Privacy Policy

Last updated: [DATE]

Csv2Email (“we,” “us,” or “the app”) is operated by [COMPANY NAME]. This policy explains what information Csv2Email collects when you connect it to your Klaviyo account, how that information is used, and how you can have it removed.

What we collect

When you connect Csv2Email to Klaviyo, we store your Klaviyo account ID and an encrypted OAuth token that lets the app act on your behalf within the scopes you approve. When you pick a template, we store a structural description of that template’s editable fields (its “Manifest”) so future CSV uploads know what they’re writing into — this description contains field names and positions, not your customers’ data. We also keep a tamper-evident log of security-relevant actions on your account (logins, template exports, campaign builds, disconnects) for audit purposes.

We do not collect payment information, and we do not use tracking or analytics cookies — the only cookie this app sets is a single signed session cookie needed to keep you logged in.

How we use it

Your Klaviyo credentials are used exclusively to read your email templates, lists, and segments, and to create draft campaigns in your account from the CSV files you upload. Csv2Email never sends or schedules a real campaign on your behalf — every campaign it creates is left as an unsent draft for you to review and send inside Klaviyo yourself.

Who we share it with

We share data with Klaviyo (as the platform this app operates against, under Klaviyo’s own privacy practices), our hosting provider, and our database provider, solely to operate the service. We do not sell your data, and we do not share it with any other third party.

Security

OAuth tokens are encrypted at rest. All traffic to and from the app is encrypted in transit. Access to Klaviyo-touching pages requires an active, signed session, and mutating actions are rate-limited to guard against abuse.

Retention and deletion

Disconnecting Klaviyo (via the “Disconnect Klaviyo” button, or automatically if Klaviyo reports your authorization as revoked) deletes your stored OAuth token and every template description we’d generated for your account. Our security audit log is kept independently of your connection, for accountability purposes, and is not deleted when you disconnect.

Your rights

You can disconnect Csv2Email from your Klaviyo account at any time from the app’s home page, which removes the data described above. To ask a question about this policy or request anything not covered by Disconnect, contact us at [CONTACT EMAIL].

Changes to this policy

If we make a material change to this policy, we’ll update the “Last updated” date above. Governing law: [STATE/COUNTRY].