staging — not production · shared · synthetic data · mail captured to the log, never sent
GGrowthAdmins

Privacy Notice

Effective 4 August 2026 · Last updated 4 August 2026

This Privacy Notice explains how Bytes Camp LLC, doing business as Qluw (“Qluw,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information.

Qluw is a business-to-business sales and relationship-management platform. This notice covers information Qluw handles for its own business purposes and information processed through the platform on behalf of Qluw customers.

1 · Our role

  • Qluw handles personal information in two different capacities.
  • When Qluw acts for its customers — organizations using Qluw (referred to in the platform as Brand Runners or Storefronts) may upload and manage information about businesses and their representatives. They decide which information to place in Qluw, why it is used, and whether they have authority to use it. For this information, the customer generally acts as the controller or business, and Qluw acts as its processor or service provider.
  • If you received an email from an organization using Qluw and want to access, correct, or delete the underlying contact information, you should normally contact that organization. If you send the request to Qluw, we may refer it to the relevant organization.
  • You can unsubscribe directly from marketing emails sent through Qluw. You do not need an account or the sender's approval to unsubscribe.
  • When Qluw acts for itself — Qluw determines how and why it processes information concerning: Qluw user accounts and access; authentication and security; billing and subscription administration; customer support; platform operation and abuse prevention; and Qluw's own legal and business obligations. For this information, Qluw generally acts as the controller or business.

2 · Information we collect

  • Account and access information — for authorized platform users, we may collect: name; work email address; access tier or role; account and Storefront memberships; invitation and account-access information; billing-related account information; and records of support access and administrative actions.
  • Qluw is invite-only and does not currently offer public self-registration.
  • Passwords are stored as cryptographic hashes rather than readable text. Authentication links, one-time codes, and session credentials are also stored using hashed or otherwise protected values.
  • Authentication and security information — session records; session creation, expiration, revocation, and “remember me” status; short-lived magic-link and verification-code records; invitation records; failed sign-in and import rate-limit counters; and security and administrative audit records.
  • Standard sessions last up to 24 hours. A session may last up to 30 days when “remember me” is selected. Magic links and one-time codes expire after approximately 10 minutes, and invitation links expire after approximately seven days.
  • Revoked session records and certain audit records are not presently deleted automatically.
  • Information customers place in Qluw — company name, domain, industry, size, location, employee count, and revenue band; a business representative's name, work email address, telephone number, and job title; source, date, verification status, and stated basis for contacting a person; relationships, relationship stages, deals, tasks, and notes; email subjects, message bodies, send times, replies, and open or delivery status; imported rows, including rejected rows and rejection reasons; the source attributed to an imported field; meeting times, duration, channel, recording references, and supplied transcripts; portal-recipient names and email addresses; email-delivery, bounce, opening, reply, and complaint information; and unsubscribe and suppression records.
  • Rejected import rows may be retained so that the same invalid information is not repeatedly imported. Customers are responsible for the information they place in Qluw and for complying with laws governing its collection and use.
  • Meetings and recordings — Qluw can store meeting metadata, a reference identifying where a recording is stored, and a transcript supplied by a user. Qluw does not currently upload, store, or transcribe meeting audio. A transcript is present only when a user or customer supplies one.
  • Information we do not currently collect — the application is not presently designed to collect: card or bank-account numbers; device push tokens; mobile-device telemetry; advertising identifiers; analytics, heat-map, or session-replay data; browser user-agent strings; or visitor IP addresses in application or network request logs.

3 · Cookies

  • Qluw currently uses only essential cookies: a session cookie used to keep an authorized user signed in; and a cookie indicating that a browser tab is operating within an authorized support session.
  • These cookies are configured as HttpOnly and SameSite=Lax, and as Secure when transmitted over HTTPS.
  • Qluw does not currently use analytics, advertising, heat-mapping, or session-replay cookies. Because the cookies currently used are necessary for the service to function, Qluw does not presently display a cookie-consent banner.

4 · How we use information

  • Depending on the context, Qluw uses personal information to: provide, operate, secure, and maintain the platform; authenticate users and administer permissions; import and organize customer records; support customer-directed business communications; record email delivery, engagement, replies, complaints, and unsubscribes; prevent suppressed addresses from being contacted again; facilitate customer support and investigate technical problems; monitor platform reliability and control abuse; administer subscriptions and billing; produce customer-requested scoring, reply-triage, and call-coaching results; keep security, support, and administrative audit records; comply with applicable law and respond to valid legal process; and establish, exercise, or defend legal claims.
  • Where applicable law requires a legal basis, processing may be based on performance of a contract, compliance with a legal obligation, consent, or a legitimate interest such as operating and securing the service. A Qluw customer determines the appropriate legal basis for contact information it places in the platform.

5 · Artificial intelligence features

  • Qluw uses Moonshot AI's Kimi K2.5 model for certain lead-scoring, reply-triage, and call-coaching functions. The model is invoked through Amazon Bedrock, within Qluw's existing AWS environment, rather than through a separate connection to a Moonshot-operated service. Qluw also maintains, but does not currently use, a direct connection to Anthropic's Messages API for the same functions.
  • Lead scoring — requests contain company-level information such as company name and domain; industry; employee count; revenue band; and location. Qluw does not intentionally include a person's name, email address, or telephone number in lead-scoring requests.
  • Reply triage — requests may contain the full text and subject of an incoming reply; earlier messages in the same thread; relationship stage; the sender's job title; and the associated company's industry and city. The sender's email address is not intentionally included, although message content could contain personal information entered by the sender or another participant.
  • Call coaching — requests may contain a customer-supplied meeting transcript. Before submission, Qluw applies pattern-based redaction intended to replace email addresses and runs of seven or more digits. This process is not anonymization. It may not remove names, contextual identifiers, or other personal information appearing in a transcript.
  • AI records retained by Qluw — after an AI request, Qluw keeps a usage record containing token counts, estimated cost, and whether the request succeeded or used a fallback. Qluw does not currently retain the prompt or model output as part of that usage record.
  • When an AI service is unavailable or has not been configured, Qluw uses the platform's stated fallback behavior, such as rules-based scoring or routing a reply for human attention.
  • Qluw's AI features support customer workflows. They are not intended to make decisions producing legal or similarly significant effects about individuals.

6 · How information is disclosed

  • Qluw may disclose information: to the customer that supplied or generated it; among Storefronts belonging to the same customer account, as described below; to personnel who need access to operate or support the service; to infrastructure and service providers; when required by law or valid legal process; to protect Qluw, its customers, users, or others; or as part of a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the business, subject to applicable law.
  • Information shared within a customer account — certain deliverability information may be shared among Storefronts controlled by the same customer account. This can include a normalized email address and whether messages sent to it were delivered, bounced, opened, answered, or reported as unwanted.
  • Unsubscribe and complaint records apply across the entire customer account so that another Storefront belonging to the same organization cannot resume contacting a suppressed address.
  • Service providers — Amazon Web Services, in the US East (Northern Virginia) region, for application hosting, databases, backups, storage, email delivery through Amazon SES, logs, DNS, secrets management, and, through Amazon Bedrock, the AI-assisted functions described above (currently served by Moonshot AI's Kimi K2.5 model); Anthropic, through its Messages API, registered as a fallback for the same functions but not presently in use.
  • Qluw may update its service providers as the platform changes. Material changes will be reflected in an updated version of this notice.
  • Payment information — Qluw does not currently collect card numbers or bank-account numbers through the live platform. Its billing system is presently configured with a test payment driver rather than a live card or bank-payment processor. If live payment processing is introduced, Qluw will update this notice and payment information will be handled by the identified payment processor rather than stored directly by Qluw, except for tokens and limited transaction metadata.

7 · Sale and targeted advertising

  • Qluw does not sell personal information.
  • Qluw does not disclose personal information for cross-context behavioral advertising or targeted advertising, and it does not operate an advertising network.
  • Because Qluw does not currently sell or share personal information for those purposes, it does not provide a “Do Not Sell or Share My Personal Information” link. If these practices change, Qluw will update this notice and provide any legally required choices.

8 · Email communications and unsubscribing

  • Every campaign email sent through Qluw is intended to contain an unsubscribe link and standard one-click unsubscribe information.
  • Using either method takes effect immediately within Qluw; applies across the sender's customer account; cancels active sequences directed to that address; and does not require a Qluw login.
  • Qluw retains the email address and associated domain on a suppression list after an unsubscribe or complaint. This record is retained to prevent the address from being imported or contacted again. Deleting the suppression record could cause a person to receive email after opting out, so Qluw does not ordinarily remove it.

9 · Data storage and international transfers

  • Qluw stores its production data in the Amazon Web Services US East region in Northern Virginia, United States. Qluw does not currently maintain a production replica in another region.
  • If you use Qluw from outside the United States, your information will be transferred to and processed in the United States. Privacy laws in the United States may differ from those in your country.
  • Important: Qluw has not yet implemented a contractual or other transfer mechanism specifically intended for restricted transfers of personal information from the European Economic Area, United Kingdom, or Switzerland. Organizations subject to those requirements should not transfer covered information to Qluw until an appropriate mechanism and data processing agreement have been established.

10 · Security

  • Qluw uses technical and organizational safeguards intended to protect information, including: encryption of the production database and storage buckets at rest; HTTPS protection for information in transit; hashed passwords, authentication tokens, and session identifiers; role- and account-based access controls; rate limiting for authentication and imports; time-limited support sessions; audit records for platform-side administrative actions; and encrypted database backups.
  • No security system is perfect, and Qluw cannot guarantee that information will never be lost, accessed, disclosed, altered, or destroyed without authorization.
  • Customer-authorized support access — Qluw personnel do not have standing support access to a customer's records through the application. A support session must be created by an authorized customer user and lasts no longer than 30 minutes; is read-only unless the customer separately grants write access and records a reason; can be ended by the customer at any time; and creates an audit record identifying records accessed and actions taken.

11 · Retention and deletion

  • Qluw currently applies the following retention periods: database point-in-time recovery data, up to 30 days; encrypted weekly database exports, up to 90 days; application logs, approximately 30 days; database performance information, approximately seven days; portal links, up to 90 days; authentication codes and magic links, approximately 10 minutes; invitation links, approximately seven days; and expired rate-limit counters, removed after the applicable counting window.
  • Other customer and account records are not currently subject to an automated deletion schedule. They remain in the live system until the relevant customer relationship ends, a customer instructs Qluw to remove them, Qluw manually removes them, or continued retention is no longer necessary or permitted.
  • A record removed from the live database may remain in point-in-time recovery data for up to 30 days and in encrypted weekly backups for up to 90 days. The deletion becomes final as the relevant backup copies expire.
  • Unsubscribe, complaint, and suppression records may be retained indefinitely to honor opt-out requests and prevent renewed contact.
  • Qluw does not currently offer self-service deletion of contacts, companies, relationships, or accounts. Requests requiring deletion must be handled manually and may require instructions from the customer that controls the relevant records.

12 · Your privacy rights

  • Depending on your location and Qluw's role in handling the information, you may have the right to: ask whether personal information about you is being processed; request access to or a copy of that information; request correction of inaccurate information; request deletion, subject to legal exceptions; object to or request restriction of certain processing; request portability of information you provided; withdraw consent where processing depends on consent; opt out of marketing communications; appeal the denial of a request where applicable; and complain to an appropriate privacy or data-protection authority.
  • These rights are not absolute and may vary by jurisdiction.
  • When Qluw processes information on behalf of a customer, the customer is generally responsible for responding to the request. Qluw may forward your request to that customer and assist it as required by applicable law and Qluw's agreement with the customer.
  • Qluw may need to verify your identity and authority before acting on a request. Authorized agents may submit requests where permitted by law, subject to appropriate verification.
  • Qluw will not discriminate against you for exercising an applicable privacy right.

13 · Available account controls

  • Authorized Qluw users can currently export their Storefront crew roster as a CSV file.
  • Qluw does not currently provide: a self-service, account-wide export of contacts, email history, or meeting information; self-service deletion; a customer-facing screen displaying the complete account audit trail; or automated account recovery.
  • These requests currently require manual assistance.

14 · Children's information

  • Qluw is a business service and is not directed to children. Customers should not use Qluw to collect or process personal information about children.
  • If you believe information about a child has been placed in Qluw, contact us using the information below.

15 · Changes to this notice

  • Qluw may update this Privacy Notice to reflect changes in the service, its providers, or applicable requirements.
  • The “Last updated” date above identifies the most recent revision. If a change materially affects how Qluw uses personal information, Qluw will provide additional notice when required by applicable law.

16 · Contact us

  • Questions and requests concerning information Qluw controls may be submitted to Bytes Camp LLC, attention: Legal.
  • Email: frank@growthadmins.com
  • Mailing address: 45 Colvin Ave, Suite 120, Albany, NY 12206

Privacy · Terms