Privacy Policy
Last updated
Effective date: August 12, 2026
This Privacy Policy explains how Kielves, Inc. (“Kielves,” “Bounceless,” “we,” “us,” or “our”) handles personal information in connection with the Bounceless business-to-business website, application, API, support, billing, email verification, and Pre-Send Decision service (collectively, the “Service”).
Kielves, Inc. is a Delaware corporation with file number 10722519. Our public notice address is Kielves, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Our privacy contact is Privacy at privacy@bounceless.io.
This Policy does not replace a Customer’s own privacy notices or obligations. Customers decide which email addresses to submit and remain responsible for having authority and a lawful basis to do so.
1. Scope and data-protection roles
This Policy applies to personal information handled through the Service and our direct business interactions. It does not apply to third-party sites or services governed by their own policies.
Kielves determines how it handles account, website, billing, security, and direct business-administration information. Customers determine which email addresses they submit for verification and instruct Kielves to process those addresses to provide the Service. Each party remains responsible for the legal obligations that apply to its own handling of personal information, subject to any separate signed data-processing terms.
The launch Service is not offered in the European Economic Area or the United Kingdom. We do not represent that EEA- or UK-specific supplements, representatives, or supervisory-authority arrangements are in place.
2. Personal information we handle
Depending on how the Service is used, we may handle:
- Account and business-contact information: name, work email address, company, role, account identifiers, authentication and account-security information, and preferences.
- Verification inputs and outputs: email addresses submitted for verification, request metadata, verification signals, result classifications, reason information, and Pre-Send Decisions.
- Billing and transaction information: purchase, credit-balance, receipt, payment-status, refund, dispute, and transaction-reference information. Checkout uses standard Stripe Payments services. Kielves is the seller of record and Stripe is its payment processor. Kielves receives card brand, last four digits, expiry, billing country and postal code, and transaction references, but never receives full card numbers.
- Service and device information: IP address, browser or device information, timestamps, API and application events, diagnostic information, security events, and feature interactions reasonably needed to operate and protect the Service.
- Communications: support requests, feedback, legal notices, and other messages sent to us.
- Website technology data: signing in to the Bounceless application sets one strictly necessary first-party authentication cookie,
bnc_session. It is HttpOnly, Secure, SameSite=Lax, limited to the/path, expires after 14 days, and is deleted on sign-out or when a session is invalid. The launch website build does not load Gist or Tapfiliate. Google Tag Manager containerGTM-M8WRPTZ3may be used for Google Analytics 4 on the website and the application, which may set_gaand_ga_*, together with strictly necessary session and consent cookies. DataFast (publisher DataFast) provides website and application analytics on all pages and may set first-party audience-measurement cookies as described at https://datafa.st/docs. To object, request access, or ask for deletion of analytics data we control, email privacy@bounceless.io.
Please do not submit data that the Service does not request, especially credentials, message bodies, government identifiers, payment-card details outside the designated checkout, health data, or other sensitive personal information.
3. Sources of personal information
We receive information directly from account users and Customers; automatically from browsers, devices, application and API use; from Stripe in connection with checkout and transaction administration; and from service providers acting on our behalf. We may also receive business-contact information when someone communicates with us or is designated by their organization as an account or legal contact.
We do not obtain Customer verification inputs for the purpose of creating or selling a prospect database.
4. Why we use personal information
We use personal information to:
- create and administer accounts, authenticate users, and provide the Service;
- process verification requests and return verification information and Pre-Send Decisions;
- calculate credit usage, ensure unknown or indeterminate results are not billed, and maintain non-expiring credit balances;
- enable checkout and administer transactions through Stripe;
- secure, troubleshoot, monitor, and prevent abuse of the Service;
- respond to support, privacy, and legal requests;
- comply with law, enforce agreements, and establish or defend legal claims; and
- improve reliability and performance using privacy-preserving, aggregate, or de-identified operational learning that does not identify a Customer or individual, disclose Customer Data, recreate customer-readable verification records, or retain those records beyond the governed ordinary window.
We do not use submitted email lists to send campaigns on a Customer’s behalf or to build a prospect database.
5. How we disclose personal information
We may disclose personal information:
- To service providers that host, secure, support, analyze, or otherwise help operate the Service, under contractual restrictions appropriate to their role.
- To Stripe for checkout, payment, and transaction administration. Stripe processes full card details; Kielves receives card brand, last four digits, expiry, billing country and postal code, and transaction references. Kielves remains seller of record and owns tax, invoice, refund, dispute, and chargeback obligations described in the Terms.
- To a Customer organization and its authorized administrators for account administration and Service results.
- For legal and safety reasons when reasonably necessary to comply with law or valid process; protect rights, safety, and security; investigate fraud or abuse; or enforce agreements.
- In a corporate transaction involving a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality and applicable privacy law.
- With direction or consent where the relevant person or Customer instructs or authorizes the disclosure.
Our launch service-provider inventory includes Stripe, Cloudflare, Hivelocity, Resend, Spamhaus, and DataFast (website and application analytics). We disclose information to them only as described above and as needed for the services they provide. Customer-submitted email lists are not sold or used to build a prospect database.
6. Retention and deletion
Our retention policy sets a 30-day ordinary window for email addresses submitted for verification, uploaded source files, generated result files, and exports, measured from finalization of a verification job. The intended process erases a submitted address in place while retaining non-identifying verification facts, and deletes the underlying stored files with an internal audit record. Customers can view and export their own requests and results but cannot configure this window or invoke self-service deletion; early-deletion requests are handled by our team.
Account, transaction, tax, invoice, refund, chargeback, support, security, and legal records may be retained for different periods when reasonably needed for the purposes described in this Policy, to meet legal or accounting obligations, to resolve disputes, or to protect the Service. We delete or de-identify them when those purposes no longer require them, subject to applicable law and ordinary backup cycles.
Privacy-preserving durable learning must not identify a Customer or individual, disclose Customer Data, allow reconstruction of customer-readable verification records, or operate as a way to keep those records beyond their approved window.
When a verified retention process reaches its end, we delete or de-identify information using measures appropriate to the system and data. Result-file deletion removes the stored object and records an internal audit event. No shorter backup-deletion promise is made until an approved and verified backup lifecycle exists.
7. International data transfers
The Bounceless application, database, queue, and verification engine run on dedicated infrastructure operated by Hivelocity in the United States. The public website is served through Cloudflare. Uploaded lists, verification results, and database backups are stored with Cloudflare R2. The governed R2 buckets are currently placed in Cloudflare’s Western Europe region, but no contractual jurisdictional restriction is configured, so this is not an EU-only or single-country storage guarantee. Stripe, Resend, Spamhaus, and other service providers may process information in the regions where they operate. We use contractual and other safeguards where applicable, but we do not promise storage in a particular country.
We will not claim a transfer mechanism, local representative, or regional availability until it is approved and implemented.
8. Security
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. Connections to our website, application, and API are encrypted in transit. Passwords, where used, are stored only as salted cryptographic hashes and never in readable form; API keys and administrative tokens are stored only as irreversible digests. Session cookies are restricted to HTTPS, are not readable by scripts, and expire automatically. Sensitive research records are encrypted at rest. Result files are not public objects; downloads use individually authorized, short-lived links. Internal maintenance interfaces require authenticated internal credentials and fail closed when those credentials are absent. Deletions are recorded in an internal audit trail. To report a suspected vulnerability, email legal@bounceless.io with “Security report” in the subject line.
No service can guarantee absolute security. Customers are responsible for securing their credentials, limiting authorized users, and using the Service in accordance with their own security and privacy obligations.
9. Privacy choices and rights
Depending on where a person lives and the context in which we handle information, they may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to appeal or complain to a regulator. These rights may be limited by law, the Customer’s instructions, the need to authenticate a request, and legitimate retention obligations.
To make a privacy request, email privacy@bounceless.io. The working public intake mechanism is email; the website contact route was not live at the pinned audit. The identity-verification method, authorized-agent process, appeal route, response timing, and jurisdiction-specific rights remain subject to counsel review for the approved launch geography.
When we process submitted verification data only on a Customer’s instructions, we may direct the requester to that Customer or assist the Customer as required by applicable law and the governing data-processing terms.
Website and application analytics are provided by DataFast using first-party audience-measurement cookies, as described at https://datafa.st/docs. Google Tag Manager / GA4 may also run as described above. To object, request access, or ask for deletion of analytics data we control, email privacy@bounceless.io.
Every Bounceless marketing email includes a one-click unsubscribe link, and unsubscribe requests made through a mail client’s built-in unsubscribe control are honored automatically. A person is added to that list only after confirming the address through a confirmation email. Service and legal notices may still be sent when necessary to administer an account or agreement.
10. Children
The Service is designed only for business use by account holders aged 18 or older and is not directed to children. If you believe a child’s information was submitted, contact privacy@bounceless.io so we can investigate and take appropriate action.
11. Automated processing
The Service produces verification information and Pre-Send Decisions about email-address handling. These outputs support a Customer’s operational sending decision; they are not intended to make decisions that produce legal or similarly significant effects on an individual. Customers must not use an output as the sole basis for such a decision.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will give account holders at least 30 days’ email notice before a material change takes effect and will identify the current effective date above. Continued use after that date constitutes acceptance; a change will not reduce an existing credit balance.
13. Contact and complaints
Questions, requests, and complaints about this Policy should be sent to:
Kielves, Inc.
Attn: Privacy
c/o Legalinc Corporate Services Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, USA
privacy@bounceless.io
No telephone contact is published.