Version 1.0 · July 2026 · Draft published for transparency, pending counsel review

Winback Data Use Agreement

Canonical text: v1.0.txt — the file whose hash is recorded with every acceptance.
SHA-256: eef4b4d5a4c310f0f4a3cf78403ad9545ad95b2ee17689314c2db24cf4c99f03
Revisions are published as new versions and apply prospectively only.

1Parties and Acceptance

This Data Use Agreement (the "Agreement") is between Winback LLC, a New York limited liability company ("Winback," "we," "us"), and the company on whose behalf you connect a Klaviyo account ("Customer," "you"). You accept this Agreement by checking the acceptance box and connecting your account. You represent that you are authorized to act for Customer and to grant the access described below. We record the version and SHA-256 hash of the Agreement text you accepted, together with a timestamp.

2The Service

Winback provides a free retention audit: we collect a read-only copy of your Klaviyo program data, analyze it, compare it against our benchmarks, and deliver sized findings through a live readout and a private audit page (the "Service"). The Service is provided at no charge and creates no obligation for either party to enter any further engagement.

3Access and Scope

Your OAuth grant is limited to the following read-only scopes: accounts:read, campaigns:read, flows:read, metrics:read, lists:read, segments:read, templates:read, forms:read. We request no write access of any kind. We do not request profile-level or event-level scopes, and we will not collect individual-consumer data (including customer profiles, individual email addresses, or individual behavioral events) through the grant. Segment and list data is limited to definitions, not membership. You may revoke access at any time in Klaviyo (Settings > Integrations) or by written notice to dean@winback.pro; revocation disables all further access.

4Purpose Limitation

Winback will access and process Customer Data solely to: (a) produce and deliver the audit and related analyses; (b) present and discuss findings with Customer; (c) maintain Customer's private deliverable; and (d) create De-identified Aggregated Data as defined in Section 5. No other use is permitted. "Customer Data" means all data retrieved from your Klaviyo account under this Agreement, together with your credentials and tokens.

5De-identified Aggregated Data

Winback may create and retain data derived from Customer Data that (i) does not identify Customer, any individual, or any specific campaign or creative; (ii) is combined with data from no fewer than nine (9) other brands before any use or publication; and (iii) cannot reasonably be re-identified. Winback may use such De-identified Aggregated Data perpetually for benchmarking, research, product improvement, and published insights. This right survives revocation and deletion; upon deletion, no identifiable Customer Data remains in any aggregate source.

6Competitive-Intelligence Wall

Winback operates and may commercialize competitive-intelligence capabilities that analyze publicly available marketing communications (for example, emails received by inboxes Winback operates as an ordinary subscriber). Winback represents and covenants that: (i) such capabilities run on infrastructure physically and logically separate from the systems that store Customer Data; (ii) Customer Data — including credentials, tokens, and anything retrieved under this Agreement — will never be used in, transferred to, or accessible by such capabilities; and (iii) no competitive-intelligence output is derived, in whole or in part, from Customer Data.

Client Exclusion: For so long as Customer is under an active managed-services agreement with Winback, Winback will additionally exclude Customer's brands from prospective collection by such capabilities.

7No Sale; Limited Disclosure

Winback will never sell Customer Data. Winback discloses Customer Data only to subprocessors that operate our platform — currently: Supabase (database and hosting), Cloudflare (delivery and security), GitHub (code hosting and automation), and Anthropic (AI processing, under commercial terms that prohibit training AI models on Customer Data) — each bound by confidentiality obligations; and where required by law, with notice to Customer where lawful.

8Security

Credentials and tokens are stored encrypted in a managed vault. Customer Data is isolated per customer with row-level security. Access is limited to personnel working on Customer's audit. Revocation is honored immediately on the platform side.

9Retention and Deletion

Customer Data is retained while your OAuth authorization remains active, which keeps your deliverable live and enables refreshed analyses. Upon revocation or written request, Winback will delete identifiable Customer Data within thirty (30) days (residual copies in encrypted backups are overwritten in the ordinary rotation cycle thereafter), excepting only Section 5 De-identified Aggregated Data and records retained as required for legal compliance (including the consent record itself).

10General

The Service and its findings are provided "as is" for informational purposes; estimates of revenue lift are projections, not guarantees, and Winback disclaims all warranties to the maximum extent permitted by law. Winback's total liability arising out of the free Service is capped at one hundred US dollars ($100). The Service is not intended for protected health information or similarly regulated data. This Agreement is governed by the laws of the State of New York, excluding conflict-of-law rules. Changes to this Agreement are versioned and published at audits.winback.pro/legal/data-use-agreement and apply prospectively only; continued authorization after a change constitutes acceptance of the new version for future processing.