Privacy
Last updated 29 August 2026
The short version
A Kestero widget sets no cookies on your visitors’ browsers, and we keep no record of any individual visitor. There is no visitor table in our database, because there is nothing per-visitor to put in one. That is why a Kestero widget needs no consent banner of its own.
What we do store is about you, our customer: your account, the widgets you design, and counts of how often they were shown and clicked.
If you are a visitor to a site using Kestero
A widget records that it was shown, and that a particular button in it was clicked. Those records contain the widget’s id and the id of the block you interacted with — never an identifier for you. Two visitors are indistinguishable to us, and so are the same visitor twice.
Depending on the site owner’s settings, an event may also carry the page address and the referring address. Those are facts about a page, not about a person, and the owner can switch both off.
If you fill in a form in a widget, what you typed is stored and sent to the site owner. That is the point of the form, and only the fields the widget actually shows you can be stored.
Some things a widget remembers are kept in your own browser’s storage — whether you dismissed it, which updates you have read, how far through a multi-step widget you were. That never leaves your device and we cannot read it. Clearing your browser data removes it.
If you are a customer
We store:
- Your email address, and either a password hash or the fact that you sign in with Google. Authentication is handled by Supabase; we never see your Google password.
- The widgets you design, which are JSON documents describing a layout.
- Images you upload for use in a widget.
- Counts of impressions, clicks and submissions for your widgets.
- Form submissions your widgets collect, which are yours and which we do not read.
- If you subscribe, a customer identifier and subscription status from Stripe. Card details go to Stripe directly and never reach us.
Who else can see it
We use a small number of processors. This list is complete, and we would rather name the awkward one than leave it out:
- Supabase — the database and file storage, hosted on AWS in Ireland (eu-west-1). It holds everything described above.
- Cloudflare — serves the application and the widget script. It processes requests in transit and, as with any host, sees the addresses they come from.
- Upstash — rate limiting. To count requests it receives a key that includes the visitor's IP address. This is the one place a visitor's address reaches a third party, it is kept only for the length of the rate-limit window, and it is not stored against anything.
- Anthropic — only when you use the AI drafter, and only the description you type. Visitor data is never sent.
- Stripe — payments, if you subscribe.
Where it lives
The database and uploaded files are in Ireland (AWS eu-west-1). The application is served from Cloudflare’s network, so requests are handled close to whoever made them, but the data at rest stays in the EU.
How long we keep it
Widgets, submissions and analytics stay until you delete them or close your account. Deleting your account removes your projects, widgets, submissions and events; the database enforces that with cascading deletes rather than leaving it to a script.
Rate-limit counters expire on their own within minutes or, for daily limits, within a day.
Your rights
If you are in the EU or UK, you have the right to access, correct, export and delete your data, and to object to processing. The dashboard can export and delete your account without asking us. For anything else, or if you are a visitor to a customer site and want something removed, write to us — the address is on the contact page.
For data collected through a widget on someone else’s website, that site’s owner is the data controller and we are their processor. If your request is about what a particular site collected, they are the right people to ask, and we will help them answer.
Changes
If this policy changes in a way that affects what we collect, we will say so on this page and date it. The date at the top is when it last changed.
Questions about any of this? Get in touch.