Who we are
| Service | KidBD |
| Operated by | Kavalsia Inc. |
| Registration | Ontario business corporation, OCN 1000576319, incorporated 22 June 2023 |
| Registered office | 312 Greenwood Drive, Angus, Ontario L0M 1B4, Canada |
| Privacy contact | # |
We are the controller of the personal information described below. This policy is written to meet Canada's PIPEDA and, where it applies to you, the GDPR and the UK GDPR.
The important part: we hold it and we cannot read it
When you build a game you type in a child's name, their age, the names of people in the room and the gifts you are offering. When you plan the day you add a guest list, allergy notes and an address.
If you keep a party in an account, a copy of it does reach us. It reaches us as ciphertext. Your browser locks it with a key derived from your password, on your own device, and that key is never sent to us and never leaves that browser in a form we could use.
We could not show you your child's name if you asked us to, and we could not hand it to anybody else who asked. We hold the locked block. We do not hold the key.
The link is separate, and it has not changed. A game link carries the whole party in the part of a web address after the # character, and browsers, by design and by specification, never transmit that part to any server. It stays in the address bar on your device and on the device of whoever you send it to.
Exactly what is on our server
This is the whole list. If you hold us to one section of this policy, hold us to this one.
| Your email address | In the clear, so we can sign you in and send you your link. |
| A random salt, and a hash of a secret derived from your password | Enough to check that a sign in is you. Your password itself never reaches us, and neither does the key it derives. |
| Your public key, and your private key and data key wrapped by your password | Wrapped means locked. We store the locked form. We cannot open it. |
| Each party you keep, as ciphertext | A block of noise, a random starting value, and the dates it was made and last touched. |
| Each reply to an invitation, as a sealed envelope | Sealed to your public key by the guest's own browser. Only your device opens it. |
| An entitlement row for a party you paid for | Which party, which tier, when the link stops, and the Stripe payment it came from. |
| A queued follow up, only if you asked for one | A guest's email address, one date, and one word saying which follow up it is. Nothing else: not their name, not your child's name, and not the invitation. Each one is deleted the moment it is sent, and the reminder is also deleted the moment that guest answers. |
What is not on our server, in any readable form: your child's name or age, the challenges you picked, the gifts you wrote, who is coming, what anybody is allergic to, and where the party is.
The one exception is the last row of that table, and it is worth saying in full. If you send invitations by email and switch the follow ups on, we hold each guest's address and a date. For a guest who has not answered, that is the reminder, and it is deleted when the reminder goes out or when they answer, whichever comes first. For a guest who answers yes, we hold their address until the party is over, to send a note the day before it and a thank-you after it, and then it is deleted. A guest who answers no is deleted straight away. We never hold their name, your child's name, or the invitation itself. That is why anything we send them can only ask them to open the invitation already in their inbox: we cannot send it again, because we did not keep it.
We record no analytics, no page views, no device fingerprint and no location. Our server never writes a request body or a link fragment to a log.
Your password is the key, and we cannot reset it
The key that opens your parties is derived from your password inside your browser. That is what makes the sentence above true rather than a promise about our intentions.
It also means a lost password loses the parties held in your account, and we cannot recover them. There is no reset that gets the content back, because there is nothing on our side to reset it with.
Two things survive a lost password, and both are worth doing on the day you buy:
- A link you already have keeps working, because the party travels inside it.
- A party you saved as a file opens again in the builder on any device.
We say this above the password field when you set it, not in a tooltip afterwards.
What is stored on your own device
Your browser's local storage holds the working copies, so a half finished party survives a reload. This never leaves your browser.
- party-builder:draft - the party you are part way through building.
- party-builder:seen-guide - so the guide only opens itself the first time.
- candlequest:shelf - the parties on your shelf, held as the same codes your links carry.
- party:<name> - on the playing device, the gifts the child picked, so the screen can be shown again.
You can clear all of it at any time with your browser's "clear site data", or with the Start over button in the builder. Clearing it does not delete your account; signing in again brings your parties back, as long as you still have the password.
Signing up, and what it costs
Creating an account carries no charge and asks for no card. It asks for an email address and a password, and nothing else. There is no trial that starts a clock, and making an account never begins a charge.
You pay per party, when you decide to send a real link, and that payment unlocks that party's game link and its planner together. There is one price, $39, and it is charged once.
No card is kept on file, by us or on our behalf. There is no subscription here, so there is nothing for a card to be kept for: the card details go to Stripe, never touch our pages or our server, and we hold no card reference of any kind afterwards.
Payment, and what Stripe sees
Payments are processed by Stripe Payments Europe, Ltd. and its affiliates. You enter your card details on Stripe's own page, not ours. We never see, receive or store your card number.
Stripe sees the payment and nothing else. It receives the amount, your card details, your email address, your name if you gave one, your country, and a short reference that says which party the payment belongs to. That reference is a random party id such as p1x9f3kq. It is not a name, and it decodes to nothing.
Stripe passes us back your email address, the amount, the country, the last four digits of the card and that reference, so we can mark the party paid and support you. Stripe is the processor for that data and has its own policy at stripe.com/privacy.
We use Brevo (Sendinblue SAS, France). To you, we send one thing and nothing else:
- Your purchase confirmation, containing your link.
That message is the only email we ever send you. We do not run a newsletter, we do not sell, rent or share your address, and every message carries an unsubscribe link. Brevo's policy is at brevo.com/legal/privacypolicy.
Invitations you send to your guests
If you ask us to email your guest list, we send one invitation per guest, each carrying that guest's own link. If you switched the follow ups on, a guest gets at most three more messages after it, never more than one of each, and which ones depends only on their own answer: one reminder while they have not answered, and if they answer yes, a note the day before the party and a thank-you after it. A guest who answers no gets nothing further at all. That is the whole list, and there is no fourth. A guest is never added to a list, never sold or shared, and never emailed about anything else, ever.
Two things about those messages, and both are the same promise the rest of this page makes:
- The invitation passes through and is not kept. The link carries the party in the part of the address after the #, and it reaches us in the body of that one message and is written down nowhere: not to a file, not to a log, not to a database.
- The addresses are not kept either, unless you asked for the follow ups. With none, nothing about your guests remains with us once the invitations have gone. With them, we hold each guest's address and a date: until the reminder is sent or they answer, and for a guest who says yes, until the party is over. Every one of those records is deleted as the message it belongs to goes out.
You are giving us other people's email addresses when you do this, so it is your call to make: send the invitations yourself from the per person links instead, and we never see a guest's address at all.
If you email us for help, we keep the email so we can answer it.
What we do not do
- We measure nothing. There is no Google Analytics, no Meta pixel and no tracking script of any kind on this site.
- We do not advertise to you. There are no advertising cookies here and we build no profiles.
- We never sell or rent personal information to anybody, for any amount, under any circumstances.
- We do not watch what you do and then email you about it. The two messages above are the whole of it.
- We load nothing from a third party. The typefaces on this page are served from our own site rather than fetched from Google, so opening it tells nobody but us that you did.
The only cookies that can be set are Stripe's own, on Stripe's checkout page, which are necessary for that payment to work and for fraud prevention.
Children
This service is sold to adults. It is designed to be bought by a parent or guardian and played by a child under that adult's supervision. We do not knowingly collect personal information from children.
A child playing the game does not create an account, is never asked for a name, an email address, an age or a photograph, and nothing they tap is transmitted anywhere. Their picks are written to that device's local storage so the final screen can be shown again, and nowhere else.
The child's name and age that appear on screen were typed by you. They travel inside your own link, and the copy we hold is locked with your key.
The same is true of a guest. A guest's parent replying to an invitation seals their answer, including an allergy line, to your public key in their own browser. We pass the sealed envelope along. We cannot open it.
How long we keep things
| Party ciphertext | Until you delete the party or close your account, then removed within 30 days. |
| Sealed replies | The same: they belong to the party they were sent to. |
| Purchase records | Seven years, because Canadian tax law requires it. |
| Email address | Until you unsubscribe or ask us to delete it, then removed within 30 days. |
| A guest's address, queued for a reminder | Until the reminder is sent or that guest answers, whichever comes first. |
| A guest's address, queued after they said yes | Until the party is over: a note the day before it, a thank-you after it, each deleted as it is sent. Never more than those two. |
| Support emails | Two years. |
Where your information goes
We are in Canada. Our server runs on Cloudflare's network. Stripe and Brevo process data in the European Union and the United States. Transfers out of the EEA and the UK rely on the European Commission's Standard Contractual Clauses, which those processors have in place.
Your rights
You can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. If you are in the EEA or the UK you can also object to processing or ask us to restrict it, and you can withdraw consent to email at any time.
One honest limit on the portability right: what we can hand over is the locked form, because that is what we have. The readable copy is produced by your own browser with your own password, and the builder's Save the party as a file button is how you take it with you.
Email # and we will answer within 30 days, at no charge.
If you are not satisfied you can complain to the Office of the Privacy Commissioner of Canada, or to your own supervisory authority in the EEA or the UK.
Security
The site is served over HTTPS. Sign in never sends your password: your browser derives a secret from it and sends a hash of that, which is what we compare against.
If somebody took everything on our server, they would have a list of email addresses, a set of password hashes, some payment references, and blocks of ciphertext they have no key for. No card numbers, no passwords and no readable party content. A Stripe payment reference names a payment that already happened; it is not a way to charge a card.
That is a real reduction in what a breach costs you. It is not a claim that nobody can ever open anything: a weak password is still a weak password, and the key is derived from it. If a breach ever did affect you, we would tell you and the relevant regulator without undue delay.
Changes
If we change this policy we will change the date at the top. If a change is significant and you have bought from us, we will email you about it rather than quietly editing the page.