SendTech Privacy Policy
This Privacy Policy describes how SendToWin LLC (“we,” “our,” or “us”) collects, uses, and discloses information when you visit our website, www.sendtowin.com (“Website”), or inquire about our services. By accessing our Website, you acknowledge the practices described in this Policy.
This Privacy Policy ("Policy") describes how SendtoWin LLC, a Florida limited liability company, operator of the SendTech platform and services ("SendTech," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information in connection with the SendTech platform and services available at app.sendtowin.com (the "Platform"). SendTech provides domain acquisition, domain maintenance and warm-up, and email account creation and warm-up services (collectively, the "Services") to business customers on a self-service basis.
The Platform and Services are intended solely for business, commercial, entrepreneurial, and professional use by adults 18 years of age or older. They are not intended for private, personal, family, household, or consumer use.
By accessing or using the Platform, purchasing any Service, or providing any personal information to SendTech, you acknowledge the data practices described in this Policy. If you do not agree with this Policy, do not use the Platform or Services.
This Policy is incorporated by reference into SendTech’s Terms and Conditions of Service. We may provide additional just-in-time disclosures or supplemental notices at specific points of data collection. Those notices supplement this Policy and do not replace it. We may update this Policy from time to time. Material changes will be communicated as described in Section 19 of this Policy.
TABLE OF CONTENTS
2. Personal Information We Collect
3. How We Use Your Information
4. How We Share Your Information
6. Email Infrastructure and Warm-Up Data
7. Cookies and Tracking Technologies
10. Your Privacy Rights and Choices
11. Notice to California Residents (CCPA/CPRA)
12. Notice to EU/EEA/UK Residents (GDPR)
13. International Data Transfers
17. Data Processing Addendum and Subprocessors
18. Limitation of Liability for Privacy Claims
1. SCOPE AND APPLICABILITY
This Policy applies to all personal information collected by SendTech through: (a) the Platform and website at app.sendtowin.com; (b) the purchase and use of any Services; (c) customer support and communications; (d) payment processing; and (e) domain registration activities conducted on Customer's behalf.
This Policy applies to individuals who interact with SendTech in a business capacity, including business owners, company representatives, authorized users, and contacts whose information is provided in connection with domain registration or account setup. The Services are intended exclusively for business use by persons 18 years of age or older. SendTech does not knowingly collect personal information from individuals under 18.
SendTech operates in two distinct capacities with respect to personal information. First, SendTech acts as a data controller or business for personal information it collects directly for its own purposes, including account and billing data, website analytics, domain registration administration, fraud prevention, security, and legal compliance. Second, SendTech acts as a data processor or service provider for personal information that Customers provide or that SendTech accesses on Customers' behalf to provide the Services, including customer-provided contact data, mailbox connection data, warm-up logs, and email infrastructure data. Processing in the second capacity is governed by the Terms and Conditions and, where applicable, a Data Processing Addendum. This Policy primarily governs SendTech's activities as a controller or business.
The definition of personal information depends on applicable law based on your physical location; only the definition applicable to your jurisdiction will apply to you under this Policy.
2. PERSONAL INFORMATION WE COLLECT
2.1 Information You Provide Directly
Account and identity information: name, company name, job title, email address, phone number, and business mailing address
Payment information: credit card, debit card, or Stripe Link payment method details. Payment data is processed and stored by Stripe, Inc. SendTech does not store raw payment card numbers, CVV codes, or full bank account numbers on its own systems
Domain registration data: domain names requested, registrant contact information required by ICANN including name, postal address, email address, and phone number
Customer support communications: records of correspondence, support requests, and chat history
Account credentials: username and hashed password. SendTech does not store plaintext passwords
Identity verification data: in limited circumstances to prevent fraud or recover account access, we may request government-issued identification through trusted third-party verification providers. Such data is used solely for security purposes and retained for a period not to exceed one (1) year, as further described in Section 8 of this Policy
2.2 Information Collected Automatically
Device and technical data: IP address, browser type and version, operating system, device identifiers, and screen resolution
Usage data: pages visited, features used, time on Platform, click patterns, and navigation paths
Geolocation data: we infer approximate geographic location from your IP address and, where permitted, device settings. This is used for fraud prevention, compliance, and service delivery. You may limit location sharing through your device settings
Transaction data: purchase history, domain registration records, service activation dates, and subscription status
Authentication data: login timestamps, session identifiers, and 3D Secure authentication outcomes
Fraud prevention data: Stripe Radar risk scores, 3DS authentication results, card type, card issuer information, and early fraud warning signals as provided by Stripe
Admin-user activity logs: actions taken within the Platform including settings changes, domain management operations, and service configuration
2.3 Email Infrastructure and Warm-Up Data
To provide email account setup, authentication, monitoring, warm-up, and deliverability-related services, SendTech and its service providers may process the following categories of data on behalf of Customer:
Mailbox connection data: email account addresses, account identifiers, and connection status
Access credentials: OAuth tokens, API credentials, or application passwords used to connect email accounts to the Platform, stored in encrypted form and used solely to provide the Services
DNS configuration records: SPF, DKIM, DMARC, and other DNS records configured or monitored through the Platform
Email headers and metadata: sender address, recipient address, timestamp, subject line, message routing information, and authentication results
Warm-up and test message data: content of warm-up and test messages generated and sent by the Platform as part of the warm-up process
Send and receive logs: records of messages sent, received, bounced, replied to, or filtered during warm-up activity
Bounce, reply, and spam placement events: delivery outcomes, non-delivery notifications, spam folder placements, and inbox placement signals
Domain and mailbox reputation metrics: sending reputation scores, blacklist status, and deliverability health indicators
Diagnostic and monitoring data: technical logs, error messages, and performance data generated during service operation
SendTech does not access, scan, read, or use the body content of Customer's actual outbound marketing or sales emails, or Customer's contact lists or prospect databases, except as necessary to provide the Services, troubleshoot technical issues, comply with law, prevent abuse, or as directed by Customer. If you have questions about what data SendTech accesses in connection with your specific configuration, contact support@sendtowin.com.
2.4 Information Received from Third Parties
Stripe, Inc.: payment processing data, card authentication results, fraud risk scores, early fraud warning signals, and chargeback information
ICANN-accredited domain registrars: domain registration confirmations, WHOIS/RDAP data, transfer status, and registry notifications
Email infrastructure and inbox providers: authentication record status (SPF, DKIM, DMARC), domain reputation data, and deliverability metrics
Analytics providers: aggregated, anonymized website usage data
3. HOW WE USE YOUR INFORMATION
3.1 To Provide and Operate the Services
Process and fulfill domain registration, renewal, and transfer requests
Create and manage email accounts and warm-up campaigns
Configure DNS records and authentication settings on Customer's behalf
Connect to Customer-designated email accounts to provide setup, monitoring, warm-up, and deliverability services
Send, receive, and log warm-up and test messages as part of the warm-up process
Monitor domain and mailbox reputation and diagnose deliverability issues
Process payments and manage subscriptions
Authenticate users and maintain account security
Send service confirmations, renewal notices, and expiration alerts
Enforce the acceptable use requirements of the Terms and Conditions and throttle or suspend risky usage.
3.2 For Fraud Prevention and Security
Screen transactions through Stripe Radar for fraud risk assessment
Apply 3D Secure authentication requirements to protect against unauthorized card use
Monitor for suspicious activity, account takeovers, and platform abuse
Maintain block and allow lists and enforce Radar rules
Respond to early fraud warnings and chargeback disputes
Comply with card network rules and chargeback protection requirements
3.3 For Legal and Compliance Purposes
Comply with ICANN Registration Data Policy and registrar requirements
Respond to lawful requests from courts, law enforcement, and government authorities
Enforce our Terms and Conditions and other agreements
Protect our legal rights and defend against claims
Comply with applicable federal, state, and international privacy laws
3.4 For Business Operations and Improvement
Analyze usage patterns to improve Platform performance and features
Generate anonymized and aggregated analytics for internal business intelligence
Communicate service updates, policy changes, and material notices
Respond to customer support requests
Facilitate corporate acquisitions, mergers, and other business transactions
4. HOW WE SHARE YOUR INFORMATION
SendTech does not sell your personal information to third parties. SendTech does not share personal information for cross-context behavioral advertising. We share personal information only as described below. We do not use retargeting pixels, advertising networks, or behavioral advertising platforms. If this changes, we will update this Policy accordingly.
4.1 Service Providers
We share personal information with third-party service providers who process data on our behalf under written contracts restricting use to providing services to SendTech:
Stripe, Inc. (payment processing, fraud detection, chargeback protection) - United States
ICANN-accredited domain registrars (domain registration and management)
DNS and email infrastructure providers (SPF, DKIM, DMARC configuration and monitoring)
Cloud hosting and infrastructure providers
Customer support, communication, and AI-assisted support tools
Identity verification providers (fraud prevention and account recovery)
Analytics providers
Session replay and error monitoring providers (LogRocket, Inc. and Sentry) - United States. These providers record how you interact with the Platform, including pages visited, clicks, navigation, and browser and device diagnostics, so we can reproduce and fix errors. We configure these tools to redact the content of form fields, network request and response bodies, and the customer data displayed on authenticated pages
We enter into data processing or service agreements with our service providers where required by applicable law. Each service provider's data practices are also governed by their own privacy policies.
4.2 Disclosure to Third-Party Email and DNS Providers
We may disclose personal information and technical data to third-party providers used by Customer or at Customer's direction, including Google Workspace, Microsoft 365, domain registrars, DNS providers, and SMTP providers, as necessary to set up, configure, and operate the Services on Customer's behalf.
4.3 ICANN and Registry Mandatory Disclosures
Domain registration data may be disclosed to ICANN, applicable registry operators, ICANN-authorized escrow services, and other parties as required by ICANN's Registration Data Policy and applicable registry agreements. Customer expressly consents to these mandatory disclosures, which are a legal condition of domain registration, and irrevocably waives any claims arising from such disclosures as set forth in the Terms and Conditions. Except where required by a specific registry, we will not publish your personal data to RDAP without your consent or as required by law.
In the event SendTech receives requests for non-public domain registration data from law enforcement, UDRP/URS proceedings, or other legal authorities, SendTech will handle such requests in accordance with applicable law, registrar requirements, and ICANN policy.
4.4 Professional Advisors
We may share personal information with lawyers, accountants, auditors, insurers, and similar professional advisors when necessary for them to provide professional services, for legal compliance, or to protect our rights.
4.5 Legal Requirements and Protection of Rights
We may disclose personal information: (a) in response to a valid subpoena, court order, or lawful government request; (b) to enforce our Terms and Conditions; (c) to protect the rights, property, or safety of SendTech, our customers, or the public; (d) to investigate fraud, security incidents, or violations of applicable law; or (e) as required by applicable law, regulation, or our industry regulator ICANN.
4.6 Business Transfers
In the event of a merger, acquisition, sale of assets, bankruptcy, or other business combination, personal information may be transferred to the successor entity. The successor will be bound by the terms of this Policy or a substantially equivalent policy.
4.7 With Your Consent
We may share your personal information with other parties when you give us specific permission or direct us to do so, such as listing your contact information in a domain registration registry.
4.8 Aggregated and De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably identify any individual or business for any lawful purpose, including benchmarking and analytics.
5. PAYMENT DATA AND STRIPE
All payment transactions are processed by Stripe, Inc. SendTech does not store, process, or have access to raw payment card numbers, CVV codes, or full bank account numbers. Payment data is transmitted directly to Stripe using industry-standard TLS encryption.
Stripe may process payment information both as SendTech's service provider and, for certain fraud prevention, compliance, regulatory, and payment-network purposes, as an independent data controller in accordance with its own privacy policy. Stripe's collection and use of payment information is governed by Stripe's Privacy Policy at stripe.com/privacy. By making a purchase, you acknowledge Stripe's processing of your payment information as described in Stripe's Privacy Policy.
SendTech receives from Stripe limited data including transaction identifiers, card type, last four digits, expiration date, billing postal code, fraud risk scores, and authentication outcomes. This data is used solely to manage your account, process recurring charges, and prevent fraud.
6. EMAIL INFRASTRUCTURE AND WARM-UP DATA
This section describes SendTech's data practices specific to its email infrastructure and warm-up services, which are the core of the SendTech platform.
6.1 Data Accessed to Provide Services
When Customer uses SendTech's email account setup, warm-up, and deliverability services, SendTech accesses and processes data on Customer's behalf as described in Section 2.3. This access is strictly limited to what is necessary to provide, secure, support, monitor, improve, and enforce the Services.
6.2 What SendTech Does Not Access
SendTech does not access, scan, read, index, or use: (a) the body content of Customer's actual outbound marketing, sales, or business emails sent to Customer's own contact lists; (b) Customer's prospect databases, lead lists, or contact databases unless Customer specifically uploads such data to the Platform; or (c) any personal information of Customer's email recipients beyond the technical metadata generated during warm-up and deliverability monitoring activities.
6.3 Customer Responsibility for Recipient Data
Customer is solely responsible for the legality, accuracy, source, consent status, and permitted use of all recipient, lead, prospect, contact, suppression, bounce, reply, engagement, and other data provided to or processed through the Services. Customer represents and warrants that it has all rights, permissions, consents, lawful bases, and notices required under all applicable laws to provide such data to SendTech and to use the Services in connection with such data. SendTech processes such data solely as processor on Customer's behalf and assumes no liability for Customer's data collection, sourcing, or use practices.
6.4 Warm-Up Logs and Retention
Technical logs, event histories, and deliverability metrics generated during warm-up and email infrastructure services are retained for the periods described in Section 8 (Data Retention). These logs are used to provide the Services, troubleshoot issues, monitor performance, and enforce the acceptable use requirements of the Terms and Conditions. Aggregated and anonymized versions may be retained for product improvement and benchmarking.
6.5 Warm-Up Pool Participation
As part of the warm-up Services, Customer's email accounts and associated metadata may interact with other accounts within SendTech's warm-up network. By using the warm-up Services, Customer acknowledges that certain technical metadata including email account addresses and message routing information may be visible to other participants in the warm-up pool solely for the purpose of generating warm-up engagement signals. Customer agrees not to capture, store, share, or use any information observed from other accounts in the warm-up pool for any purpose whatsoever.
7. COOKIES AND TRACKING TECHNOLOGIES
The Platform uses cookies and similar tracking technologies. Below is a summary of the types we use:
Strictly necessary cookies: required for Platform functionality including login sessions, checkout flow, and security. These cannot be disabled without impairing Platform operation
Analytics cookies: used to understand Platform usage in aggregate using privacy-respecting, minimized data collection configurations. Where required by applicable law, we will seek consent before setting non-essential analytics cookies
Session replay: we use LogRocket to record your interactions with authenticated pages of the Platform - pages visited, clicks, scrolling, navigation, console output, and the timing, method and status of network requests - so we can reproduce errors you encounter. Session replay is not aggregated or anonymized and is linked to your account. We configure LogRocket to withhold the content of form fields, the bodies of network requests and responses, authentication credentials and tokens, and the customer data rendered on authenticated pages; that content is removed in your browser and is never transmitted to LogRocket. Recordings are retained for the period set in our LogRocket subscription and are deleted on request. Where required by applicable law, we will seek consent before session replay begins
Fraud prevention: Stripe embeds device fingerprinting and session monitoring as part of its fraud detection services, which is a condition of using Stripe as our payment processor
By creating an account and accepting the Terms and Conditions at registration, you acknowledge and accept SendTech's use of cookies as described in this Section. You may configure your browser to refuse or delete cookies, but doing so may impair your ability to use the Platform. We do not use cookies for cross-site behavioral advertising. Where required by applicable law, we honor applicable opt-out preference signals such as Global Privacy Control (GPC). We do not currently respond to Do Not Track (DNT) browser signals beyond the standard privacy practices described in this Policy.
We honor applicable opt-out preference signals, including Global Privacy Control (GPC), as required by applicable law, including CCPA. We do not currently respond to Do Not Track (DNT) browser signals beyond the standard privacy practices described in this Policy.
8. DATA RETENTION
We retain personal information only as long as necessary to fulfill the purposes in this Policy, to provide the Services, and to comply with legal obligations:
Account and registration data: duration of active account plus three (3) years following termination, or longer as required by applicable law (this retention period applies to SendTech’s own account and billing records; for Customer-uploaded data governed by the Terms and Conditions, the retention period is sixty (60) days post-termination as set forth therein)
Domain registration data: duration of domain registration plus the period required or permitted by ICANN policy, registrar agreements, registry requirements, and applicable law and compliance needs
Payment and transaction records: seven (7) years from transaction date, consistent with tax and financial record-keeping requirements
Fraud prevention and security logs: three (3) years from the relevant transaction or security event, or longer if required for active legal proceedings or regulatory investigations
Customer support communications: two (2) years from resolution, or longer if relevant to active or anticipated legal proceedings
Contractual acceptance records including clickwrap T&C acceptance with IP timestamp: retained for the duration of the customer relationship and for the applicable statute of limitations period thereafter, or longer where reasonably necessary for legal, tax, audit, security, fraud prevention, or dispute resolution purposes
Email infrastructure and warm-up logs: duration of active service plus one (1) year, after which logs are deleted or anonymized
Identity verification data: retained only as long as necessary for the specific verification purpose, not to exceed one (1) year
When personal information is no longer required, we securely delete or anonymize it. Backups may persist for a limited period before secure deletion in accordance with our backup rotation practices. Some data may be retained longer if required by law, regulation, or ongoing legal proceedings. If you cancel your account, your data will be retained for the periods above and then securely deleted. Privacy Risk Assessments: To the extent required by applicable law, including CCPA 2026 regulations effective January 1, 2026, SendTech conducts and maintains privacy risk assessments for processing activities that present a significant risk to consumer privacy. Risk assessments are reviewed and updated whenever material changes to applicable processing activities occur, and at minimum every three years.
9. DATA SECURITY
SendTech implements commercially reasonable technical and organizational security measures to protect personal information:
Encryption of data in transit using TLS/SSL
Encryption at rest for sensitive data categories including access credentials and payment-related data
Payment data handled exclusively through Stripe's PCI-DSS compliant infrastructure
Access controls and least-privilege principles limiting personal data access to authorized personnel with a need to know
Multi-factor authentication for administrative access to the Platform
3D Secure authentication requirements for payment transactions
Stripe Radar fraud detection and real-time transaction screening
Regular monitoring for unauthorized access and security vulnerabilities
Vendor due diligence for material third-party service providers
Incident response procedures for security events
No method of transmission or electronic storage is completely secure. We cannot guarantee absolute security. In the event of a data breach triggering notification obligations under applicable law or our customer agreements, we will provide notice within the timeframes required by applicable law. This includes: (a) notifying affected California residents within 30 calendar days of discovery of the breach, and notifying the California Attorney General within 15 calendar days of consumer notification if 500 or more California residents are affected, as required by California SB 446 (effective January 1, 2026); (b) notifying affected Florida residents within 30 calendar days as required by Florida law; and (c) notifying affected individuals in other jurisdictions within the applicable statutory deadline. Where applicable, we will also provide notice as required by our agreements with Customers. If you believe your account security has been compromised, contact us immediately at support@sendtowin.com.
10. YOUR PRIVACY RIGHTS AND CHOICES
10.1 Rights Available to All Users
Access: request a copy of the personal information we hold about you
Correction: request correction of inaccurate or incomplete information
Deletion: request deletion of your personal information, subject to legal retention requirements
Portability: request your personal information in a structured, machine-readable format
Objection: object to certain processing activities based on legitimate interests
Opt-out of marketing: opt out of non-essential marketing communications at any time
Rights may vary by jurisdiction and may be subject to exceptions. To exercise any right, submit a written request to billing@sendtowin.com. We will respond within the timeframe required by applicable law: 45 days for CCPA requests (with a possible 45-day extension upon notice); 30 days for GDPR requests (with a possible 60-day extension for complex requests); or such other period as required by the applicable law of your jurisdiction. We may require identity verification before processing your request. We will not discriminate against you for exercising your rights.
10.2 Authorized Agents
You may designate an authorized agent to submit privacy rights requests on your behalf. To do so, you must: (a) provide the authorized agent written, signed permission to submit the request; and (b) verify your own identity directly with us. We may deny requests from agents who cannot provide proof of authorization. Authorized agent requests should be submitted to billing@sendtowin.com with documentation of authorization.
10.3 Right to Appeal
If we decline to take action on your privacy rights request, you have the right to appeal. To appeal, submit a written request to billing@sendtowin.com referencing your original request and explaining why you believe we should reconsider. We will respond to appeals within 45 days. If your appeal is also denied, you may have the right to escalate to the applicable regulatory authority in your jurisdiction.
10.4 Session Replay Deletion and Opt-Out
You may request deletion of your session replay recordings at any time. Signed-in users can do this from Settings > Compliance using the request under "Right to be Forgotten": it deletes every session recording associated with your account and adds you to a do-not-record list so that no further sessions are captured. You may also request the same by writing to billing@sendtowin.com. Because session replay is used to diagnose errors and is not necessary to deliver the Services, opting out does not affect your access to the Platform or the Services.
10.5 Marketing Communications
We may send service-related communications that are not promotional and from which you cannot unsubscribe, as they are necessary to provide the Services. If we send promotional communications, you may opt out at any time by following the unsubscribe instructions in the communication.
11. NOTICE TO CALIFORNIA RESIDENTS (CCPA/CPRA)
To the extent the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively "CCPA") applies to SendTech, and in some cases as a voluntary customer accommodation, California residents may exercise the rights and have access to the disclosures described in this Section. This Section supplements the rest of this Policy.
11.1 Categories of Personal Information Collected
The following table discloses the categories of personal information we have collected, the purposes for collection, and the categories of recipients, for the preceding 12 months:
Category of Personal Information | Purpose of Collection and Categories of Recipients |
|---|---|
Identifiers: name, email, phone, IP address, account number, device identifiers | Provide Services; fraud prevention; legal compliance; customer support; enforce agreements. Shared with: service providers, registrars, payment processors, professional advisors, law enforcement. |
Commercial information: purchase history, transaction records, payment card data, subscription status | Provide Services; billing; fraud prevention; legal compliance; enforce agreements. Shared with: Stripe, professional advisors, law enforcement. |
Internet activity: browsing history on Platform, pages visited, click patterns, session data | Platform improvement; fraud prevention; security monitoring. Shared with: analytics providers, service providers. |
Geolocation data: approximate location inferred from IP address | Fraud prevention; legal compliance; service delivery. Shared with: service providers, law enforcement. |
Domain registration data: registrant name, address, email, phone number | Provide domain Services; ICANN compliance; legal obligations. Shared with: ICANN, registrars, registry operators, data escrow providers, law enforcement. |
Email infrastructure and warm-up data: mailbox connection data, OAuth tokens, email headers, warm-up logs, reputation metrics | Provide email and warm-up Services; security; AUP enforcement. Shared with: email infrastructure providers, cloud hosting providers. |
Fraud prevention data: Radar risk scores, 3DS authentication outcomes, card type and issuer | Fraud detection; payment security; chargeback defense. Shared with: Stripe, card networks, professional advisors. |
Inferences: usage preferences and behavior patterns derived from above | Service improvement; fraud pattern detection. Used internally; shared with service providers only. |
11.2 No Sale or Sharing for Advertising
SendTech does not sell personal information. SendTech does not share personal information for cross-context behavioral advertising. We do not sell or share the personal information of consumers under 16 years of age. Where required by applicable law and technically feasible, We honor opt-out preference signals, including Global Privacy Control (GPC), as required by applicable law, including CCPA.
11.3 California Privacy Rights
Right to Know: request disclosure of categories and specific pieces of personal information collected in the past 12 months
Right to Delete: request deletion of personal information, subject to exceptions
Right to Correct: request correction of inaccurate personal information
Right to Portability: receive personal information in a structured, machine-readable format
Right to Opt-Out of Sale or Sharing: not applicable as we do not sell or share for advertising
Right to Limit Sensitive Personal Information: we collect government-issued identification in limited circumstances for fraud prevention and account recovery. To the extent such data constitutes sensitive personal information under CCPA, we use it solely for security purposes and do not use it to infer characteristics about you
Right Against Discrimination: we will not discriminate against you for exercising any CCPA rights
Right to Appeal: see Section 10.3
To exercise California rights, contact billing@sendtowin.com. We will respond within 45 days with a possible 45-day extension upon notice. You may designate an authorized agent per Section 10.2.
11.4 Sensitive Personal Information
To the extent we process sensitive personal information under CCPA, including payment card details processed through Stripe, government-issued identification collected for fraud prevention, and neural data (as defined under CCPA 2026 regulations effective January 1, 2026), we do not use it to infer characteristics about you and use it solely as necessary to provide the Services and protect security. Privacy Risk Assessments and Cybersecurity Audits: To the extent SendTech meets applicable thresholds under CCPA 2026 regulations (Cal. Code Regs. tit. 11, §§ 7100 et seq.), SendTech conducts privacy risk assessments for high-risk processing activities and cybersecurity audits as required by law.
12. NOTICE TO EU/EEA/UK RESIDENTS (GDPR)
This Section applies to individuals located in the European Union, European Economic Area, United Kingdom, and Switzerland (collectively "European Countries") when using or accessing the Services. SendtoWin LLC is the Controller of personal data collected through the Platform for its own purposes. SendtoWin LLC does not currently have a designated Data Protection Officer.
12.1 Legal Bases for Processing
The following table maps our processing activities to the applicable GDPR legal basis:
Processing Activity | Legal Basis |
|---|---|
Providing the Services; processing payments; fulfilling domain registrations; managing subscriptions; sending service communications | Contract performance - Article 6(1)(b) GDPR |
Complying with ICANN policies; responding to legal requests; tax and financial record-keeping; fraud reporting to card networks | Legal obligation - Article 6(1)(c) GDPR |
Fraud detection and prevention; platform security; improving Services; aggregated analytics; defending legal claims; warm-up logging and monitoring | Legitimate interests - Article 6(1)(f) GDPR |
Marketing communications (where elected); publishing registrant data in RDAP with your permission; identity verification where not legally required | Consent - Article 6(1)(a) GDPR |
Where we rely on consent as a legal basis, you have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
12.2 GDPR Individual Rights
Right of access: obtain a copy of personal data we hold about you
Right to rectification: correct inaccurate or incomplete data
Right to erasure: request deletion subject to legal retention requirements
Right to restriction: restrict processing in certain circumstances
Right to data portability: receive data in a structured, machine-readable format
Right to object: object to processing based on legitimate interests or direct marketing
Right to withdraw consent: where processing is based on consent, withdraw at any time
Right not to be subject to automated decision-making: we do not make solely automated decisions that significantly affect you without human involvement
Right to lodge a complaint: with your national supervisory authority. EEA authorities listed at edpb.europa.eu. UK: Information Commissioner's Office at ico.org.uk. Switzerland: Federal Data Protection and Information Commissioner at edoeb.admin.ch
To exercise GDPR rights, contact billing@sendtowin.com. We will respond within 30 days. We may require identity verification before processing your request.
12.3 International Transfers from European Countries
Personal data collected from individuals in European Countries may be transferred to and processed in the United States. We do not rely on consent as the basis for routine international data transfers. Where required by applicable law, we use appropriate safeguards for such transfers, including Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms recognized under GDPR and UK GDPR.
13. INTERNATIONAL DATA TRANSFERS
SendtoWin LLC is based in Palm Beach County, Florida, United States. The Platform is operated from the United States. Personal information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. Such countries may not provide the same level of data protection as your home jurisdiction.
We do not rely on consent as the sole basis for routine international transfers of personal data. Where required by applicable law, international transfers are made under appropriate safeguards, including Standard Contractual Clauses, adequacy decisions, data processing agreements, or other lawful transfer mechanisms. By using the Platform, you acknowledge that your personal information may be transferred to and processed in the United States in accordance with this Policy and applicable law.
14. CHILDREN'S PRIVACY
The Platform and Services are intended exclusively for business use by adults 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we become aware we have collected information from a person under 18, we will terminate access and promptly delete the information. If you believe we may have collected information from a minor, contact support@sendtowin.com immediately.
15. ARTIFICIAL INTELLIGENCE
The Platform and our customer support channels may use artificial intelligence and machine learning technologies ("AI Tools") including AI-assisted support assistants and fraud detection models. When you interact with AI Tools:
AI-assisted support tools may analyze your support requests and interactions to provide responses and improve service quality
SendTech does not intentionally use Customer Data, domain registration data, mailbox content, warm-up logs, or support communications to train third-party foundation AI models unless expressly disclosed, required by law, or consented to by Customer
Stripe uses machine learning models as part of its Radar fraud detection service to analyze transaction patterns and assess risk. Stripe's AI processing is governed by Stripe's Privacy Policy
We do not make solely automated decisions that have significant legal or similarly significant effects on you without human involvement.Where required by applicable law, human review is available for material account decisions. SendTech will provide consumers with applicable rights regarding automated decision-making technology (ADMT) as required by applicable law, including opt-out rights required under CCPA 2026 ADMT regulations effective January 1, 2027.
If you prefer not to interact with AI-assisted support, you may request assistance from a human team member by contacting support@sendtowin.com directly.
16. THIRD-PARTY LINKS
The Platform may contain links to third-party websites and services not owned or controlled by SendTech. This Policy applies only to information collected through the Platform. We are not responsible for the privacy practices, security, or content of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
17. DATA PROCESSING ADDENDUM
SendTech's data collection and processing activities in connection with the Services are described in Sections 2 through 6 of this Policy. SendTech does not process customer contact lists, prospect databases, or recipient personal data as part of its domain acquisition, warm-up, or email infrastructure services.
18. LIMITATION OF LIABILITY FOR PRIVACY CLAIMS
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, SENDTECH'S LIABILITY FOR ANY CLAIM ARISING OUT OF OR RELATED TO THIS POLICY OR THE PROCESSING OF PERSONAL INFORMATION SHALL BE LIMITED IN ACCORDANCE WITH THE LIMITATION OF LIABILITY PROVISIONS IN SENDTECH'S TERMS AND CONDITIONS OF SERVICE. SENDTECH SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM UNAUTHORIZED ACCESS TO OR DISCLOSURE OF PERSONAL INFORMATION, EXCEPT TO THE EXTENT CAUSED BY SENDTECH'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.
Nothing in this Section limits SendTech's liability to the extent such limitation is prohibited by applicable law, including limitations on privacy-law regulatory penalties imposed by the California Privacy Protection Agency, relevant EU/UK data protection authorities, or other regulatory bodies with jurisdiction. Regulatory complaints remain available to individuals regardless of the limitation of liability provisions applicable to private civil claims.
Private disputes arising out of or relating to this Policy shall be resolved exclusively through binding arbitration in Palm Beach County, Florida, in accordance with the dispute resolution provisions of SendTech's Terms and Conditions of Service.
19. CHANGES TO THIS POLICY
SendTech reserves the right to update this Policy at any time. When we make material changes, we will update the effective date at the top of this Policy and post the updated Policy at app.sendtowin.com/privacy. Your continued use of the Platform after the effective date constitutes acknowledgment of the revised Policy. If you do not agree, you must discontinue use and cancel all active subscriptions before the effective date. SendTech will use commercially reasonable efforts to maintain an archive of prior versions at app.sendtowin.com/privacy. This Policy must be reviewed and updated at minimum every twelve (12) months in accordance with CCPA/CPRA requirements.
20. CONTACT US
For privacy questions, rights requests, or billing inquiries, please contact:
SendtoWin LLC d/b/a SendTech
Billing Inquiries: billing@sendtowin.com
General Support: support@sendtowin.com
Website: https://app.sendtowin.com/
Palm Beach County, Florida, United States
SendtoWin LLC reserves all rights.