SamplePal Application Privacy Policy

Last updated: August 24, 2026 · Applies to: the SamplePal application at app.samplepal.net (the “Application” or “Service”)

1. Who we are and about this policy

SamplePal is a product of Kiwi Tech Lab, LLC (“Kiwi Tech Lab,” “we,” “us,” or “our”), the company legally responsible for the Application. References to “SamplePal” in this policy mean the Application itself. SamplePal is software that lighting agencies and manufacturers use to track physical sample loans: who requested a sample, which manufacturer’s product it is, where it went, and when it came back.

Contact for privacy matters: support@samplepal.net. Postal address: 10361 NW 41st Ct, Coral Springs, FL 33065.

This Privacy Policy explains how Kiwi Tech Lab handles personal data in connection with the Application. It is written to meet the requirements of applicable federal and state privacy laws as of the “Last updated” date above.

This policy does not cover the SamplePal marketing website at samplepal.net, which is governed by a separate privacy policy. The marketing site uses visitor-identification, analytics, and marketing technologies that are not used inside the Application.

2. This policy is addressed to two different audiences

This distinction determines nearly everything below, so we state it first.

2.1 Customer Content: we are a service provider

When a lighting agency or manufacturer (“Customer”) uses SamplePal, the Customer decides what to put in the system. That includes records about the Customer’s own customers: lighting designers, specifiers, architects, distributors, and contractors who borrow samples. For this data the Customer is the business (California) or controller (other states), and Kiwi Tech Lab is the service provider (California) or processor (other states).

We process Customer Content only on the Customer’s documented instructions, only to provide the SamplePal service, and for no other purpose. Specifically, and as required by Cal. Civ. Code § 1798.140(ag), we certify that we will not:

  • sell or share Customer Content, as those terms are defined under the CCPA
  • retain, use, or disclose Customer Content for any purpose other than performing the services specified in our agreement with the Customer, including any commercial purpose of our own
  • retain, use, or disclose Customer Content outside our direct business relationship with the Customer, or
  • combine Customer Content with personal information received from any other source, except as permitted by § 1798.140(ag)(1)(D) and the CCPA regulations

We do not use Customer Content to train machine-learning models, to build profiles, or to generate cross-customer analytics that identify any Customer, individual, or product.

2.2 Account and Business Data: we are a business/controller

For the account holder relationship itself (the Customer’s own staff who sign up, log in, and pay) we act as the business/controller. That means signup details, billing records, support correspondence, and product telemetry described in Section 4.

2.3 A note if your data is in a Customer’s account

If you are a designer, specifier, distributor, or contractor whose name appears in a Customer’s SamplePal account, the Customer, not Kiwi Tech Lab, is your point of contact for privacy requests. Section 11.5 explains how we route requests that reach us first.

3. Note on California and business contacts

California is currently the only state whose comprehensive privacy law covers people acting in a commercial or employment context. Every other state’s law is consumer-only. Because most SamplePal records describe professionals acting on behalf of their firms, the CCPA rights in this policy will often be the operative ones, while other states’ laws may not apply to the same records at all. We do not use this distinction to narrow what we offer: the rights in Section 11 are extended to everyone regardless of state and regardless of whether the record is commercial or personal.

4. What we collect

4.1 Categories under the CCPA

CCPA category (§ 1798.140(v))What this means in SamplePalCollected?
IdentifiersName, work email, phone, company, account ID, IP addressYes
Customer records (§ 1798.80(e))Billing name and address, payment statusYes
Commercial informationSample loan history, requests, returns, product recordsYes
Internet/network activityLog data, pages accessed, device and browser type, error reportsYes
Geolocation dataApproximate city/region inferred from IP, no precise locationCoarse only
Professional or employment informationJob title, firm, agency territoryYes
Audio, electronic, visual informationPhotographs of samples and installations uploaded by usersYes
Sensitive personal informationSee Section 4.3No
Biometric informationSee Section 4.4No
Education informationNo
Inferences / profilesNo

4.2 Where it comes from

Directly from Customer users who type or upload it, automatically from your device when you use the app, from Stripe when a payment succeeds or fails, and, in the case of end-customer records, from the Customer rather than from the individual.

4.3 Sensitive personal information

We do not collect sensitive personal information as defined by the CCPA (§ 1798.140(ae)) or by the Virginia-model state laws: no government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, health data, sexual orientation, union membership, or contents of private communications. We therefore do not use or disclose sensitive personal information for any purpose requiring a “Limit the Use of My Sensitive Personal Information” mechanism, and none is provided.

We also do not collect “consumer health data” within the meaning of Washington’s My Health My Data Act, Nevada SB 370, or Connecticut’s health data provisions.

4.4 Photographs and biometric identifiers

SamplePal stores photographs uploaded by users, typically of samples and sample cases. We do not run facial recognition, face geometry extraction, or any other biometric analysis on uploaded images, and we do not collect, capture, store, or disclose biometric identifiers or biometric information within the meaning of the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, or Washington RCW 19.375. If a person appears incidentally in an uploaded photograph, that image is treated as ordinary Customer Content and is not analyzed.

4.5 Cookies and local storage

The Application is a progressive web app. It uses the following, all of which are strictly necessary for the Service to function:

  • session and authentication cookies: keep you logged in and maintain your session
  • security tokens: protect against cross-site request forgery and session hijacking
  • local storage and the service worker cache: store interface preferences and enable offline, app-like behavior on mobile devices

Each of these exists only to deliver the Service you have requested. None is used for advertising, analytics, cross-site tracking, or profiling, and none results in the sale or sharing of personal information. The Application sets no advertising, analytics, or cross-site tracking cookies and therefore presents no cookie consent banner. If we ever introduce a third-party analytics tool inside the Application, we will update this policy and Section 6 before doing so.

5. Why we use it

  • To operate SamplePal: authenticate users, store and display sample records, send loan and return notifications
  • To bill and collect payment, and to keep records required by tax and accounting law
  • To provide customer support and respond to your requests
  • To keep the service secure: detect fraud, abuse, and unauthorized access, and investigate incidents
  • To diagnose crashes and errors and improve reliability
  • To send service and administrative messages about your account
  • To send marketing about SamplePal to Customer account holders, subject to Section 9
  • To comply with law and to establish, exercise, or defend legal claims

We do not use personal information for targeted advertising, cross-context behavioral advertising, or profiling that produces legal or similarly significant effects.

6. Disclosure

6.1 We do not sell or share your data and we do not disclose sample data to other businesses

We have never sold personal information and do not sell it now. We do not share personal information for cross-context behavioral advertising. We have not sold or shared the personal information of any consumer, including any consumer we know to be under 16, in the preceding twelve months. There is accordingly no “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of. We nonetheless honor Global Privacy Control and other universal opt-out signals as an opt-out of sale and sharing should our practices ever change.

Separately and specifically: we do not disclose a Customer’s sample data, (including which products were sampled, by whom, for which projects, in what volume, or with what outcome), to any other business, and we never disclose one Customer’s data to another Customer. This rule applies identically whether the Customer is a lighting agency or a manufacturer: each Customer’s account is walled off from every other, and neither can see, query, or receive the other’s data. The businesses to whom we do not disclose Customer data include, without limitation:

  • other lighting agencies
  • manufacturers’ representative agencies or agencies of any other type
  • lighting manufacturers, including manufacturers whose own products appear in the data, and manufacturers who are themselves SamplePal Customers
  • any other SamplePal Customer, whether a lighting agency, a manufacturer, or any other type of subscriber
  • electrical distributors
  • contractors of any type
  • specification firms, market research firms, and data brokers

This is not a discretionary practice. Because Customer Content is processed under the Customer’s instructions (Section 2.1), a disclosure of this kind would require the Customer’s own documented instruction to make it. We will not make such a disclosure without the Customer’s prior written permission, given per Customer. It will never be a default, a silent rollout, or a change effected by amending this policy. Where the Customer is a manufacturer, the same protection runs in its favor: that manufacturer’s own sample activity, customer records, and product data are equally unavailable to any other Customer of SamplePal, including the lighting agencies that carry its line.

We anticipate building partnership features with manufacturers as SamplePal grows. Any data sharing in those features will be opt-in, per Customer, and off unless affirmatively enabled. Where a partnership feature would involve data belonging to two Customers, (i.e. a lighting agency and a manufacturer), it requires the separate affirmative opt-in of each of them. Neither Customer can enable it on the other’s behalf, and we will not treat one Customer’s participation as consent for the other. Where such a feature would disclose contact records for a Customer’s own customers, that Customer’s separate obligations to those individuals apply, and we will design the feature so that they can be met.

6.2 Service providers we use

All of the following are located in, and store data in, the United States. Each is bound by a written agreement containing the service-provider terms required by Cal. Civ. Code § 1798.100(d) and § 1798.140(ag) and the equivalent processor terms under other state laws.

ProviderFunctionData location
Hetzner Online GmbHApplication hosting, database, backupsUnited States
CloudinaryImage storage and deliveryUnited States
SentryError monitoring and crash reportingUnited States
ResendTransactional and notification emailUnited States
StripePayment processingUnited States
Google (Workspace)Business email, documents, support correspondenceUnited States

6.3 Business-purpose disclosures

In the preceding twelve months we disclosed the categories of personal information in Section 4.1 to the service providers in Section 6.2 for the business purposes in Section 5. We disclosed no categories of personal information to third parties for their own purposes.

6.4 Legal and corporate disclosures

We may disclose personal information where we are legally compelled to do so, where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of any person. Section 10 describes how we handle government demands. In a merger, acquisition, financing, or sale of assets, personal information may transfer to the acquiring entity, which will remain bound by this policy for information collected before the transfer, we will notify Customers before any such transfer becomes effective.

6.5 Links to third-party websites

Sample records may contain links to manufacturers’ cut sheets, specification documents, and other third-party resources. These links are provided for convenience. When you follow one, you leave the Application and the destination site’s own privacy practices apply. We do not control those sites, do not share your personal data with them, and are not responsible for their content or their handling of your data. Following such a link will disclose to the destination site the standard information any web request carries, including your IP address and browser type.

6.6 Within your Company

The Application is a shared workspace. Data you enter is visible to other Users of your company according to their role. Administrators can see each User’s checkout and check-in activity, the samples in that User’s possession, the customers a User has loaned samples to, and User activity reporting. If you are a representative or regional, your employer can and will see this record of your activity in the Application.

7. Where your data is stored

SamplePal is hosted entirely in the United States. Every provider in Section 6.2 stores data in U.S. facilities. We do not currently store or process SamplePal data outside the United States, and we do not transfer it internationally except where a user chooses to access the service from abroad.

Data stored in the United States is subject to U.S. federal and state law, including lawful access by U.S. government authorities. Section 10 sets out what we do when we receive such a demand. Should we change this and our data is then stored outside the U.S., we will update this policy to disclose that.

8. Payments

Payments are processed by Stripe. Card numbers, CVCs, and expiration dates are transmitted directly to Stripe and are never received, processed, or stored on Kiwi Tech Lab servers. We receive only the transaction outcome, the last four digits, the card brand, and billing metadata. Stripe is a PCI-DSS Level 1 service provider.

9. Email, text messages, and marketing

Service messages. Sample loan notifications, return reminders, password resets, receipts, security alerts, and material changes to terms are transactional. They are necessary to the service and cannot be unsubscribed from separately while your account is active.

Marketing. We send marketing email only to Customer account holders and people who have asked to hear from us. Every marketing message identifies Kiwi Tech Lab, includes our physical postal address, and carries a working unsubscribe link honored within ten business days, as required by the CAN-SPAM Act. We do not sell or rent our mailing list.

Text messages. We do not currently send SMS. If we introduce SMS notifications, we will send them only with prior express consent, and replying STOP will end them. We do not use autodialed or prerecorded marketing calls.

California “Shine the Light” (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for those parties’ own direct marketing purposes. California residents may confirm this by writing to the address in Section 1.

10. Government and law enforcement requests

When we receive a subpoena, warrant, court order, or other demand for Customer data, we:

  • review it for validity and scope, and object to demands that are overbroad, defective, or unlawful
  • produce the narrowest set of data responsive to a valid demand
  • notify the affected Customer before producing anything, unless a court order or statute prohibits notice, in which case we notify as soon as the prohibition lifts, and
  • direct requesters to the Customer where the Customer, rather than Kiwi Tech Lab, is the appropriate recipient of the demand

We have received no national security demands that we are permitted to disclose.

11. Your rights

We extend the following rights to everyone, without regard to which state law technically applies.

11.1 What you can ask for

  • Know / access the categories and specific pieces of personal information we hold about you, the sources, the purposes, and the categories of recipients
  • Delete your personal information, subject to the exceptions below
  • Correct inaccurate personal information
  • Portability: a copy in a portable, machine-readable format
  • Opt out of sale, sharing, targeted advertising, and profiling: we do none of these, so there is nothing to opt out of. The right is stated for completeness
  • Limit use of sensitive personal information: we collect none, so no limitation mechanism is required
  • Non-discrimination: we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right. We offer no financial incentives for personal information.

11.2 How to exercise them

Email support@samplepal.net with the subject line “Privacy Request,” or write to the postal address in Section 1. Customer account holders can also export and delete much of their data directly in the application.

11.3 Verification and timing

We verify requests by matching the request to the account email on file, and, for higher-risk requests such as deletion of an entire account, by confirming through a second factor already associated with the account. We do not require you to create an account to make a request, and we collect no new personal information for verification beyond what is necessary.

We acknowledge requests within 10 business days and respond substantively within 45 days. Where reasonably necessary we may extend once by a further 45 days and will tell you why within the first 45. Access and portability responses cover the 12 months preceding the request. California residents may request information beyond that period where it is available and not disproportionately burdensome to produce.

11.4 Authorized agents and appeals

You may use an authorized agent, who must provide written permission signed by you. We may ask you to verify your identity directly.

If we decline a request, we will tell you why and give you a way to appeal. Appeals go to support@samplepal.net with the subject line “Privacy Appeal” and are decided within 45 days (60 in Connecticut, and 60 in the states that allow it) by someone other than the person who made the original decision. If we deny the appeal, we will provide you with a method to contact your state Attorney General.

11.5 If your data is in a Customer’s account

Where we hold your information as a service provider, we cannot make decisions about it. If you contact us directly, we will identify the relevant Customer, forward your request to them within 5 business days, and tell you we have done so. The Customer, not Kiwi Tech Lab, decides how to respond.

Where the Customer instructs us to act, we act promptly on reasonable written instructions. Locating, exporting, correcting, or deleting records using the application’s existing features is part of the service we already provide to that Customer, and we do it at no additional charge. If a Customer’s instructions would require work beyond that, we may agree a fee with that Customer in advance under our agreement with them. Any such arrangement is solely between Kiwi Tech Lab and the Customer. You will never be charged for exercising a right — consistent with the non-discrimination commitment in Section 11.1 — and no fee discussion will delay our response to you or the Customer’s obligation to respond to you.

We may decline an instruction that is unlawful, technically infeasible, or that would compromise the security or integrity of the application or another Customer’s data. If we decline, we will tell the Customer why, and where you contacted us directly, we will tell you that we have done so. Your rights against the Customer as the controller of your information are unaffected, and the appeal route in Section 11.4 remains open to you.

11.6 Exceptions

We may retain information we are required to keep by law (tax and accounting records, for example), information necessary to complete a transaction you requested, to detect security incidents, to defend legal claims, or where deletion would be impossible or involve disproportionate effort. Deleting a shared record, (such as a sample loan involving both a Customer and one of its own customers), may not be possible without destroying the Customer’s own business record. In that case we de-identify rather than delete.

12. Children

The Application is a business tool intended for use by employees and contractors of subscribing Customers. It is not directed to children and we do not knowingly collect personal data from anyone under 16.

California residents under 18 who are registered users may request removal of content they posted, under Cal. Bus. & Prof. Code § 22581, by writing to the address in Section 1.

13. Security

We maintain reasonable security procedures and practices appropriate to the nature of the information, as required by Cal. Civ. Code § 1798.81.5 and comparable state statutes. These include encryption in transit (TLS 1.2 or higher), role-based access control, least-privilege administrative access, authentication for staff, logging and monitoring, access-controlled backup storage, and periodic review of access rights. No system is perfectly secure, and we do not claim otherwise.

Breach notification. If we become aware of a breach of the security of the system involving personal information, we will notify the affected Customer without unreasonable delay and in any event within 72 hours of becoming aware, with the information the Customer needs to meet its own obligations. Where we are the business/controller for the affected data, we notify affected individuals and any required regulators in the most expedient time possible and without unreasonable delay, consistent with the breach-notification statute of each affected individual’s state.

California residents should note that Cal. Civ. Code § 1798.150 provides a private right of action for certain breaches of nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security.

14. Retention

We keep personal information only as long as needed for the purposes in Section 5.

DataRetention
Active account dataFor the life of the account
Customer Content after account closure30 days, then deleted, backups purge within 30 days
Billing and tax records7 years, as required by law
Server and access logs12 months
Error and crash reports (Sentry)90 days
Support correspondence24 months after resolution
Marketing contactsUntil unsubscribe, then a suppression record only
User accountsUntil the account is deleted by a Customer administrator, or 30 days after the Customer’s subscription ends
Free trial data where no subscription follows30 days after the trial expires

15. Do Not Track

Browsers send Do Not Track signals inconsistently and there is no accepted standard for honoring them, so we do not respond to DNT. We do honor Global Privacy Control as described in Section 6.1. We do not permit third parties to collect personal information about your activity across other websites through the SamplePal application.

16. Not a data broker

Kiwi Tech Lab is not a data broker. We collect personal information only through direct relationships with our Customers and their designated users, and we are not required to register under the California Delete Act, Texas Bus. & Com. Code § 509, Oregon HB 2052, or Vermont’s data broker statute.

17. State-specific notes

JurisdictionNote
CaliforniaThe CCPA/CPRA rights and disclosures above are the operative ones for most SamplePal records, since California uniquely covers business and employment contacts. Sections 4.1, 6.1, 6.3, 9, 11, and 13 are the CCPA notice at collection and annual disclosure.
Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, WashingtonAccess, correction, deletion, portability, opt-out, and appeal rights are provided as described in Section 11. We conduct no processing that requires a data protection assessment, as we neither sell data, target advertising, nor profile individuals.
MarylandMaryland prohibits the sale of sensitive personal information outright and imposes strict data minimization. We collect no sensitive personal information and sell nothing.
NevadaWe do not sell covered information as defined by NRS 603A.
Illinois, Texas, WashingtonSee Section 4.4 on biometrics.
Oklahoma, Louisiana (Jan 1, 2027), Alabama (May 1, 2027), Vermont (Jan 1, 2028)These laws are enacted but not yet effective. The rights in Section 11 already meet their requirements. We will update this policy if that changes.
European Union / EEA / UKSee our separate GDPR privacy policy.

18. Changes

We will post any change here and update the “Last updated” date. For a material change such as a new category of data, a new purpose, a new recipient, or anything affecting Section 6.1, we will notify Customer account holders by email at least 30 days before it takes effect and will not apply it retroactively to information already collected without consent.

19. Contact

Questions, requests, or complaints about this policy or our privacy practices:

Email: support@samplepal.net
Address: Kiwi Tech Lab, LLC, 10361 NW 41st Ct., Coral Springs, FL 33065, United States

To exercise a right, use the subject line “Privacy Request.” To appeal a decision, use “Privacy Appeal.” California residents may also contact the California Privacy Protection Agency or the California Attorney General. Residents of other states may contact their state Attorney General.