Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how Kwii Digital Ltd. ("Threadliner," "we," "us," or "our") collects, uses, and shares information when you use Threadliner. It covers both account data (about you, the person or team using Threadliner) and Customer Data (the contacts, subscribers, and deals you store in Threadliner) — we call out which applies in each section.
1. Information we collect
Account data
- Name, email address, and password (stored as a salted hash) when you sign up;
- Workspace/tenant name and team member roles;
- Billing information, handled directly by Stripe — we don't store card numbers;
- Usage data such as login timestamps and IP address (used for suspicious-login alerts and rate limiting), and error/performance data captured by our error monitoring tool.
Customer Data
Data you submit into Threadliner as part of using the product — contact records, form submissions, newsletter subscribers and campaign content, CRM deals, and automation configuration. We process this data on your behalf, as a processor, to provide the service; we don't use it for our own marketing.
2. How we use information
- To provide, maintain, and secure the service (including fraud/abuse prevention);
- To send transactional email — welcome, password reset, team invites, billing, and security alerts;
- To respond to support requests;
- To monitor and fix errors and performance issues; and
- To comply with legal obligations.
3. Cookies and sessions
Threadliner uses a single essential, httpOnly session cookie to keep you signed in. It isn't used for advertising or cross-site tracking, and it can't be read by JavaScript. We don't use third-party advertising cookies.
4. Who we share data with
We share data with the subprocessors that host and operate Threadliner, under agreements that require them to protect it and use it only to provide their service to us:
- Stripe — payment processing and subscription billing;
- Brevo — sending transactional and campaign email on your behalf;
- Neon — Postgres database hosting;
- Upstash — Redis (background job queue) hosting;
- Cloudflare R2 — file storage for uploaded assets;
- Fly.io and Vercel — application hosting; and
- Sentry — error and performance monitoring.
We don't sell your data or Customer Data, and we don't share it with third parties for their own marketing purposes. We may disclose information if required by law or to protect the rights, property, or safety of Threadliner, our users, or others.
5. Data retention
We retain account and Customer Data for as long as your account is active. If you delete a contact, subscriber, or your account, we remove the associated data from production systems within a reasonable period, subject to what we need to retain for legal, tax, or security purposes (e.g. abuse prevention logs).
6. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data. Account owners can export or permanently erase a contact's data directly from Threadliner. For anything else, or if you're a contact whose data was submitted by a Threadliner customer and want to exercise your rights, email us at hello@threadliner.io and we'll help directly or route you to the relevant workspace owner.
7. Security
We use industry-standard measures to protect data in transit (TLS) and at rest, including password hashing, scoped API keys, and role-based access control within workspaces. No method of transmission or storage is 100% secure, but we work to protect your data appropriately.
8. Children's privacy
Threadliner is intended for business use and is not directed at children. We do not knowingly collect personal data from children under 16.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll provide reasonable notice before they take effect.
10. Contact
Questions about this policy? Reach us at hello@threadliner.io.