Website privacy policy
This policy explains what the IncidentKit website collects, why, who we share it with, and how to control it.
1. Scope
This policy applies to the public marketing website at incidentkit.ai (the “Website”), operated by IncidentKit (“IncidentKit,” “we,” “us”).
It does not apply to the IncidentKit application at app.incidentkit.ai, which is governed by separate application terms and privacy documentation.
2. Information we collect
Information you provide. When you request a demo, book a time, contact us, subscribe, download a template or apply to partner, we collect your name, work email, organization, role, number of sites, the type of site, and any message you choose to write.
Information collected automatically. Technical data (IP address, browser, device, language), usage data (pages viewed, referrer, clicks, time on page), approximate location from IP address at city or region level, and, if you accept analytics cookies, identifiers set by the analytics and advertising tools described below.
Campaign attribution. If you arrive from an ad, email or search link, we store the campaign parameters (for example UTM tags and click IDs) in your browser so we can connect a request to the campaign that led to it. This is stored only if you have not declined cookies.
3. How we use information
- To respond to requests, schedule demos and send the resources you ask for.
- To send the monthly email and product updates if you opt in. You can unsubscribe at any time.
- To understand how the Website is used and to improve content, performance and campaigns.
- To measure which marketing channels lead to demo requests, including searches and referrals from AI assistants.
- To keep the Website secure and prevent abuse, including bot traffic.
- To comply with legal obligations.
4. Tools we use and when they run
We use a small set of vendors to run the Website. Analytics and advertising tools run only after you accept cookies. Declining keeps only what the Website needs to work, and we honor the Global Privacy Control signal as a decline.
| Purpose | Vendor | What it does |
|---|---|---|
| Hosting and performance | Vercel | Serves the Website. Speed measurement is aggregated and cookieless. |
| Product analytics | PostHog | Page views, clicks on marked buttons, heatmaps and masked session replay. Text typed into forms is masked. Before consent, PostHog runs without cookies. |
| Web analytics | Google Analytics | Page views and conversions. Loaded only after you accept. Google signals and ad personalization are turned off. |
| Advertising measurement | Google Ads, LinkedIn Insight Tag | Measure whether ads lead to demo requests. No remarketing audiences are built from this Website. |
| Forms and email | Loops | Stores your contact details and sends the emails you request. |
| Scheduling | Cal.com | Shows our calendar and records the booking you make. |
| Bot protection | Cloudflare Turnstile (when enabled) | Verifies that a form is submitted by a person. |
6. No patient or health information on this Website
The Website is a public marketing site. It is not designed to receive, process, store or transmit protected health information, patient data, incident reports or clinical documentation.
Do not enter patient names, medical records or other sensitive healthcare information in any form on this Website. If you believe you submitted such information by mistake, email privacy@incidentkit.ai right away so we can remove it.
7. Retention
- Demo requests and contact submissions are kept for the length of the business relationship and a reasonable period after to support follow-up and records.
- Email preferences are kept until you unsubscribe or ask for deletion, after which we keep the minimum needed to honor your opt-out.
- Analytics data is kept according to each provider's retention settings that we configure, and in aggregate form after that.
- Server logs with IP addresses are kept for up to 90 days for security and debugging.
8. Your rights and choices
Depending on where you live you may have the right to access, correct, delete or port your personal information, to object to or restrict some processing, to withdraw consent, and to opt out of marketing.
To exercise a right, email privacy@incidentkit.ai. You can change your cookie choice at any time with “Cookie settings” in the footer. California residents have additional rights under the CCPA; we do not sell personal information as that law defines it.
9. Children
The Website is not directed to children under 13 and we do not knowingly collect their personal information.
10. International visitors
The Website is operated from the United States. If you visit from elsewhere, your information may be transferred to and processed in the United States.
11. Security
We use HTTPS for all traffic, limit access to administrative systems and monitor for threats. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Third-party links
The Website links to other sites that we do not own or control. We are not responsible for their privacy practices.
13. Changes
We may update this policy as our practices, technology or the law change. When changes are material we will update the date on this page.
14. Contact
Privacy questions and requests: privacy@incidentkit.ai. General inquiries: support@incidentkit.ai.
This page describes the marketing website. For the product, see the security overview and the HIPAA page.