Data & Enrichment
W

Wavo

Wavo sells a contact database of ecommerce store owners who do not appear in the databases everyone else licenses, and bundles a sending tool to reach them.

The thesis is narrow and specific. Mainstream prospecting tools build their files from professional network profiles, and most people running profitable ecommerce brands do not maintain one. They are running stores and buying traffic instead. So the tools every agency uses share a blind spot, and every agency ends up competing over the same visible fraction of the market while the rest sits uncontacted.

Wavo identifies brands through how their stores actually operate, using traffic patterns, advertising activity, technology stack and revenue signals, then works out who owns the brand. Its own published analysis of 2.8 million United States ecommerce brands puts the share missing from mainstream databases at roughly 40 percent.

Around the data sits a sending platform with warmup, address rotation, custom tracking domains, authentication and automatic suppression of contacts already reached, plus generated personalisation.

The buyer is an ecommerce agency, named down to the discipline, from solo operators to twenty person teams.

Access is gated. There is no self serve signup and no published price. The trial is activated on a booked call during which the vendor filters the database to the buyer's niche with them.

The founder publishes an explicit restraint standard, arguing for fifty relevant messages over five thousand poor ones and that every message should survive being screenshotted and shared.

The operator is Carsy Inc. of Toronto, trading since 2017.

Last VerifiedAugust 24, 2026
Compare Wavo with other vendors
Founded
2017
Headquarters
Toronto, Ontario, Canada
Website
wavo.co
Categories
data-and-enrichment, sales-engagement
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

Generated personalisation sits on top of a data business, and the founder's own pitch never mentions it.

The feature is real and appears on both the home page and the features page. It generates outreach copy intended to sound like the sender wrote it, and the claimed effect is three times more replies. Directory listings maintained by the vendor add that the generation runs through an external provider.

Everything else is data engineering. Brands are identified by traffic patterns, advertising activity, technology stack and revenue signals, then the owner behind each brand is resolved. That work is plausibly assisted by models and the vendor claims nothing about it either way.

Remove the generation feature and the product is entirely intact. A buyer still gets the database that nobody else has, the warmup and address rotation, the tracking domains, the suppression of contacts already reached and the sequencing. The founder's own argument for the product is that the failure of cold outreach was never the message, it was the list, which is an argument that the model layer is not where the value sits.

The strongest evidence for the grade is what the vendor chooses to lead with. The trial page runs to well over a thousand words on why the data is different and does not mention generation once.

Ask whether the personalisation draws on the store level signals held about each brand or only on the fields in the record, because the first would be a genuine use of the underlying asset and the second is commodity copywriting.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

A conventional sequencing tool with modest automation, described too thinly to audit.

What runs without a person is bounded and ordinary for the category. Sequences send on a schedule. Follow ups fire on stated conditions, with an independent reviewer describing rules such as sending only when no response has arrived within five days. Suppression filters out contacts already reached without being asked. Deliverability infrastructure rotates sending addresses on its own. Copy is generated rather than written.

The low ceiling on autonomy is itself the mitigation. Nothing here decides who to contact, scores a prospect, judges a reply or acts on an inbound message. There is no agent framing anywhere in the product and the vendor does not claim one, so the surface area for an unsupervised mistake is small.

What is missing is the documentation a buyer would need to confirm any of that. Two passes located no description of what executes unattended, no approval step between generation and send, no statement of whether a human reviews generated copy before it reaches a recipient, and no controls page describing limits, pacing or pause conditions.

One automation deserves specific mention because it acts on people rather than on infrastructure. Automatic suppression decides that a contact has already been reached and removes them from a campaign, and the rule behind that judgement is unpublished.

The onboarding model supplies informal oversight that the product does not. Setup runs two weeks with hands on configuration by the vendor, and the trial list is built with the buyer on a call, so a person is in the loop at the start whether or not the software requires it.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

The model provider is named, but only on aggregator listings, and the governing documents predate the feature entirely.

Where the disclosure exists it is clear enough. Vendor written copy on five separate software directories states that the personalisation integrates with a named external provider's assistant, identifying who processes the generation. That copy is the vendor's own, so it counts.

The problem is where it does not exist. The current website, rebuilt during 2025 and 2026, describes the same feature as generating outreach that sounds like the sender wrote it and names no provider, no model and no version. The disclosure survived the redesign only on third party pages the vendor does not control the presentation of, which means a buyer researching on the primary surface finds nothing.

The legal layer is silent in a way that matters more. The privacy policy was last revised in June 2021, years before generated personalisation existed, and describes only customer uploaded contact data. It contains no statement about model processing at all. A buyer therefore has no disclosed answer to the question that governs whether they can use the feature on European or Californian prospects, which is whether prospect records are transmitted to an external model provider and what that provider may retain or train on.

The terms of use, revised more recently in February 2025, are equally silent on the feature.

Two passes located no statement that customer or prospect data is excluded from provider training, no data processing terms covering the model layer, and no description of what the generation is conditioned on.

A one line provider statement on the features page and a clause in the privacy policy would move this grade substantially.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
BB on Operational and Outcome EvidenceReal outcome evidence published, with named customers and numbers, but the measurement basis is incomplete: population, period, or definition unstated.
Third Party Estimated

Five named references with employers and figures, plus a market claim carrying a stated denominator, against almost nothing independent.

The references are the strong part and they are specific in the way that makes them checkable. A revenue chief at an Amazon growth agency reports a five to one close rate against other sources and four times more leads, and separately reports growing from seven staff to forty five with this as the leading client source over seven years. A digital strategy lead at another agency reports four percent response rates against under one percent from traditional databases. A paid media operator reports five to seven quality conversations and one to two new clients monthly. A development shop owner describes being stuck at twenty thousand dollars monthly beforehand. Each carries a full name, a role and a named company.

The market claim is better still because it has a denominator. The vendor publishes an analysis of 2.8 million United States ecommerce brands concluding that roughly forty percent are absent from the databases most agencies rely on, and gives it a dedicated page. A falsifiable methodological claim behind the central product thesis is rare in this index.

The independent layer is where it thins badly. One major directory carries a single review, that reviewer was offered a gift card as disclosed by the platform, and the review describes newsletters and mass mail rather than the database. Another directory records no reviews at all. An independent comparison notes the absence of social proof and observes that access by application makes the tool difficult to evaluate from outside.

Customer logos appear as unlabelled image files with no company names anywhere in the page.

The headline percentages, eighty eight percent better inbox placement and three times more replies, carry no method, sample or baseline and are hedged as up to.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

A detailed acceptable use policy governing the sending, and nothing at all governing the database.

The contractual apparatus is better than the category average and it is specific rather than gestural. Spam, spoofing, phishing and header manipulation are each defined as terms and then prohibited. Impersonation and disguising data origin are prohibited. Content categories including hate speech, incitement to violence and fraudulent inducement are prohibited. The vendor reserves the right to review campaigns sent through the service and to delete an offending account without notice.

Two obligations are placed on the user in explicit language. Where applicable law requires it, the user must give notice to contacts and obtain consent before reaching them. And no message may go to anyone who has expressed a wish to be excluded from further correspondence. Sending is contractually limited to business to business scope.

The gap is on the other side of the transaction. People in Wavo's own database have no published route to get out of it. The removal clause in the privacy policy grants the right to every user, meaning every customer, and a store owner whose address was assembled from store signals and public records is not a user. Two passes located no suppression request form, no data subject contact route for database subjects and no exclusion register.

One omission is conspicuous for a Canadian sender. The commercial electronic messages regime in the vendor's own jurisdiction is among the strictest consent frameworks anywhere and is not named once across the site, the terms or the privacy policy.

A compliance statement that the terms define as binding is referenced twice and published nowhere.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
DD on Data Privacy PostureNothing a buyer can check: no DPA located, no lawful basis stated, no privacy documentation beyond boilerplate, on a product that processes personal data at scale.
Vendor Published

The privacy policy describes a different product from the one being sold, and the difference is the entire database.

It was last revised in June 2021 and it covers a tool where the customer uploads their own contacts. It states that the service processes any information the user chooses to upload, and commits firmly that such contact data will never be shared or used. That commitment is real and it is worth something.

What the policy never mentions is the contact file the product is now sold on. Personal data concerning hundreds of thousands of store owners, assembled from store signals and public records without those people ever interacting with the company, has no privacy notice, no stated lawful basis, no retention period, no accuracy commitment and no data subject rights attached to it anywhere on the site.

A second privacy policy remains live at a different path with a different corporate address and names a hosting platform staging subdomain as the company website. Two conflicting notices are published simultaneously.

The policy advises anyone wishing to remain anonymous to use private browsing so the company is unable to collect any data. That is incorrect, and the same document contradicts it four paragraphs later by listing the address, browser type and requested pages recorded in server logs, none of which private browsing affects. Publishing wrong guidance to data subjects is a defect in itself.

The data protection officer named is the founder and chief executive, which is the conflict the role exists to prevent.

The security section consists of a pointer to a document that is not published. A Californian notice is absent despite a file of United States decision makers. The company reserves the right to change the policy without notice.

Processors are named individually with their function, which is the one modern element in a five year old document.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
CC on Data Licensing and ProvenanceData is described by its size and coverage with its origin unstated. The provenance question is answerable only by asking the vendor.
Vendor Published

The collection method is described more openly than most, and the licence to hold any of it is never addressed.

On method the vendor is genuinely forthcoming, because the method is the differentiator and hiding it would defeat the pitch. Brands are mapped through how their stores operate online, using traffic patterns, advertising activity, technology stack and growth or revenue signals. The vendor states plainly what it does not use, naming professional network profiles and purchased lists, and identifies two named competitors as the tools that rely on the former. Directory copy adds proprietary web crawling and public records. Once a brand is identified, the decision maker behind it is resolved and the address verified, with the vendor stressing that these are real owner addresses rather than generic company inboxes.

On licence there is nothing. Two passes located no lawful basis for holding personal data about people who never contacted the company, no notice to those people, no definition of what public records means in this context, no supplier list for any purchased component, no correction route and no accuracy or bounce rate figure behind the word verified.

The published counts do not reconcile across surfaces. Directories carry 1.4 million United States decision makers. The features page offers 2.8 million United States brands tracked, 735,000 store owners and 13 million global brands. The trial page offers 885,000 untouched brands. Some of these count brands and some count people, and no page states which is which or how they relate.

The home page and features page counters render their figures only through client side animation, so the numbers are absent from the served markup entirely.

Refresh cadence appears as monthly on directories and nowhere on the vendor's own pages.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

The architecture avoids the exposure that dominates this category, and the residual obligations go unaddressed.

The central decision is deliberate and the vendor argues for it openly. The database is built from ecommerce storefronts and public records rather than harvested from a platform whose terms forbid it, and the entire marketing thesis rests on that being a better source. There is no platform account to automate, no credential connection, no proxy layer, no account rotation and no pacing engineered to evade detection. Sending runs over the customer's own mail infrastructure with authentication and custom tracking domains. Set against the professional network automation cohort elsewhere in this index, the difference in exposure is large and structural.

The acceptable use policy reinforces it by prohibiting spoofing, header manipulation and disguising data origin as contractual terms with definitions attached.

The residuals are real and undisclosed. Crawling storefronts at scale engages the terms and machine readable crawl directives of every site touched, and two passes located no statement of how either is honoured. Bulk sender requirements imposed by the major mailbox providers govern the sending side and are not mentioned. The privacy policy contains a section on synchronised mail accounts from a major provider, and that provider's limited use requirements for such access are not addressed anywhere.

The consent regime of the vendor's own jurisdiction goes unnamed, which is an exposure the company carries rather than one it passes on.

A buyer inherits far less platform risk here than from most vendors in this category, and should still ask how crawl directives are handled before signing.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
DD on AI Safety and Data StewardshipNothing published on how customer data is used in model development, on a product built to ingest the customer’s commercial conversations and pipeline.
Vendor Published

The generation feature arrived years after the documents that would govern it, and nothing was written to cover it.

The acceptable use policy is genuinely detailed about content a user may send, prohibiting spam, phishing, hate speech, incitement and fraudulent inducement. Every one of those obligations runs against the user. Two passes located nothing governing what the model itself may produce, no guardrail description, no accuracy statement, no requirement that a person review generated copy before it reaches a recipient, and no policy on generated impersonation of a real individual's voice.

On data stewardship the position splits sharply by whose data it is. Customer uploaded contacts are protected by a firm and unqualified commitment that they will never be shared, sold or used, with internal access limited to maintenance and support and the reasons enumerated. That is a proper commitment and it is honoured in the drafting.

The millions of records the company holds about people who are not customers receive no equivalent. Two passes located no accuracy obligation, no correction route for a store owner whose record is wrong, no retention limit and no deletion mechanism.

On model interactions specifically there is silence in both directions. Whether prospect records are transmitted to an external provider, what that provider retains, and whether any of it may be used for training are all unstated across the privacy policy, the terms and the product pages.

A document titled Safety and Security is defined by the terms as part of the binding agreement between the parties and is not published, so the one artefact that might address any of this cannot be read by the person agreeing to it.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

Genuine sender identity and a published restraint standard, set against undisclosed generation and concealed measurement.

The authenticity floor is solid and partly contractual. Messages go out over the customer's own mail domain with proper authentication, from a real person at a real agency. There is no fabricated persona, no rotation across accounts to disguise a campaign's origin and no borrowed identity. The acceptable use policy defines spoofing, phishing and impersonation as terms and prohibits all three, along with manipulating headers or otherwise hiding where a message came from. Prohibiting concealment in the contract is more than most vendors in this category do.

The founder publishes a restraint standard as product philosophy, arguing against volume outreach, preferring fifty relevant messages to five thousand poor ones, and proposing that every message should be one the sender would still be comfortable with if it were screenshotted and shared publicly. Recording that because it is unusual: a vendor whose revenue scales with sending volume is arguing publicly for less of it.

What the recipient is not told runs the other way. The message is generated and marketed on sounding as though the sender wrote it, with no marking of any kind. Opens and clicks are recorded through custom tracking domains, and the specific function of a custom tracking domain is to prevent the recipient recognising the tracker.

The recipient is in the database because their store was analysed, was never informed, cannot see what is held and has no route to be removed. The obligation to honour an opt out exists in the terms and binds the customer rather than the vendor.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
CC on Ecosystem and Integration DepthIntegrations are listed as logos. Depth, direction, and limits are not documented anywhere a buyer can read.
Vendor Published

Every integration surface is claimed and almost none of it is evidenced.

The claims are broad. Programmatic interfaces, webhook support, native record system integrations, support for all major record systems, and developer documentation at a published address. Synchronised mail accounts from a major provider are covered in the privacy policy, so that connection is real.

The evidence stops well short. The integrations showcase on the features page renders exactly one logo, for a single mid market record system, and it renders with the raw design tool export string still attached to the asset name. Two passes located no integration directory, no marketplace listing, no named connector list and no partner page. Support for all major record systems is asserted beside a display of one.

The developer documentation sits behind the application login rather than on a public documentation site, so a buyer cannot assess the interface, its objects, its rate limits or its authentication model before signing a contract. For a product sold on the quality of its data, the inability to inspect how that data comes out is a meaningful evaluation barrier.

What does exist is coherent with the buyer. An ecommerce agency running a light stack needs a record system connector, a webhook and a way to pull a list, and all three are offered.

The absence of an ecosystem in the other direction is more surprising given the market. Two passes located no connection to any ecommerce platform, advertising platform or analytics tool, despite the database being built from precisely those signals.

Ask for the documentation before the trial call rather than after.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
DD on Deployment Model and Data ResidencyNothing published on where or how the product runs and where customer data is stored.
Vendor Published

Cloud delivery with no disclosed infrastructure of any kind.

Two passes located no hosting provider, no region, no availability zone, no architecture description, no infrastructure subprocessor list, no service status page, no uptime commitment, no recovery point or recovery time objective, and no backup description. Encryption appears once as a single word on the features page with no algorithm, scope or distinction between transit and rest.

The residency question is left entirely open and the facts make it pointed. The operating company is Canadian, the database is composed of United States decision makers, and the customer base is agencies serving brands in multiple jurisdictions. Nothing anywhere states where any of that data is processed or stored, and no residency option is offered.

The document that would ordinarily answer this is defined by the terms of use as part of the binding agreement and is not published. The privacy policy's entire information security section is a single sentence directing the reader to that unpublished document.

One infrastructure detail is retrievable and only by accident. A superseded privacy policy still live at another path names a hosting platform staging subdomain as the company website, which is the sole hosting signal available anywhere and one the vendor plainly did not intend to publish.

Delivery is cloud only with no self hosted or dedicated option, which is consistent with the buyer and closes off anyone whose procurement requires one.

The processor list does disclose two session recording tools, which tells a security reviewer something real about what is observed inside the application, and is a point in the vendor's favour on candour if not on posture.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
DD on Security Certifications and Trust CenterNo verifiable security posture published for a product that ingests commercial data at scale.
Vendor Published

One line on the features page stands in for the entire security posture.

That line reads that data stays protected with role based access and encryption. Two passes located nothing else: no examination report, no information security management certification, no penetration test summary, no trust portal, no security questionnaire response, no vulnerability disclosure route and no named security contact.

The structural failure is worse than the absence. A document titled Safety and Security is defined in the terms of use as forming part of the binding agreement between the parties, alongside the terms and the privacy policy. It is referenced a second time in the privacy policy, where the whole of the information security section consists of an instruction to read it. It is not published anywhere on the site and two passes failed to locate it. A customer is therefore contractually bound to a security document they cannot read, and the only security disclosure the vendor makes is a pointer to it.

The same pattern repeats with a compliance statement that the terms likewise define as an inherent part of the agreement and which is equally unpublished.

For a company holding personal data on hundreds of thousands of people who are not its customers, and synchronising customer mail accounts, the disclosed control set amounts to two nouns.

What the vendor does disclose is the processor stack, naming six third parties and what each handles, including two session recording tools that observe user behaviour inside the application. That is genuine transparency and it sits in the privacy policy rather than in any security material.

Publishing the two referenced documents would be the cheapest available improvement to this grade.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
DD on Commercial TransparencyBook a demo is the entire commercial disclosure. In a category this competitive, silence on price is a choice, and this grade records it.
Vendor Published

Access begins with a booked call and no figure is published anywhere.

Two passes located no price, no tier, no range, no unit rate, no per seat figure, no credit rate and no starting point, across the vendor's own site and five software directories, all of which record pricing as available on request. The terms of use define a pricing plan as a governing term of the contract and no plan is published.

The gating is by design rather than oversight. There is no self serve signup. Even the free trial is activated during a fifteen minute call, on which the vendor filters the database to the buyer's niche with them and helps them decide what to say. The buyer leaves with an account and a list, which is a genuinely useful evaluation experience and is also a sales conversation that cannot be avoided.

The commercial mechanics that are published are unusually clear, and they keep this off the bottom of the scale. Billing runs month to month, charged in advance through a named payment processor. Either party may terminate without giving a reason. All amounts paid are non refundable. Price changes require thirty days notice by site posting or mail. If the vendor cancels an account without cause it refunds the unused portion, and if there is cause it does not. Trial users are not charged unless they add campaign mail accounts before the trial expires, which names the one way a free trial can generate a bill.

Stated setup time contradicts itself on a single page, promising full configuration within two weeks in one place and reaching brands in days rather than weeks in another.

A buyer cannot compare this vendor on cost against any alternative without first taking a sales call.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
DD on Exit and Data PortabilityNo published export path and no public terms on what survives termination, or terms that require purging delivered data on exit without saying so anywhere a buyer would look before signing.
Vendor Published

The termination clause permits immediate and permanent deletion of everything, with no window in which to leave.

The wording is explicit. Once terminated, the vendor may permanently delete the account and all data associated with it, including the customer's messages held in the service. Termination requires no reason from either side. Two passes located no grace period, no export window, no notice requirement before deletion, no retention commitment after cancellation and no undertaking to make data available on request.

A customer who cancels at the end of a monthly cycle has no stated assurance that their campaign history, reply data or contact lists survive the moment access ends. That is the harshest exit clause recorded in this sweep, harsher than the one hour deletion found elsewhere, because here deletion is discretionary and no timeframe binds it at all.

Ownership is settled correctly in principle. The terms confirm the customer retains all rights to data and content they upload and that the vendor may use it only as described.

Routes out exist while the subscription is live. Programmatic interfaces and webhooks are offered, and a record system connector moves contacts into a system the buyer owns. Two passes located no documented export function, no stated file format and no bulk account export covering campaigns, sequences and message history.

The asymmetry matters more than usual for this product. The value a buyer accumulates is the list of brands surfaced for their niche and the conversation history against it, and the contract that governs both permits their deletion at termination without notice.

A buyer should negotiate a written export window before signing and should hold a current copy externally throughout.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
BB on Deliverability and Sending DisciplineReal deliverability features documented, with the operating discipline (limits, monitoring, intervention) asserted rather than specified.
Vendor Published

Warmup, address rotation and authentication, wrapped in an argument for sending less.

The mechanics are complete for the category. Built in warmup. Address rotation handled by the platform. Custom tracking domains. Mail authentication. Domain monitoring. Automatic suppression of contacts already reached, which removes the commonest cause of a recipient hearing from the same agency twice. Duplicate detection on import, noted by an independent reviewer as working where comparable tools did not. Conditional follow ups that fire on a stated rule rather than a fixed schedule.

The contractual layer supports it. Spam is a defined term and prohibited. Anyone who has expressed a wish to be excluded may not be contacted. The vendor reserves the right to inspect campaigns and terminate accounts that violate either.

The distinctive part is the argument rather than the tooling. The founder's published position is that the failure of cold outreach was never the channel and never the copy, it was the list, and that a correctly targeted fifty beats an untargeted five thousand. The stated test for any message is whether the sender would be comfortable seeing it screenshotted and shared. A deliverability posture built on contacting fewer, better matched people is the only version of this that addresses the underlying cause rather than the symptom, and a vendor billing by volume arguing for lower volume is worth recording.

The supporting claim is unverifiable but coherent: these store owners are not in everyone else's database, so they are not already saturated, so mail to them performs better.

Measurement is the weakness. The eighty eight percent inbox placement figure is hedged as up to and carries no method, sample, baseline or period. Two passes located no bounce rate, complaint rate or placement benchmark, and no disclosed sending limit or bulk sender posture for the major mailbox providers.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

One buyer, named down to the discipline, with the boundary stated rather than blurred.

The buyer is an ecommerce agency and the vendor lists which kinds: paid media, storefront development, marketplace growth, retention, search, conversion optimisation and short form social. Size runs from a solo operator to a twenty person team, stated in those words. Directory listings extend the buyer set to software companies and third party logistics providers, which is a modest and plausible adjacency.

The end market is direct to consumer ecommerce brands, principally in the United States, with a larger global brand count claimed and no evidence of comparable depth outside the domestic file.

What lifts this above a merely narrow focus is that the segment is defined by a number rather than by a persona. The vendor's published analysis puts roughly forty percent of the United States ecommerce brand universe outside mainstream databases, and that figure is simultaneously the market definition, the reason to buy and a falsifiable claim. Most vendors describe who they serve. This one sizes the gap it serves.

The boundaries are hard and the vendor does not pretend otherwise. Outside ecommerce the database has no application whatsoever, since it is built from storefront signals. Outside outbound prospecting the platform offers little. Nothing addresses enterprise buyers, and the two week assisted setup with a mandatory activation call confirms a high touch motion aimed at small teams.

The contradiction to note sits on the same page as the claim: full setup within two weeks in one place, reaching brands in days rather than weeks in another.

A buyer outside ecommerce agencies has no reason to evaluate this at all, and the vendor makes that easy to determine quickly.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Processing Terms Implementation Source
Not published; access and trial activation both require a booked call
No price is published on the vendor's website or on any of five software directories carrying the product, all of which record pricing as available on request. Access is gated: there is no self serve signup and the free trial is activated during a booked fifteen minute call. The terms of use define a pricing plan as a term of the contract without publishing one. The published commercial mechanics are as follows. Subscriptions run month to month and are charged in advance through a named third party payment processor, which holds all card details. Either party may terminate the agreement without providing a rationale. All amounts paid are non refundable. Price changes require thirty days notice, given either by posting on the website or by mail at the vendor's option. Where the vendor cancels an account without cause it refunds a prorated portion of the monthly prepayment, and where cause exists, such as a breach of the terms or the privacy policy, it does not. Trial users are not charged during the trial period unless they opt in to additional campaign mail accounts before the trial expires. Billing disputes must be raised within thirty days of invoice. On termination the vendor may permanently delete the account and all data associated with it, including stored messages, with no export window stated. A data protection addendum is available but not standard. The terms of use define the agreement as comprising the terms, the privacy policy, a safety and security document and a data protection compliance statement, and state that it may be extended to cover a non disclosure agreement or a data protection addendum upon individual establishment of both parties. Two of the four documents named as part of the standing agreement are not published anywhere, so a buyer signs bound to terms they cannot read. A processing addendum is therefore negotiable rather than offered, and a buyer needing one should raise it on the activation call. None published, and no implementation charge is mentioned anywhere, though the deployment is assisted rather than self serve. The vendor states it handles configuration and guides the buyer through everything needed to begin, with most agencies fully set up within two weeks. The same page elsewhere promises to start reaching brands in days rather than weeks, which contradicts the two week figure directly. Onboarding begins before any contract exists: the trial is activated on a fifteen minute call during which the vendor filters the database to the buyer's niche, builds an initial list with them and advises on messaging. Custom workflows, integrations and hands on support are offered as part of the relationship with no rate attached to any of them. Two passes located no setup fee, onboarding charge, migration cost, training rate, minimum term or annual commitment requirement. The costs a buyer should establish on the call are the subscription itself, whether campaign mail accounts are charged separately given that adding them during a trial triggers billing, and whether the assisted configuration is included at every subscription level or only above some threshold. Vendor Published

The mechanics of the contract are clear and the number is absent.

Nothing about the price is discoverable before a sales conversation. Two passes across the vendor's own site and five software directories produced no figure of any kind, and every directory records pricing as available on request. The terms of use name a pricing plan as a governing element of the contract without publishing one.

The gating is deliberate rather than neglectful, and it is worth separating the two. There is no self serve signup, and even the free trial is activated during a booked fifteen minute call on which the vendor filters the database to the buyer's niche alongside them and helps them work out what to say. A buyer leaves that call with a live account and a real list for their own market. As an evaluation experience that is more substantial than most self serve trials deliver. As a commercial posture it means no buyer can compare this vendor on cost against an alternative without first entering a sales process.

What the vendor does publish is the shape of the commitment, and it is unusually legible. Month to month billing charged in advance. Termination by either party without a reason. Everything paid is non refundable. Thirty days notice on any price change. A prorated refund only where the vendor cancels without cause, and none where cause exists.

One provision deserves attention because it names the single route by which a free trial becomes a bill: trial users are not charged unless they add campaign mail accounts before the trial expires. Publishing the trap rather than burying it is a point in the vendor's favour.

The termination clause is the one a buyer should price into the decision. On termination the vendor may permanently delete the account and all associated data, with no stated export window.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 24, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746