This Privacy Policy explains how QBIT Commerce Inc., which operates Fluxify (“Fluxify,” “we,” “us”), handles information across the fluxify.ai website, our products, and our professional services. It sits alongside our Terms of Service. Individual products may publish their own policy on their own domain; where they do, that policy governs that product.
For customer data we process on your behalf, you are the controller and we act as a processor, handling that data on your documented instructions.
1. Information We Collect
1.1 Information you give us
Contact and account information: name, business name, email address, and anything else you include when you write to us or create an account.
Engagement information: the documents, samples, requirements, and correspondence you share while we scope or run a project.
Billing information: billing contact and address. Card details, where applicable, are handled by our payment processor and are never stored on our systems.
1.2 Customer Data from systems you connect
Where you authorize us to connect to a platform or system you use, we receive the data those APIs return within the scopes you grant. Across our products and engagements that can include:
business and operational records such as catalog, listing, pricing, inventory, order, advertising, and settlement data;
engine, build, and gameplay telemetry such as session events, progression, and in-game economy activity.
Separately, we use reference and market data such as public listings, prices, and catalog attributes, obtained from licensed and public sources. That data is not Customer Data and is not tied to your account.
Some of this may contain personal information, for example a buyer name or address in an order record, or an identifier tied to an individual account. We request only the scopes a feature requires, minimize what we retain, and never use personal information found in Customer Data for marketing.
1.3 Information collected automatically
Service logs: IP address, browser and device type, pages or endpoints accessed, timestamps, and error diagnostics, used to keep the Services secure and working.
Product usage: which features an account uses and when, so we can tell what is worth improving.
2. How We Use Information
to provide, operate, secure, and support the Services;
to ingest, normalize, enrich, model, and present data in the way a product or engagement requires;
to communicate with you about your account, an engagement, changes to the Services, and security matters;
to detect, investigate, and prevent fraud, abuse, and security incidents;
to bill for the Services and keep required financial records;
to comply with legal obligations and enforce our Terms.
We rely on the performance of our contract with you, our legitimate interest in operating and securing the Services, your consent where required, and compliance with law as our bases for processing.
3. AI and Model Training
We do not train models that are made available to other customers on your Customer Data.
Where a feature sends content to a third-party model provider to generate an output, we use enterprise or API terms that prohibit the provider from training its general models on that content. The providers we use are listed on request.
Models built specifically for you under an engagement are yours as set out in that engagement.
We may use aggregated, de-identified information that does not identify you, your business, or any individual to evaluate and improve the Services.
4. Data Retention
Customer Data is retained for as long as your account or engagement is active, because the history is what makes trend analysis possible.
After termination we delete or de-identify Customer Data within 90 days, except where we must keep it to comply with a legal obligation, resolve a dispute, or enforce our agreements. You may request earlier deletion in writing.
Backups are retained on a rolling schedule and are purged within 90 days of deletion from live systems.
Service logs are retained for up to 12 months, and billing records for as long as tax and corporate law requires.
5. How We Share Information
We do not sell personal information, and we do not share Customer Data with other customers. We share information only with:
Service providers who host, secure, monitor, or support the Services, or who provide model inference, under contracts that limit them to acting on our instructions;
Platforms you connect, to the extent a feature writes back or acts on your behalf within the authorization you granted;
Professional advisers such as auditors and lawyers, under duties of confidentiality;
Authorities, where required by valid legal process, after review and with notice to you where we are legally permitted to give it;
A successor, in a merger, acquisition, or sale of assets, subject to this Policy continuing to apply.
6. Security
Encryption in transit with TLS 1.2 or higher, and at rest.
Least-privilege access limited to the people who operate the Services, with multi-factor authentication required.
Credentials and platform tokens stored in a managed secret store, never in source code.
Environment separation between development and production, and audit logging of administrative and agent actions.
Vulnerability patching, dependency monitoring, and periodic access review.
No system is perfectly secure. If a breach affects your data, we will notify you and any applicable regulator without undue delay and within the time the law requires.
7. Your Rights and Choices
Access, correction, and deletion: you can request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it.
Portability and objection: where the law provides it, you may request your data in a portable format, object to certain processing, or ask us to restrict it.
Withdraw authorization: you can revoke a platform authorization at the source at any time, which stops further collection from that platform.
Marketing: you can unsubscribe from any non-essential email at any time. We will still send service and security notices.
Write to info@fluxify.ai and we will respond within 30 days. Where we process data on a customer’s behalf, we will refer an individual’s request to that customer and support them in answering it. Canadian residents may also complain to the Office of the Privacy Commissioner of Canada; EU and UK residents may complain to their local supervisory authority.
8. International Data Transfers
We are based in Canada and use service providers located in Canada, the United States, and the European Union. Where personal information is transferred out of your region, we rely on recognized transfer mechanisms, such as the European Commission’s Standard Contractual Clauses, together with contractual and technical safeguards.
9. Cookies
The fluxify.ai website does not use advertising or cross-site tracking cookies, and it does not run third-party analytics or advertising scripts. Our products may set strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. If we later add analytics, we will update this Policy and, where required, ask for consent first.
10. Children’s Privacy
The Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, write to us and we will delete it.
11. Changes to This Policy
We may update this Policy from time to time. For material changes we will give notice by email or in-product notice at least 14 days before they take effect, and we will update the effective date above.