Legal
Privacy Policy
Last updated July 25, 2026
TrafficWins stores account, billing, website context, article, and job data needed to run the service. Google user data accessed: when a user connects YouTube, TrafficWins accesses the authorized YouTube channel ID, channel name, channel image, granted OAuth scopes, and the user's own video upload and processing status. TrafficWins requests only the YouTube read-only and upload permissions needed to identify the selected channel, upload user-approved videos, and confirm their processing and publication status. How Google user data is used: TrafficWins uses the channel details to show the connected YouTube account inside the user's workspace. It uses the OAuth access and refresh tokens only to maintain that connection, upload videos the user has explicitly approved for publishing, and check those uploads for completion or errors. TrafficWins does not use Google user data for advertising or to train generalized AI or machine-learning models. Google user data sharing and disclosure: TrafficWins does not sell Google user data. We disclose it only to Google to perform the user-requested YouTube operations and to contracted infrastructure providers that host, secure, store, or operate TrafficWins on our behalf. Those providers may process the minimum data needed to provide their services and are bound by applicable confidentiality and data-protection obligations. We may also disclose data when legally required or as part of a business transfer subject to this policy and applicable law. Google user data protection: OAuth access and refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption and are transmitted only over HTTPS. Access is limited to authorized TrafficWins services and personnel with an operational need. We use tenant-scoped access controls, secret-management practices, logging safeguards that exclude tokens, and local token removal when a connection is disconnected. Google user data retention and deletion: OAuth access and refresh tokens are retained only while the YouTube connection remains active and are removed from TrafficWins when the user disconnects that channel. Channel identifiers, display details, granted-scope records, and publication history may remain for account continuity, security, audit, and legal obligations until the TrafficWins account or associated data is deleted. Users can disconnect YouTube in workspace settings, revoke TrafficWins in their Google Account, or contact support to request deletion of their account and Google user data. We delete or de-identify eligible data from active systems and allow encrypted backups to expire under our backup-retention schedule, subject to legal requirements.
We also use WorkOS for authentication, Stripe for billing, Glitchtip for error reporting, and infrastructure providers for hosting and storage. PostHog Cloud US, Google Analytics, and Microsoft Clarity. Random pseudonymous ID, page path, CTA action, coarse referral/UTM attribution, event time, and stable event ID. PostHog receives canonical events; Google Analytics receives aggregate acquisition events and browser, device, and referral context; Microsoft Clarity captures masked page interaction, heatmaps, and session replay. Input values are masked. No email, phone, person profile, or advertising audience. Provider endpoints may process the request IP; provider settings control its storage. PostHog retains events for up to one year. Google Analytics retains user and event data for up to 14 months while aggregate reports are treated differently. Microsoft Clarity retains playback data for 30 days and click/heatmap data plus labeled or favorited sessions for 13 months. Exact deletion is provider-dependent. Use the privacy-policy rights request to request deletion.
We do not ask customers for AI provider API keys. TrafficWins uses contracted third-party AI service providers, including OpenAI, to research, generate, review, and improve content. Content a user submits and relevant organization, website, campaign, article, and publishing context may be sent to those providers only to provide requested TrafficWins functionality. The iOS app presents this disclosure and obtains explicit consent before the workspace can be used. Users should not submit sensitive personal information and may withdraw consent by requesting account deletion or contacting support. The TrafficWins iOS app may store a rotating WorkOS refresh token in the iOS Keychain and an APNs device token on our servers. APNs notifications use non-sensitive status text for article, publishing, and social-post events. Users choose whether to enable notifications and can remove the device registration by signing out. Storefront country is read on-device only to determine whether the US mobile Checkout flow is available and is not sent to TrafficWins analytics.
Users can request account deletion inside TrafficWins settings. The request signs the user out, is recorded for duplicate prevention, and is fulfilled within 30 days. Users may also contact support for account, social-token, or data deletion and revocation requests.