Privacy Policy
Last updated: September 2, 2026
This Privacy Policy describes how NewsletterFIT ("NewsletterFIT," "we," "us," or "our") collects, uses, discloses, and protects information when you visit newsletterfit.com, join our waitlist, or use our sponsorship intelligence platform (collectively, the "Services"). By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.
1. Definitions
- Personal Data means information that identifies, relates to, or could reasonably be linked with an individual or household (e.g., work email address).
- Business Contact Data means professional contact information you provide in a B2B context (e.g., corporate email on our waitlist).
- Usage Data means technical and analytics information about how you interact with our website and product (e.g., pages viewed, referrers, device type).
- Product Data means information generated when you use in-app features (e.g., searches, saved publications, alert preferences) once accounts are available.
- Subprocessors means third-party service providers that process data on our behalf to operate the Services.
2. Information we collect
2.1 Information you provide
- Waitlist and early access — when you request early access, we collect your work email address and may record which form or page you used, your approximate submission time, and optional notes you include.
- Communications — if you email us or respond to outreach, we retain the content of those messages and associated contact details.
- Account information — when authentication and team features launch, we may collect name, organization, role, billing contact, and credentials managed through our auth provider.
2.2 Information collected automatically
- Cookies and similar technologies — we use cookies, local storage, and comparable technologies for essential site operation, session continuity, and analytics. See Section 6 for details.
- Analytics — we use Google Analytics (or comparable tools) to understand traffic patterns, page performance, and marketing effectiveness. This may include IP address (often truncated), browser type, operating system, referring URL, and pages visited.
- Server logs — our VPS infrastructure records standard request metadata (timestamps, URLs, status codes) for security, debugging, and reliability.
- Product usage logs — when you use the app, we may log feature interactions (searches, filters, exports) to improve performance and product design.
2.3 Information we do not collect by default
We do not intentionally collect sensitive categories of personal data (health, biometric, precise geolocation for consumer tracking, etc.) through the public website. We do not purchase email lists. We do not sell Personal Data.
3. How we use information
We use collected information to:
- Operate, maintain, and improve the Services, including our newsletter corpus and enrichment pipelines.
- Notify waitlist members about early access, product updates, and relevant B2B outreach.
- Respond to support requests, security incidents, and legal obligations.
- Measure marketing and product performance through aggregated analytics.
- Detect, prevent, and address fraud, abuse, and unauthorized access.
- Develop new features such as saved watchlists, alerts, and team collaboration.
We do not use waitlist emails for unrelated consumer marketing. Outreach is limited to NewsletterFIT product and partnership context unless you separately opt in.
4. Legal bases for processing (EEA/UK visitors)
If you are in the European Economic Area or United Kingdom, we rely on:
- Consent — for waitlist signup and non-essential cookies/analytics where required.
- Legitimate interests — to operate a B2B SaaS platform, secure our systems, and communicate with business prospects who expressed interest, balanced against your rights.
- Contract — when processing is necessary to provide paid or trial Services you request.
- Legal obligation — when we must retain or disclose data to comply with law.
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Contact us using the details in Section 12.
5. Email marketing & CAN-SPAM compliance
When we send commercial email to U.S. recipients, we comply with the CAN-SPAM Act and similar rules:
- Messages identify NewsletterFIT as the sender and include a valid physical/postal contact where required.
- Subject lines accurately reflect message content.
- Every marketing email includes a clear unsubscribe mechanism honored within a reasonable time (typically 10 business days).
- We honor opt-out requests across our systems and do not require login to unsubscribe from marketing.
Transactional messages (e.g., security alerts, access confirmations) may still be sent when necessary to operate your account.
6. Cookies & tracking
We use the following categories of cookies and storage:
- Strictly necessary — required for site security, load balancing, and basic functionality. These cannot be disabled without breaking the site.
- Analytics — Google Analytics helps us understand aggregate usage. You may limit analytics via browser settings, opt-out browser add-ons, or blocking third-party scripts.
- Outreach link attribution — when we email a tracked product link in B2B
outreach, clicks go through our server first (token only; destination stored server-side).
We may set a first-party cookie (
nf_attr) to associate later visits on newsletterfit.com with that outreach lead for campaign measurement. We do not capture email address in that cookie; it stores an opaque lead id. Clear site cookies to reset. - Product preferences — local storage keys (e.g., saved watchlist slugs before account sync) remain on your device until you clear them.
We do not deploy third-party advertising pixels for retargeting on the public marketing site at this time. If that changes, we will update this Policy.
7. How we store & protect data
Data is hosted on infrastructure we control, including a dedicated VPS and MongoDB database for application data. We apply reasonable administrative, technical, and organizational measures: encrypted transport (HTTPS/TLS), access controls, least-privilege credentials, and regular backups. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
If we become aware of a data breach affecting Personal Data, we will notify affected individuals and regulators as required by applicable law.
8. Retention
- Waitlist emails — retained until you unsubscribe, request deletion, or we determine the waitlist entry is no longer active, plus any period required by law.
- Account data — retained for the life of your account and a reasonable period afterward for backups, billing records, and dispute resolution.
- Analytics — retained according to our analytics provider's settings (typically 14–26 months for Google Analytics unless configured otherwise).
- Server logs — rotated on a schedule appropriate for security monitoring (generally 30–90 days unless needed for an investigation).
9. Sharing & subprocessors
We do not sell Personal Data. We share information only:
-
With subprocessors who help us run the Services under contractual
confidentiality and data-protection terms, including:
- Cloud/VPS hosting provider(s) for application and web servers
- MongoDB or managed database services for product data
- Email delivery providers for waitlist and product notifications
- Google Analytics for website analytics
- Authentication providers when account features launch
- With professional advisers (legal, accounting) under confidentiality obligations.
- In connection with a merger, acquisition, or asset sale, with notice where required.
- When required by law, subpoena, or to protect rights, safety, and integrity of the Services.
A current subprocessor list is available on request at support@newsletterfit.com.
10. International transfers
NewsletterFIT is operated from the United States. If you access the Services from outside the U.S., your information may be transferred to, stored, and processed in the U.S. and other countries where our subprocessors operate. Where required, we implement appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers.
11. Your privacy rights
Depending on your location, you may have the right to:
- Access the Personal Data we hold about you.
- Correct inaccurate or incomplete data.
- Delete data, subject to legal retention exceptions.
- Restrict or object to certain processing.
- Data portability for information you provided in a structured format.
- Opt out of marketing emails at any time.
- Lodge a complaint with your local supervisory authority (EEA/UK).
California residents may have additional rights under the CCPA/CPRA (know, delete, correct, opt out of "sale"/"sharing" — we do not sell Personal Data). To exercise rights, email support@newsletterfit.com. We may verify your request before responding.
12. Children's privacy
The Services are intended for business users aged 18 and older. We do not knowingly collect Personal Data from children under 16. If you believe we have collected such data, contact us and we will delete it promptly.
13. Changes to this Policy
We may update this Privacy Policy to reflect product, legal, or operational changes. Material updates will be posted on this page with a revised "Last updated" date. Continued use after changes constitutes acceptance where permitted by law.
14. Contact us
Privacy questions, data requests, or subprocessors list: support@newsletterfit.com
NewsletterFIT
Attn: Privacy
Email: support@newsletterfit.com