How this pilot handles data.
Demo requests and accounts
Demo requests store your name, work email, business, requested plan and request time in Supabase for up to 90 days. The operator uses them to arrange access. Authentication is handled by Supabase using passwords or Google, when configured. A secure session cookie keeps approved members signed in for up to eight hours.
Organisation invitations
Invitations store the recipient’s email, assigned role, expiry, status and a hash of the invitation token. Only organisation owners can view pending invitations. Links expire after seven days; expired invitation records are removed after a further 30 days when scheduled cleanup runs. Membership remains until removed. A separate secure invitation cookie lasts up to one hour while you sign in.
Owners send links themselves using copy, share or an email draft. KnockVI does not send invitation emails. Your device’s email or sharing app handles messages you choose to send.
Business forms
Published pages collect the answers you choose to submit, booking or role selections and optional electronic signature receipts. The business responsible for the page should explain its purpose and contact details in that page’s privacy notice. Ask that business to access or delete your submission.
Responses expire after 30 days on Free and 12 months on Growth. Complete responses remain until deleted, within storage safeguards. Expired responses are hidden immediately and removed by scheduled cleanup after the operator enables it. Provider backups may have separate retention.
Website monitoring
Checks store configured public URLs, result summaries, timestamps and last-known passing results. Fetched HTML is processed temporarily and not saved as monitoring data. The checker never submits customer forms. Do not put private access links or customer details into monitored URLs.
Infrastructure and activity
The application uses Supabase and the operator’s hosting service, which may be Netlify or a standalone server. Google is used only when you choose its configured sign-in option. No advertising trackers are included. Security rate limits use keyed digests of identifiers. Authorised organisation owners and log managers choose 1–365 days for activity and check history. Defaults are 365 days for activity and 30 days for check history. Expired history is hidden immediately and removed by scheduled cleanup, which also limits each category to the latest 10,000 records per organisation. Current journey status and last-known passing timestamps remain operational state. Owners control access to historical logs. Hosting providers may retain operational logs under their own settings.
Operator information
This is pilot data information. Before opening public access, the operator must add their business identity, privacy contact, applicable terms and deployment-specific retention details. Until then, contact the person who invited you to the pilot.