Privacy Policy
Last updated: 01/05/2026
1. Introduction
kallie is a referral code management platform operated by EURL Undefined (“we”, “our”). This Privacy Policy describes how we collect, use, store and protect your personal data when you use our web application available at app.getkallie.com, our website getkallie.com, and our Chrome and Firefox browser extension.
Contact: [email protected]
2. Data collected
2.1 Account information
When creating your account, we collect:
- Email address
- First and last name
- Phone number
- Profile information (biography, profile picture) if you choose to provide them
- Password (stored securely via bcrypt hashing)
2.2 Referral codes
We store the referral codes and links you create, along with associated information (partner, usage statistics: number of copies, number of uses).
2.3 Google account data
If you choose to sign in via Google or import your Google contacts, we access the following data with your explicit consent:
- Authentication (Google Sign-In): your name, email address and profile picture from your Google account, used solely to create and authenticate your kallie account.
- Google Contacts (optional): the names and email addresses of your contacts, used solely to help you invite contacts to kallie and share referral codes. Contact data is not permanently stored on our servers — it is fetched on demand and displayed only during your session.
2.4 Audience measurement data (getkallie.com only)
The website getkallie.com uses Google Analytics to measure audience and improve the service. These cookies are only set after obtaining your consent via the cookie banner. The data collected includes anonymized information about your browsing (pages visited, visit duration, traffic source). This data is processed by Google LLC (United States) in accordance with Google\’s privacy policy.
The web application app.getkallie.com does not use any audience measurement tools.
2.5 Technical data
We do not collect IP addresses, browser fingerprints or browsing behavior beyond what is strictly necessary for the service to function (server logs for error debugging, retained for a maximum of 30 days).
3. Use of data
We use your personal data exclusively to:
- Create and manage your kallie account
- Store and display your referral codes
- Allow you to share codes with your contacts
- Send transactional emails (account verification, password reset)
- Send service notifications you have subscribed to
- Improve the service via anonymized audience data (getkallie.com only, with consent)
We do not sell, rent or share your personal data with third parties for commercial or advertising purposes.
4. Google API Services — Limited Use Disclosure
kallie\’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request access to data strictly necessary for the features you use (sign-in, contact import).
- We do not use Google data for advertising purposes or for purposes unrelated to the features you have enabled.
- We do not transfer Google data to third parties unless necessary to provide the service or required by law.
- We do not use Google data to build advertising profiles.
- Human access to Google user data is only possible with your consent, for support purposes, security investigation or legal obligation.
5. Data storage and security
Location: all data is stored on servers located in the European Union (Amsterdam, Netherlands).
Encryption: all communications are encrypted via HTTPS/TLS. Passwords are hashed with bcrypt.
Authentication: we use short-lived JWT tokens and secure httpOnly cookies for refresh tokens with rotation.
CSRF protection: double-submit cookie on all data-modifying requests.
Rate limiting: applied to authentication endpoints to prevent abuse.
6. Data retention
Account data: retained for the duration of the account\’s activity.
Google Contacts: not permanently stored. Fetched on demand and displayed only during the session.
Server logs: retained for a maximum of 30 days.
Deleted accounts: all personal data is permanently deleted within 30 days of account deletion.
7. Your rights
In accordance with the GDPR, you have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure of your account and all associated data (accessible in Settings > Account > Delete account)
- Right to portability of your data in a usable format
- Right to withdraw your consent to Google data access at any time via your Google account permissions
- Right to object to the processing of your data
- Right to lodge a complaint with the CNIL (www.cnil.fr)
To exercise any of these rights, contact us at: [email protected]
8. Cookies
8.1 Web application (app.getkallie.com)
We only use cookies strictly necessary for the service to function:
- refreshToken: secure httpOnly cookie for authentication session management.
- csrf_token: CSRF protection cookie.
- locale: stores your language preference.
8.2 Website (getkallie.com)
In addition to strictly necessary cookies, the website getkallie.com uses, with your consent:
- Google Analytics cookies (_ga, _gid, _gat): anonymized audience measurement. Set only after acceptance via the cookie banner.
You can withdraw your consent or change your cookie preferences at any time via the cookie management banner accessible on getkallie.com.
9. Browser extension
The kallie browser extension (Chrome and Firefox) communicates with our API to allow you to manage your referral codes. The extension:
- Only accesses the URL of the active tab to compare it with known partners.
- Stores your authentication token locally in the browser extension storage.
- Does not collect browsing history, keystrokes or any data not described above.
10. Changes to this policy
We may update this Privacy Policy at any time. Registered users will be informed of any significant changes by email. The current version is always available at: https://app.getkallie.com/privacy-policy
11. Contact
For any questions regarding this Privacy Policy or your personal data:
Company: EURL Undefined
SIRET: 94880427300019
Address: 26 RUE DU PLATEAU DES BRUYERES, 95520 OSNY, France
Email: [email protected]