Privacy Policy
Last updated [OPERATOR: date]. Written for the deployment at [OPERATOR: service address].
Two kinds of data, two roles
This service holds two things that are governed differently, and conflating them is the most common way a policy like this misleads someone.
- Your account. The name, address, password and settings of the person who signed up. For this, the operator is the controller — it decides what is collected and why.
- Your contacts and their mail. The addresses, names and message contents belonging to people on your list, and the messages in any hosted mailbox. For this, you are the controller and the operator is a processor: it holds this only to carry out your instructions and decides nothing about it.
If you are the data subject of a contact entry, your request belongs with the organization that put you there rather than with the operator — the operator cannot know what consent you gave them, and will pass the request on rather than answer it.
What is held
The precise answer is available to you at any time: Download a copy in Settings returns a machine-readable file naming every table and column that belongs to your organization. It is generated from the same list this page describes, and it states what it does not include and why.
- Your account: name, address, password hash, and display preference.
- Your organization: contacts, segments, topics, templates, campaigns.
- Sending history: recipients, subjects, delivery status, and per-message events such as delivery, bounce and complaint.
- Hosted mailbox contents, if you have any — the messages themselves, on the operator's storage.
- Operational records: API request logs, and the sign-in attempts used to rate-limit abuse.
Signing keys and stored credentials are not available in an export. They are held in a form that cannot be read back, and an export is not the place to make them readable.
How long
- Sending history and the contents of sent messages: [OPERATOR: retention days, default 30] after sending.
- API request logs: [OPERATOR: retention days, default 30].
- Hosted mailbox contents: until you delete them, or delete the account.
- Your account: until you delete it.
Suppression records — the list of addresses that asked not to be emailed — are kept for as long as the organization exists, because deleting one would mean mailing somebody who has already opted out.
Who can see it
- Members of your organization, according to their role.
- [OPERATOR: secondary operators, or “none”]. Operators can read across accounts for support. Access is recorded, and reading requires a second factor.
- Payment processing is handled by Stripe. Message delivery involves no third party: this service runs its own mail transport.
Getting it out, or gone
Both are self-service, and neither requires asking anyone.
- Export — Settings → Download a copy. Everything listed above, as a file.
- Deletion — Settings → Delete this account. If you are the last member of your organization this removes the contacts, the messages, the mailboxes and the mail inside them. If others remain, it removes you and leaves their data alone.
Write to [OPERATOR: privacy contact address] for anything those two do not cover.
Where it is held
[OPERATOR: hosting location and jurisdiction]. There is no multi-region replication, and no transfer to a third country beyond whatever the payment processor does.
Changes
Material changes will be sent to the address on your account, since that is how this service reaches you.
See also the Terms of Service.