Privacy Policy
First Name Cleaner is a product of Waterloo Digital LLC. · Last updated: September 29, 2026
Waterloo Digital LLC
Effective Date: June 23, 2026
Last Updated: September 29, 2026
1. Introduction
First Name Cleaner (“First Name Cleaner,” “we,” “our,” or “us”) is a service operated by Waterloo Digital LLC that cleans and standardizes first names in your contact data and extracts first names from email addresses. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the First Name Cleaner application at app.firstnamecleaner.com and our website at firstnamecleaner.com.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name and email address. If you sign in with Google or GitHub, we receive basic profile information (your name, email address, and a profile identifier) from that provider. If you register with an email and password, your password is stored only in hashed form — we never store it in plain text.
2.2 Data You Submit for Processing
To clean or extract names, you provide contact data — typically a CSV file you upload, or a marketing or commerce platform you connect — containing names, email addresses, and related fields. We process this data to produce cleaned or extracted first names, confidence scores, and a change report, and we store these results so you can review, export, and restore them. When you write cleaned names back to a connected platform, we also keep a per-record change log of that write-back — the prior first name (where available from the platform), the new first name, and the outcome — so you can audit and download exactly what changed in your account. These records are part of your job data and follow the retention schedule in Section 6.
Platforms you connect. The service can connect to your own accounts on supported platforms — currently Klaviyo, HubSpot, and Mailchimp (Shopify is coming soon). When you connect a platform, you authorize us to access it using the credentials you grant, to read your contacts’ names and email addresses for cleaning, and — only when you request it — to write cleaned first names back to that platform. These are your own platform accounts, governed by your agreements with those providers; we access them solely at your direction to provide the features you request. The API keys and access tokens you grant are stored encrypted, and you can disconnect a platform at any time (see Section 13).
2.3 Google Account Data
If you connect your Google account, then with your authorization we access: (a) your basic Google profile and email address, to sign you in and identify your account; and (b) if you use the Google Sheets export feature, the Google Sheets permission needed to create a new spreadsheet in your Google account and write your results to it. To carry out the exports you request, we securely store the access and refresh tokens Google issues to us. We request only the access these features require.
2.4 Payment Information
Payments are processed by our payment provider, Stripe. We do not store full payment-card details; we retain limited billing identifiers (such as a customer or subscription ID) to manage your plan.
2.5 Usage Information
We collect limited operational data, such as the number of records processed and job metadata, to enforce plan limits and operate the service.
When you visit our website or use the application, our hosting infrastructure automatically records standard server logs: your IP address, your browser’s user agent, the referring page, the page or endpoint requested, and the time and response status of the request. We use these logs only to operate, secure, and troubleshoot the service. Our application’s own log entries record technical events with internal identifiers, not your contact data.
2.6 Cookies
We use cookies that are essential to sign you in and keep you signed in. See Section 7.
3. How We Use Information
- Service delivery: clean and extract names, show you a preview before any change, maintain your change log and restore points, and export results to your Google Sheets when you request it.
- Name processing: we clean and standardize names using our own deterministic, rule-based engine running entirely on our infrastructure. Your contact data is not sent to OpenAI, Anthropic, or any other third-party AI provider, and we do not use your data to train AI models. When our engine cannot confidently clean a record, it holds that record for your review rather than guessing.
- Account & billing: manage your account, subscription, usage limits, and support requests.
- List Health Monitoring: if you enable List Health Monitoring, we analyze the contact data in your connected accounts when you request a scan and, if you turn on List Health update emails, on a regular schedule (monthly, or weekly on paid plans), to count records that need cleaning and to generate your List Health updates. Email addresses and first names are processed transiently to compute the results; only aggregate counts and synthetic examples are retained. You can disable this at any time in your account settings.
- Product & service communications: we send you (a) transactional messages about your account and (b) product and List Health emails. We send List Health update emails only if you turn them on in your account settings. You can opt out of product and List Health emails at any time via the unsubscribe link or your account settings, without affecting transactional messages or your use of the Service.
We do not sell your data, and we do not use the contacts in your lists, or Google user data, for advertising.
4. Google API Services User Data Policy — Limited Use
First Name Cleaner’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide the features you request (signing you in and exporting your results to your Google Sheets); we do not transfer or sell this data, except as necessary to provide the service, for security reasons, or to comply with applicable law; and we do not use it for advertising or to train generalized or transferable AI/ML models.
5. How We Share Information
We do not sell personal information. We share information only in these circumstances:
- Service providers (subprocessors): cloud hosting, database, and background-job infrastructure that store and process your data, our payment processor (Stripe), our transactional email provider, our customer-relationship and marketing email platform (GoHighLevel), which holds your account contact details and sends product and List Health emails, abuse-prevention (rate-limiting) infrastructure, error-monitoring infrastructure (Sentry), and log-management infrastructure (Axiom), which stores the server logs described in Section 2.5 — each under data-protection terms and only to operate the service. Our error monitoring is configured not to receive personal data: it captures technical error details and non-identifying context, not your contact data.
- Platforms you connect: when you use a connected platform (such as Klaviyo, HubSpot, or Mailchimp), we send data to that platform only at your direction — for example, writing cleaned first names back to your account there. These are your own accounts with those providers, not our service providers.
- Legal requirements: when required by law, regulation, or legal process.
- Business transfers: in connection with a merger, acquisition, or sale of assets.
6. Data Retention
Processed job data is deleted automatically. The contact data and results associated with a completed processing job — including uploaded records, cleaned results, and write-back change logs — are automatically and permanently deleted 90 days after the job is created. This automatic deletion runs daily. Before a job's data is scheduled for deletion, we notify you by email so you can export your results first (CSV or Google Sheets export is available on every plan); the app also shows a deletion notice on jobs approaching their deletion date. Jobs that are still processing are never deleted mid-run. We may shorten this retention window in the future; if we do, we will update this policy and provide notice before the change takes effect.
Account data (your name, email, and settings) is retained for as long as your account is active. You can delete a processing job, request deletion of your data, or close your account at any time, after which we delete the associated data — except for limited records we must keep for legal, security, or accounting purposes: billing transaction records and fraud-/abuse-prevention records are retained after account deletion, with their link to your account identity removed (see Section 13). No personal data is retained longer than necessary for its stated purpose.
Server logs (Section 2.5) are kept for up to 30 days and then deleted automatically.
7. Cookies and Tracking
Essential cookies. The First Name Cleaner application uses cookies that are required to sign you in and keep your session secure. These are always set.
Attribution cookie, only with your consent. On our marketing website, nothing beyond essential cookies is set until you choose Accept on the privacy banner. If you accept, we set one first-party cookie on firstnamecleaner.com that identifies your browser so we can see which campaign, link, or search brought you here and, if you later sign up or buy, connect that to your account. It lasts up to two years unless you withdraw. With your consent we also load Google Analytics, Meta's measurement tools, and the visitor-tracking script of our customer relationship system (GoHighLevel), which set their own cookies for the same purpose. Attribution data we hold is deleted 90 days after it is collected. If you accept and have an account with us, we save your choice to your account and use it to share account activity, such as sign-ups and purchases, with our advertising and analytics partners for campaign attribution and to improve your experience. You can withdraw at any time from Privacy choices.
Your choices. Reject on the banner sets nothing. You can withdraw consent at any time from Privacy choices in the site footer: withdrawing removes the attribution cookies from your browser (the Google, Meta and GoHighLevel cookies above, and the analytics identifiers our measurement server sets, FPID and FPLC, which it expires on the same request) and stops any further attribution for it. You can also control cookies through your browser settings.
8. Data Security
We implement appropriate technical and organizational measures to protect information, including:
- Encrypted storage of credentials and access tokens
- Access controls limiting data access to authorized personnel
- Regular security reviews of our systems and processes
- Secure deletion of data when no longer needed
9. GDPR Compliance
For individuals in the European Economic Area (EEA), United Kingdom, or Switzerland:
Legal Basis for Processing: we process personal data to perform our contract with you (providing the service you sign up for), on the basis of our legitimate interests in operating and securing the service, and, where applicable, with your consent.
Your Rights Under GDPR: you have the right to access the personal data we hold about you; request rectification of inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; data portability; and lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@waterloo.digital.
10. Your Rights
Depending on your location, you may have rights to access the personal information we hold about you, request correction or deletion, object to or restrict certain processing, and request data portability. To exercise these rights, contact us using the information below.
11. Children’s Privacy
Our services are not directed to individuals under 18, and we do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last Updated” date.
13. Revoking Access and Deleting Your Data
You can disconnect First Name Cleaner from your Google account at any time at myaccount.google.com/permissions, and from GitHub in your GitHub authorized-apps settings. You can disconnect a connected marketing or commerce platform (Klaviyo, HubSpot, or Mailchimp) at any time from the integrations area of the app, and additionally revoke our access from that platform’s own settings. To request deletion of your data, email privacy@waterloo.digital with the subject “First Name Cleaner Data Deletion Request.” We will confirm receipt and delete the associated data within 30 days, then send a confirmation.
When your account is deleted, your profile, processing jobs, and all associated contact data and results are permanently deleted immediately. Two categories of records are retained after account deletion, with the link to your account identity removed: billing transaction records (kept for accounting and tax purposes) and fraud-/abuse-prevention records (kept to enforce free-tier limits and protect the service). Neither retains your contact lists or processing results. The email address on a billing transaction record is masked 90 days after your purchase, leaving the transaction itself (amount and date) on record without a readable address. Early-access sign-up details you submit that do not lead to an account are deleted automatically one year after submission.
14. Contact Us
For questions about this Privacy Policy or to exercise your rights:
Waterloo Digital LLC
510 Austin Avenue
Suite 1000 #25599
Waco, TX 76701
Email: privacy@waterloo.digital
Website: firstnamecleaner.com