Privacy Policy

Last updated: July 30, 2026

This Privacy Policy explains how Kwii Digital Ltd. ("Threadliner," "we," "us," or "our") collects, uses, and shares information when you use Threadliner. It covers both account data (about you, the person or team using Threadliner) and Customer Data (the contacts, subscribers, and deals you store in Threadliner) — we call out which applies in each section.

1. Information we collect

Account data

  • Name, email address, and password (stored as a salted hash) when you sign up;
  • Workspace/tenant name and team member roles;
  • Billing information, handled directly by Stripe — we don't store card numbers;
  • Usage data such as login timestamps and IP address (used for suspicious-login alerts and rate limiting), and error/performance data captured by our error monitoring tool.

Customer Data

Data you submit into Threadliner as part of using the product — contact records, form submissions, newsletter subscribers and campaign content, CRM deals, and automation configuration. We process this data on your behalf, as a processor, to provide the service; we don't use it for our own marketing.

2. How we use information

  • To provide, maintain, and secure the service (including fraud/abuse prevention);
  • To send transactional email — welcome, password reset, team invites, billing, and security alerts;
  • To respond to support requests;
  • To monitor and fix errors and performance issues; and
  • To comply with legal obligations.

3. Cookies and sessions

Threadliner uses a single essential, httpOnly session cookie to keep you signed in. It isn't used for advertising or cross-site tracking, and it can't be read by JavaScript. We don't use third-party advertising cookies.

4. Who we share data with

We share data with the subprocessors that host and operate Threadliner, under agreements that require them to protect it and use it only to provide their service to us:

  • Stripe — payment processing and subscription billing;
  • Brevo — sending transactional and campaign email on your behalf;
  • Neon — Postgres database hosting;
  • Upstash — Redis (background job queue) hosting;
  • Cloudflare R2 — file storage for uploaded assets;
  • Fly.io and Vercel — application hosting; and
  • Sentry — error and performance monitoring.

We don't sell your data or Customer Data, and we don't share it with third parties for their own marketing purposes. We may disclose information if required by law or to protect the rights, property, or safety of Threadliner, our users, or others.

5. Data retention

We retain account and Customer Data for as long as your account is active. If you delete a contact, subscriber, or your account, we remove the associated data from production systems within a reasonable period, subject to what we need to retain for legal, tax, or security purposes (e.g. abuse prevention logs).

6. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data. Account owners can export or permanently erase a contact's data directly from Threadliner. For anything else, or if you're a contact whose data was submitted by a Threadliner customer and want to exercise your rights, email us at hello@threadliner.io and we'll help directly or route you to the relevant workspace owner.

7. Security

We use industry-standard measures to protect data in transit (TLS) and at rest, including password hashing, scoped API keys, and role-based access control within workspaces. No method of transmission or storage is 100% secure, but we work to protect your data appropriately.

8. Children's privacy

Threadliner is intended for business use and is not directed at children. We do not knowingly collect personal data from children under 16.

9. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll provide reasonable notice before they take effect.

10. Contact

Questions about this policy? Reach us at hello@threadliner.io.