Privacy Policy

DRAFT — pending operator legal sign-off. This draft was produced from an audit of the actual codebase (2026-07-24, repo HEAD 45c65dc + working tree). Bracketed items are placeholders the operator must complete. This document is not legal advice; it must be reviewed by a qualified privacy lawyer before publication.

Last updated: [DATE — set at publication] Version: 0.1 (draft)

InboxTempo (inboxtempo.com) is an email campaign platform operated by [OPERATOR LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("we", "us", "the platform"). You can reach us about privacy at [email protected].

We are an Australian business, and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This document is our APP privacy policy.

This policy covers two different situations. Please start with the one that applies to you:

Shared sections — sub-processors, where data lives, retention, security, your rights — apply to both.


Part A — If you received an email sent through our platform

Businesses use our platform to send email campaigns to their own contact lists. For that data, the sender is the data controller — they decide who is on their list and why — and we are a data processor acting on their instructions. Each sender is contractually required to attest to the consent basis for every list they upload, and to include their own name and physical mailing address in every email.

What we process about you, on the sender's behalf

  • Contact details the sender uploaded: your email address, optionally your first and last name, and any custom fields the sender chose to include in their list (we do not control what those fields contain).
  • Sending records: which campaigns were addressed to you, whether the message was delivered, deferred, or bounced, and the receiving mail server's response.
  • Engagement tracking data — see the next section.
  • Bounce and complaint reports: if your mailbox provider returns a delivery failure report or a spam-complaint report about a message, we process it to stop further mail to you. The raw report content is deleted after 90 days; a structured record (your address, the failure/complaint type, timestamp) is kept as evidence.
  • Unsubscribe and suppression records: if you unsubscribe or complain, we keep your bare email address on a suppression list indefinitely, so that the opt-out keeps working. Deleting it would re-enable email you asked to stop.

Email tracking: exactly what we do

We are specific here because most email platforms are not:

  • Open tracking. Campaign emails contain a small invisible image (a "tracking pixel"). When your mail client loads it, our server records that the message was opened, with a timestamp, your device's IP address, and your mail client's user-agent string.
  • Click tracking. Links in campaign emails are rewritten to pass through our redirect service. When you click one, we record which link was clicked, with a timestamp, IP address, and user-agent, and then forward you to the real destination.
  • Automated-fetch filtering. Mail security scanners and Apple Mail Privacy Protection open pixels and links automatically. We classify these machine fetches (by user-agent patterns, click timing, and request bursts) and report them separately, so senders see them flagged rather than counted as your activity. Apple-privacy-proxy opens are counted in their own bucket and are never presented as a confirmed human open.
  • What we do not do: we set no cookies on tracking endpoints, we do not build cross-sender profiles of recipients, we do not fingerprint your device, and we do not sell or share recipient data with advertisers or data brokers.

Tracking events are stored in an append-only event log; the IP address and user-agent captured with each event are deleted after 90 days (the anonymized event itself — type, timestamp, campaign — is kept for statistics).

How to stop the email

Every campaign message sent through our platform carries, by technical enforcement:

  • a one-click unsubscribe function in your mail client (RFC 8058 — the "Unsubscribe" button in Gmail, Apple Mail, Yahoo, etc.), and
  • an unsubscribe link to a hosted preference page where you can leave a specific mailing list or stop all email from that sender.

Unsubscribes take effect immediately — the suppression is written before we acknowledge the request, not within a statutory grace period.

Your rights as a recipient

Because the sender is the controller, requests about why you were emailed, access to the data the sender holds, correction, or deletion should go to the sender — their identity and physical address are in every email footer. If you contact us instead at [email protected], we will forward your request to the sender and assist them in honoring it. Our platform gives every sender a working erasure function for individual contacts, and we honor erasure with two narrow exceptions we believe the law requires us to keep: (1) your suppressed email address, so the opt-out survives, and (2) minimal records proving that past sends to you were made under an attested consent basis (a compliance/legal-claims retention — e.g. evidence of consent under the Spam Act 2003 (Cth), under which the sender bears the burden of proving consent; CASL record-keeping where mail was sent into Canada; and GDPR Art. 17(3)(e) where that law applies).


Part B — If you have an account with us or visit our website

For customer and visitor data we are the data controller.

What we collect

  • Account data: name, email address, and a password (stored only as a cryptographic hash). We verify your email address before activating the account.
  • Session data: when you sign in we record the session's IP address and browser user-agent, and set a first-party session cookie (see Cookies below).
  • Organization and vetting data: because we operate shared email infrastructure, every sending account is reviewed before it may send. The vetting questionnaire collects your company name, website, industry, physical mailing address, a description of how your contact lists were built, your opt-in method, and expected sending volume. Approval, rejection, or suspension decisions and their reasons are recorded.
  • Consent attestations: each list import requires a signed statement of the list's origin and consent basis; we record the statement, the submitting user, and the IP address it was submitted from. These are compliance records and are retained indefinitely, including after account closure.
  • Billing data: payment is handled by Stripe. We send Stripe your email address and an internal account reference; card details are entered directly with Stripe and never touch our servers. We store only Stripe's customer/subscription identifiers and subscription status.
  • Content you upload: contact lists (CSV files), email templates, and campaign content. Recipient data inside these is covered by Part A.
  • Operational logs: administrative actions affecting your account (vetting decisions, sending-limit overrides, support impersonation of your session) are written to an append-only audit log.

We collect, hold, and use this information only for the purposes below (APPs 3 and 6). The right-hand column additionally states the GDPR lawful basis for the limited cases where that law applies to a particular customer.

PurposeDataLegal basis (GDPR/UK GDPR, where applicable)
Providing the service (accounts, campaigns, sending)account, contentContract (Art. 6(1)(b))
Vetting senders, enforcing anti-abuse guardrails, protecting shared IP reputationvetting data, sending statistics, audit logsLegitimate interests (Art. 6(1)(f)) — ours and all customers' interest in deliverable, lawful email
Billingbilling dataContract; legal obligation (tax/accounting)
Anti-spam law compliance (consent attestations, suppression, send-proof records)attestations, suppressions, send recordsLegal obligation (Art. 6(1)(c)); legitimate interests
Transactional service email (verification, security, billing notices)account emailContract

We do not use customer data for advertising and do not sell it.

Cookies

The application sets only first-party, strictly-necessary authentication cookies (session token and related state from our auth layer). There are no analytics cookies, no advertising cookies, and no third-party trackers on the application. Because no non-essential cookies are set, no cookie-consent banner is currently required.


Sub-processors and service providers

ProviderRoleData touchedLocation
OVH (dedicated server)Hosting for the entire platform: application, database, mail server, uploaded filesAll platform dataOVH data center, Beauharnois, Québec, Canada
CloudflareDNS and reverse proxy for the application domainVisitor/customer web traffic metadata (IPs, requests) in transitGlobal network
StripePayment processing (customers only)Customer billing dataStripe's infrastructure (US/global); Stripe acts under its own privacy terms
Spamhaus (DQS)IP-reputation monitoring of our own sending IPNo personal data — queries concern our server IP only

Our outbound mail server (Mailcow/Postfix) is self-hosted on our own OVH server — email sending does not involve a third-party email service provider.

Where your data lives

All platform data (database, uploaded files, mail queues) is stored on a single dedicated server operated for us by OVH in Beauharnois, Québec, Canada. Database backups are encrypted (AES-256) before leaving the server and stored off-site in Cloudflare R2 object storage [CONFIRM R2 bucket region/jurisdiction — bucket predates this project]; Cloudflare cannot read them. Payment processing runs on Stripe's infrastructure in the United States.

Because we are an Australian business, this means personal information we hold is stored with, or disclosed to, recipients located overseas (APP 8) — currently in Canada (hosting), the United States (payments), and [R2 backup region — to be confirmed]. We take reasonable steps to ensure it stays protected wherever it sits: the safeguards in the Security section apply on our own server regardless of its location, backups are encrypted before they leave that server, and our providers are bound by contractual protections. We remain accountable for our providers' handling of personal information. Where EEA/UK data-protection law applies to a particular customer's data, the transfer safeguards in our Data Processing Addendum (§9) apply.

How long we keep data

DataRetention
Account and organization dataLife of the account + [PERIOD — operator to set] after closure
Contact lists and campaign contentUntil you delete them or your account closes (subject to the compliance carve-outs below)
Suppression lists (unsubscribes, complaints, hard bounces)Indefinitely — kept so opt-outs keep working; survives account closure
Consent attestations and per-send consent recordsIndefinitely — anti-spam compliance evidence; survives account closure
Raw bounce (DSN) and complaint (ARF) reports90 days, then the raw content is deleted; structured records are kept
Delivery/engagement event logEvent rows kept for statistics; IP and user-agent deleted after 90 days
Uploaded CSV files on diskDeleted when the import finishes (completes or fails); on-screen preview rows deleted with it
Audit logsIndefinitely (operational compliance record)
Session recordsDeleted within 7 days of session expiry

Security

Honest summary of what is actually in place: TLS on all public endpoints; passwords stored as cryptographic hashes; per-tenant data isolation enforced in the data-access layer; mail-relay credentials encrypted at the application layer (AES-256-GCM); tracking and unsubscribe links signed with HMAC so they cannot be forged or enumerated; secrets held outside the codebase with restricted file permissions; administrative access to customer accounts is audit-logged. We do not currently claim full-disk encryption at rest or independent security certifications. No system is perfectly secure; if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988 (Cth)), and any other notification required by law that applies to the breach.

Your rights

Under the Privacy Act 1988 (Cth) you may request access to the personal information we hold about you (APP 12) and correction of it (APP 13). Depending on where you live, other laws may give you further rights (EEA/UK — GDPR/UK GDPR rights to access, correct, delete, restrict, port, and object; Canada — PIPEDA; elsewhere — local equivalents), including withdrawing consent you previously gave. To exercise any of these, email [email protected]. We respond within 30 days (or within one month where the GDPR applies), extendable as the law allows. Recipients of customer email: see Part A — your request usually belongs with the sender, but we will route and assist regardless.

If you believe we have mishandled your personal information, complain to us first at [email protected] — we will acknowledge your complaint and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) (oaic.gov.au). If you are outside Australia you may also complain to your local authority — for the EEA your data protection authority; for the UK the ICO; for Canada the Office of the Privacy Commissioner.

Children

The platform is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16 (or the applicable local age). Customers are prohibited from using the platform to email children's lists.

Automated decision-making

Sending accounts are subject to automated deliverability guardrails (e.g. a campaign pauses automatically if bounce or complaint rates exceed thresholds, and an account can be automatically suspended for sustained abuse signals). These decisions affect customer accounts, not recipients, and every automated suspension can be reviewed by a human on request.

Changes to this policy

We will post updates here with a new "last updated" date, and notify account holders by email of material changes before they take effect.

Contact

[OPERATOR LEGAL ENTITY NAME] (an Australian business), [REGISTERED ADDRESS] — [email protected]