Legal · Listfit

Privacy Policy

Effective date: June 6, 2026 · Last updated: June 6, 2026

This Privacy Policy applies specifically to the Listfit product operated at listfit.app and describes how we handle your Mailchimp list data. The AVSaaS company-wide Privacy Policy also applies and governs any areas not specifically addressed here.

1. What Data Listfit Accesses from Mailchimp

Listfit connects to your Mailchimp account using your API key. Listfit reads: contact engagement data for your selected audience (open rate, click rate, and last activity timestamps) to compute a hygiene score for each contact. It does not read email message content, payment data, or data from other Mailchimp products outside the audience you connect.

The data we store is: your Mailchimp API key (encrypted, never in plaintext), scan results including per-contact scores and band assignments, and the timestamps of each scan. We retain scan data for 90 days on a rolling basis.

2. Archive Feature

If you use the archive feature (Standard plan), Listfit sends archive requests to Mailchimp for the specific contacts you select and confirm. This is a soft archive in Mailchimp — contacts are not hard-deleted and can be restored from your Mailchimp account. Listfit never permanently deletes contacts. Archive actions are logged per scan for your reference.

3. Data Residency

Scan data is stored in the region you select at account creation: EU-Central (Frankfurt) or US-East (Virginia). Data does not replicate across regions.

4. API Key Storage

Your Mailchimp API key is encrypted at rest and in transit. It is used only to read engagement data for scoring and to submit archive requests you explicitly confirm. We will never expose your key to other users, include it in logs, or use it for any purpose beyond the Listfit product functions.

5. Retention and Deletion

Scan results are retained for 90 days on a rolling basis. When you disconnect your Mailchimp account or cancel your Listfit account, all scan data is deleted within 30 days. You can request immediate deletion by emailing [email protected].

6. Notification Data

To deliver account and waitlist emails, Listfit stores the email address associated with your account. This address is stored encrypted and used only for account-related and service communications. We do not use it for marketing.

7. Contact

Data privacy questions for Listfit: [email protected]