Privacy Policy

QUBITOWL, INC., a corporation organized under the laws of the State of Utah, with its principal place of business located at 2825 E Cottonwood Pkwy, Salt Lake City, Utah 84121-7055, United States (US), provides this Privacy Policy to explain how we — together with our digital platform developed by Qubi Owl and hosted at www.qubiowl.autos — collect, use, disclose, retain, safeguard, and otherwise process personal information. This document is designed to meet or exceed the requirements of applicable data protection frameworks, including the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the General Data Protection Regulation (GDPR) where applicable, and other relevant privacy statutes and regulations that may be enacted from time to time in jurisdictions where we operate or where our users reside.

By accessing, browsing, or otherwise interacting with any website, mobile application, API endpoint, chatbot interface, or other digital service branded as QUBITOWL or Qubi Owl (collectively, the Services), you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with any portion of this document, you must immediately discontinue all use of the Services and refrain from providing any personal information to us. We reserve the right to modify this Privacy Policy at any time in our sole discretion; continued use of the Services following the posting of any revised version constitutes acceptance of the changes.

1. Scope and Applicability

This Privacy Policy applies to all personal information that QUBITOWL, INC. collects, receives, or otherwise obtains in the course of operating the Services, whether that information is provided directly by you, generated automatically through your use of the Services, or obtained from third-party sources with whom we maintain contractual relationships. The policy governs our data practices across all jurisdictions and covers information collected through every channel, including but not limited to web browsers, mobile devices, connected vehicle interfaces, in-vehicle infotainment integrations, voice assistants, developer APIs, partner platforms, and offline interactions such as telephonic communications, postal correspondence, and in-person events.

1.1 Territorial Reach

QUBITOWL, INC. is headquartered in the United States of America. Our data processing operations are primarily conducted within the United States, though we may utilize cloud infrastructure, content delivery networks, and third-party service providers located in other countries. By using the Services, you consent to the transfer of your personal information to, and its processing in, the United States and any other jurisdiction where our affiliates or service providers maintain facilities. Where required by applicable law, we implement Standard Contractual Clauses (SCCs), Binding Corporate Rules, or other approved transfer mechanisms to ensure adequate protection for cross-border data flows.

1.2 Exclusions

This Privacy Policy does not apply to information that has been anonymized, aggregated, or de-identified such that it can no longer reasonably be associated with an identified or identifiable natural person. It also does not apply to publicly available information lawfully made available from federal, state, or local government records, nor to information governed by separate contractual agreements that explicitly supersede this policy. Employment-related data handled in the context of job applications or workforce administration is addressed in our separate Employee and Applicant Privacy Notice, which is made available to relevant individuals at the time of collection.

2. Categories of Personal Information We Collect

We collect, and have collected within the preceding twelve (12) months, the following categories of personal information. The specific data points within each category vary depending on the nature of your interaction with the Services, the products or features you utilize, and the preferences and consents you have provided to us.

2.1 Identifiers

This category includes, but is not limited to: your first and last name, postal address, billing address, shipping address, unique personal identifiers, online identifiers, Internet Protocol (IP) address, email address, account username, telephone number, driver’s license number, vehicle identification number (VIN), license plate number, and other similar identifiers. We also collect device identifiers such as advertising IDs, IDFA, AAID, and cookie-based identifiers assigned by our analytics and advertising partners.

2.2 Personal Records

Personal information described in California Civil Code Section 1798.80(e), including your signature, physical characteristics or description, insurance policy number, bank account number, credit card number, debit card number, and any other financial, medical, or health insurance information you choose to provide when interacting with finance-related or insurance-related features of the Services. We do not retain full payment card numbers on our own systems; payment processing is handled by PCI-DSS-certified third-party processors.

2.3 Protected Classification Characteristics

In limited circumstances — for example, where you voluntarily participate in demographic surveys, apply for certain regulated financial products facilitated through the Services, or interact with accessibility features — we may collect information related to age, gender, disability status, and veteran or military status. Collection of protected-class data is always optional and is clearly identified at the point of collection.

2.4 Commercial and Transactional Information

Records of products or services purchased, obtained, or considered through the Services, including vehicle configurations, financing pre-qualifications, insurance quotes requested, test drive appointments scheduled, maintenance service history, subscription plan details, loyalty program participation, and other purchasing or consuming histories and tendencies.

2.5 Biometric Information

We do not actively collect biometric identifiers or biometric information as those terms are defined under applicable biometric privacy laws. However, should you use voice-activated features of the Services, voice recordings may be captured and processed; these recordings are not used to extract biometric templates or create biometric identifiers, and they are retained only as necessary to provide the voice-interaction functionality you have requested.

2.6 Internet and Network Activity

Browsing history, search history, clickstream data, session replay recordings, heatmap data, and other information regarding your interaction with our websites, mobile applications, and advertisements. This includes the date and time of each visit, the pages or screens viewed, the duration of each session, referring and exit URLs, operating system type and version, browser type and version, device type and manufacturer, screen resolution, language preferences, and mobile network carrier information.

2.7 Geolocation Data

Precise geolocation data derived from GPS, Wi-Fi access point triangulation, cell tower signals, Bluetooth beacons, or IP-address-based geolocation when you grant permission through your device settings or browser preferences. We also collect coarse location information, such as city-level and ZIP-code-level location, inferred from your IP address for the purposes of fraud detection, regulatory compliance, and content localization.

2.8 Sensory Data

Audio recordings of customer service calls (with notice and, where required, consent), electronic communications including chat logs and email correspondence, and photographs or videos you upload in connection with vehicle listings, condition reports, insurance claims, or other features that support media attachments.

2.9 Vehicle-Specific Telemetry Data

For users of connected vehicle features, we may collect data from the vehicle’s onboard diagnostic systems, including but not limited to odometer readings, fuel or battery charge levels, tire pressure readings, engine diagnostic trouble codes (DTCs), geographic location history, trip logs, speed patterns, acceleration and braking metrics, and vehicle health and maintenance alerts. Such data is collected solely with the vehicle owner’s explicit consent and in accordance with the applicable connected-services agreement.

2.10 Professional and Employment-Related Information

If you apply for fleet management services, commercial financing, or business accounts, we may collect your professional title, employer name, employer identification number, business address, business telephone number, trade references, and any other information necessary to evaluate your eligibility for commercial or fleet-oriented products.

2.11 Inferences Drawn from Personal Information

We and our service providers may create profiles reflecting your preferences, characteristics, psychological trends, predispositions, behavior patterns, attitudes, intelligence, abilities, and aptitudes. These inferences are derived from the categories of data described above and are used to personalize your experience, recommend vehicles or services that may interest you, improve the accuracy of our predictive models, and deliver targeted advertising.

2.12 Sensitive Personal Information

Under the CPRA and similar state privacy laws, certain data elements constitute sensitive personal information. We may collect precise geolocation data (as described in Section 2.7), account log-in credentials in combination with any required security or access code, and, in limited circumstances, information concerning your health if you use accessibility features or file an insurance claim through the Services. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you. We only process sensitive personal information for the specific business purposes for which it was collected or as otherwise authorized by applicable law.

3. Sources from Which We Collect Personal Information

The personal information we collect is obtained from a diverse array of sources, each of which carries its own set of collection practices and disclosure obligations, which we have carefully integrated into our overall data governance framework. We categorize the principal sources as follows.

3.1 Direct Collection from You

We collect information directly when you create an account, fill out a form, subscribe to a newsletter, request a quote or pre-qualification, schedule a test drive, make a purchase, contact our customer support team by telephone, email, or chat, participate in a survey or promotion, upload content, or otherwise voluntarily submit information through the Services.

3.2 Automated Collection Technologies

As described in greater detail in Section 7 (Cookies and Tracking Technologies), we use cookies, web beacons, pixel tags, software development kits (SDKs), session replay scripts, and similar technologies to automatically collect information about your device and your interaction with the Services. We also collect log data generated by our servers and network infrastructure, including access logs, error logs, and security event logs.

3.3 Third-Party Business Partners

We receive information from affiliated and unaffiliated third parties, including but not limited to automobile manufacturers and authorized dealerships, financing institutions, insurance carriers, credit reporting agencies (with your consent where required), marketing and advertising networks, data analytics providers, social media platforms, payment processors, identity verification services, fraud prevention vendors, and lead-generation partners.

3.4 Publicly Available Sources

We may collect information from publicly accessible government databases (including vehicle registration records and DMV title databases), public social media profiles, business directories, trade publications, and other sources of information that are lawfully made available to the public.

3.5 Connected Vehicle and IoT Data Feeds

With your explicit consent, we receive telemetry and diagnostic data from connected vehicle platforms, aftermarket telematics devices, and original equipment manufacturer (OEM) data feeds that you have authorized to share vehicle data with our platform.

4. Business and Commercial Purposes for Collection and Processing

We collect, use, and otherwise process personal information for the business and commercial purposes enumerated below. Each purpose is linked to one or more categories of personal information described in Section 2, and we do not use personal information for purposes that are materially different from, or incompatible with, the purposes described herein without first providing you with additional notice and, where required by law, obtaining your affirmative consent.

4.1 Service Delivery and Fulfillment

We use personal information to process and fulfill your orders, complete transactions, deliver digital and physical products, schedule appointments, manage reservations, provide customer support, communicate about your account, and otherwise perform the core functions of the Services that you have requested.

4.2 Personalization and User Experience Enhancement

We use your preferences, behavioral data, and inferred interests to personalize the content, product recommendations, vehicle search results, financing offers, and advertisements that we display to you on and off the Services. This includes A/B testing features, optimizing page layouts, and customizing the user interface to improve usability and relevance.

4.3 Marketing, Advertising, and Promotional Communications

We use personal information to send you marketing communications — including email newsletters, SMS and MMS messages, push notifications, in-app messages, and direct-mail promotions — about our products, services, offers, and events that we believe may be of interest to you. Where required by law, we obtain your opt-in consent before sending such communications, and every marketing message includes a clear and conspicuous mechanism for opting out of future communications.

4.4 Research, Analytics, and Product Development

We analyze aggregated, pseudonymized, and de-identified data to understand user behavior, measure the effectiveness of our marketing campaigns, identify trends, develop new products and features, conduct market research, perform statistical modeling, and improve the overall quality and reliability of the Services.

4.5 Security, Fraud Detection, and Risk Mitigation

We monitor account activity, authenticate users, detect and prevent fraudulent transactions, investigate suspicious or unauthorized access events, enforce our Terms of Service, protect the rights and safety of our users and the public, and defend against legal claims. This includes the use of automated decision-making systems, including machine learning models, to identify patterns indicative of fraudulent or abusive behavior.

4.6 Legal Compliance and Regulatory Reporting

We process personal information as necessary to comply with applicable federal, state, and local laws, regulations, court orders, subpoenas, and other legal process; to respond to lawful requests from public and governmental authorities; to comply with tax, accounting, and financial reporting obligations; and to maintain records as required by applicable statutes of limitation and record-retention regulations.

4.7 Business Transfers and Corporate Transactions

In connection with a merger, acquisition, reorganization, sale of assets, joint venture, assignment, transfer, or other disposition of all or any portion of our business or assets, including in connection with any bankruptcy, dissolution, or similar proceeding, we may transfer or assign personal information to the relevant successor entity, subject to the terms of this Privacy Policy and applicable law.

5. Disclosure of Personal Information

We may disclose the categories of personal information identified in Section 2 to the following categories of recipients for the business purposes described in Section 4. We do not sell personal information for monetary consideration in the traditional sense; however, certain disclosures to advertising partners, analytics providers, and social media platforms in connection with interest-based advertising and cross-context behavioral advertising may constitute a sale or sharing under the laws of certain states. The categories of third parties with whom we share information, and the categories of personal information shared, are described below.

5.1 Service Providers and Contractors

We disclose personal information to vendors, consultants, and other service providers who perform functions on our behalf or at our direction, pursuant to written contracts that include privacy, confidentiality, and data security obligations at least as protective as those set forth in this Privacy Policy. These service providers include, but are not limited to, cloud hosting and infrastructure providers (such as Amazon Web Services, Google Cloud Platform, and Microsoft Azure), email delivery services, SMS gateway providers, payment processors, customer relationship management platforms, identity verification services, fraud detection and prevention services, data analytics and business intelligence platforms, customer support and live-chat software, survey and feedback platforms, and marketing automation tools.

5.2 Affiliated Entities

We may share personal information with current and future corporate affiliates, parent companies, and subsidiaries of QUBITOWL, INC. for purposes consistent with this Privacy Policy. Any such affiliate that receives personal information is contractually bound to adhere to privacy practices at least as protective as those described herein.

5.3 Automotive and Financial Partners

We may share information with automobile manufacturers, authorized dealerships, financing institutions, leasing companies, insurance carriers, and extended-warranty providers in connection with your requests for vehicle pricing, financing pre-qualification, insurance quotes, or warranty products. Such partners may use the information for their own purposes, and their privacy practices are governed by their respective privacy policies.

5.4 Advertising and Marketing Partners

We disclose limited categories of personal information — primarily online identifiers, internet activity data, and commercial information — to advertising networks, demand-side platforms, data management platforms, social media networks, and other partners that assist us in delivering interest-based advertisements and measuring advertising campaign performance. These disclosures may constitute a sale or sharing under certain state privacy laws. You have the right to opt out of such disclosures as described in Section 11.

5.5 Legal and Regulatory Recipients

We may disclose personal information to courts, law enforcement agencies, regulatory authorities, government bodies, and other third parties as we believe in good faith is necessary or appropriate to comply with applicable law, respond to valid legal process (including subpoenas, search warrants, and court orders), enforce our Terms of Service, protect our operations or those of our affiliates, protect our rights and the rights of others, investigate and defend against third-party claims or allegations, or protect the personal safety of our users or the public.

5.6 Professional Advisors

We may disclose personal information to our external legal counsel, auditors, accountants, consultants, and other professional advisors who require access to such information to provide professional services to QUBITOWL, INC., subject to the applicable professional obligations of confidentiality that bind those advisors.

5.7 Successors and Transferees

As described in Section 4.7, we may disclose or transfer personal information to a successor entity or third party in connection with a corporate transaction, including any due diligence process preceding such a transaction. In such event, we will use reasonable efforts to require that the recipient agrees to use personal information in a manner consistent with this Privacy Policy.

6. Data Retention

We retain personal information only for as long as is reasonably necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. The criteria we use to determine the appropriate retention period for each category of personal information include the nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, whether we can achieve those purposes through other means, and applicable legal obligations.

6.1 Retention Schedules by Data Category

Account and profile information is retained for the duration of your account’s active status plus a period of three (3) years following account closure, unless a longer retention period is required by law. Transaction records are retained for a minimum of seven (7) years to comply with tax and accounting obligations. Marketing preference records are retained indefinitely to ensure we respect your opt-out choices. Server and access logs are retained for eighteen (18) months. Call recordings and chat transcripts are retained for twelve (12) months. Vehicle telemetry data is retained for the duration of the connected-services agreement plus ninety (90) days.

6.2 Disposal and De-Identification

When personal information is no longer required, we securely dispose of or permanently de-identify it using methods designed to ensure that the data cannot be practicably re-identified or reconstructed, including cryptographic erasure, physical destruction of storage media, and irreversible anonymization algorithms, as appropriate to the nature of the data and the storage medium.

7. Cookies, Tracking Technologies, and Do-Not-Track Signals

We and our authorized third-party partners use cookies, web beacons, pixels, tags, SDKs, local storage objects, and similar technologies (collectively, Tracking Technologies) on the Services. These technologies enable us to recognize your browser or device, store your preferences and settings, understand how you interact with the Services, deliver and measure advertising effectiveness, and enhance security and fraud-detection mechanisms.

7.1 Types of Cookies We Use

Strictly Necessary Cookies are essential for the operation of the Services and enable core functionality such as user authentication, session management, security, and load balancing. These cookies cannot be disabled in our systems. Performance and Functionality Cookies collect information about how you use the Services, which pages you visit most often, and whether you encounter error messages, and allow us to remember choices you make (such as your language preference or vehicle search parameters) to provide enhanced, more personalized features. Targeting and Advertising Cookies are used to deliver advertisements that are relevant to your interests, limit the number of times you see an advertisement, and measure the effectiveness of advertising campaigns. These cookies may be set by us or by third-party advertising networks with our permission.

7.2 Cookie Management and Your Choices

Most web browsers automatically accept cookies but allow you to modify your browser settings to decline cookies, delete existing cookies, or alert you when a cookie is being sent. Please note that if you choose to block or delete cookies, certain features of the Services may not function properly, and your user experience may be degraded. You may also use industry-developed opt-out tools, such as the Network Advertising Initiative (NAI) opt-out page and the Digital Advertising Alliance (DAA) WebChoices tool, which allow you to opt out of interest-based advertising from participating companies.

7.3 Do-Not-Track Signals and Global Privacy Control

Some web browsers and browser extensions support a Do Not Track (DNT) signal or a Global Privacy Control (GPC) signal that communicates your preference regarding online tracking. When we detect a valid GPC signal from your browser, we automatically treat it as an opt-out of the sale and sharing of personal information and the processing of personal information for targeted advertising purposes for that browser and device. We do not currently respond to DNT signals because there is no universally accepted standard for how such signals should be interpreted; however, we continue to monitor developments in this area and may modify our practices in the future.

8. Children’s Privacy

The Services are not directed to individuals under the age of sixteen (16) years, and we do not knowingly collect personal information from children under the age of sixteen. In accordance with the federal Children’s Online Privacy Protection Act (COPPA) and analogous state laws, if we become aware that we have inadvertently collected personal information from a child under the age of sixteen without verifiable parental consent, we will take prompt steps to delete that information from our systems and terminate the associated account, if any. Parents and legal guardians who believe that their child has provided us with personal information without their consent should contact us immediately using the information provided in Section 14 so that we may take appropriate remedial action.

8.1 Teen Drivers and Graduated Licensing

Certain features of our Services — particularly those related to financing pre-qualification, insurance quoting, and vehicle purchase — require users to be of legal age to enter into binding contracts. We implement age-verification mechanisms where feasible and may restrict access to specific features for users who cannot verify that they meet applicable age thresholds. We comply with state-specific graduated driver licensing (GDL) regulations and do not knowingly facilitate transactions that would violate the GDL restrictions of any jurisdiction.

9. Data Security

QUBITOWL, INC. implements and maintains a comprehensive information security program consisting of administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of the personal information in our possession. These safeguards are calibrated to account for the sensitivity of the data, the risks posed by unauthorized access and disclosure, and the evolving threat landscape.

9.1 Administrative Safeguards

We maintain written information security policies and procedures that are reviewed and updated at least annually. All employees and contractors receive privacy and security training at onboarding and on a recurring annual basis. Access to personal information is restricted to personnel with a legitimate business need, and access privileges are reviewed on a quarterly basis. We conduct periodic risk assessments, maintain an incident response plan, and carry cyber-insurance coverage commensurate with our risk profile.

9.2 Technical Safeguards

We employ encryption at rest and in transit using industry-standard protocols, including Transport Layer Security (TLS) 1.3 for all data transmitted between your browser and our servers, and AES-256 encryption for sensitive data stored in our databases. We deploy network firewalls, intrusion detection and prevention systems (IDS/IPS), endpoint detection and response (EDR) solutions, multi-factor authentication for administrative access, automated vulnerability scanning, and regular penetration testing conducted by independent third-party security assessors.

9.3 Physical Safeguards

Our physical infrastructure — whether owned or leased — is protected by biometric access controls, 24/7 video surveillance, redundant power and environmental controls, and on-site security personnel where appropriate. We rely on SOC 2 Type II-certified and ISO 27001-certified data center providers for our primary hosting infrastructure.

9.4 No Guarantee of Absolute Security

Despite our best efforts and the robust safeguards we have implemented, no method of electronic transmission or storage is one hundred percent secure. We cannot and do not guarantee that personal information will be absolutely secure against every possible threat. In the event that a security breach affects your personal information, we will notify you and the appropriate regulatory authorities in accordance with applicable breach notification statutes, and we will take all reasonable steps to mitigate the impact of the breach and prevent its recurrence.

10. Third-Party Websites, Plugins, and Services

The Services may contain links to third-party websites, embedded content, social media plugins, and other resources that are not owned, operated, or controlled by QUBITOWL, INC. This Privacy Policy does not govern the privacy practices of those third parties. We are not responsible for the content, privacy policies, or data-handling practices of any third-party website or service, even if you access them through links or integrations made available on the Services.

10.1 Third-Party Authentication and Social Login

If you choose to log in to the Services using a third-party authentication provider — such as Google, Apple, or Facebook — that provider may share certain profile information with us in accordance with its own privacy policy and the permissions you grant during the authentication process. We encourage you to review the privacy settings and policies of any social media platform or authentication provider you use in conjunction with the Services.

10.2 Embedded Content and Widgets

Certain pages of the Services may include embedded content (such as vehicle configurators, financing calculators, insurance quoting widgets, video players, and interactive maps) that is hosted and served by third parties. Interacting with such embedded content is governed by the privacy practices of the third-party provider, not by this Privacy Policy. We recommend that you review the privacy policies of these third-party providers before interacting with their embedded content.

11. Your Privacy Rights and Choices

Depending on your state of residence and the nature of your relationship with us, you may have certain rights with respect to the personal information we hold about you. We honor all verifiable consumer requests submitted in accordance with this section, regardless of where you reside within the United States. The following is a comprehensive enumeration of the privacy rights that may be available to you.

11.1 Right to Know and Access

You have the right to request that we disclose to you the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting, selling, or sharing the information, and the categories of third parties to whom we have disclosed the information. You may submit a request to know up to twice within any twelve-month period.

11.2 Right to Correction

You have the right to request that we correct inaccurate personal information that we maintain about you, taking into account the nature of the information and the purposes for which we process it. If you identify information in your account that you believe is inaccurate, you may correct it directly through your account settings, or you may contact us using the information in Section 14 to request a correction.

11.3 Right to Deletion

You have the right to request that we delete personal information we have collected from you, subject to certain exceptions. We may deny your deletion request — in whole or in part — if retaining the information is necessary for us or our service providers to complete the transaction for which the information was collected, detect security incidents and protect against malicious or fraudulent activity, debug and repair errors, exercise free-speech rights, comply with a legal obligation, or otherwise use the information internally in a lawful manner that is compatible with the context in which you provided it.

11.4 Right to Opt Out of Sale and Sharing

You have the right to direct us not to sell your personal information to third parties for monetary or other valuable consideration, and not to share your personal information for cross-context behavioral advertising purposes. You may exercise this right by clicking the Do Not Sell or Share My Personal Information link available in the footer of every page of the Services, by broadcasting a Global Privacy Control (GPC) signal through your browser, or by contacting us using the information provided in Section 14.

11.5 Right to Limit Use of Sensitive Personal Information

You have the right, subject to certain exceptions, to direct us to limit our use and disclosure of your sensitive personal information to those uses that are necessary to perform the Services, fulfill your requests, or as otherwise authorized by applicable regulations. We currently do not use or disclose sensitive personal information for purposes beyond those expressly authorized by the CPRA, and as a result, no additional mechanism for exercising this right is strictly necessary at this time.

11.6 Right to Data Portability

You have the right to request a copy of your personal information in a structured, commonly used, and machine-readable format, to the extent technically feasible. Where your request relates to information processed by automated means and you initially provided the information with consent or for the performance of a contract, we will use commercially reasonable efforts to deliver the information directly to you or, at your direction, to another entity.

11.7 Right to Non-Discrimination

We will not discriminate against you for exercising any of the privacy rights enumerated in this Section 11. Specifically, we will not deny you goods or services, charge you different prices or rates, provide a different level or quality of goods or services, or suggest that you may receive a different price or level of quality because you exercised a privacy right. However, we may offer certain financial incentives — such as loyalty programs or promotional discounts — that are reasonably related to the value of your data, provided that we give you prior notice, obtain your opt-in consent, and allow you to withdraw from the incentive program at any time.

11.8 Right to Appeal

If we deny your privacy request in whole or in part, we will inform you of the reason for the denial and provide you with instructions for how you may appeal our decision. You may submit an appeal by contacting us using the information in Section 14 and referencing the request number we provided in our denial response. We will review your appeal and respond in writing within the timeframe prescribed by applicable law. If your appeal is denied, we will provide you with information on how to contact your state attorney general’s office or other relevant regulatory authority to submit a complaint.

11.9 Authorized Agents

You may designate an authorized agent to submit privacy requests on your behalf. We will require the authorized agent to provide proof of their authority to act on your behalf — such as a valid power of attorney or a notarized letter of authorization — and we may also require you to verify your identity directly with us before we process the request. We reserve the right to deny requests from agents who cannot demonstrate valid authorization.

11.10 Verification Procedures

To protect the security of your personal information, we are required to verify your identity before processing your privacy request. Verification procedures vary depending on the nature and sensitivity of the request. For requests to know or delete categories of personal information, we typically require you to confirm certain data points we already hold about you. For requests for specific pieces of personal information or requests involving sensitive data, we may require enhanced verification — including a notarized affidavit, a video-identification session, or similar measures — to reduce the risk of unauthorized disclosures.

11.11 State-Specific Disclosures

California Residents: Pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), California residents have all the rights enumerated above. The categories of personal information we have collected, the sources, and the business purposes are detailed in Sections 2, 3, and 4 respectively. The categories of personal information we have disclosed for a business purpose and the categories of third-party recipients are detailed in Section 5. The categories of personal information we have sold or shared in the preceding twelve months are identifiers, internet activity data, and commercial information, disclosed to advertising networks and social media platforms for the purpose of cross-context behavioral advertising. We have no actual knowledge of selling or sharing the personal information of consumers under sixteen years of age. Colorado, Connecticut, Virginia, and Utah Residents: Residents of these states have rights substantially similar to those described in this Section, as provided under the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Virginia Consumer Data Protection Act (VCDPA), and the Utah Consumer Privacy Act (UCPA), respectively. The applicable rights, exceptions, and procedures set forth in each respective statute govern our processing of personal information belonging to residents of those states.

12. International Data Transfers and Non-U.S. Users

Although QUBITOWL, INC. is a United States-based company and the Services are primarily designed for a United States audience, we recognize that individuals located outside the United States may access the Services. This section applies to users located in the European Economic Area (EEA), the United Kingdom (UK), Switzerland, Canada, Australia, and any other jurisdiction with data protection laws that regulate cross-border data transfers.

12.1 Legal Basis for Processing (EEA, UK, and Swiss Users)

Where GDPR, UK GDPR, or Swiss data protection law applies, we process personal information on the following legal bases: (a) your consent, where you have given clear, affirmative consent for a specific processing purpose; (b) the performance of a contract with you or to take pre-contractual steps at your request; (c) compliance with a legal obligation to which we are subject; and (d) our legitimate interests, provided that those interests are not overridden by your fundamental rights and freedoms. You have the right to withdraw consent at any time, though such withdrawal will not affect the lawfulness of processing carried out before the withdrawal.

12.2 Cross-Border Transfer Safeguards

Personal information transferred from the EEA, UK, or Switzerland to the United States is protected by the Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner’s Office, as applicable. We conduct transfer impact assessments (TIAs) for each cross-border data flow and implement supplementary technical, contractual, and organizational measures where the TIA identifies residual risks. A copy of the relevant SCCs is available upon request by contacting us at the address or email provided in Section 14.

12.3 Rights of Non-U.S. Data Subjects

In addition to the rights enumerated in Section 11, individuals located in the EEA, UK, and Switzerland have the right to request restriction of processing, the right to object to processing based on legitimate interests or for direct marketing purposes, and the right to lodge a complaint with their local supervisory authority. If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to challenge the accuracy and completeness of your information. Australian residents have rights under the Privacy Act 1988 (Cth), including the right to access and correct personal information and to complain to the Office of the Australian Information Commissioner (OAIC).

13. Changes to This Privacy Policy

We reserve the right to update, modify, or replace this Privacy Policy at any time and in our sole discretion. When we make material changes, we will post the revised policy on this page and update the Last Updated date at the top of the document. For changes that materially affect the way we use or disclose personal information that we have previously collected from you, we will provide you with additional notice — which may include an email notification, a prominent banner on the Services, an in-app alert, or such other notification method as we deem appropriate in the circumstances.

13.1 Your Obligation to Review

It is your responsibility to review this Privacy Policy periodically for changes. Your continued use of the Services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the revised terms. If you do not agree with any change to this Privacy Policy, you must immediately cease all use of the Services and may request deletion of your personal information in accordance with Section 11.3.

13.2 Archived Versions

We maintain an archive of prior versions of this Privacy Policy for a period of no fewer than four (4) years. If you wish to review a prior version, you may contact us using the information provided in Section 14, and we will make reasonable efforts to furnish the requested version within a commercially reasonable time frame.

14. Contact Information, Inquiries, and Complaint Resolution

If you have any questions, concerns, requests, or complaints regarding this Privacy Policy, our data practices, or your rights with respect to your personal information, please contact us using any of the channels listed below. We endeavor to acknowledge all privacy-related inquiries within five (5) business days and to provide a substantive response within thirty (30) calendar days, unless a shorter response period is mandated by applicable law.

14.1 Corporate Contact Details

QUBITOWL, INC.
Attn: Privacy Office / Data Protection
2825 E Cottonwood Pkwy
Salt Lake City, Utah 84121-7055
United States (US)

Email: office@qubiowl.autos
Phone: +1 (276) 305-9102
Website: www.qubiowl.autos

14.2 Privacy Request Web Portal

To streamline the submission of privacy rights requests under Section 11, we maintain a dedicated privacy request portal accessible through the footer of every page of the Services. This portal allows you to submit access requests, deletion requests, correction requests, and opt-out requests, and to track the status of your submissions through a unique reference number. You may also submit requests by email to the address listed above or by calling our toll-free privacy line.

14.3 Supervisory Authority Complaint Rights

If you are not satisfied with our resolution of your privacy concern, you have the right to file a complaint with the appropriate supervisory authority. In the United States, you may contact the Federal Trade Commission (FTC), your state attorney general’s office, or the California Privacy Protection Agency (CPPA) if you are a California resident. Residents of the EEA may contact their national Data Protection Authority (DPA). UK residents may contact the Information Commissioner’s Office (ICO). We encourage you to contact us first so that we have an opportunity to address your concerns directly, but you are not required to do so as a precondition to contacting a regulatory body.