Home / Privacy

Privacy

Last updated: August 17, 2026 · Effective the same day

Gonevertical LLC (“Gonevertical,” “we,” “us”), a Hawaii limited liability company doing business as Krest, operates www.getkrest.com (the “Site”). This notice is how we handle personal information on the Site.

The Site is a marketing site: product pages, a blog, a waitlist, and a contact form. There is no public Krest account, no checkout, and no customer app on this host. Product interface on the Site is illustrative.

English controls. Questions: sales@getkrest.com.

Who this covers

This Part A applies to visitors, waitlist submitters, and people who use the contact form. We are the controller of that Site data.

Joining the waitlist does not create a product account. When we invite you and you use Krest, Part B below also applies.

What we collect on this Site

You type it

Waitlist (/waitlist):

  • Work email (required)
  • Name, role, team size, company, product URL (optional)

Contact (/contact):

  • Name, work email, topic, message (required)
  • Role, company, product URL (optional)

A hidden honeypot field may be submitted. We use it only to drop spam. We do not market to it. The optional product URL is stored as the string you typed. Submitting the form does not make us crawl that URL.

Your browser and our host generate it

  • Firebase Hosting request data: IP address, user agent, path, referrer, timestamps
  • Google Tag Manager container GTM-K8QG6LCM on every public page. The container loads Google Analytics 4 (G-WG04GG8HX8). It does not load advertising or retargeting pixels today.
  • Google Fonts (Inter): your browser requests font files from Google
  • A copy of the last 50 form payloads in your browser’s localStorage key krest-leads, so a failed send can be recovered on your device

We do not collect payment cards, government IDs, precise GPS, biometrics, or phone numbers on this Site. There is no chat widget and no SMS path.

Why we use it

  • Reply to a message you sent
  • Run the waitlist and decide invite order (our discretion)
  • Email you about access and “your turn.” That is not a newsletter
  • Keep the Site up and reject spam
  • See which pages are used
  • Comply with law and defend claims

We do not sell personal information. We do not share it for cross-context behavioral advertising. If we ever add an ads tag to GTM, we will change this notice before that tag ships.

We may share Site data with professional advisors (for example a lawyer or accountant) who are bound to keep it confidential, and with a buyer or successor if Gonevertical LLC is sold, merged, or transfers assets. That successor must use the data only as this notice allows, or we will tell you if the rules change.

For a form you send, we use the information to take steps at your request. For hosting logs, spam rejection, and invite order, we rely on operating a B2B waitlist site. That is not a full GDPR lawful-bases table. If the EU or UK becomes a market we serve on purpose, we will write that table first.

We do not make automated decisions about you that produce legal or similarly significant effects.

Who we send it to

RecipientRoleWhat they see
Firebase Hosting (Google)Serves the SiteRequest logs
FormSubmit (formsubmit.co)Relays the formThe fields you submitted
Google WorkspaceMailbox for sales@getkrest.comThe relayed email
Google Tag Manager / GA4Tag load and page measurementPage URL, device, approximate location from IP
Google FontsTypefacesThe font request

We do not use Stripe, AWS, xAI, or Resend on this Site. Those names appear in Part B only because they are how the invited product is built, not because the public Site sends them your waitlist form.

Cookies and local storage

A cookie is a small file a site or an analytics vendor stores in your browser. GTM and GA4 may set cookies to recognize a later visit. krest-leads is local storage on your device, not a cookie. We do not run a cookie banner because we do not run advertising pixels. We do not honor a generic DNT header. We do not operate a “do not sell/share” link because we do not sell or share for ads today.

You can block or delete cookies and site data in your browser. Blocking them may break nothing essential on this Site except measurement. How cookies work: allaboutcookies.org. How Google uses data from sites that load its tags: policies.google.com/technologies/partner-sites. To opt out of GA4 in this browser: Google Analytics opt-out.

Email

Mail comes from sales@getkrest.com. If you submitted waitlist, we may email you about access. If you submitted contact, we may reply to that thread. If you do both, we may connect those two records. We do not buy lists for this Site. Submitting a form is not consent to SMS.

How long we keep it

  • Waitlist: until you ask us to delete it, or 24 months after we close the waitlist
  • Contact threads: 24 months, unless a longer legal hold applies
  • Hosting logs: the host’s default
  • Analytics: the GA4 property default (two months of event-level data unless we change it)
  • localStorage: until you clear it; we only write the last 50 payloads on that browser

Your choices

Email sales@getkrest.com from the same address you used on the form to ask us to access, correct, delete, or export what we have. We will verify by that address. We aim to finish within 45 days. There is no self-serve portal. An authorized agent may write on your behalf; we may still verify you. We will not deny you the Site because you asked. We may keep what the law requires.

California residents: the categories we collect are identifiers (name, email, company) and internet activity (pages, logs). We do not sell them. We do not collect sensitive personal information on this Site by design. Shine-the-Light requests go to the same address.

When we may disclose

We may disclose Site data if we reasonably believe we must:

  • Satisfy a law, regulation, subpoena, or enforceable government request
  • Investigate a breach of these terms or of the Privacy notice
  • Detect or respond to fraud, spam, or a security incident
  • Protect the rights, property, or safety of Gonevertical, a visitor, or the public

We will try to tell you first when the law lets us. We cannot promise notice when we are forbidden to give it.

Security

The Site is served over HTTPS on Firebase Hosting. Forms use a honeypot, not a CAPTCHA. Access to the sales inbox is limited to people who need it. The internet is not a sealed pipe: FormSubmit and email can be intercepted. We do not claim SOC 2, ISO 27001, or “bank-grade” encryption at FormSubmit or in the mailbox. If a breach of Site data requires notice, we will give it.

Children

The Site is for people 18 or older acting for a business. It is not directed at children. We do not knowingly collect information from anyone under 13. If we learn we did, we will delete it.

Public pages and archives

Search engines and similar services may copy public pages (this notice, the blog, product copy). We do not control those copies. Removing something from the Site does not remove it from a third-party cache.

People outside the United States

The Site is operated from the United States. FormSubmit, Google, and Firebase process data in the U.S. If you visit from elsewhere, you are sending information to the U.S. This is not a full GDPR program. If the EU or UK becomes a market we serve on purpose, we will expand this section first.

Changes

We will change the date at the top. If we change how we use waitlist or contact addresses in a material way, we will also email the address we have. Continued use of the Site after the new date is acceptance of the new notice.

Part B. The Krest product. Not generally available. This part applies only after we invite you and you use the product (the operator app, the live API, and the embed on your pages). Joining the waitlist is not an account and is not consent to run Krest on your users.

When you use the invited product

You (the customer) own your workspace content and your end users’ data. You are the controller of that end-user data. Gonevertical processes it to provide the product. We own the software. A data processing agreement is available on request and applies when we have executed one with you. This notice is not a signed DPA, is not standard contractual clauses, and is not legal advice.

If you put the Krest embed on your app, you must tell those people what you collect and why. Your notice, not this page, is the one they should see. We process that data only to provide Krest to you.

Models draft sequences, emails, and in-app guide answers. You publish. Drafts are not legal, privacy, or compliance advice for your product.

Who signs in

Operators sign in with Google on an allowlisted address. We store the operator’s Google account identifier and email so we can keep the workspace. There is no public self-serve signup.

What the product may store about people

Part A still does not collect phone numbers on this Site. The product (Part B) may store data you, the embed, or a signed inbound webhook send about a person, including:

  • Email
  • Name and handle
  • Phone, when an operator or an identify call enters one
  • Traits (including form answers mapped to traits)
  • Acquisition fields: campaign, source, medium, term, content, and an http(s) referral URL, when the embed or identify payload sends them
  • Events (page views, form submit, checklist and tour progress, custom track names we allow)
  • Checklist, tour, play, and email send history
  • Email consent and suppression state

Public identify cannot grant marketing consent. An operator sets marketing consent or suppression in the product. That write goes to the live person for staging and production embed keys. Missing person records are not mailed.

Do not upload data that is regulated as HIPAA protected health information, payment-card data under PCI-DSS, or other special-category data, unless we have a written agreement that covers that class. The invited product is not built or contracted for that use today.

Embed, keys, and environments

One workspace can have staging and production embed keys. The embed key is a customer-controlled public token. Anyone who has it can identify and track against that key. The publish key is a secret. We store a hash of it. The raw publish key is shown once at create or rotate. You protect both.

Live people and events are stored per embed key. We do not join people across keys. Operator workspace people and events live in your workspace. Published snapshots power the embed.

Guide chat

In-app guide chat is off unless you turn guideChatEnabled on and republish. When it is on, a person on your page may send a question. We send a redacted prompt (your published documentation layer, published articles, the question, and untrusted page title as data, not instructions) to xAI and return a draft answer plus article ids that exist in your snapshot. Guide chat cannot send email or publish experiences. Production callers are denied unless we have allowlisted that origin. Default is localhost only.

Webhooks you configure

Live inbound webhooks require HMAC, a timestamp, and a nonce before any write. The only mutating action today is identify_user. Invalid or missing signatures are rejected. HubSpot and Salesforce buttons in Settings are local simulations. They do not call those vendors. If you add destination URLs, we may POST a portable person record, signed with your HMAC secret, when identify or form submit happens. Those destinations are processors you chose, not Gonevertical subprocessors.

Product infrastructure we actually use in the private app (not on this Site):

  • Google Firebase: Auth, Firestore, Functions, hosting of closed app targets, in us-central1
  • xAI: Grok drafts for operators, and guide-chat answers when you enable that flag, from redacted prompts
  • Resend: email you choose to send, when live email is enabled

There is no SMS channel. There is no public payment on this Site, and we do not collect cards here. Product fees will be described when they exist.

Email you send through Krest

You are responsible for your own marketing lists, for collecting consent, and for not sending without it. When live marketing email is sent through Krest and the unsubscribe secret is configured, we add List-Unsubscribe and List-Unsubscribe-Post headers. The link uses an HMAC token, not the raw email address. That helper does not replace your duty to have a lawful basis. Transactional one-offs still honor suppression. We do not claim a message was delivered unless Resend returns a provider id.

Access, export, and erase (DSR)

There is no public self-serve portal. End users of your product should send requests to you. In the product, an invited operator can export a person from User detail. That export includes the workspace User record and the live person and events for both the staging and production embed keys. The same screen can erase that person in both environments. Erase requires the publish key. If live erase cannot run, we keep the local record. If you cannot reach the product, write sales@getkrest.com. We may still ask you to verify the request. Ask us to export or delete a workspace before access ends. After we end private access we may delete that workspace. We will try to give you a chance to export first.

How long product data is kept

  • Workspace content and people: until you erase them, or until we delete the workspace after access ends
  • Live events: recent events are capped per person; we may delete older events
  • Audit records of send and publish: kept for security and legal holds. We do not treat them as a mailbox of full email bodies

Contact

Gonevertical LLC · Krest
sales@getkrest.com · Contact form · Terms