SamplePal Application Privacy Policy
Last updated: August 24, 2026 · Applies to: the SamplePal application at app.samplepal.net (the “Application” or “Service”)
1. Who we are and about this policy
SamplePal is a product of Kiwi Tech Lab, LLC (“Kiwi Tech Lab,” “we,” “us,” or “our”), the company legally responsible for the Application. References to “SamplePal” in this policy mean the Application itself. SamplePal is software that lighting agencies and manufacturers use to track physical sample loans: who requested a sample, which manufacturer’s product it is, where it went, and when it came back.
Contact for privacy matters: support@samplepal.net. Postal address: 10361 NW 41st Ct, Coral Springs, FL 33065.
This Privacy Policy explains how Kiwi Tech Lab handles personal data in connection with the Application. It is written to meet the requirements of applicable federal and state privacy laws as of the “Last updated” date above.
This policy does not cover the SamplePal marketing website at samplepal.net, which is governed by a separate privacy policy. The marketing site uses visitor-identification, analytics, and marketing technologies that are not used inside the Application.
2. This policy is addressed to two different audiences
This distinction determines nearly everything below, so we state it first.
2.1 Customer Content: we are a service provider
When a lighting agency or manufacturer (“Customer”) uses SamplePal, the Customer decides what to put in the system. That includes records about the Customer’s own customers: lighting designers, specifiers, architects, distributors, and contractors who borrow samples. For this data the Customer is the business (California) or controller (other states), and Kiwi Tech Lab is the service provider (California) or processor (other states).
We process Customer Content only on the Customer’s documented instructions, only to provide the SamplePal service, and for no other purpose. Specifically, and as required by Cal. Civ. Code § 1798.140(ag), we certify that we will not:
- sell or share Customer Content, as those terms are defined under the CCPA
- retain, use, or disclose Customer Content for any purpose other than performing the services specified in our agreement with the Customer, including any commercial purpose of our own
- retain, use, or disclose Customer Content outside our direct business relationship with the Customer, or
- combine Customer Content with personal information received from any other source, except as permitted by § 1798.140(ag)(1)(D) and the CCPA regulations
We do not use Customer Content to train machine-learning models, to build profiles, or to generate cross-customer analytics that identify any Customer, individual, or product.
2.2 Account and Business Data: we are a business/controller
For the account holder relationship itself (the Customer’s own staff who sign up, log in, and pay) we act as the business/controller. That means signup details, billing records, support correspondence, and product telemetry described in Section 4.
2.3 A note if your data is in a Customer’s account
If you are a designer, specifier, distributor, or contractor whose name appears in a Customer’s SamplePal account, the Customer, not Kiwi Tech Lab, is your point of contact for privacy requests. Section 11.5 explains how we route requests that reach us first.
3. Note on California and business contacts
California is currently the only state whose comprehensive privacy law covers people acting in a commercial or employment context. Every other state’s law is consumer-only. Because most SamplePal records describe professionals acting on behalf of their firms, the CCPA rights in this policy will often be the operative ones, while other states’ laws may not apply to the same records at all. We do not use this distinction to narrow what we offer: the rights in Section 11 are extended to everyone regardless of state and regardless of whether the record is commercial or personal.
4. What we collect
4.1 Categories under the CCPA
| CCPA category (§ 1798.140(v)) | What this means in SamplePal | Collected? |
|---|---|---|
| Identifiers | Name, work email, phone, company, account ID, IP address | Yes |
| Customer records (§ 1798.80(e)) | Billing name and address, payment status | Yes |
| Commercial information | Sample loan history, requests, returns, product records | Yes |
| Internet/network activity | Log data, pages accessed, device and browser type, error reports | Yes |
| Geolocation data | Approximate city/region inferred from IP, no precise location | Coarse only |
| Professional or employment information | Job title, firm, agency territory | Yes |
| Audio, electronic, visual information | Photographs of samples and installations uploaded by users | Yes |
| Sensitive personal information | See Section 4.3 | No |
| Biometric information | See Section 4.4 | No |
| Education information | — | No |
| Inferences / profiles | — | No |
4.2 Where it comes from
Directly from Customer users who type or upload it, automatically from your device when you use the app, from Stripe when a payment succeeds or fails, and, in the case of end-customer records, from the Customer rather than from the individual.
4.3 Sensitive personal information
We do not collect sensitive personal information as defined by the CCPA (§ 1798.140(ae)) or by the Virginia-model state laws: no government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, health data, sexual orientation, union membership, or contents of private communications. We therefore do not use or disclose sensitive personal information for any purpose requiring a “Limit the Use of My Sensitive Personal Information” mechanism, and none is provided.
We also do not collect “consumer health data” within the meaning of Washington’s My Health My Data Act, Nevada SB 370, or Connecticut’s health data provisions.
4.4 Photographs and biometric identifiers
SamplePal stores photographs uploaded by users, typically of samples and sample cases. We do not run facial recognition, face geometry extraction, or any other biometric analysis on uploaded images, and we do not collect, capture, store, or disclose biometric identifiers or biometric information within the meaning of the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, or Washington RCW 19.375. If a person appears incidentally in an uploaded photograph, that image is treated as ordinary Customer Content and is not analyzed.
4.5 Cookies and local storage
The Application is a progressive web app. It uses the following, all of which are strictly necessary for the Service to function:
- session and authentication cookies: keep you logged in and maintain your session
- security tokens: protect against cross-site request forgery and session hijacking
- local storage and the service worker cache: store interface preferences and enable offline, app-like behavior on mobile devices
Each of these exists only to deliver the Service you have requested. None is used for advertising, analytics, cross-site tracking, or profiling, and none results in the sale or sharing of personal information. The Application sets no advertising, analytics, or cross-site tracking cookies and therefore presents no cookie consent banner. If we ever introduce a third-party analytics tool inside the Application, we will update this policy and Section 6 before doing so.
5. Why we use it
- To operate SamplePal: authenticate users, store and display sample records, send loan and return notifications
- To bill and collect payment, and to keep records required by tax and accounting law
- To provide customer support and respond to your requests
- To keep the service secure: detect fraud, abuse, and unauthorized access, and investigate incidents
- To diagnose crashes and errors and improve reliability
- To send service and administrative messages about your account
- To send marketing about SamplePal to Customer account holders, subject to Section 9
- To comply with law and to establish, exercise, or defend legal claims
We do not use personal information for targeted advertising, cross-context behavioral advertising, or profiling that produces legal or similarly significant effects.
6. Disclosure
6.1 We do not sell or share your data and we do not disclose sample data to other businesses
We have never sold personal information and do not sell it now. We do not share personal information for cross-context behavioral advertising. We have not sold or shared the personal information of any consumer, including any consumer we know to be under 16, in the preceding twelve months. There is accordingly no “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of. We nonetheless honor Global Privacy Control and other universal opt-out signals as an opt-out of sale and sharing should our practices ever change.
Separately and specifically: we do not disclose a Customer’s sample data, (including which products were sampled, by whom, for which projects, in what volume, or with what outcome), to any other business, and we never disclose one Customer’s data to another Customer. This rule applies identically whether the Customer is a lighting agency or a manufacturer: each Customer’s account is walled off from every other, and neither can see, query, or receive the other’s data. The businesses to whom we do not disclose Customer data include, without limitation:
- other lighting agencies
- manufacturers’ representative agencies or agencies of any other type
- lighting manufacturers, including manufacturers whose own products appear in the data, and manufacturers who are themselves SamplePal Customers
- any other SamplePal Customer, whether a lighting agency, a manufacturer, or any other type of subscriber
- electrical distributors
- contractors of any type
- specification firms, market research firms, and data brokers
This is not a discretionary practice. Because Customer Content is processed under the Customer’s instructions (Section 2.1), a disclosure of this kind would require the Customer’s own documented instruction to make it. We will not make such a disclosure without the Customer’s prior written permission, given per Customer. It will never be a default, a silent rollout, or a change effected by amending this policy. Where the Customer is a manufacturer, the same protection runs in its favor: that manufacturer’s own sample activity, customer records, and product data are equally unavailable to any other Customer of SamplePal, including the lighting agencies that carry its line.
We anticipate building partnership features with manufacturers as SamplePal grows. Any data sharing in those features will be opt-in, per Customer, and off unless affirmatively enabled. Where a partnership feature would involve data belonging to two Customers, (i.e. a lighting agency and a manufacturer), it requires the separate affirmative opt-in of each of them. Neither Customer can enable it on the other’s behalf, and we will not treat one Customer’s participation as consent for the other. Where such a feature would disclose contact records for a Customer’s own customers, that Customer’s separate obligations to those individuals apply, and we will design the feature so that they can be met.
6.2 Service providers we use
All of the following are located in, and store data in, the United States. Each is bound by a written agreement containing the service-provider terms required by Cal. Civ. Code § 1798.100(d) and § 1798.140(ag) and the equivalent processor terms under other state laws.
| Provider | Function | Data location |
|---|---|---|
| Hetzner Online GmbH | Application hosting, database, backups | United States |
| Cloudinary | Image storage and delivery | United States |
| Sentry | Error monitoring and crash reporting | United States |
| Resend | Transactional and notification email | United States |
| Stripe | Payment processing | United States |
| Google (Workspace) | Business email, documents, support correspondence | United States |
6.3 Business-purpose disclosures
In the preceding twelve months we disclosed the categories of personal information in Section 4.1 to the service providers in Section 6.2 for the business purposes in Section 5. We disclosed no categories of personal information to third parties for their own purposes.
6.4 Legal and corporate disclosures
We may disclose personal information where we are legally compelled to do so, where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of any person. Section 10 describes how we handle government demands. In a merger, acquisition, financing, or sale of assets, personal information may transfer to the acquiring entity, which will remain bound by this policy for information collected before the transfer, we will notify Customers before any such transfer becomes effective.
6.5 Links to third-party websites
Sample records may contain links to manufacturers’ cut sheets, specification documents, and other third-party resources. These links are provided for convenience. When you follow one, you leave the Application and the destination site’s own privacy practices apply. We do not control those sites, do not share your personal data with them, and are not responsible for their content or their handling of your data. Following such a link will disclose to the destination site the standard information any web request carries, including your IP address and browser type.
6.6 Within your Company
The Application is a shared workspace. Data you enter is visible to other Users of your company according to their role. Administrators can see each User’s checkout and check-in activity, the samples in that User’s possession, the customers a User has loaned samples to, and User activity reporting. If you are a representative or regional, your employer can and will see this record of your activity in the Application.
7. Where your data is stored
SamplePal is hosted entirely in the United States. Every provider in Section 6.2 stores data in U.S. facilities. We do not currently store or process SamplePal data outside the United States, and we do not transfer it internationally except where a user chooses to access the service from abroad.
Data stored in the United States is subject to U.S. federal and state law, including lawful access by U.S. government authorities. Section 10 sets out what we do when we receive such a demand. Should we change this and our data is then stored outside the U.S., we will update this policy to disclose that.
8. Payments
Payments are processed by Stripe. Card numbers, CVCs, and expiration dates are transmitted directly to Stripe and are never received, processed, or stored on Kiwi Tech Lab servers. We receive only the transaction outcome, the last four digits, the card brand, and billing metadata. Stripe is a PCI-DSS Level 1 service provider.
9. Email, text messages, and marketing
Service messages. Sample loan notifications, return reminders, password resets, receipts, security alerts, and material changes to terms are transactional. They are necessary to the service and cannot be unsubscribed from separately while your account is active.
Marketing. We send marketing email only to Customer account holders and people who have asked to hear from us. Every marketing message identifies Kiwi Tech Lab, includes our physical postal address, and carries a working unsubscribe link honored within ten business days, as required by the CAN-SPAM Act. We do not sell or rent our mailing list.
Text messages. We do not currently send SMS. If we introduce SMS notifications, we will send them only with prior express consent, and replying STOP will end them. We do not use autodialed or prerecorded marketing calls.
California “Shine the Light” (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for those parties’ own direct marketing purposes. California residents may confirm this by writing to the address in Section 1.
10. Government and law enforcement requests
When we receive a subpoena, warrant, court order, or other demand for Customer data, we:
- review it for validity and scope, and object to demands that are overbroad, defective, or unlawful
- produce the narrowest set of data responsive to a valid demand
- notify the affected Customer before producing anything, unless a court order or statute prohibits notice, in which case we notify as soon as the prohibition lifts, and
- direct requesters to the Customer where the Customer, rather than Kiwi Tech Lab, is the appropriate recipient of the demand
We have received no national security demands that we are permitted to disclose.
11. Your rights
We extend the following rights to everyone, without regard to which state law technically applies.
11.1 What you can ask for
- Know / access the categories and specific pieces of personal information we hold about you, the sources, the purposes, and the categories of recipients
- Delete your personal information, subject to the exceptions below
- Correct inaccurate personal information
- Portability: a copy in a portable, machine-readable format
- Opt out of sale, sharing, targeted advertising, and profiling: we do none of these, so there is nothing to opt out of. The right is stated for completeness
- Limit use of sensitive personal information: we collect none, so no limitation mechanism is required
- Non-discrimination: we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right. We offer no financial incentives for personal information.
11.2 How to exercise them
Email support@samplepal.net with the subject line “Privacy Request,” or write to the postal address in Section 1. Customer account holders can also export and delete much of their data directly in the application.
11.3 Verification and timing
We verify requests by matching the request to the account email on file, and, for higher-risk requests such as deletion of an entire account, by confirming through a second factor already associated with the account. We do not require you to create an account to make a request, and we collect no new personal information for verification beyond what is necessary.
We acknowledge requests within 10 business days and respond substantively within 45 days. Where reasonably necessary we may extend once by a further 45 days and will tell you why within the first 45. Access and portability responses cover the 12 months preceding the request. California residents may request information beyond that period where it is available and not disproportionately burdensome to produce.
11.4 Authorized agents and appeals
You may use an authorized agent, who must provide written permission signed by you. We may ask you to verify your identity directly.
If we decline a request, we will tell you why and give you a way to appeal. Appeals go to support@samplepal.net with the subject line “Privacy Appeal” and are decided within 45 days (60 in Connecticut, and 60 in the states that allow it) by someone other than the person who made the original decision. If we deny the appeal, we will provide you with a method to contact your state Attorney General.
11.5 If your data is in a Customer’s account
Where we hold your information as a service provider, we cannot make decisions about it. If you contact us directly, we will identify the relevant Customer, forward your request to them within 5 business days, and tell you we have done so. The Customer, not Kiwi Tech Lab, decides how to respond.
Where the Customer instructs us to act, we act promptly on reasonable written instructions. Locating, exporting, correcting, or deleting records using the application’s existing features is part of the service we already provide to that Customer, and we do it at no additional charge. If a Customer’s instructions would require work beyond that, we may agree a fee with that Customer in advance under our agreement with them. Any such arrangement is solely between Kiwi Tech Lab and the Customer. You will never be charged for exercising a right — consistent with the non-discrimination commitment in Section 11.1 — and no fee discussion will delay our response to you or the Customer’s obligation to respond to you.
We may decline an instruction that is unlawful, technically infeasible, or that would compromise the security or integrity of the application or another Customer’s data. If we decline, we will tell the Customer why, and where you contacted us directly, we will tell you that we have done so. Your rights against the Customer as the controller of your information are unaffected, and the appeal route in Section 11.4 remains open to you.
11.6 Exceptions
We may retain information we are required to keep by law (tax and accounting records, for example), information necessary to complete a transaction you requested, to detect security incidents, to defend legal claims, or where deletion would be impossible or involve disproportionate effort. Deleting a shared record, (such as a sample loan involving both a Customer and one of its own customers), may not be possible without destroying the Customer’s own business record. In that case we de-identify rather than delete.
12. Children
The Application is a business tool intended for use by employees and contractors of subscribing Customers. It is not directed to children and we do not knowingly collect personal data from anyone under 16.
California residents under 18 who are registered users may request removal of content they posted, under Cal. Bus. & Prof. Code § 22581, by writing to the address in Section 1.
13. Security
We maintain reasonable security procedures and practices appropriate to the nature of the information, as required by Cal. Civ. Code § 1798.81.5 and comparable state statutes. These include encryption in transit (TLS 1.2 or higher), role-based access control, least-privilege administrative access, authentication for staff, logging and monitoring, access-controlled backup storage, and periodic review of access rights. No system is perfectly secure, and we do not claim otherwise.
Breach notification. If we become aware of a breach of the security of the system involving personal information, we will notify the affected Customer without unreasonable delay and in any event within 72 hours of becoming aware, with the information the Customer needs to meet its own obligations. Where we are the business/controller for the affected data, we notify affected individuals and any required regulators in the most expedient time possible and without unreasonable delay, consistent with the breach-notification statute of each affected individual’s state.
California residents should note that Cal. Civ. Code § 1798.150 provides a private right of action for certain breaches of nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security.
14. Retention
We keep personal information only as long as needed for the purposes in Section 5.
| Data | Retention |
|---|---|
| Active account data | For the life of the account |
| Customer Content after account closure | 30 days, then deleted, backups purge within 30 days |
| Billing and tax records | 7 years, as required by law |
| Server and access logs | 12 months |
| Error and crash reports (Sentry) | 90 days |
| Support correspondence | 24 months after resolution |
| Marketing contacts | Until unsubscribe, then a suppression record only |
| User accounts | Until the account is deleted by a Customer administrator, or 30 days after the Customer’s subscription ends |
| Free trial data where no subscription follows | 30 days after the trial expires |
15. Do Not Track
Browsers send Do Not Track signals inconsistently and there is no accepted standard for honoring them, so we do not respond to DNT. We do honor Global Privacy Control as described in Section 6.1. We do not permit third parties to collect personal information about your activity across other websites through the SamplePal application.
16. Not a data broker
Kiwi Tech Lab is not a data broker. We collect personal information only through direct relationships with our Customers and their designated users, and we are not required to register under the California Delete Act, Texas Bus. & Com. Code § 509, Oregon HB 2052, or Vermont’s data broker statute.
17. State-specific notes
| Jurisdiction | Note |
|---|---|
| California | The CCPA/CPRA rights and disclosures above are the operative ones for most SamplePal records, since California uniquely covers business and employment contacts. Sections 4.1, 6.1, 6.3, 9, 11, and 13 are the CCPA notice at collection and annual disclosure. |
| Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, Washington | Access, correction, deletion, portability, opt-out, and appeal rights are provided as described in Section 11. We conduct no processing that requires a data protection assessment, as we neither sell data, target advertising, nor profile individuals. |
| Maryland | Maryland prohibits the sale of sensitive personal information outright and imposes strict data minimization. We collect no sensitive personal information and sell nothing. |
| Nevada | We do not sell covered information as defined by NRS 603A. |
| Illinois, Texas, Washington | See Section 4.4 on biometrics. |
| Oklahoma, Louisiana (Jan 1, 2027), Alabama (May 1, 2027), Vermont (Jan 1, 2028) | These laws are enacted but not yet effective. The rights in Section 11 already meet their requirements. We will update this policy if that changes. |
| European Union / EEA / UK | See our separate GDPR privacy policy. |
18. Changes
We will post any change here and update the “Last updated” date. For a material change such as a new category of data, a new purpose, a new recipient, or anything affecting Section 6.1, we will notify Customer account holders by email at least 30 days before it takes effect and will not apply it retroactively to information already collected without consent.
19. Contact
Questions, requests, or complaints about this policy or our privacy practices:
Email: support@samplepal.net
Address: Kiwi Tech Lab, LLC, 10361 NW 41st Ct., Coral Springs, FL 33065, United States
To exercise a right, use the subject line “Privacy Request.” To appeal a decision, use “Privacy Appeal.” California residents may also contact the California Privacy Protection Agency or the California Attorney General. Residents of other states may contact their state Attorney General.