Privacy Policy

Last updated August 31, 2026

This Privacy Policy explains how Kinney Health Compliance (“Kinney Health,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with https://kinneyhealth.com, the Cafeteria Plan Generator (“CPG”), and related support and compliance services (collectively, the “Services”). Kinney Health Compliance is located in Minnesota at 15141 Cherry Ln, Burnsville, MN 55306.

1. Scope and Our Business-to-Business Role

The Services are offered to employers and their authorized representatives for business purposes. They are not intended for employees to submit personal benefit information or for consumer use. This Policy applies to personal information about website visitors, customer representatives, authorized account users, prospective customers, and other people who communicate with us.

When Kinney Health determines the purposes of processing

Kinney Health generally acts as the business or controller that determines why and how personal information is processed when we handle website and analytics data, account and authentication data, billing and subscription records, direct communications, security data, and our own business records.

When Kinney Health processes information for an employer

Customers control the organization and plan-design information they enter into CPG. To the extent that this customer-supplied plan data contains personal information, Kinney Health generally processes it to provide the Services on the customer’s instructions and acts as a processor or service provider for the employer or other customer. The customer remains responsible for its own privacy notices, instructions, authority to provide information, and responses to requests concerning customer-controlled data. If you submit a request concerning information controlled by a customer, we may direct you to that customer or assist the customer as required by law or contract.

CPG is not intended for employee-level sensitive information

CPG is designed to use organization-level business and cafeteria-plan information. Do not submit employee personal records, Social Security numbers, protected health information, medical or claims information, individual benefit elections, biometric information, government identification numbers, full payment credentials outside an authorized Stripe payment interface, or other unnecessary sensitive personal information through CPG, contact forms, support channels, or the optional AI assistant. If we learn that prohibited information was submitted, we may restrict access, delete it, or take other reasonable action, subject to applicable legal, security, evidentiary, contractual, public-records, and backup requirements.

2. Personal Information We Collect

The information we collect depends on how a person interacts with the Services. We may collect the following categories:

  • Contact and account information. Name, business email address, business telephone number, mailing or billing address, username, authentication credentials, account settings, and identifiers assigned to an account.

  • Professional and customer information. Employer or organization name, job title, role, authorized-user relationship, and customer-administration information.

  • Organization and plan information. Employer business details, plan-design selections, effective dates, document settings, generated documents, versions, amendments, restatements, and related service records. CPG is not designed to collect employee-level data.

  • Commercial and transaction information. Products and subscriptions purchased, plan credits, invoices, transaction identifiers, Stripe customer identifiers, subscription and payment status, limited payment-method details supplied by Stripe, refunds, failed payments, disputes, and reversals.

  • Communications and support information. Inquiries, support requests, feedback, correspondence, and any information a person chooses to include in those communications.

  • AI assistant information. Prompts, conversation content, generated responses, and technical information associated with use of the optional AI assistant.

  • Internet, device, and usage information. IP address, browser type and settings, device type, operating system, referring pages, pages and files viewed, features used, dates and times of activity, session information, cookie identifiers, approximate location inferred from an IP address, and diagnostic, performance, and error information.

  • Security and audit information. Login events, authentication and access records, document activity and version history, suspected abuse or fraud indicators, and records created to secure, troubleshoot, and administer the Services.

We collect information directly from users and customer account administrators, automatically from browsers and devices, and from service providers involved in a transaction or service interaction, such as Stripe returning payment status to us. A customer may also provide a business contact’s information when establishing or administering authorized access.

3. Information Collected Automatically

When a person visits or uses the Services, our systems and service providers may automatically collect internet, device, usage, cookie, diagnostic, and security information. We use this information to deliver pages and account sessions, remember settings, authenticate users, prevent abuse, diagnose errors, understand use of the Services, and improve performance. An IP address may indicate a general area, but the Services are not designed to collect precise device location.

Some automatic collection uses cookies or similar technologies. Browser controls may allow a user to block or delete cookies, but blocking cookies required for authentication, security, payments, or core site functions may prevent parts of the Services from working.

4. Payments and Subscriptions

Stripe processes payment-card and bank-account credentials through its payment interfaces. Kinney Health does not receive or store full payment-card numbers, card security codes, or full bank-account credentials. Stripe may provide us with transaction identifiers, customer identifiers, payment and subscription status, billing details, limited payment-method information such as card brand and last digits, and information about refunds, failures, disputes, or reversals. Stripe processes payment information under its applicable terms and privacy practices. Stripe’s privacy policy is available at https://stripe.com/privacy.

Annual subscriptions purchased online are set to renew automatically unless canceled in accordance with the applicable subscription terms. Arrangements billed separately by invoice do not automatically renew unless the invoice, order, or other written arrangement states otherwise. We use and retain the related billing, entitlement, renewal, cancellation, accounting, and transaction records as described in this Policy.

5. How We Use Personal Information

We may use personal information to:

  • create, authenticate, secure, and administer accounts and authorized users;

  • configure cafeteria plans and generate, preview, store, update, version, and deliver requested documents;

  • provide subscriptions, plan credits, purchased access, customer support, corrections, amendments, restatements, and available compliance updates;

  • process transactions and administer invoices, renewals, cancellations, payment status, refunds, failures, disputes, and reversals;

  • send service, account, transaction, security, and policy communications;

  • respond to inquiries and troubleshoot technical or document-generation issues;

  • maintain document history, audit records, customer records, and service continuity;

  • protect the Services, users, and customers; authenticate activity; detect or prevent fraud, abuse, and security incidents; and enforce applicable agreements;

  • measure and understand website and product use, maintain functionality, and improve the Services;

  • operate the optional AI assistant when a user chooses to use it;

  • comply with legal, tax, accounting, audit, records-management, and regulatory obligations; respond to lawful process; and establish, exercise, or defend legal claims; and

  • support a merger, financing, reorganization, sale of assets, or similar business transaction, subject to appropriate confidentiality and legal requirements.

6. How We Disclose Personal Information

We disclose personal information only as reasonably necessary for the purposes described in this Policy, as directed by a customer for customer-controlled data, or as permitted or required by law. Recipients may include:

  • Automattic and WordPress.com provide managed website hosting, storage, security, backups, performance services, and website operations. Related Automattic services may include Jetpack for security, backups, performance, and site statistics, and Akismet where spam filtering is applied. These services may process account, content, communication, log, device, security, and usage information as needed to provide their functions. See Automattic’s Privacy Notice.

  • WP Media and RocketCDN provide caching, content delivery, and website-performance services. They may process IP addresses, request information, device or browser information, and requested asset URLs needed to deliver cached website files. We do not intentionally send CPG plan inputs to RocketCDN. See the WP Rocket Privacy Policy.

  • Stripe processes online payments and returns transaction, customer, subscription, payment-status, and limited payment-method information to us. See Stripe’s Privacy Policy.

  • GoDaddy provides business email hosting and SMTP services used to send, receive, and store operational email. It may process email addresses, message content, attachments, delivery information, and related account or security data. See GoDaddy’s Privacy Policy.

  • Anthropic provides the Claude model used to generate responses when a user chooses to use the optional AI assistant. See Anthropic’s Privacy Policy.

  • OpenAI provides the vector knowledge base used to store, index, and search KHC reference materials for the optional AI assistant. See OpenAI’s Privacy Policy.

  • Professional advisers such as attorneys, accountants, auditors, or insurers when reasonably necessary;

  • Government authorities or other parties when disclosure is required by law or legal process, or reasonably necessary to protect rights, safety, and security; and

  • Transaction participants and successors in connection with a proposed or completed merger, financing, reorganization, sale, or transfer of all or part of the business.

Service providers are permitted to access information only to perform services for us or as otherwise allowed by their agreements and applicable law. Operational disclosures to service providers are different from selling personal information or sharing it for cross-context behavioral or targeted advertising.

7. Optional AI Assistant

The optional chat assistant is provided through the AI Puffer WordPress plugin on designated CPG pages. The core document-generation service can be used without submitting information to the assistant. When a user chooses to use it, Anthropic’s Claude service processes the prompt, relevant conversation context, and retrieved reference material to generate the main chat response. An OpenAI vector knowledge base stores and indexes KHC reference materials and processes query content or search terms as needed to retrieve information relevant to the question. The retrieved information may then be included in the context sent to Claude. AI Puffer coordinates these functions through the website.

The shared vector knowledge base contains KHC reference and training materials and is not intended to contain customer-specific plan records. Depending on the configured chat-history and logging settings, prompts, responses, and related technical records may also be stored in our WordPress.com-hosted website environment and processed by the applicable AI provider under its API terms and settings.

Do not enter employee personal information, protected health information, medical or claims data, Social Security numbers, individual benefit elections, confidential payment credentials, or other sensitive personal information into the AI assistant. AI prompts and responses may be inaccurate and should not be used to make decisions about an individual.

8. Analytics, Cookies, and Privacy Choices

We use cookies and similar technologies that support essential functions such as page delivery, account sessions, authentication, security, preferences, payment workflows, diagnostics, and first-party source attribution. WordPress.com and Jetpack may also provide site statistics and performance information as part of the hosted website service. These technologies may process an IP address, cookie or device identifiers, browser and device information, referring information, and interactions with pages or features.

The MonsterInsights plugin is installed, but it is not currently configured with Google Analytics and does not currently add a MonsterInsights Google Analytics tracking code to the Services. We do not use analytics data for targeted advertising. If we later enable Google Analytics or another materially different analytics service, we will update our disclosures and cookie controls as appropriate. Additional information about cookies and available controls is in our Cookie Policy.

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising or process it for targeted advertising. We also do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects. Because we do not engage in those activities, an opt-out of sale, targeted-advertising sharing, or such profiling should not be necessary. We will process legally recognized opt-out preference signals where applicable law requires us to do so.

9. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, to follow a customer’s lawful instructions, or to satisfy legal, contractual, accounting, security, dispute-resolution, and records-management needs. We use the following criteria rather than a single retention period:

  • Account, contact, and professional information is generally kept while the account or customer relationship is active and afterward as reasonably necessary for account closure, communications, contracts, security, fraud prevention, disputes, audits, and legal records.

  • Organization, plan, document, version, and audit information is generally kept while needed to provide purchased services, preserve requested document history and continuity, follow customer instructions, and meet contractual, evidentiary, audit, public-records, and legal requirements.

  • Commercial, invoice, subscription, and transaction information is kept as reasonably necessary to administer purchases, access, renewals, cancellations, refunds, disputes, reversals, taxes, accounting, audits, contracts, and other business records. Full payment credentials are retained by Stripe under its practices, not by Kinney Health.

  • Communications and support records are kept based on the nature of the request and as needed for follow-up, service history, quality assurance, disputes, security, and legal records.

  • AI prompts and responses are retained according to the feature configuration, operational needs, customer instructions where applicable, and the practices and contractual settings of the AI provider used for the interaction.

  • Cookie, analytics, log, diagnostic, and security information is kept according to operational, analytics, troubleshooting, fraud-prevention, and security needs and the retention settings of the relevant hosting, analytics, and security systems.

When information is no longer required, we take reasonable steps to delete, deidentify, or otherwise dispose of it. Information may remain for a limited additional time in backups, archives, or systems where immediate deletion is not reasonably feasible, and it may be retained longer if required by law, legal hold, public-records obligation, or an active dispute.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information in light of the nature of the information and the Services. These measures are intended to reduce risks such as unauthorized access, loss, misuse, alteration, or disclosure. No internet transmission, service, or storage system is completely secure, and we cannot guarantee absolute security. Users are responsible for protecting their credentials, using secure devices and networks, limiting authorized access, and promptly notifying us of suspected unauthorized account activity.

11. Adults Only

The Services are intended only for users who are at least 18 years old. People under 18 may not register for or use the Services. We do not knowingly collect personal information from users under 18. If we learn that a person under 18 has provided personal information through the Services, we will take reasonable steps to remove it and deactivate any associated account, subject to applicable law and necessary security or records requirements. Concerns may be reported to info@kinneyhealth.com.

12. United States Privacy Rights

Depending on a person’s state of residence, the nature of the relationship, and whether a particular privacy law applies to Kinney Health or the information, the person may have rights to:

  • confirm whether we process personal information about the person;

  • access or obtain a copy of personal information;

  • correct inaccurate personal information;

  • delete personal information;

  • obtain personal information in a portable format;

  • obtain information about categories of personal information, sources, purposes, and recipients, or a list of specific third parties where required by law;

  • opt out of sale, targeted advertising, or qualifying profiling, if those activities occur; and

  • receive equal service and not be unlawfully discriminated against for exercising a privacy right.

These rights are not absolute. Business-to-business, employment-context, public-sector, legal-compliance, security, privileged, deidentified, and other exemptions may apply. We may retain information that applicable law permits or requires us to keep. Kinney Health does not currently sell personal information, share it for targeted advertising, or conduct qualifying profiling as described above.

Submitting a request

To submit a privacy request, email info@kinneyhealth.com, call (+1) 612-735-7705, use our contact page, or write to the address in the Contact section. Please describe the request and the relationship with Kinney Health. We may ask for information reasonably necessary to verify identity, authority, and the scope of the request. We use verification information only for verification, security, fraud prevention, and request administration.

An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may need to verify the requester directly. If the requested information is controlled by an employer or other customer, we may refer the request to that customer and assist as required.

Appeals

If we deny a request and applicable law provides a right to appeal, the requester may appeal by emailing info@kinneyhealth.com with the subject “Privacy Appeal” and explaining the basis for the appeal. We will review and respond as required by applicable law. If an appeal is denied, the requester may have the right to contact the appropriate state attorney general or privacy regulator.

13. Public-Entity Customers and Public Records

Government and other public-entity customers may be subject to public-records, freedom-of-information, open-meetings, data-practices, records-retention, procurement, audit, or similar laws. Those obligations may require the public entity or Kinney Health to preserve or disclose information despite a deletion request or a different contractual preference. Nothing in this Policy is intended to override a lawful public-records duty, records schedule, legal hold, governmental immunity, statutory limitation, or controlling signed procurement or data-protection addendum. Requests for records held by a public-entity customer may need to be directed to that entity.

14. Changes to This Policy

We may update this Policy to reflect changes in the Services, vendors, data practices, or legal requirements. We will post the revised Policy with a new last-updated date. If changes are material, we may also provide notice through the Services, by email, or by another reasonable method. The version posted when information is processed will govern unless applicable law requires otherwise.

15. Contact Us

Questions, concerns, and privacy requests may be directed to:

Kinney Health Compliance

15141 Cherry Ln

Burnsville, MN 55306

United States

Email: info@kinneyhealth.com

Phone: (+1) 612-735-7705

Website: https://kinneyhealth.com