Tag Introduction

What is required to activate Kahoona’s tag on the website?

  1. Provide staging access and purchase flow instructions (to access order confirmation page).
  2. Implement Kahoona’s custom tag (using Tag manager / add to HTML head)
  3. Make sure *.kahoona.io is allowed in the website’s CSP (content security policy)

What does Kahoona tag track?

Our tag collects general information about the website and device, user behavior from your site’s pages and other in-page interaction events. The tags batches the events and sends them using asynchronous non-blocking POST requests to our servers at khn-ecom.kahoona.io.

How does the tag track all the user actions?

We develop a custom script to each of our customers. It will have dedicated collection mechanism to your website’s stack and layout.

In order to finalize the customization of the script we require access to staging environment purchase flow testing instructions.

Privacy and compliance

image.png

image.png

image.png

Our Data Protection, InfoSec, and AI White Paper is available upon request to [email protected]

Kahoona is CCPA and GDPR compliant, and SOC2 Type II certified.

We are a data processor

Kahoona is a data processor under privacy laws. We employ substantial efforts to keep data protection by design (DPbD) in mind throughout all stages of the solution’s life cycle.

We process personal data as part of the larger shopping processes conducted by our customers, and while we do determine some technical aspects related to the processing, we only process personal data in accordance with our customers’ instructions, as manifested under our commercial and data processing agreement with our customers. Accordingly, in this respect we act as the data processor, processing personal data on behalf of our customers who assume the position of data controllers. As such, we have implemented various measures and controls meant to support our customers’ compliance efforts with laws and regulations governing the protection of privacy and personal data (privacy laws).

We do not collect any direct identifiers

We do not process direct identifiers, such as names, government issued IDs, SSNs, account credentials, telephone numbers, and raw email addresses. Email addresses of your registered users are hashed on the client side before collection and are not stored or processed in a raw form.