Legal

Privacy Policy

How Keystona collects, uses, and protects information.

Last updated: May 2026

Keystona treats the data you entrust to us with the same care your finance and people teams treat it inside your organization. This page explains what we collect, why, and what you control.

The short version. We collect what we need to run your account and improve the product. We don't sell your data. We don't share it with third parties for marketing. You can export or delete your data at any time.

1. What we collect

When you use Keystona, we collect:

  • Account information — your name, work email, company, and authentication credentials.
  • Operational data — the people, payroll, time, leave, and audit data you create in the platform.
  • Usage data — page views, feature interactions, and performance metrics, used to improve the product.
  • Technical data — browser type, device, IP address, and similar information collected automatically when you access the platform.

2. How we use it

We use the data we collect to:

  • Provide, operate, and maintain the platform.
  • Process and complete the transactions you initiate (payroll runs, leave approvals, etc.).
  • Send you operational notices, security alerts, and support communications.
  • Improve product performance and reliability.
  • Detect, investigate, and prevent fraud, security incidents, or abuse.
  • Comply with legal obligations.

3. What we don't do

  • We don't sell your data.
  • We don't share your operational data with third parties for marketing.
  • We don't read your customer data outside of providing support — and only with your authorization.
  • We don't profile your employees for any purpose other than the operational work you've configured.

4. How long we keep it

Operational data is retained for as long as your account is active, plus the period required to meet our legal and accounting obligations. You can request data export or deletion at any time by writing to privacy@keystona.io.

5. Where it's stored

Data is encrypted at rest and in transit. Production data is stored in secure, audited data centers. Backups are encrypted and retained on the same standard. Access is restricted to authorized personnel and logged.

6. Your rights

You can:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to legal retention requirements).
  • Export your data in a structured, machine-readable format.
  • Withdraw consent for any optional processing.
  • Lodge a complaint with a data protection authority.

7. Subprocessors

We use a small number of carefully vetted infrastructure subprocessors (cloud hosting, payment processing, email delivery, analytics). A current list is available on request at privacy@keystona.io. Each subprocessor is bound by data protection agreements no weaker than this policy.

8. Cookies

We use a small number of strictly necessary cookies for session management and security. Optional analytics cookies are disabled by default and can be enabled in your account preferences. We don't use cross-site tracking cookies.

9. Changes to this policy

If we materially change how we handle your data, we'll notify you by email and in-product before the change takes effect. The current version is always available at this URL with a "last updated" date.

10. Contact

Questions, requests, or concerns about this policy: privacy@keystona.io