Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal information when you use WithCold's email automation platform.

Last updated: January 27, 2025
GDPR & CCPA Compliant

Privacy Overview

Quick Summary

We collect information you provide when using WithCold's email automation platform, including contact details, email content, and recipient data. We use this information to deliver our cold email services, improve your experience, and comply with legal obligations. We don't sell your personal data to third parties.

This Privacy Policy describes how withcold.com ("we," "us," or "our") collects, uses, and shares information about you when you use our cold email automation platform and related services (collectively, the "Services").

We are committed to protecting your privacy and maintaining the security of your personal information. This policy applies to all users of WithCold's cold email automation platform, including both account holders who send campaigns and recipients of cold emails sent through our service.

Information We Collect

We collect several types of information to provide and improve our Services:

Account Information

Information you provide when creating and managing your account.

Name and email address
Company information
Billing and payment details
Account preferences and settings

Cold Email Campaign Data

Content and metadata related to your cold email campaigns and outreach.

Email subject lines and message content
Campaign sequences and templates
Send times and scheduling preferences
A/B testing variations and results

Prospect & Recipient Data

Information about prospects and people who receive your cold email campaigns.

Contact details (name, email, company)
Custom prospect fields and segmentation tags
Email engagement metrics (opens, clicks, replies)
Unsubscribe and opt-out preferences

Platform Usage & Performance

Information about how you use WithCold's features and campaign performance.

Login sessions and platform activity
Campaign creation and management patterns
Email deliverability and response rates
Feature usage and system interactions

Automatic Data Collection

We automatically collect certain information when you use our Services, including log data, device information, and usage analytics. This helps us improve our platform's performance and security.

How We Use Your Information

We use the information we collect for the following purposes:

1

Cold Email Service Delivery

To provide our core cold email automation services, including sending personalized email campaigns, tracking engagement metrics, managing recipient databases, and providing detailed analytics and reporting on campaign performance.

2

Account Management

To create and maintain your account, process payments, provide customer support, and communicate important service updates.

3

Platform Enhancement

To analyze email campaign performance, optimize deliverability rates, develop new automation features, and enhance the overall effectiveness of our cold email platform.

4

Legal Compliance

To comply with applicable laws, respond to legal requests, protect our rights, and ensure platform security and integrity.

Marketing Communications

We may send you updates about WithCold's new features, cold email best practices, and platform improvements, but only if you've opted in. You can unsubscribe at any time using the link in our emails or through your account settings.

Information Sharing

We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:

Service Providers

We work with trusted third-party companies that help us operate our platform:

  • Cloud hosting and infrastructure providers
  • Payment processing services
  • Email delivery and monitoring services
  • Analytics and performance monitoring

Legal Requirements

We may disclose information when required by law, such as in response to a court order, subpoena, or other legal process, or when we believe disclosure is necessary to protect our rights or comply with legal obligations.

Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations:

Account Data

Retained while your account is active and for 30 days after account deletion to allow for reactivation.

Includes: Profile information, preferences, billing data

Email Campaign Data

Retained for up to 7 years for analytics and compliance purposes, or until deletion is requested.

Includes: Email content, recipient lists, engagement metrics

Log and Usage Data

Automatically deleted after 2 years, or sooner if no longer needed for security or improvement purposes.

Includes: Access logs, analytics data, error reports

Legal Hold Data

Retained as required by law or legal proceedings, which may extend normal retention periods.

Includes: Data subject to regulatory requirements

Data Deletion

When data is deleted, it is permanently removed from our active systems. Some information may remain in backups for up to 90 days before being permanently purged.

Your Privacy Rights

You have important rights regarding your personal information. These rights may vary depending on your location:

Access Your Data

You have the right to know what personal information we have about you and how we use it.

How to Exercise This Right:

Contact us through our support portal or use your account settings to view and download your data.

Correct Your Data

You can request that we correct any inaccurate or incomplete personal information.

How to Exercise This Right:

Update your information directly in your account settings or contact our support team.

Delete Your Data

You can request that we delete your personal information, subject to certain legal limitations.

How to Exercise This Right:

Use the account deletion option in settings or contact our support team with a deletion request.

Data Portability

You can request a copy of your personal information in a machine-readable format.

How to Exercise This Right:

Use the data export feature in your account or contact us for assistance with data transfer.

Opt-Out of Processing

You can object to certain types of data processing, including marketing communications.

How to Exercise This Right:

Adjust your communication preferences in account settings or use unsubscribe links in emails.

Restrict Processing

You can request that we limit how we process your personal information in certain circumstances.

How to Exercise This Right:

Contact our support team with your specific restriction request and reasoning.

California Residents (CCPA)

If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected and sold
  • Right to opt-out of the sale of personal information (we don't sell data)
  • Right to non-discrimination for exercising privacy rights

Data Security

We implement comprehensive security measures to protect your personal information:

Technical Safeguards

  • Encryption: Data encrypted in transit (TLS) and at rest (AES-256)
  • Access Controls: Multi-factor authentication and role-based permissions
  • Network Security: Firewalls, intrusion detection, and secure hosting
  • Regular Audits: Security assessments and penetration testing

Operational Safeguards

  • Employee Training: Regular security awareness and privacy training
  • Data Access: Strict need-to-know basis and audit trails
  • Incident Response: 24/7 monitoring and response procedures
  • Vendor Management: Security requirements for all partners

Physical Safeguards

  • Secure Data Centers: SOC 2 certified facilities with 24/7 security
  • Access Controls: Biometric and badge-based facility access
  • Environmental Controls: Climate control and power redundancy

Data Breach Notification

In the unlikely event of a data breach that may affect your personal information, we will notify you and relevant authorities as required by law, typically within 72 hours of discovery.

International Data Transfers

Our services are primarily hosted in the United States. If you are located outside the U.S., your information may be transferred to and processed in the United States or other countries where our service providers operate.

EU Data Transfers

For transfers of personal data from the European Union, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for certain countries
  • Additional safeguards as required by applicable law

Data Protection Commitments

Regardless of where your data is processed, we maintain the same high standards of data protection and comply with applicable privacy laws in your jurisdiction.

Children's Privacy

Our Services are not directed to children under 16 years of age, and we do not knowingly collect personal information from children under 16.

If We Learn of Children's Data

If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a child, please contact us immediately.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • Material Changes: 30-day advance notice via email
  • Minor Updates: Posted notice on our website
  • Version History: Previous versions available upon request

Your Options

If you disagree with changes to our Privacy Policy, you may delete your account before the changes take effect. Continued use of our Services after changes become effective constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, we're here to help:

Privacy Team

Contact us through our support portal
Response within 48 hours

Data Protection Officer

Available through support channels
EU Representative Available

Supervisory Authority

If you're in the EU and have concerns about our privacy practices that we haven't resolved, you have the right to file a complaint with your local data protection authority.