Privacy Policy
Learn how MailSend collects, processes, protects, and respects personal information in compliance with international data protection laws.
Last updated at : September 16, 2026
MailSend ("we", "us", or "our"), operated from India, operates the MailSend transactional and marketing email platform, developer APIs, SMTP gateways, and website at mailsend.dev (collectively, the "Service"). This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of personal information.
We are committed to operating in full compliance with applicable international data privacy and communication standards, including the General Data Protection Regulation (EU & UK GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the U.S. CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), the Australian Privacy Act 1988, the Indian Digital Personal Data Protection Act 2023 (DPDP), and the Singapore Personal Data Protection Act (PDPA).
1. Definitions & Legal Roles
- Data Controller: When you register a MailSend account, manage billing, visit our website, or interact with customer support, MailSend acts as the Data Controller of your account and profile data.
- Data Processor: When you upload recipient email addresses, contact attributes, and email content to dispatch messages via our platform or API, you act as the Data Controller and MailSend acts as a Data Processor (or Service Provider under CCPA). We process recipient data strictly pursuant to your instructions and in accordance with our Terms of Service and Data Processing Addendum (DPA).
- Recipient Data: Email addresses, contact metadata, and message contents provided by you to deliver emails. We never sell, rent, or use recipient lists for our own commercial marketing purposes.
2. Information We Collect
Information You Provide Directly
- Account Registration: Name, work email address, company or workspace name, encrypted password, and authentication identifiers.
- Billing Information: Payment transactions are handled by our certified, PCI-DSS compliant payment gateway, Razorpay (supporting domestic payments and international transactions via integrated PayPal). MailSend never stores raw credit card numbers or banking secrets on our servers; we store only payment tokens, subscription IDs, plan tier records, and transaction receipts.
- Support & Communications: Details, log snippets, or feedback shared when contacting customer support or requesting assistance.
Information Collected Automatically
For account security, we keep successful login history including the sign-in method, time, IP address, approximate city, region and country when available, and browser, operating system, device type and user-agent metadata. Location is inferred from trusted network metadata; we do not request GPS permission or store latitude or longitude. Access to this history is restricted to authorized platform administrators for security and support.
- Technical Diagnostics: IP address, device type, operating system, browser user-agent, routing latency, and API error codes.
- API Usage Metrics: Request timestamps, endpoint paths, response times, token authorization IDs, and payload size metrics.
3. Email Tracking Technologies
MailSend provides analytics features to measure email deliverability, engagement, and operational reliability on behalf of our customers:
- Open Tracking: Outgoing HTML emails may include a transparent, single-pixel image (1x1 invisible GIF). When a recipient's mail client loads the image, our servers log the request timestamp, IP address, and mail client user-agent string to record that an email was opened.
- Click Tracking: Links within emails can be automatically wrapped with MailSend tracking endpoints. When a recipient clicks a tracked link, our servers record the interaction before instantaneously redirecting the recipient to the target destination.
- Customer Responsibility: As a Data Controller of your email campaigns, you are responsible for informing your recipients of email tracking and obtaining consent where required by ePrivacy or local privacy regulations. Customers may disable open and click tracking in their workspace settings or API payload options.
5. How We Use Your Information
We process personal data for legitimate business purposes under lawful bases recognized under global privacy laws:
- Service Delivery (Contractual Necessity): To provision accounts, authenticate logins, route and deliver transactional emails, manage bounce suppression lists, and process subscription billing.
- Security & Abuse Prevention (Legitimate Interest): To monitor for unauthorized access, detect spam floods, block phishing or malware distribution, and enforce our Acceptable Use Policy.
- Service Improvements (Legitimate Interest): To debug application errors, track API latency, and optimize infrastructure capacity.
- Legal & Tax Compliance (Legal Obligation): To retain billing transaction records for statutory accounting, tax reporting, and law enforcement requests.
6. Subprocessors & Third Parties
MailSend does not sell, rent, or trade personal information to data brokers or third-party advertisers. We disclose data solely to vetted third-party service providers (subprocessors) that perform operational functions on our behalf under strict data processing agreements:
- Cloud Infrastructure: Amazon Web Services (AWS SES) for email sending; Supabase Inc. / PostgreSQL for database and authentication hosting; Cloudflare, Inc. for edge CDN and DDoS security.
- Payment Processors: Razorpay Software Private Limited (with integrated PayPal for international payments) for merchant subscription processing and billing.
- Monitoring & Analytics: Sentry (Functional Software, Inc.) for application error telemetry; Google LLC for aggregate web traffic metrics.
For our complete subprocessor directory, please review our Subprocessors Page.
7. International Data Transfers (SCCs)
MailSend operates cloud infrastructure primarily located in the United States and global edge points of presence. If you access the Services from the European Economic Area (EEA), United Kingdom, Switzerland, or other regions with cross-border transfer laws, your data may be transferred to and processed in the United States.
We protect cross-border data transfers through recognized legal safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, ensuring contractual protections equivalent to GDPR standards.
8. Data Security
We implement enterprise-grade technical, physical, and administrative security measures, including:
- Encryption in transit using modern TLS 1.3 cryptographic protocols.
- Encryption at rest for all database volumes, backups, and customer configurations (AES-256).
- Role-based access control (RBAC), multi-tenant Row Level Security (RLS), and zero-trust API credential hashing.
- Continuous network vulnerability scanning, audit logging, and isolated sandbox environments.
Login security history is automatically removed after our configured retention period (90 days by default). We may adjust this period to meet security requirements; contact [email protected] for the current period or to request access or erasure. Deleting an authentication account also deletes its login history.
9. Data Retention & Account Deletion
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, maintain active customer accounts, resolve disputes, and comply with legal obligations.
When a customer deletes an account or requests data erasure, customer contact lists, suppression registries, email templates, and credentials are permanently purged in accordance with our deletion runbooks. Customers may export contact lists and campaign archives prior to account termination.
10. Your Global Privacy Rights
Depending on your geographic location, you enjoy specific legal rights regarding your personal information:
EU & UK Residents (GDPR / UK GDPR)
- Right of Access & Portability: Request a copy of your personal data in a structured, machine-readable format.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data.
- Right to Restrict or Object: Restrict processing or object to processing based on legitimate interest.
- Right to Lodge a Complaint: File a grievance with your local Data Protection Supervisory Authority.
California Residents (CCPA / CPRA)
- Right to Know & Delete: Know what categories of personal information we collect and request deletion.
- No Sale or Sharing: MailSend does not sell personal data and does not share personal data for cross-context behavioral advertising.
- Global Privacy Control (GPC): We recognize and honor browser-based GPC opt-out signals.
- Non-Discrimination: We will never discriminate against you for exercising your CCPA rights.
Canada (PIPEDA & CASL) & Australia (Privacy Act 1988)
Canadian and Australian residents may access their personal data, withdraw consent for marketing communications, and request correction under statutory privacy frameworks.
India (DPDP Act 2023)
Data principals in India may exercise rights of access, correction, erasure, and grievance redressal through our designated Grievance Officer.
11. Anti-Spam & Email Compliance
MailSend strictly enforces international anti-spam standards. Customers must ensure verified opt-in consent, clear sender identification, valid physical postal addresses, and real-time unsubscribe facilities. Accounts generating excessive spam complaints or hard bounces face immediate operational throttling or suspension.
12. Children's Privacy
The Services are designed exclusively for business enterprises and individuals aged 18 and older. We do not knowingly collect personal data from minors under 16 years of age. If we discover inadvertent collection of data belonging to a minor, we will immediately delete the data and terminate the account.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any material changes will be notified via prominent notice on the dashboard or by email before taking effect. The "Last updated" date at the top of this policy reflects the effective date of the current revision.
14. Contact Us & Grievance Officer
To exercise your privacy rights, submit a data subject request, or communicate with our Data Protection and Grievance Officer, please contact:
mailsend
MailSend (India) — Privacy & Data Protection Office
Email: [email protected]
Support: [email protected]
Response SLA: All data protection and privacy inquiries are acknowledged within 24–48 hours.
TABLE OF CONTENTS
- Definitions & Roles
- Information We Collect
- Email Tracking Technologies
- Cookies & Local Storage
- How We Use Your Information
- Subprocessors & Third Parties
- International Data Transfers (SCCs)
- Data Security
- Data Retention & Account Deletion
- Your Global Privacy Rights (GDPR / CCPA / DPDP)
- Anti-Spam & Email Compliance
- Children's Privacy
- Changes to This Privacy Policy
- Contact Us & Grievance Officer