Privacy at Agility Business Services
We build several products, and they handle data very differently. Rather than blur that into one vague policy, each product has its own — stated plainly below. Choose the product you use. Agility Business Services, Inc. is the controller for all three.
Quantum Trading Platform — Privacy Policy
A product of Agility Business Services, Inc. · Effective August 1, 2026
Not investment advice. The Quantum Trading Platform and its signals, scores, and analytics are provided for informational and educational purposes only. Agility Business Services is not a broker-dealer, investment adviser, or financial planner, and nothing on the platform is a recommendation to buy or sell any security. Trading involves risk, including the loss of principal. You are solely responsible for your own decisions.
This policy explains how we collect, use, and protect information when you use the Quantum Trading Platform — including the QET Portfolio Intelligence calculator, the signal pipeline, the P&L dashboard, and any connected brokerage features.
United States only. The Quantum Trading Platform is offered solely to residents of the United States and is not directed to, or intended for use by, anyone outside the US. It is governed by the laws of the State of North Carolina and applicable US federal law.
1. Information we collect
Information you provide
- Account and contact details — your name, email address, and anything you submit through early-access, demo-request, or contact forms.
- Trading inputs and preferences — tickers, watchlists, portfolio configurations, and strategy settings you enter into the calculator or pipeline.
- Communications — support requests, feedback, and correspondence you send us.
Information collected automatically
- Device and connection data — IP address, browser type, operating system, and similar technical identifiers.
- Usage data — pages viewed, features used, timestamps, and interaction patterns, used to operate and improve the platform.
- Cookies — strictly necessary cookies for authentication and security, and limited, privacy-respecting analytics. We do not use advertising cookies or cross-site tracking. See §5.
Information from third parties
- Market data providers — we ingest real-time and historical market data from third-party financial data services to power the signal engine. This concerns publicly traded securities, not your personal data.
- Brokerage connections — if you connect a brokerage account, we receive order status and position data required to place and monitor trades on your behalf. We never receive or store your brokerage password or funding credentials.
2. How we use your information
- Operate, maintain, and improve the platform and the signal pipeline.
- Generate and deliver signals, risk analytics, and portfolio intelligence you request.
- Place and monitor paper trades, and — only where you have explicitly connected and authorized a live account — live trades, subject to our safety gates and human sign-off.
- Maintain a complete, queryable audit trail of trading decisions, which is core to how the platform is designed to operate.
- Respond to your inquiries and provide support.
- Meet legal, regulatory, and financial-recordkeeping obligations.
3. How we share information
We do not sell your personal information. We share it only as needed to run the service:
- Service providers — hosting (Vercel), database and authentication (Supabase), email delivery, and infrastructure partners that process data on our behalf under contract.
- Brokerage partners — when you connect an account, we transmit order instructions and receive execution data through their API.
- Legal and safety — where required by law, regulation, subpoena, or to protect rights, property, or safety.
- Business transfers — in a merger, acquisition, or sale of assets, subject to this policy.
4. Data retention
We keep personal information while your account is active or as needed to provide the service. Because trading records can carry recordkeeping obligations, decision and audit records may be retained longer where required by law or regulation. You may request deletion at any time (§7); we will honor it except where retention is legally required.
5. Cookies and tracking
We use strictly necessary cookies for authentication and security, and limited first-party analytics to understand usage. We do not use advertising cookies, and we do not participate in cross-site tracking. You can control cookies through your browser settings.
6. Security
- TLS/HTTPS encryption for data in transit.
- Encrypted storage for sensitive credentials and API keys.
- Row-level security and role-based access controls on the database.
- A full audit log of trading and gate decisions, plus a kill switch and exposure limits.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
7. Your rights and choices
Depending on your US state of residence (for example, under the California CPRA and comparable state laws), you may have the right to know, access, correct, and delete your personal information, to opt out of its sale or sharing (we do not sell or share it), and to non-discrimination for exercising these rights. To exercise any right, contact us at admin@agilityserv.com. We will verify your request and respond within the time required by applicable law.
8. Children's privacy
The Quantum Trading Platform is intended for adults 18 and older. We do not knowingly collect information from anyone under 18.
9. Changes
We may update this policy and will revise the "last updated" date above. Material changes will be communicated on this page before they take effect.
Quantlys Vertical AI Platform — Privacy Policy
A product of Agility Business Services, Inc. · Effective August 1, 2026
Quantlys is local-first by architecture. Your source code, your API keys, and the content of what you build stay on your own machine. There is no Quantlys cloud that reads your work — not because we promise not to, but because the product is built so the data never reaches us.
This policy explains the narrow set of information we do handle to run the Quantlys website and beta program, and — just as importantly — what we deliberately never touch.
1. What stays on your machine (and never reaches us)
- Your source code and project files. The council builds on your hardware; code is written, compiled, and signed locally.
- Your API keys. Model-provider keys live in your own keychain. They are used from your machine and are never transmitted to or stored by us.
- Your prompts and the content of your work. When the platform calls an AI model, the request goes from your machine to the provider whose key you supplied — we are not in that path.
- Your signing certificate and the apps you produce. They are yours, signed by your own Apple developer identity, on your Mac.
2. What we do collect
Information you provide
- Account and early-access details — name, email, and anything you submit through beta-access or contact forms.
- Feedback — bug reports, feature requests, and messages you choose to send us.
Information collected automatically
- Website analytics — limited, privacy-respecting usage data for the marketing site (pages viewed, referrer, approximate region). No advertising cookies, no cross-site tracking.
- Beta metering — during any promotional period where we cover model tokens, we process the minimum usage metadata needed to apply that credit. We do not read the content of your prompts to do so.
3. Third parties in the loop
- AI model providers — the providers whose keys you bring. Your prompts reach them directly from your machine, under their terms and privacy policies. We encourage you to review them.
- Apple — used to sign and distribute the apps you build (including to TestFlight). The developer relationship and account are yours.
- Our service providers — website hosting and email delivery for the marketing site and beta communications.
4. How we use what we collect, and our legal bases
We process the limited personal information described above to operate the website, run the beta program, respond to inquiries, and improve the product using feedback and aggregate, non-identifying usage. Where the GDPR, UK GDPR, or similar laws apply, we rely on these legal bases:
- Performance of a contract — to provide the beta and the services you request.
- Consent — for optional marketing emails and any non-essential analytics; you may withdraw it at any time.
- Legitimate interests — to secure our systems, prevent abuse, and improve the product, balanced against your rights.
- Legal obligation — to comply with laws that apply to us.
5. Sharing
We do not sell your personal information and do not "share" it for cross-context behavioral advertising. We disclose the limited data we hold only to service providers acting on our documented instructions, where required by law, or in a business transfer subject to this policy.
6. International data transfers
We are based in the United States and our service providers may process data in the US and other countries. When we transfer personal information out of the EEA, the UK, India, or Australia, we use appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent contractual protections — so your information carries protection comparable to that of your home jurisdiction. You may request a copy of the safeguards we use.
7. Security & breach notification
The strongest protection is architectural: data we never collect cannot be breached on our side. For the limited information we do hold, we use TLS in transit, encrypted storage, and access controls. No system is perfectly secure. If a breach affecting your personal information occurs, we will notify you and the relevant regulators within the timeframes required by applicable law — including the GDPR/UK GDPR (without undue delay, and to the supervisory authority within 72 hours where required), Australia's Notifiable Data Breaches scheme, and India's Digital Personal Data Protection Act.
8. Your rights — everywhere, and by region
Whoever and wherever you are, you can ask us to access, correct, or delete the personal information we hold, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent. Because Quantlys is local-first, most of your work never reaches us — data that only ever existed on your own machine is already under your sole control, and there is nothing on our side to act on.
European Economic Area & United Kingdom (GDPR / UK GDPR)
You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ICO). We will not require a fee or make your rights conditional on unrelated terms.
India (Digital Personal Data Protection Act, 2023)
As a Data Fiduciary, we process your personal data on the basis of your consent or a legitimate use, after clear notice. As a Data Principal you may access and correct your data, request erasure, nominate another person to exercise your rights, and seek grievance redressal. You may withdraw consent as easily as you gave it. Grievances can be raised with our contact below and, if unresolved, escalated to the Data Protection Board of India.
Australia (Privacy Act 1988 & the Australian Privacy Principles)
You may request access to and correction of your personal information. We will tell you before disclosing personal information to overseas recipients (APP 8) and take reasonable steps to ensure it is handled consistently with the APPs. If you are unhappy with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
United States (California CPRA and similar state laws)
You may request to know, delete, and correct your personal information, and opt out of its sale or sharing (we do not sell or share it). We will not discriminate against you for exercising these rights.
To exercise any right, email admin@agilityserv.com and tell us your region so we can apply the correct process. We will verify your request and respond within the time your law requires.
9. Children's privacy
Quantlys is intended for adults aged 18 and older, and we do not knowingly collect personal information from anyone under 18. We set the threshold at 18 deliberately so that we do not process the data of a "child" as defined by India's DPDP Act (which treats anyone under 18 as a child requiring verifiable parental consent) or of a minor under other applicable laws. If you believe a minor has provided us information, contact us and we will delete it.
10. Grievance & privacy contact
Our privacy and grievance contact for all regions is admin@agilityserv.com (Agility Business Services, Inc., Apex, North Carolina, USA). Users in India may use this address to reach our grievance officer function under the DPDP Act. We aim to acknowledge requests promptly and resolve them within the period your local law prescribes.
11. Changes
We may update this policy and will revise the "last updated" date. Material changes will be posted here before taking effect, and where the law requires, we will seek your fresh consent.
Turtle Rock Dodge — Privacy Policy
A product of Agility Business Services, Inc. · Effective August 1, 2026
Turtle Rock Dodge does not collect any data. Not your name, not your email, not your location, not your device identifiers, and not how you play. There is nothing for us to store, share, or lose.
What we collect
Nothing. Turtle Rock Dodge is a game, and only a game. It does not ask you for information and it does not gather any in the background. Specifically, it does not collect:
- Personal information — name, email, phone number, or postal address
- Account credentials — there are no accounts and no sign-in
- Location data of any kind, precise or approximate
- Device identifiers, advertising IDs, or persistent tracking identifiers
- Usage or gameplay analytics, session recordings, or crash telemetry
- Contacts, photos, camera, microphone, calendar, or files
- Payment or financial information
Cookies and tracking
The game uses no cookies, web beacons, pixels, or fingerprinting. It contains no third-party analytics SDKs, no advertising networks, and no social media trackers.
Data sharing
We do not share, sell, rent, or disclose your data to anyone — because we never have any. There are no advertisers, data brokers, or partners receiving information about you from this game.
Data storage and retention
Because no data is collected, none is transmitted to us and none is retained. Any game progress or settings stay on your own device, under your control, and are removed if you delete the game.
Children's privacy
Turtle Rock Dodge is suitable for players of all ages. We do not knowingly or unknowingly collect information from children, because we do not collect information from anyone. The game requires no personal details to play.
Your rights
Laws such as the GDPR and CCPA give you rights over personal data a company holds about you. We hold none, so there is nothing to access, correct, delete, or port. If you would like written confirmation of this, contact us and we will provide it.
Changes to this policy
If Turtle Rock Dodge ever changes so that it does collect data, we will update this policy and revise the effective date before that change takes effect. We will not begin collecting anything under the cover of this notice.
Contact & data controller
All three products are operated by Agility Business Services, Inc., Apex, North Carolina, USA. For any privacy question or to exercise a data right, email admin@agilityserv.com and name the product your request concerns.