LEGAL & COMPLIANCE

Privacy policy and telemetry standards.

At Koba HQ, we treat privacy and data isolation as fundamental engineering requirements. This document details how we handle information across our public marketing website, our high-throughput redirection infrastructure, and our client software platforms.

EFFECTIVE DATE
October 10, 2026
REDIRECTION TELEMETRY
Zero retail customer PII captured
DATA ISOLATION
Strict multi-tenant partitioning
DATA SHARING
Never sold or shared with ad brokers

Technical data protection commitments.

Scope and overview.

This privacy policy governs data practices across Koba HQ ("Koba", "we", "our", or "us"), encompassing:

  • Marketing Website: Our public informational site at kobahq.com.
  • Direct Communications: Inquiries submitted via email to hello@kobahq.com.
  • Redirection Infrastructure: Our dynamic HTTP routing endpoints accessible via https://app.kobahq.com/r/{code}.
  • Client Platforms: The Koba Command telemetry dashboard and custom software modules at app.kobahq.com.

We are committed to operating lean, secure, and privacy-preserving systems that collect only the technical telemetry strictly required to deliver fast, dependable service.

Marketing website visitors and communications.

When you browse kobahq.com, our servers deliver pre-rendered, lightweight static pages. We do not load third-party advertising cookies, behavioral tracking pixels, or invasive surveillance scripts. Standard web server logs may temporarily record connection details (such as requesting IP address and requested path) solely to maintain security, mitigate denial-of-service threats, and diagnose server errors.

When you send an inquiry to hello@kobahq.com, we retain your email address, message body, and supplied contact information exclusively to review your request, respond to your inquiry, and fulfill requested engineering or hardware support. We do not subscribe your contact information to automated third-party marketing lists.

Redirector infrastructure and tap telemetry.

Our physical Koba Tap cards contain NTAG213 chips encoded with unique redirect URLs pointing to our dynamic redirection service. When a retail customer taps a card with their smartphone, our servers process an ephemeral HTTP 302 redirection to send the user directly to the business's official Google review destination.

We engineered this redirection architecture with strict privacy guarantees:

  • Zero Retail Customer PII: Koba does not collect, capture, or store the personal identity, name, phone number, Google account credentials, or payment details of the retail customer tapping the card.
  • Ephemeral Processing: Redirections resolve immediately without presenting intermediate tracking interstitials or requiring app downloads.
  • Aggregated Operational Telemetry: To calculate tap volume in Koba Command and detect hardware issues, our workers record non-blocking operational data: timestamp of the tap event, general user-agent family (to verify mobile browser compatibility), and coarse network origin. This telemetry is decoupled from individual consumer identities.

Command Center and business data isolation.

For merchants utilizing Koba Command or our custom business software, account information is stored in secure, multi-tenant partitioned databases. We access your Google Business Profile data strictly via official Google APIs following explicit merchant authorization, solely to synchronize publicly posted reviews, compute review velocity, and assist in drafting public responses.

Merchant account credentials, private operational workflows, customer intake records, and business metrics are never sold, rented, monetized, or shared with third-party advertising networks or data aggregators. Your operational records belong entirely to your business.

Data security, retention, and your rights.

All data transmitted across our infrastructure is encrypted in transit using modern Transport Layer Security (TLS 1.3) protocols. Data stored within our production databases is protected with encryption at rest, stringent firewall policies, and strict access controls restricted to authorized engineering personnel.

We retain operational telemetry and merchant account records only for as long as necessary to fulfill active business engagements, maintain historical analytics for account owners, and comply with legal requirements. Verified account holders may request a copy of their stored operational records or request complete deletion of their account data at any time by contacting hello@kobahq.com.

Frequently asked questions.

Does tapping a Koba Tap NFC card collect personal data from customers?

No. When a customer taps a Koba Tap card, their device resolves our dynamic redirect route and opens their official Google review form. Koba does not capture, request, or store customer names, phone numbers, payment details, or personal identity.

Does Koba sell or share client business data with third parties?

No. We do not sell, rent, monetize, or share merchant account data, telemetry counts, or customer inquiries with data brokers, ad networks, or external marketing entities under any circumstances.

How does Koba access and handle Google Business Profile data?

When an authorized business connects their Google Business Profile to Koba Command, our systems access review text and ratings solely to calculate performance telemetry and generate response drafts for the business owner.

How can a business owner request data export or deletion?

Account holders can submit a data export or deletion request at any time by contacting our engineering team at hello@kobahq.com. We process and confirm verified requests in accordance with applicable privacy regulations.

Have questions about our privacy practices?

If you have questions regarding data security, compliance standards, or our redirection infrastructure, contact our engineering team directly.