Kenro
Kenro
Get Started
We know privacy policies are usually written to protect the company, not the user. This one is written for you.
Last updated: September 2026 · Applies to usekenro.com and all Kenro mobile apps
When you create an account, we collect your name, email address, and business information (shop name, phone number). When you use the app, we store the data you enter — job cards, customer records, invoices, expenses, and related files like photos. We also collect basic usage logs (page visits, errors) to keep the app running smoothly.
Everything we collect is used to run Kenro for you. Your data powers your dashboard, your reports, your invoices. We don't sell it. We don't share it with advertisers. We don't use it to train AI models. It's yours.
Your data is stored on Supabase (PostgreSQL), hosted on AWS infrastructure in Mumbai (ap-south-1) for Indian users. Backups are encrypted and retained for 30 days. Files and photos are stored on Supabase Storage with private access — no public URLs unless you explicitly share a job tracker or quote link.
Only you and the team members you invite can access your workshop data. Our engineering team can access anonymised logs for debugging — but not your customer records, job cards, or financial data unless you explicitly share access for support. We will never access your data without your permission except as required by law.
We use a single session cookie to keep you logged in. On our public marketing pages we count page views and button taps with Vercel Web Analytics, served from our own domain: it sets no cookie, stores no personal data, and never runs inside the app you log in to. Nothing else. No Facebook Pixel, no Google Analytics, no ad cookies, no hidden tracking.
We invoice you directly — pay by UPI or bank transfer. Paying online is coming; your price doesn't change. Kenro does not process or store card numbers. Your own customers' payments stay entirely between you and them — Kenro only records them.
You can export your data at any time from the app. You can request deletion of your account and all associated data by emailing us. We'll action data deletion requests within 14 business days. If you're in a jurisdiction with specific data rights (GDPR, DPDP Act), those rights apply in full.
We retain your data for as long as your account is active. If you cancel or your account lapses, the account goes read-only: you keep the ability to log in, read every record and export it, indefinitely and at no charge. Nothing is deleted on lapse. Records are removed only when you ask us to delete them, or under the retention periods above (invoices and GST records after seven years, in line with Indian law).
All data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to a small team with 2FA enforced. We run row-level security policies so no user can ever access another shop's data, even if a bug exists in our application layer.
If we make material changes to how we handle your data, we'll notify you by email before the changes take effect. Minor clarifications may be updated without notice — the "last updated" date below will always reflect the current version.
Privacy questions, data requests, or concerns — email us at hello@usekenro.com. We'll respond within 5 business days.