We run an approval-first business: every client is reviewed by a human before any access is granted, every campaign is reviewed by the client before any send happens, and we never ask for passwords. Here's the full picture, in plain language.
Last updated: 2026-08-11
Every engagement starts at /apply. You submit a short business intake — your industry, monthly volume, platform, and what you want to fix — and your application lands in an admin approval queue.
Nothing is automatic. No account, no portal access, no shared link, no payment request is created until a human reviews your application and approves it. If we are not the right fit, we tell you before any money or data changes hands.
We do not run unattended campaigns. Every draft — report, segment, email, SMS, or reactivation flow — passes through your approval queue before it leaves the platform. The flow is always:
We draft → we send to the queue → you review → you explicitly approve or you reject and we revise → only then does the message go to your customers.
If you do nothing, nothing sends. There is no schedule that runs without you, no AI that puts words in front of your customers without your eyes on them first, and no overnight send window.
Card payments for the Customer Loss Audit and ongoing monthly retainers are processed by Stripe Checkout. Stripe collects the card number, expiry, and CVV directly in their hosted form. Co & Co never receives, stores, or transmits raw card data — at no point does a card number touch our servers or database.
What we do receive from Stripe is the minimum we need to reconcile an invoice: a Stripe payment identifier, the amount paid, the timestamp, and the package you selected (see current pricing). Stripe's own privacy and security practices apply to the card data they handle.
To work on your customer list we use the same access paths your platform already supports — the ones that don't require you to share a password:
Shopify collaborator invites, Klaviyo and Omnisend read-only API keys, approved CSV exports that you share through a secure link, or read-only booking-platform access. We never ask you to share a username and password.
Credentials we do receive as part of those official paths are encrypted at rest. We do not persist raw passwords in our database. When an engagement ends, we revoke our access on your platform side.
All email goes through one address: coandcogrowthsystems@polsia.app. We don't use personal Gmail or Outlook accounts for client communication, and we don't copy you on internal mail.
Every transactional email we send — payment links, application confirmations, approval-queue notifications, onboarding reminders, reactivation drafts — is logged in our email_sends table with timestamp, recipient, and send type so we have a clean record of what went out and when.
If you want to stop receiving a non-essential message, every email contains an unsubscribe link backed by the /unsubscribe route, and we honour those requests within one business day.
We're happy to answer in plain language. No legal jargon, no sales call required.
Questions? Email coandcogrowthsystems@polsia.app