Legal
Privacy Policy
Effective May 2026
KAZ Automated Fire Effects ("KAZ", "we", "us", or "our") is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, how we use it, and your rights regarding that information.
By using kaztiki.com or submitting our contact form, you acknowledge this policy. If you are in the European Union, United Kingdom, Australia, or California, additional rights apply to you — see the relevant sections below.
1. Who We Are
KAZ Automated Fire Effects is a luxury fire systems company based in Kailua Kona, Hawaii, USA. We design, fabricate, and support automated tiki torches, fire bowls, fire pits, fire strips, and custom fire systems.
For privacy purposes, KAZ is the data controller for personal information collected through this website. To contact us regarding privacy matters: team@kaztiki.com
2. Data We Collect
Contact Form
When you submit our contact form, we collect:
- Full name
- Email address
- Phone number (optional)
- Customer type (homeowner, architect, builder, etc.)
- Project or property name (optional)
- Project description / message
- Torch configuration details (if arriving from the product configurator)
We do not collect payment information through this website. No credit card or financial data is processed here.
Analytics Data (with your consent)
If you accept cookies, we collect anonymized usage data via Google Analytics 4, including:
- Pages visited and time spent
- General geographic location (country/region — not precise location)
- Device type, browser, and operating system
- Referring website or search terms
- Anonymized IP address
This data is only collected if you explicitly accept cookies.
Automatically Collected Technical Data
Our hosting provider (Vercel) may collect standard server logs including IP addresses and request timestamps for security and performance purposes. This is strictly necessary for the site to function and is not used for marketing.
3. How We Use Your Information
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Contact form data | Responding to your inquiry, preparing quotes, coordinating your project | Legitimate interest / pre-contractual steps |
| Email address | Sending a confirmation email and follow-up communications about your project | Legitimate interest / pre-contractual steps |
| Analytics data | Understanding how visitors use the site to improve content and performance | Consent |
| Server logs | Security, abuse prevention, site reliability | Legitimate interest |
We do not use your information for automated decision-making or profiling. We do not send marketing emails unless you explicitly request them. We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
5. Third-Party Services
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Database | Supabase (hosted on AWS) | Storing contact form submissions | Contact form fields |
| Email delivery | Resend | Sending confirmation and notification emails | Name, email address |
| Hosting | Vercel | Website hosting and serverless functions | Standard server logs |
| Analytics | Google Analytics (Google LLC) | Anonymous usage analytics (consent-gated) | Anonymized usage data |
All third-party providers are contractually required to protect your data and may only use it for the services they provide to us.
6. Data Retention
- Contact form submissions — retained for as long as necessary to manage your project and fulfill our legitimate business purposes, typically up to 3 years. You may request deletion at any time.
- Email communications — retained in our business email system for up to 3 years.
- Google Analytics data — retained for 14 months per Google's default settings, then automatically deleted.
- Server logs — retained by Vercel for up to 30 days for security and operational purposes.
7. Your Rights
Depending on your location, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — request that we limit how we use your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — withdraw cookie consent at any time via the footer link
To exercise any of these rights, contact us at team@kaztiki.com. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
If you are in the EU/EEA and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority.
8. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights:
- Know what personal information is collected about you
- Know whether your personal information is sold or disclosed and to whom
- Opt out of the sale of your personal information
- Request deletion of your personal information
- Not be discriminated against for exercising your privacy rights
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. The categories of personal information we collect are described in Section 2 above.
To exercise your California privacy rights, contact us at team@kaztiki.com.
9. Australian Residents
If you are located in Australia, we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
You have the right to access and correct personal information we hold about you. If you believe we have breached the Australian Privacy Principles, you may contact us directly or lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Personal information submitted through our contact form may be stored on servers located outside Australia (United States). We take reasonable steps to ensure overseas recipients handle your data consistently with the APPs.
10. Security
We take reasonable technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data in transit
- Row-level security on our database
- Access controls limiting who can view submitted data
- Security headers on all pages (HSTS, CSP, X-Frame-Options)
No method of transmission over the internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
11. Contact Us & Cookie Settings
For any privacy-related questions, requests, or to change your cookie preference:
This policy was last updated in May 2026. We may update this policy from time to time. Material changes will be noted at the top of this page with a revised effective date.