Who we are
KickThemBot is operated by Šimon Robin Mach, a sole trader registered in Czechia under business registration number (IČO) 06316760.
Registered seat: Nová cesta 761, 252 29 Dobřichovice, Czech Republic.
Not registered for VAT. Prices carry no VAT.
Šimon Robin Mach is the data controller for data about owners, their helpers and visitors to this website. Contact: support@kickthembot.com.
For privacy questions, write to that address with "Privacy" in the subject line.
Owners, members and our role
An owner uses KickThemBot to run a paid Telegram group or channel. A helper is someone an owner lets help run a project. A member is someone who joins or buys access to an owner's community.
For owner accounts, billing, security and product analytics, we decide how data is used, so we are the controller.
For the member data an owner manages through KickThemBot, the owner is the controller and we are the owner's processor. That covers member records, access codes, USDT payment claims and member messages. The section "Data processing for owners" explains how we handle it.
If you are a member, the owner of the community you joined decides who is admitted and why. Send requests about that community to its owner first. If you write to us instead, we help the owner answer.
What the website collects
The marketing site sets no advertising cookies and runs no cross-site tracking.
Web fonts are served from this domain, not from a third party, so loading a page sends your IP address to nobody but us.
Our web servers keep access and error logs: your IP address, the time, the requested URL, your browser's user agent and the response status. This applies to the website and to the application server behind the bot, Mini App and API. The logs are rotated daily and deleted after 14 days.
What the bot collects
When you start the bot it stores your Telegram user ID, and your username and display name if your Telegram privacy settings expose them. This is how access is granted, tracked, and removed.
For paid plans it also stores your plan, membership status, start and expiry dates, and the identifier of the related payment.
Email address: when you redeem an access code, the bot asks for your email address before it shares the invite link, unless the code already carries one. If you pay by card, Stripe checkout can collect it. If an owner's own website sends you to checkout, that website may pass us the email address and name you gave it.
It does not store your card details. Card data is handled by Stripe and never reaches our servers.
What we collect from owners
Email address: before you buy a paid plan, you verify an email address. We send a code to it through our email provider. Only a hash of the code is stored, and the code expires after 10 minutes.
The verified address stays on your account and is used for your KickThemBot plan checkout with Stripe.
Plan and billing: your KickThemBot plan, billing interval, status and period dates, plus the Stripe customer, subscription and checkout identifiers.
Project settings: project names and descriptions, the IDs and titles of connected groups and channels, membership plans and prices, reminder texts, payment instructions, and any webhook or website links you set.
Telegram bot tokens: to run your project's own service bot, we store the bot token you created with @BotFather, encrypted, in our database on our servers. The service bot uses it to work with Telegram for you.
Helpers: when you add a helper, we store their Telegram user ID, name and username, and which projects they can operate. Changes a helper makes are recorded in an audit log for that project.
USDT payments
An owner can let buyers pay in USDT straight to the owner's own wallet. KickThemBot never receives, holds or forwards crypto.
Wallet addresses: we store each wallet address the owner saves, with its network and an optional label and payment instructions. The address is shown to any buyer who chooses USDT in that owner's service bot, so it is effectively public.
Payment claims: when a buyer says they have paid, we store their Telegram user ID and name, the network, the wallet address they were shown, the amount they were asked to send, and the transaction hash if they give one. A transaction hash points to a public record on the blockchain.
The owner or a helper confirms or rejects each claim by hand. We record the decision, who made it and when, and an audit event for every wallet change and claim decision.
Claims nobody confirms expire after 7 days. Payment details a buyer was shown but never used are deleted after 7 days.
Messages to members
Owners and helpers can send a plain-text message to members of a project from the Mini App. That project's own service bot delivers it.
We store the message text, the members or member filter it was sent to, and who sent it: their Telegram user ID, name and role. For each recipient we store their Telegram user ID, the delivery status and the Telegram message ID.
The owner and helpers of that project can see its messages and delivery counts in the Mini App. Each member sees only the message they receive.
AI agents
An owner can connect an AI agent to their account and approves or denies each request in @KickThemBot. For each request we store the agent name it gives, the permissions it asks for, its status, and who decided.
The pairing code and the agent's polling secret are stored only as SHA-256 hashes. The request record is deleted automatically about a day after it is made.
An approved agent receives an owner token. We store only a SHA-256 hash of the agent token, its last four characters, its label and permissions, when it was last used, and when it was revoked. Project API keys are also stored only as hashes.
Every change an agent makes with a token is recorded in an audit log with the source agent_api, the project and the action. These records never hold tokens, API keys, bot tokens or checkout links.
Wallet proposals: an agent can propose USDT wallet addresses and a buyer note for a project, but nothing changes until the owner confirms in @KickThemBot. We store each proposal with the agent name, the proposed networks, addresses, labels and note, any address it would replace, and whether it was confirmed, rejected or expired.
A proposal expires if the owner does not answer within 30 minutes. Every proposal record is deleted automatically 90 days after it is made.
Owners can revoke an agent at any time with /agents in @KickThemBot.
Product analytics
The bot and Mini App record limited product-usage events, such as bot starts, dashboard opens, and setup and checkout stages. Events are linked to internal account and project references, not to individual members.
They contain no message content, and reports omit names, usernames, email addresses and Telegram IDs. Events are deleted automatically after 400 days. The full disclosure is on the Product Privacy and Analytics page at /privacy/.
Who else processes your data
Stripe — payment processing and subscription state. KickThemBot plans are billed through our Stripe account. A member's card payment runs on the owner's own Stripe account, connected through Stripe Connect. Stripe receives the buyer's email address and name when they are given.
Telegram — message delivery and group membership actions, under Telegram's own terms.
DigitalOcean (application, database and website) — server hosting and database storage. The application and its MongoDB database run on a DigitalOcean server in New York, USA (NYC3). The website is served from a DigitalOcean server in Frankfurt, Germany (FRA1).
Our email provider — sends email verification codes. The service can use either the Google Gmail API or Resend for this.
Owners' own systems — if an owner sets up a membership webhook or website activation, member updates go to the address the owner chose.
We do not sell personal data and do not use it for advertising.
International transfers
Account and member data are stored in the USA, because the application and its database run on DigitalOcean's server in New York.
Stripe, Telegram and our email provider may also process data outside the European Union and the European Economic Area.
These transfers rely on the providers' contractual safeguards, such as the European Commission's Standard Contractual Clauses.
Write to support@kickthembot.com if you want to know more about a specific transfer.
Why we are allowed to use it
Contract (GDPR Art. 6(1)(b)): to create and run your account, projects, service bots, memberships, checkouts and payment claims, and to send verification codes.
Legitimate interests (GDPR Art. 6(1)(f)): to keep the service secure and prevent abuse, for example with rate limits, verification limits and audit logs of helper and agent actions, and to improve the product with limited analytics. You can object to this use.
Legal obligation (GDPR Art. 6(1)(c)): to keep the payment and accounting records the law requires.
For member data we process for an owner, the owner decides the legal basis.
How long we keep it
Payment and accounting records are kept for 10 years, as Czech accounting and VAT law requires.
Owner accounts, projects, membership records, member messages, payment claims and audit logs are kept while the owner's account is open, so support can resolve access and billing disputes.
Closing an account: an owner can close their account with /delete_account in @KickThemBot. After the owner confirms, the service stops. The account, its projects and its member data are deleted 90 days later, unless the owner cancels the closure first. Payment and accounting records are kept for the 10 years the law requires.
Some records are deleted automatically sooner: email verification codes after they expire, AI agent requests about a day after they are made, unused USDT payment details after 7 days, agent wallet proposals after 90 days, and product analytics events after 400 days.
Web server access and error logs are deleted after 14 days. Application error logs, which can include technical details such as Telegram user IDs, are kept for troubleshooting and deleted when no longer needed.
Backups: the database is backed up every night. The backups are encrypted and kept for 14 days, on a second server in Frankfurt and on the application server. We are also turning on DigitalOcean's weekly backups of the application server. Deleted data can stay in a backup until that backup expires.
You can ask for deletion sooner at any time by emailing support@kickthembot.com. Deleting your membership record ends any active paid access.
Your rights
You can ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be deleted. You can also ask us to restrict or stop using it, or to give it to you in a portable format. We answer these requests within 30 days.
If you are a member of an owner's community, you can also ask that owner. Owners can export their member list from @KickThemBot.
You have the right to complain to a data protection authority. In the Czech Republic that is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), www.uoou.cz. You can also complain in the EU country where you live or work.
Data processing for owners
When you run a project, you are the controller for your members' data and we process it on your instructions. Those instructions are the settings you choose and the actions you, your helpers and your approved agents take.
We use member data only to run KickThemBot for you: invites and access codes, join checks, checkout, USDT claims, reminders, member messages, removal of ended access, and the webhooks you set up.
Sub-processors: Telegram, Stripe, DigitalOcean and our email provider (the Google Gmail API or Resend). We tell owners at least 14 days before adding or replacing a sub-processor. An owner who objects can close their account with /delete_account.
Security: a project is open only to its owner, the helpers the owner adds, and agents the owner approves with the permissions shown. Owners' bot tokens are stored encrypted, agent tokens, API keys and verification codes are stored as hashes, database backups are encrypted, Stripe webhooks are checked against Stripe's signature, and helper and agent changes are logged.
Deletion: when you close your account with /delete_account, your members' data is deleted 90 days later, or sooner if you ask. Payment and accounting records the law requires us to keep are the exception. You can export your member list first.
Requests and incidents: if a member asks you to exercise their rights, we help you find, export, correct or delete their records. We tell you without undue delay if we become aware of a personal data breach affecting your members' data.
Changes to this policy
The current version is always on this page with the date it was updated. If a change materially affects how we use your data, existing customers are told before it takes effect.