Founding 10 · First 10 customers lock in $99/mo for 12 months.
Legal

Terms of service

Last updated: August 15, 2026 · GST-TOS-001 v2.0

These Terms are the agreement between GullStack Trust, a Utah trust doing business as Cinch, and the business that creates or uses a Cinch tenant. Cinch is software. It is not your club, not a bank, not an insurer, and not your lawyer. A signed order form or Master Services Agreement controls if it conflicts with this page. Marketing copy does not amend these Terms. New customers are bound on acceptance. Customers on a prior version are bound on September 14, 2026 unless they cancel first.

1. Parties, authority, and business use only

The contracting party is GullStack Trust, a Utah trust, d/b/a Cinch and, where relevant, Walkthru Labs (“Provider,” “Cinch,” “we,” “us”). Josh Cohen acts solely as Trustee. He does not contract in his personal capacity. No trustee, beneficiary, employee, contractor, or affiliate of Provider is a party to these Terms or has personal liability under them except to the extent a statute forbids that limitation.

You (“Customer”) represent that you are entering these Terms as a business, organization, or public entity — not as a consumer — and that you have authority to bind the organization named on the account. If you lack that authority, you accept these Terms personally as well.

The Service is offered only for business use. To the maximum extent Utah law allows, you waive consumer-protection, implied-warranty, and cooling-off rights that apply only to consumer transactions.

Your members, guests, employees, instructors, contractors, parents, and other individuals who use a Cinch-powered site, app, kiosk, register, or message channel (“End Users”) are your customers or personnel, not ours. These Terms do not create a contract between Provider and any End User. End Users are not third-party beneficiaries.

2. The Service

Provider grants you access to Cinch’s hosted software and related documentation (the “Service”) for your own internal operations: membership, scheduling, booking, point of sale, payments facilitation through Stripe, waivers and contracts you configure, messaging you initiate, websites and member portals, workforce tools, reporting, optional bank-reconciliation connections, optional AI features, and other modules we enable for your tenant.

The Service does not include operating your physical location; supervising staff or End Users; practicing law, medicine, tax, accounting, or insurance; underwriting or binding coverage; storing card primary account numbers; or guaranteeing bookings, revenue, or attendance. Output from the Service — including AI output, reports, fee quotes, and insurance-related screens — is a tool for you to review. You decide what to do with it.

We may add, change, or remove features. We have no duty to maintain feature parity with a competitor or a prior version. Features marked alpha, beta, preview, lab, or experimental are provided as-is, may be withdrawn at any time, and are excluded from any service commitment.

3. Accounts and Authorized Users

You must provide accurate account information and keep the owner email current. Legal notices sent to that address are effective when sent without bounce. You are responsible for every action taken under your tenant, including actions by staff you invite, integrators you authorize, and anyone who obtains credentials you failed to protect. Use unique logins, keep credentials confidential, and promptly disable access for departed personnel. We may assume instructions from an owner or admin login are authorized.

4. License and restrictions

Subject to these Terms and timely payment, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access the Service during the term for your internal operations. The Service is licensed, not sold. We reserve all rights not expressly granted.

You will not, and will not allow others to:

  • Copy, modify, or create derivative works of the Service except as the interface allows
  • Reverse engineer, decompile, or attempt to extract source code except to the limited extent a statute forbids this restriction
  • Rent, resell, white-label, or provide the Service to a third business except as an express written reseller addendum allows
  • Use the Service to build a competing product
  • Probe, scan, or load-test the Service except with our prior written consent
  • Bypass technical limits, tenant isolation, or payment flows
  • Scrape End User data from other tenants
  • Remove proprietary notices, or use the Service in violation of law or Section 14

5. Fees, taxes, and payment

Fees are as stated at signup or on a signed order form. Published plans as of this version:

  • Cinch Standard.$249 per month, billed in advance, software fees only. Card processing is billed by Stripe to your connected account at Stripe’s then-current rates, not by us as a Cinch surcharge.
  • Founding 10. $99 per month for the first twelve months for the first ten paying Customers, then Standard. When the allotment is filled, the offer closes.
  • Public Golf pass-through. $0 monthly software fee to qualifying public or municipal golf courses; a $1.50 online booking convenience fee is disclosed to the golfer and routed to Provider via Stripe application_fee_amount. Eligibility is determined by Provider.
  • Enterprise / multi-location. The signed order form.

Subscriptions renew each billing period until cancelled. You authorize Provider and its payment processors to charge the payment method on file. Fees are earned when the period begins. We do not prorate or refund the current period except where a statute requires it.

We may change published rates on at least 30 days’ notice to the owner email. The new rate applies to the next period after that notice. Continued use is acceptance. Order-form pricing changes only as that form says.

Fees exclude taxes. You are responsible for sales, use, and similar taxes (not taxes on our net income). Amounts unpaid 15 days after the due date may accrue interest at 1.5% per month or the maximum lawful rate, whichever is less. You will pay our reasonable collection costs, including attorneys’ fees. We may suspend the Service if any amount is more than 15 days past due after notice, and we may set off amounts you owe us.

You are responsible for End User payment disputes, chargebacks, refunds, and unfulfilled bookings. If a chargeback or fee is assessed to Provider, you will reimburse us on demand.

6. Customer Data and roles

“Customer Data” means data you or your End Users submit to the Service. As between the parties, you own Customer Data. You grant us a worldwide, non-exclusive license to host, copy, process, transmit, display, and create derivative works of Customer Data solely to provide, secure, maintain, and support the Service, to prevent fraud and abuse, to comply with law, and to produce de-identified or aggregated statistics that do not identify you or an End User. We own those statistics.

You are the controller(or “business”) of Customer Data. We are your processor(or “service provider”) under the Data Processing Addendum, which is incorporated into these Terms. You decide the purposes of collection, the notices End Users see, retention in your business, and whether a given message or campaign is lawful.

You represent that you have all rights, consents, and notices required to provide Customer Data to us, including from End Users, employees, and parents of minors. You will not upload data you have no right to share.

We do not sell Customer Data. We do not share it for cross-context behavioral advertising. We do not solicit your End Users for another tenant’s competing business. We do not operate a marketplace that charges your members a fee to book with you except where a published pass-through plan discloses a convenience fee. If the Privacy Policy conflicts with these Terms or the DPA as to Customer Data, these Terms and the DPA control.

7. Connectors, credentials, and third-party platforms

The Service may connect to third-party platforms you authorize (each a “Connected Service”), including Stripe, Plaid, Meta, Google, email providers, SMS carriers, access-control vendors, CRMs, and advertising tools. Those platforms are not us. Their availability, security, pricing, and policy changes are outside our control.

You supply and may revoke credentials, OAuth grants, and API keys. Use the least privilege the work allows. We store secrets only in server-side secret managers or environment configuration. Plaid access tokens, when used, are stored server-side and encrypted at rest with AES-256-GCM.

High-risk connectors (bank/Plaid, full inbox or CRM dump, health-adjacent data, production SMS under a number we provide) require written authorization (email is enough) identifying the service, purpose, and scope. We may refuse a connector until that record exists.

You must keep Connected Service accounts in good standing and comply with their terms. A ban, hold, or policy change at a Connected Service is not a breach by us. If you revoke access, we are not responsible for functions that depend on it. We are not liable for outages, data loss, or security incidents at a Connected Service or at our infrastructure vendors except to the extent caused by our failure to apply the safeguards in Section 16. Your remedies against a third party lie under that party’s terms.

8. Communications, SMS, email, and marketing

You control who is messaged, the content, the list, and the campaign. We provide tooling and, where configured, connectivity (including SignalWire or similar, and SendGrid or similar).

You own consent. You are solely responsible for obtaining, storing, and honoring legally sufficient consent and opt-outs under the Telephone Consumer Protection Act, CAN-SPAM, state mini-TCPA laws, carrier and 10DLC rules, and similar laws. That includes STOP/HELP handling you enable or we configure at your instruction. You will not use the Service to send spam, unlawful robocalls, or messages to lists you do not have the right to contact.

If we provide a sending number or brand registration, you remain the maker or initiator of the messages for TCPA and carrier purposes unless a statute independently makes us one — and even then, you will indemnify us under Section 22. Advertising pixels, offline conversions, and audience uploads are your campaigns. You warrant the data was collected lawfully and that your ad accounts comply with the platform’s terms.

9. Payments and Stripe

You connect your own Stripe account. Stripe’s Connected Account Agreement is between you and Stripe. We are not a bank or a party to your charge of an End User. We do not store primary account numbers or CVV. On Standard, Cinch does not take a per-transaction software cut. You pay Stripe’s processing rates. On a pass-through plan, the disclosed convenience fee is collected as described in Section 5. Refunds, voids, disputes, and payout timing are Stripe’s systems plus your staff. We are not responsible for delayed or failed payouts caused by Stripe, your bank, or information you entered.

10. Bank connections (Plaid)

If you enable bank reconciliation, a user authenticates through Plaid Link for the stated purpose — reconciliation of your business money, not a consumer financial product we offer to your members. We do not sell, rent, or monetize Plaid-derived consumer data.You are the controller of that connection for your business. You will not instruct us to use Plaid data for a purpose Plaid’s terms or law forbid.

11. AI features

The Service may include AI concierge, drafting, classification, or similar features. Outputs can be wrong, incomplete, or outdated. You will review outputs before relying on them with End Users or in any legal, medical, financial, or safety decision. We do not warrant that AI output is accurate, unique, or non-infringing. You are responsible for the messages and decisions you send or take. We will not paste your secrets or bulk End User records into AI tools outside the production inference path used to provide the feature.

12. Your premises, waivers, members, and minors

Software only. You operate the physical or unmanned location. You are solely responsible for premises safety, staffing, supervision, emergency procedures, access-control hardware, cameras, and the decision to admit or refuse an End User.

Membership agreements, waivers, assumption-of-risk forms, cancellation policies, late-cancel fees, house rules, and parental consents are your contracts with End Users. We host the text you configure and the signature record. We do not draft those documents as your lawyer, we do not warrant they are enforceable in your state, and we are not a party to them. A signed waiver in Cinch is evidence you may use. It is not a guarantee a court will enforce it, and it does not shift liability for your operations onto Provider.

If you enroll or message anyone under 18 (or under 13 where COPPA applies), you are responsible for parental consent, notices, and age-gated practices. Workforce, payroll-adjacent, timekeeping, and handbook features are tools. You remain the employer and are responsible for wage-and-hour, classification, and employment-law compliance.

13. Insurance and Protection features

Cinch may display, quote, or facilitate optional insurance or “Protection” products. Cinch is not an insurer and does not bind coverage. Any policy is a contract between the insured and the licensed carrier. Quotes, estimates, and checkboxes in the software are not binders. Where GullStack Trust (or a licensed affiliate) acts as a producer or agency of record, that role is separate from the software subscription. You and your End Users are responsible for the accuracy of applications and for maintaining required coverage for your operations. We are not liable for uninsured loss, denied claims, or coverage gaps.

14. Acceptable use

You will not use the Service to violate law; defraud End Users or card networks; infringe IP; traffic in malware; interfere with other tenants; send unlawful communications (Section 8); process PHI or 42 C.F.R. Part 2 substance-use records unless a BAA and, if needed, a QSOA is fully executed; store PAN/CVV outside Stripe; or operate verticals we refuse (including illegal gambling and unlawful adult content). We may suspend immediately for this Section, for security risk, or for a Connected Service demand.

15. Availability; no SLA

We aim for high uptime. Standard, Founding 10, and pass-through plans have no service-level agreement, no uptime credit, and no warranty of uninterrupted or error-free operation. Hosting on Vercel and Neon (or successors) is the practical floor. A written SLA exists only if an Enterprise order form states one. Scheduled maintenance, force majeure, and third-party outages are not breaches.

16. Security and incidents

We maintain commercially reasonable administrative, technical, and physical safeguards described in our Information Security Policy (GST-ISP-001), including TLS in transit, managed-cloud encryption at rest, additional AES-256-GCM for Plaid tokens, server-side tenant isolation, and MFA on critical operator assets. We do not represent SOC 2, ISO 27001, independent pen-test reports, 24/7 SOC, commercial vulnerability scans of all endpoints, or universal End User 2FA unless a later written addendum says so.

A “Security Incident” means confirmed unauthorized access to, or acquisition, disclosure, or loss of, Customer Data in our possession. Unsuccessful scans, blocked logins, and failed phishing are not Security Incidents. We will notify the owner email without undue delay and in any event within five (5) business days after we confirm a Security Incident affecting your Customer Data. Notice may be preliminary. Notice is not an admission of fault. You remain responsible for notifying End Users and regulators unless law places that duty on us.

You will maintain MFA on Connected Services you control, use least-privilege roles, and tell us at josh@gullstack.com (subject [SECURITY]) if you suspect credential compromise.

17. Term, suspension, termination

These Terms start when you first accept them and continue until terminated. You may cancel at any time from the admin tools we provide or by emailing bryce@gullstack.com from the owner address. Cancellation takes effect at the end of the then-current paid period unless we agree otherwise. The current period is non-refundable.

We may terminate for convenience on 30 days’ notice to the owner email. We may suspend or terminate immediately if you materially breach and do not cure within 10 days of notice (or immediately if the breach is incurable, illegal, or a security risk); you become insolvent; a Connected Service requires it; or we are required by law. Sections 4, 5, 6, 8, 11–13, 16, 18–27, and 29 survive.

18. Export and deletion

During the term you may export Customer Data the product or API makes available. After termination, we will make a commercially reasonable export available on written request received within 14 days, then delete or anonymize Customer Data in production systems within 30 days, except backups that age out on their cycle, records we must keep for law, billing, security, or dispute, and de-identified statistics. We do not promise a seven-day hand-delivery SLA. Keep your own copies of records you are legally required to retain.

19. Intellectual property and feedback

Provider and its licensors own the Service, software, models, prompts, design systems, documentation, and all improvements. Customer Data remains yours. If you give feedback, you grant us a perpetual, irrevocable, royalty-free license to use it without restriction or attribution. We may identify you by name and logo in our portfolio and marketing unless you opt out in writing.

We will defend you against a third-party claim that the Service, as provided by us and used per these Terms, infringes a U.S. copyright or trademark, and we will pay damages finally awarded. We have no duty for claims arising from Customer Data, your combination or modification, your misuse, or a Connected Service. If the Service is enjoined, we may procure a license, modify the Service, or terminate and refund prepaid unused fees. This paragraph is your exclusive IP remedy against us and is subject to Section 23.

20. Confidentiality

Each party will protect the other’s non-public business information with reasonable care and use it only to perform under these Terms. Exceptions: public information, independent development, lawful third-party receipt, and compelled disclosure (with notice where lawful). Customer Data is your Confidential Information; the Service and these commercial terms are ours.

21. Disclaimers

EXCEPT FOR THE NARROW IP INDEMNITY IN SECTION 19, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” PROVIDER DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF HARMFUL CODE, OR THAT DATA WILL NOT BE LOST. NO SECURITY PROGRAM ELIMINATES ALL RISK. REPORTS, AI OUTPUT, FEE QUOTES, AND INSURANCE-RELATED SCREENS ARE INFORMATIONAL. WE ARE NOT YOUR LAWYER, ACCOUNTANT, BROKER-DEALER, OR CARRIER.

22. Customer indemnification

You will defend, indemnify, and hold harmless Provider, the Trustee, beneficiaries, employees, and contractors from any third-party claim, demand, investigation, or government action, and all related damages, fines, and reasonable attorneys’ fees, arising out of or related to:

  • Customer Data or content you configure
  • Your premises, events, classes, lodging, treatments, products, or other operations
  • Injury, death, or property damage involving an End User or employee
  • Your membership contracts, waivers, cancellation policies, or fees
  • Your failure to obtain consent or honor opt-outs (including TCPA, CAN-SPAM, 10DLC, and state mini-TCPA)
  • Your ads, pixels, and audience uploads
  • Your breach of a Connected Service’s terms or of these Terms
  • Your employees, wage claims, or employment practices
  • Your tax, licensing, or franchise obligations
  • Your instructions to us
  • An End User’s claim that we are responsible for your business

We will give prompt notice (delay excuses you only to the extent you are materially prejudiced), and you will control the defense with counsel reasonably acceptable to us. You may not settle a claim that imposes any obligation on us, other than payment of money you fund, without our written consent.

23. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST DATA, COST OF SUBSTITUTE SOFTWARE, REPLACEMENT OF END-USER RELATIONSHIPS, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE SERVICE OR THESE TERMS — WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE AND, TO THE EXTENT UTAH LAW ALLOWS, GROSS NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE — IS LIMITED TO THE GREATER OF (A) THE FEES YOU ACTUALLY PAID TO PROVIDER FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY, OR (B) FIVE THOUSAND U.S. DOLLARS ($5,000). IF YOU ARE ON A $0 PASS-THROUGH PLAN AND HAVE PAID NO SOFTWARE FEES, THE CAP IS FIVE THOUSAND DOLLARS ($5,000) UNLESS AN ORDER FORM SETS A DIFFERENT FLOOR.

That cap is a single aggregate cap. It is not multiplied for multiple claims or for a Security Incident. It applies to any Provider indemnity. It does not limit your payment obligations, your indemnity in Section 22, your breach of Sections 4 or 6, or a party’s fraud or willful misconduct.

We have no liability for loss caused by your credentials, users, configuration, instructions, failure to export, or a Connected Service, except to the extent caused by our failure to apply Section 16. Fees reflect this allocation of risk. You agree it is the essential basis of the deal. If a signed order form states different liability terms and expressly references this Section, that form controls for that engagement.

24. Your insurance

You will maintain insurance customary for your operations, including commercial general liability and, where applicable, workers’ compensation, professional liability, and cyber. Our software subscription is not a substitute. On request you will provide certificates.

25. Trustee and entity

You agree to look solely to the assets of GullStack Trust for any obligation under these Terms. You waive, to the maximum extent law allows, any claim against Josh Cohen personally, any beneficiary, and any other trust or DBA except a signed writing that names that person as a party.

26. Governing law, venue, class waiver, claim period

Utah law governs, excluding conflict-of-law rules and excluding the U.N. Convention on Contracts for the International Sale of Goods. The state and federal courts located in Salt Lake County, Utah have exclusive jurisdiction. Each party consents to personal jurisdiction there and waives forum non conveniens.

Before filing, the complaining party will give written notice and 30 days to escalate to principals. Either party may seek injunctive relief at any time for misuse of IP, Confidential Information, or a violation of Section 4 or 14.

Disputes must be brought only in an individual capacity. You waive any right to a class, collective, coordinated, or representative action to the maximum extent Utah and federal law allow. EACH PARTY WAIVES ANY RIGHT TO A JURY TRIAL. Any claim must be filed within one (1) year after it accrued, or it is permanently barred, except for your nonpayment or a claim that may not be shortened by statute.

27. General

These Terms, the DPA, the Privacy Policy (as to public-site data), and any signed order form are the entire agreement. Terms on your purchase order or vendor portal are void. You may not assign these Terms without our consent, except to a successor of substantially all of your assets if the successor is not a competitor and assumes these Terms in writing. We may assign to an affiliate or to a successor of the Cinch business.

We may use the subprocessors listed in the DPA and Privacy Policy. Neither party is liable for delay caused by events beyond its reasonable control, including hosting or Connected Service failures. You will not use the Service in violation of U.S. export or sanctions laws. If you are a public entity, you represent you have authority to agree to venue, the liability cap, and the indemnity to the extent your enabling law allows.

Legal notices to Provider: josh@gullstack.com with a copy to bryce@gullstack.com, and to GullStack Trust, Draper, Utah. Notices to you: the owner email on the tenant. Email is effective when sent without bounce. Nothing creates a partnership, joint venture, employment, or fiduciary relationship. There are no third-party beneficiaries except the indemnified persons in Section 22. Invalid terms are severed. Failure to enforce is not a waiver. Electronic acceptance, clickwrap, and electronic signatures are binding. We may keep records of version, timestamp, IP, and account identity. English controls.

Order of precedence: signed order form (only where it expressly overrides) → these Terms → DPA → Privacy Policy.

28. Changes to these Terms

We will post a revised version at this URL and email the owner address at least 30 days before a material change takes effect (except changes required by law, which may take effect sooner). Continued use after the effective date is acceptance. If you do not agree, cancel before that date.

29. Contact

Legal / Trustee: josh@gullstack.com. Accounts: bryce@gullstack.com. Security: same Trustee address, subject [SECURITY]. Or book a call.