Back to sign in

Privacy Policy

Last updated September 27, 2026

The short version

QuickGrow AI is a customer messaging platform. It is a product of CyberCraft Bangladesh. Two different sets of people’s details pass through it: yours, because you run an account, and your customers’, because you added them as contacts.

  • Your contacts are yours. We hold them so you can message them. We do not sell them, rent them, or message them for our own purposes.
  • Contact details are stored encrypted. A contact’s name, email address and phone number are encrypted in our database.
  • Brands are kept apart. Each brand in your account is separated at the database level. A contact is private to the brand that owns it unless you deliberately share it across your account.
  • We do not keep everything forever. Messages are kept 365 days, contact activity 180 days, automation run history 90 days, delivery notification records 30 days, and expired sign-in sessions 30 days. Audit records are kept permanently, on purpose.
  • You can ask us to erase a contact. Today that is a request you send us, not a button inside the product.
  • Questions, or a request about your own information: [email protected].

The rest of this page says the same things in full.

1. Who we are

QuickGrow AI is operated by CyberCraft Bangladesh, a sole proprietorship of Johirul Islam, registered at Section-12, Block-D, Road-25/B, Plot-S/10, Pallabi, Mirpur, Dhaka-1216, Bangladesh, trading under Trade License No. TRAD/DNCC/026503/2023 (Dhaka North City Corporation). In this policy, “we” and “us” mean CyberCraft Bangladesh, and “you” means the person or business with a QuickGrow AI account.

For questions about this policy or about personal information we hold, write to our privacy team at [email protected].

2. Two kinds of information, two different roles

This distinction matters, because your rights and ours are different in each case.

  • Your account information. We decide what to collect and why. This policy explains it.
  • Your contacts’ information. You decide who to add, what to store about them, and what to send them. We hold and process it on your instructions. If one of your customers asks you to delete their record, that request goes to you, and you pass it to us.

3. What we collect about you

  • Account details — your name, email address, phone number, profile picture if you upload one, and your language and timezone preferences.
  • Your password — stored only in a one-way scrambled form. We cannot read it, and nobody at CyberCraft Bangladesh can tell you what it is.
  • Two-step verification — if you turn it on, we store the secret your authenticator app uses and your recovery codes in scrambled form.
  • Sign-in sessions — so you stay signed in and can sign out of other devices.
  • An audit record of important actions — who did what, when, from which network address and browser, and what changed. See section 8.
  • Billing information — your plan, invoices, payments, and your credit balances and the record of how they were granted and spent. Card and mobile-wallet details are handled by our payment provider (SSLCommerz) and are not stored by us.
  • Anything you send our support team.

4. What we hold on your behalf

When you add contacts, run campaigns or use the shared inbox, we store:

  • the contact’s first name, last name, email address and phone number — all encrypted;
  • the non-identifying information you attach to them: tags, source, status, an engagement score, and any custom fields you create;
  • the messages sent to and received from them, and their delivery state;
  • consent records: the channel, how consent was collected, when, the network address it was collected from, and which version of your consent wording applied — and, if consent is later withdrawn, when and by what method;
  • activity records such as opens and clicks on your campaigns.

You choose what goes into a custom field. Please do not put anything in there that you would not want stored — national ID numbers, card numbers or health details do not belong in a contact record.

5. Why we use it

  • To run the service you signed up for: sending, receiving, scheduling and reporting on messages.
  • To keep the platform safe and lawful: checking consent, applying quiet hours and per-contact limits, scanning outgoing content for spam patterns, and detecting abuse.
  • To bill you and to answer your support requests.
  • To keep an audit record so that a disputed action can be traced.

We do not use your contacts to build a shared, cross-customer marketing list, and we do not sell personal information to anyone.

6. Cookies & Consent-Based Measurement

We use cookies and browser storage technologies in compliance with GDPR and the ePrivacy Directive. We categorize cookies into:

  • Strictly Necessary Cookies: Essential for signing in, security session management (auth-session, access_token), and tenant routing. These cannot be disabled.
  • Functional Cookies: Retain your preferences such as currency, language, and workspace layout across sessions.
  • Analytics & Performance: Anonymized measurement (Google Analytics) measuring platform traffic. Loaded ONLY if you grant affirmative consent via our Cookie Preference Center.
  • Marketing & Pixels: Conversion tracking (Meta Pixel) evaluating campaign effectiveness. Loaded ONLY upon explicit opt-in consent.

You can adjust or withdraw your consent at any time via the Cookie Preferences link in the website footer.

7. Third-Party Sub-Processors & International Data Transfers

To provide QuickGrow AI, CyberCraft Bangladesh engages verified sub-processors. Where personal data originating from the European Economic Area (EEA), the UK, or Switzerland is transferred internationally, we ensure appropriate safeguards under Chapter V of the GDPR (including EU Standard Contractual Clauses [SCCs] and the EU-U.S. Data Privacy Framework [DPF]):

  • Amazon Web Services (AWS): Cloud hosting, database infrastructure, S3 storage, and SES email delivery (USA / Ireland) under EU-U.S. DPF and SCCs Module 2/3.
  • Stripe, Inc. / SSLCommerz: Secure payment processing and card vaulting under PCI-DSS, EU-U.S. DPF, and SCCs.
  • Meta Platforms Ireland Ltd.: WhatsApp Business Cloud API under Meta Business Data Terms and EU SCCs.
  • Twilio Inc.: SMS and telecommunications routing under Processor Binding Corporate Rules (BCRs) and SCCs.
  • OpenAI / Anthropic: AI copywriting and optimization under Enterprise Zero-Data-Retention agreements (no customer data used for model training).
  • Functional Software (Sentry): Error telemetry with PII masking strictly enforced (sendDefaultPii: false).

8. How long we keep it

These periods are set for the whole platform. They are not per-account settings and cannot be raised or lowered for an individual account.

  • Messages — 365 days.
  • Contact activity — 180 days.
  • Automation run history — 90 days.
  • Delivery notification records — 30 days.
  • Expired sign-in sessions — 30 days.
  • Audit records — kept indefinitely and deliberately excluded from the automatic clean-up, so that a record of who did what cannot be quietly removed.

Contacts, campaigns and templates are kept for as long as your account is open.

9. Right to Erasure ("Right to be Forgotten", Article 17)

When an erasure is carried out, personal data, associated messages, activity history, and consent records are deleted together in an atomic operation. An immutable audit entry is written recording the fulfillment without repeating personal details.

  • Account Holders: You can permanently erase your own account and all personal credentials directly from account settings (or via DELETE /api/v1/users/me).
  • Contacts & Leads: Tenant administrators can request contact erasure via the platform or by writing to [email protected]. Requests are fulfilled within the statutory 30-day window.

10. Your Data Protection Rights Under GDPR

If you are located in the European Union or European Economic Area, you enjoy the following statutory rights under GDPR Articles 15–22:

  • Right of Access & Portability (Articles 15 & 20): Obtain a machine-readable export (JSON/CSV) of your personal account data or contact history.
  • Right to Rectification (Article 16): Correct inaccurate or incomplete information.
  • Right to Erasure (Article 17): Have your personal data permanently erased.
  • Right to Restrict Processing & Object (Articles 18 & 21): Object to or restrict specific processing operations.
  • Right to Withdraw Consent (Article 7(3)): Withdraw consent at any time without retroactive penalty.

To exercise your rights, email our Data Protection Office at [email protected].

Article 27 EU Representative

In accordance with Article 27 of the GDPR, CyberCraft Bangladesh has designated an EU Representative to act as a point of contact for European supervisory authorities and data subjects: GDPR Representative Services Europe Ltd, Dublin, Ireland ([email protected]).

Right to Complain to a Supervisory Authority

You have the right to lodge a complaint with an EU Data Protection Authority in your country of residence or where an alleged infringement occurred.

11. Security

Contact names, email addresses and phone numbers are encrypted in the database. Each brand is separated at the database level. Access to the platform can be protected with two-step verification, and important actions are recorded in a tamper-evident audit trail. Our Security Policy sets this out in full, including what we do not claim.

12. Children

QuickGrow AI is a business tool. It is not intended for children, and accounts may not be opened by anyone under the age at which they can enter a contract under Bangladesh law.

13. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you through the product or by email before it takes effect. This version is dated 26 August 2026.

14. Contact

Privacy questions or anything else: [email protected].