Founding 10 · First 10 customers lock in $99/mo for 12 months.
Legal

Privacy policy

Last updated: August 15, 2026 · GST-PRIV-001 v2.0

Operated by GullStack Trust, a Utah trust, d/b/a Cinch. If you are a member of a club that runs on Cinch, that business is the controller of your account — contact them first. Tenant processing is also governed by the Terms and DPA.

1. Who we are

GullStack Trust, a Utah trust, operates Cinch from Draper, Utah. Trustee: Josh Cohen, acting as Trustee.

2. Two roles

Marketing site. When you visit usecinch.com, book a demo, or start signup, we are the business/controller of that visitor information.

Tenant / product.When a business (“Customer”) runs Cinch, that Customer is the controller of member, guest, employee, and booking data. We are the Customer’s processor / service provider. We process that data on the Customer’s instructions.

3. What we collect on the marketing site

  • Technical logs: IP address, user agent, referrer, pages viewed, timestamps (security and operations)
  • Demo and signup information you type: name, business, email, phone, location, vertical, current vendor, approximate member count, brand preferences
  • First-touch attribution we can actually see (for example a referrer), so our team knows how you found us
  • First-party cookies needed to keep a session or remember a form
  • Aggregate analytics via Vercel Analytics (page views). No third-party advertising pixel on the marketing site as of this version

We do not sell marketing-site leads. We do not currently run Google Analytics or a Meta pixel on usecinch.com. If that changes, we will update this policy before or when it happens.

4. What we process inside a tenant

Depends on what the Customer turns on. Typical categories: identity and contact; bookings, visits, purchases, membership status; waiver and contract signatures the Customer presents; message content the Customer sends or receives; payment metadata (last4, amounts, Stripe IDs) — not full card numbers; optional bank-reconciliation data via Plaid; staff scheduling; images and files; device and log data needed to operate the product.

We do not use tenant End User lists to market Cinch to those people. We do not share one tenant’s data with another tenant. Isolation is enforced in application code on the server.

5. Why we use information

  • Provide, secure, and support the Service
  • Create and bill the Customer account
  • Prevent fraud, abuse, and security incidents
  • Comply with law and enforce the Terms
  • Improve the product using de-identified or aggregated signals
  • Respond to the Customer’s instructions (exports, deletions, campaigns)

Legal bases (where a statute requires one): contract, legitimate interests in operating a B2B SaaS, consent (where the Customer or we collected it), and legal obligation.

6. What we do not do

  • We do not sell personal information
  • We do not sell, rent, or monetize Plaid-derived consumer data
  • We do not store primary account numbers or CVV (Stripe does)
  • We do not claim SOC 2 or a consumer 2FA mandate we do not operate
  • We do not use Customer Restricted data in unapproved AI tools outside the production feature path

7. Subprocessors

We use infrastructure vendors to run Cinch. They process data only to provide their service to us:

  • Vercel — hosting, edge, Blob storage, analytics
  • Neon — managed Postgres
  • Stripe — payments, Connect, Terminal
  • Plaid — optional bank link and transactions for reconciliation
  • SendGrid — transactional email
  • SignalWire (or a successor SMS/voice vendor) — optional SMS and voice
  • Anthropic / xAI (or similar) via an AI gateway — optional AI features
  • Cloudflare R2 (if used) — object storage

A platform account the Customer owns (their Stripe, Meta, or Google) is the Customer’s vendor, not our subprocessor.

8. Retention

  • Marketing leads: as needed to follow up and for a reasonable business record
  • Active tenant data: for the life of the Customer account
  • After offboard: delete or anonymize production Customer Data within 30 days, except backups that age out, legal holds, and billing/security records
  • Plaid tokens: deleted on disconnect or offboard
  • Logs: platform defaults, not a long-term PII archive

9. Your choices and rights

Customers can export tenant data from admin tools or by asking us, and can close the account under the Terms.

Members / End Users should contact their club or business. We will point you there, and we will honor a verified deletion or access request that the Customer instructs us to perform, or that law requires us to perform directly.

California / state privacy (CPRA and similar). We act as a service provider to Customers for tenant data. We do not sell or share that data for cross-context behavioral ads. Marketing-site visitors may request access or deletion of the lead record we hold by emailing privacy@cinch.club. We will not discriminate for exercising a privacy right. If we deny a request, you may reply to the same address and ask the Trustee to review.

10. Children

Cinch is a business product. We do not knowingly collect personal information from children on the marketing site. Customers who enroll minors are responsible for parental consent and COPPA / state youth-privacy compliance.

11. Security

We use commercially reasonable safeguards (encryption in transit, managed-cloud encryption at rest, extra encryption for Plaid tokens, MFA on critical operator systems). No method of transmission is perfectly secure. Incident notice to Customers is described in the Terms: without undue delay and within five business days after we confirm a Security Incident.

12. International

We operate in the United States. If you access the Service from elsewhere, you understand your information is processed in the U.S.

13. Changes

We will post updates here and change the date above. Material changes that affect Customers will also follow the notice rule in the Terms (owner email, generally 30 days).

14. Contact