given to any other company without your consent, except as necessary to deliver the Service. Below are the third parties that may have access to your data:

Third PartyReason
SupabaseDatabase and backend hosting provider.
VercelApplication hosting, deployment, and aggregate website analytics.
OpenAIImage generation for workspace artwork. When an Admin generates an icon for a value, team, or reward, the name and description they entered are sent to OpenAI as an image prompt. No recognition messages, member names, avatars, or email addresses are sent.
StripeBilling and payment processing (Workspace Admin data only).
SlackPlatform integration, user profiles, workspace identity, and message events.

We may also disclose your information when required by law, to enforce our policies, or to protect the rights, property, or safety of others.

How You Can Control Your Data

Workspace Admins can request that we send, modify, or delete any information about their workspace and its members by emailing support@kaboon.io. We will action requests within 30 days.

For an access or portability request, we send a single JSON file containing every record we hold for the workspace: members, recognition history, values, teams, seasons, rewards, and billing records. It is structured and machine-readable, so it can be loaded into another system rather than only read. Uploaded images are referenced by name in that file, and we will send the image files too on request.

Members should contact their Workspace Admin to request data access, modification, or deletion. If you cannot reach your Admin, contact us directly at support@kaboon.io.

Consent

If you do not consent to the collection, use, or disclosure of your personal information as outlined in this policy, please do not use the Service or agree to our Terms of Service. To withdraw consent, contact us at support@kaboon.io.

Data Protection Rights

Subject to applicable law, you have the right to access, correct, delete, restrict, or object to our use of your personal data, and to receive it in a portable format. To exercise any of these rights, contact us at support@kaboon.io.

You also have the right to lodge a complaint with a supervisory authority. Because KaBoon is established in the Netherlands, our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens. If you live elsewhere in the European Economic Area, you may instead complain to the supervisory authority where you live or work.

Please reach out to us before filing a complaint, we will do our best to address your concerns directly.

Contact

KaBoon is a registered trade name of Tales For Two, registered in the Netherlands under Chamber of Commerce (KVK) number 99322021, VAT identification number NL005378832B84. Tales For Two is the data controller for account, billing, security, and analytics data, and acts as a processor for the member data inside each workspace. See Our Role and Legal Basis above.

Tales For Two | KaBoon
Joan Melchior Kemperstraat 62-2
1051 TT Amsterdam
Netherlands

Questions about this Privacy Policy? Contact us at support@kaboon.io.