HomeSign in

Privacy policy

What NockNock stores, why it is needed and the choices available to account holders and kiosk customers.

Last updated 13 August 2026

Who we are

NockNock is based in Houston, Texas. This policy explains how NockNock handles data for account holders, their businesses and customers who use a NockNock kiosk.

The short version

We store account details, the businesses an account manages, kiosk customer captures, message delivery records, opt-outs and public Google review-count readings. We use them to run the review-request service. We do not sell personal information, run advertising networks or place analytics trackers on NockNock.

What we store

Account. Email address, password hash and salt, account and subscription state, session information and the businesses attached to the account. We cannot read the original password.

Business. Name, address, Google place id, kiosk token, message template, sending settings and public rating and review-count readings over time.

Kiosk customer. First name if supplied, normalized mobile number, business, consent time and source, scheduled send time, delivery attempts and outcome. Successful sends retain the provider message id, encoding, segment count and estimated cost.

Opt-out. A hashed key derived from the normalized number, when the person opted out and how. The opt-out applies across businesses so another kiosk visit cannot silently subscribe the same person again.

Payment. Stripe handles card and billing details on its pages. NockNock stores only the customer, subscription and plan references needed to recognize payment.

Why and how customer numbers are used

The number is used to send the single review request described beside the kiosk field, to prevent duplicate requests, to process STOP and to maintain an auditable delivery record. It is not used for NockNock advertising and is not sold or shared between the businesses that use the service.

The account holder and business are responsible for placing the kiosk consent notice in front of the customer and using the service only where they have a lawful basis to send.

Processors

Render hosts NockNock and the persistent files used by the service in the United States.

Twilio receives the destination number, sender number and final message to send SMS, returns delivery information, and forwards inbound replies such as STOP. Carrier networks necessarily process messages for delivery.

Google Maps Platform receives business search terms or a Google place id so NockNock can locate the correct listing and read its public rating and review count. It does not receive kiosk customer names or numbers from NockNock.

Resend processes account email addresses and message contents when NockNock sends account email.

Stripe processes subscription payments and card information under its own privacy notice.

Cookies

NockNock uses one necessary signed session cookie to keep an account logged in. It is not used for advertising or cross-site tracking.

Retention and deletion

Business records, kiosk captures and delivery records remain while the business belongs to an active account, unless removed earlier. Deleting a business deletes its captures. Deleting the account deletes its businesses and captures. Opt-out records may be retained as needed to ensure the person is not contacted again.

Review-count history may include public business information. Password-reset and verification tokens expire automatically. Provider billing and legal records may remain where required by law or legitimate accounting and fraud-prevention needs.

Your choices and rights

A customer can reply STOP to any message. Depending on where you live, you may also have rights to access, correct, export, restrict or erase personal information. Account holders can request account deletion using the contact address shown on this site.

NockNock is not directed to children under 16. If you believe a child's information was entered, contact us so it can be removed.

Security and changes

Passwords are hashed, sessions are signed, kiosk tokens are random, customer numbers are masked in the dashboard, writes are atomic and Twilio webhooks are signature-checked. No system is perfectly secure. We will notify affected account holders when required if we discover a breach.

Material changes to this policy update the date above and will be communicated to the account email when reasonably possible.

Questions or requests?

Email hello@nocknock.org.