Privacy policy
This policy explains what personal data winful handles, why, who it goes to, how long we keep it and what you can ask us to do with it. It covers winful.app, the product at app.winful.app, the video pages we host for brands and the tracking snippet brands put on their own sites.
Last updated: 12 September 2026
The company behind winful is called winful. Its registered address will be listed here, and in your contract, once registration is complete.
Who we are and our role
winful is operated by winful.app. For the people who use winful for their company and for visitors to winful.app, we decide how personal data is used, so we are the controller.
For data about a brand's own customers, which reaches us through the brand's store, ad accounts, tracking snippet or video pages, we work for that brand. The brand is the controller and we process the data on its instructions. If you are one of those customers, you can contact the brand or us, and we will help either way.
What we collect
What we handle depends on how you meet winful.
- If you use winful: your name, work email, company and role, sign-in events, the settings you change and the messages you send us. You sign in with a one-time code sent by email, or with Google.
- If you visit winful.app: the pages you request, recorded in server logs with your IP address and browser type. The calculator on Run your numbers works inside your browser, and nothing you type in it is sent to us.
- From a brand's Meta ad accounts: the access the brand grants us; account, page, Instagram and pixel ids; campaigns, ad sets, ads, budgets and targeting settings; results such as spend, impressions, clicks and conversions; and a record of every change the machine makes.
- From a brand's store, for example Shopify: order number, amount, currency, date, refunds, and the ad, campaign and page that brought the buyer. The buyer's email or customer id is turned into a one-way pseudonymous reference when the order arrives, and we keep the reference, not the email.
- If you film a video for a brand: your first name, your email (stored encrypted), the video and its transcript, the scripts you were offered, the permission you accepted with the time, your IP address and browser, and any reward, such as a discount code.
- If you visit a brand's site that uses our snippet: the first and last ad you arrived from, a random visitor id and one page view per page, as described under cookies below.
- For billing: the company's legal name, billing email and address, tax id, invoices and payment records. Card details go straight to the payment provider, and we never see full card numbers.
How we use it
- To provide winful: run and measure campaigns, cut videos, compute the ledger and send invoices. The basis is our contract with the brand, or the brand's instructions.
- To keep winful secure: prevent abuse, protect accounts and investigate problems. The basis is our legitimate interest in a safe service.
- To talk to you: service emails, invoices, support answers and, for people who film, the reward and news about their video. The basis is our contract, or the permission you gave.
- To meet legal duties, such as keeping tax records and answering lawful requests.
- To improve the machine, using statistics that identify neither a brand nor a person. The basis is our legitimate interest in a better service.
We do not sell personal data. We never use one brand's data for another brand, and we do not build profiles of people across brands.
Data from Meta
When a brand connects a Meta ad account, we use the data from it only to run, measure and report on that brand's own advertising. We do not sell it, give it to other clients, use it for any other advertiser or use it to build audiences for anyone else.
Access tokens are stored encrypted. A brand can remove winful's access at any time in its Meta business settings, and from then on the machine stops reading or changing that account. The data deletion page explains how to have the stored data deleted.
We follow Meta's Platform Terms for data we receive from Meta.
Customers' videos
The video pages we host for a brand ask for your first name, your email and a video you film. Before you upload, you accept the brand's permission text, which says how the brand may use your video. We keep a record of that acceptance with the video.
The machine transcribes the video, checks its quality and cuts it into versions that may run as ads in the brand's accounts. Your email is used to send your reward and news about your video. It is never shown in an ad.
To have your video removed, write to the brand, or to privacy@winful.app from the email you used. Within 2 business days the video is taken out of new ads and the ads that use it are paused. Within 30 days the video, its cuts and its transcript are deleted from our storage. Copies people already saved or shared outside winful are beyond our reach.
Where data is stored
winful stores data in the United States. When personal data moves from the European Economic Area, the United Kingdom, Switzerland or Israel to a country without an adequacy decision, we use safeguards the law recognizes, such as the standard contractual clauses approved for the EU.
How long we keep it
- Workspace data: while your contract runs. For 30 days after it ends you can ask us for a copy. We delete it within 90 days after the contract ends.
- Invoices and payment records: as long as tax law requires, usually 7 years.
- Customers' videos: while the brand uses them within the permission given. A video is deleted within 30 days of a removal request, and with the rest of the workspace after the brand's contract ends.
- Raw events from stores and ad platforms: up to 30 days. After that we keep only the processed records described above.
- Server logs: kept by our hosting and database providers, who delete them within 30 days.
- Security and audit records: up to 2 years.
How we protect it
Connections are encrypted in transit. Access tokens, webhook secrets and the emails of people who film are also encrypted at rest. Each brand's data is kept apart by access rules in the database. Our staff open a workspace only to support it, read-only, for a limited time and with a recorded reason, and every such access is written to an audit log.
Your rights
Depending on where you live, you can ask to see the personal data we hold about you, correct it, delete it, get a copy, limit or object to how it is used, and withdraw permission you gave. Residents of California and other US states with privacy laws can ask to know, delete and correct their data. We do not sell personal data or share it for cross-context behavioral advertising.
Write to privacy@winful.app. We answer within 30 days. If we hold the data for a brand, we pass your request to that brand and help it answer.
You can also complain to a data protection authority, such as the one in your EU country, the UK Information Commissioner's Office or Israel's Privacy Protection Authority.
Children
winful is for businesses, and the video pages are for people 18 and over. We do not knowingly collect data from children. If you think a child sent us personal data, write to privacy@winful.app and we will delete it.
Changes to this policy
When we change this policy, we update the date at the top. If a change matters, we email workspace owners before it applies.
Contact
Write to privacy@winful.app with any question about your data. To have data deleted, follow the data deletion instructions.