Privacy policy
Kuumba is designed to help readers receive physical books while keeping private account, payment, safety, and delivery information out of public view.
Before the pilot expandsThis policy describes the limited United States pilot operated by Kuumba LLC. For privacy questions, contact support@kuumba.app.
Information you provide
Account information includes your email address, password credential, display name, username, profile photo, profile banner, general location, biography, website address, and privacy choices. Your email address and password are not displayed on your public profile.
Product information may include books on your private shelf, reading progress, bookmarks, book requests, request stories, posts, comments, likes, follows, shares, reports, blocks, notification choices, and messages sent to support.
For named-reader requests, Kuumba collects private delivery details before funding to verify the delivered price. With your explicit consent, Kuumba sends only the street address, city, state, postal code, and country to Shopify to calculate shipping and tax and to refresh that calculation. The calculation itself does not create an order or payment. Community-first campaigns, including new future-reader copies funded with disclosed delivery allowances, collect delivery details only after a successful funded claim. Saving a claimed copy’s address with explicit delivery consent may trigger the separately verified funded order; the reader is not charged.
Public and private information
Public profiles and campaigns may show the display name, username, reader-approved general location, profile photo, profile banner, biography, website link, requested book, request story, and public community activity. Public material can be viewed, indexed, copied, or shared by other people outside Kuumba.
Street addresses, private email addresses, password credentials, full payment-card details, shelf titles and reading progress, bookmarks, safety reports, staff notes, and nonpublic payment records are not shown to funders or other readers. Public profiles may show aggregate shelf and request counts without showing the private shelf titles.
Community-first campaigns show the book, goal, and funding status without a named recipient, general location, or request story. If a reader later claims the funded book, their identity as claimant and their delivery information remain private, although the campaign may show the book’s general fulfillment stage.
Payments and fraud prevention
Stripe hosts checkout and processes payment credentials, fraud checks, receipts, disputes, and refunds. Kuumba does not receive or store full card numbers. Kuumba stores the campaign, contribution amount, Stripe references, payment state, refund state, and optional supporter name needed to operate and reconcile the contribution.
To protect accounts and campaigns, Kuumba may create pseudonymous one-way identifiers derived from account, connection, and device signals, record sign-in and registration attempts, and retain security, audit, moderation, contribution, and payment-event records. Registration-abuse identifiers are short-lived; a contribution identifier may remain with the payment record for reconciliation and fraud prevention. These identifiers are not used for advertising.
Sessions, service measurement, and notifications
Kuumba uses a secure, HttpOnly session cookie to keep you signed in for up to 30 days. It is used for authentication, not advertising. You can end the session by signing out.
Kuumba measures product health and impact from its own operational records, such as requests, contributions, fulfillment stages, shelves, and conversations. Kuumba does not use third-party advertising pixels or sell behavioral profiles. If aggregate page-view measurement is added later, this policy will be updated before that collection begins.
Kuumba stores in-app notifications and your email-notification preference. Transactional email is sent only when the sending service is configured and the message is relevant to your account, request, contribution, delivery, or safety activity.
Delivery information
For an eligible fully funded request, Kuumba automatically sends the recipient name and delivery address to Shopify to place the paid book order. Emersoft and Ingram receive the delivery details needed to fulfill it. The reader is not charged again. Reader-offered copies follow a separate reader-to-reader shipping process.
Private delivery addresses are encrypted at rest. Authorized staff may decrypt the current address only when fulfillment or documented support requires it, and Kuumba records staff access. Kuumba shares the minimum necessary address and contact details with the selected bookseller and delivery carrier so they can ship the book.
When you type into address or location suggestion fields, Kuumba sends that search text and the selected country to Geoapify. Kuumba does not send your account identity, recipient name, apartment field, or phone number with these searches. Suggestions are optional: you can turn off street suggestions or enter an address manually. Selecting a suggestion does not verify deliverability. Kuumba keeps short-lived pseudonymous quota records without the search text to protect the service.
If you choose to save an address for future deliveries, Kuumba offers it privately for your review and confirmation each time. Opening a saved address does not trigger an address-provider lookup.
For new Shopify-priced campaigns, the reader may edit the address before publication; changes invalidate the previous quote and approval. Once published, address changes require support to review the effect on shipping, tax, and any contributions. For earlier campaigns, the reader may edit the address until ordering begins. After ordering, corrections must go through support and may depend on the bookseller or carrier. Delivery information is never shown to campaign funders.
Service providers
Kuumba uses trusted service providers for hosting and storage, public book metadata, payment processing, transactional email when enabled, bookselling, and delivery. These may include Shopify, Emersoft, Ingram, Kuumba’s infrastructure providers, Google Books, Geoapify for address suggestions, Stripe, an email-delivery provider, the selected bookseller, and the delivery carrier. Each receives only the information reasonably needed for its role.
Retention and deletion
Account, shelf, and community records are generally kept while the account remains active. Delivery addresses are kept only as long as reasonably needed to complete delivery, handle a problem, and meet applicable recordkeeping duties. Payment, refund, accounting, fraud, safety, and audit records may be retained longer when required to reconcile transactions, meet law, resolve disputes, or protect the community.
You may request access, correction, account closure, or deletion of eligible information by emailing support@kuumba.app. Kuumba may verify the request through the account email. Closing an account can remove access and may delete or de-identify eligible content, but it cannot reverse completed payments or erase records that Kuumba must retain.
Children and safety
The current pilot is for people age 13 or older. A parent, guardian, school, or community organization should manage participation for a younger reader. Kuumba may preserve and disclose information when reasonably necessary to address apparent exploitation of a child, credible threats, fraud, unlawful conduct, or a valid legal request.
Your choices and questions
You can change profile visibility, location visibility, notification preferences, blocks, and shelf information from your account. Privacy requests and questions may be sent to support@kuumba.app with the subject “Privacy request.”
Kuumba does not sell personal information or share it for cross-context behavioral advertising. Material policy changes will be posted here with a new effective date and, when appropriate, an account notice.
Write to support@kuumba.app and we’ll help you find the right answer.
