Privacy Policy

DRAFT — pending operator legal sign-off. This draft was produced from an audit of the actual codebase (2026-07-24, repo HEAD 45c65dc + working tree). Bracketed items are placeholders the operator must complete. This document is not legal advice; it must be reviewed by a qualified privacy lawyer before publication.

Last updated: [DATE — set at publication] Version: 0.1 (draft)

InboxTempo (inboxtempo.com) is an email campaign platform operated by [OPERATOR LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("we", "us", "the platform"). You can reach us about privacy at [email protected].

This policy covers two different situations. Please start with the one that applies to you:

Shared sections — sub-processors, where data lives, retention, security, your rights — apply to both.


Part A — If you received an email sent through our platform

Businesses use our platform to send email campaigns to their own contact lists. For that data, the sender is the data controller — they decide who is on their list and why — and we are a data processor acting on their instructions. Each sender is contractually required to attest to the consent basis for every list they upload, and to include their own name and physical mailing address in every email.

What we process about you, on the sender's behalf

  • Contact details the sender uploaded: your email address, optionally your first and last name, and any custom fields the sender chose to include in their list (we do not control what those fields contain).
  • Sending records: which campaigns were addressed to you, whether the message was delivered, deferred, or bounced, and the receiving mail server's response.
  • Engagement tracking data — see the next section.
  • Bounce and complaint reports: if your mailbox provider returns a delivery failure report or a spam-complaint report about a message, we process it to stop further mail to you. The raw report content is deleted after 90 days; a structured record (your address, the failure/complaint type, timestamp) is kept as evidence.
  • Unsubscribe and suppression records: if you unsubscribe or complain, we keep your bare email address on a suppression list indefinitely, so that the opt-out keeps working. Deleting it would re-enable email you asked to stop.

Email tracking: exactly what we do

We are specific here because most email platforms are not:

  • Open tracking. Campaign emails contain a small invisible image (a "tracking pixel"). When your mail client loads it, our server records that the message was opened, with a timestamp, your device's IP address, and your mail client's user-agent string.
  • Click tracking. Links in campaign emails are rewritten to pass through our redirect service. When you click one, we record which link was clicked, with a timestamp, IP address, and user-agent, and then forward you to the real destination.
  • Automated-fetch filtering. Mail security scanners and Apple Mail Privacy Protection open pixels and links automatically. We classify these machine fetches (by user-agent patterns, click timing, and request bursts) and report them separately, so senders see them flagged rather than counted as your activity. Apple-privacy-proxy opens are counted in their own bucket and are never presented as a confirmed human open.
  • What we do not do: we set no cookies on tracking endpoints, we do not build cross-sender profiles of recipients, we do not fingerprint your device, and we do not sell or share recipient data with advertisers or data brokers.

Tracking events are stored in an append-only event log; the IP address and user-agent captured with each event are deleted after 90 days (the anonymized event itself — type, timestamp, campaign — is kept for statistics).

How to stop the email

Every campaign message sent through our platform carries, by technical enforcement:

  • a one-click unsubscribe function in your mail client (RFC 8058 — the "Unsubscribe" button in Gmail, Apple Mail, Yahoo, etc.), and
  • an unsubscribe link to a hosted preference page where you can leave a specific mailing list or stop all email from that sender.

Unsubscribes take effect immediately — the suppression is written before we acknowledge the request, not within a statutory grace period.

Your rights as a recipient

Because the sender is the controller, requests about why you were emailed, access to the data the sender holds, correction, or deletion should go to the sender — their identity and physical address are in every email footer. If you contact us instead at [email protected], we will forward your request to the sender and assist them in honoring it. Our platform gives every sender a working erasure function for individual contacts, and we honor erasure with two narrow exceptions we believe the law requires us to keep: (1) your suppressed email address, so the opt-out survives, and (2) minimal records proving that past sends to you were made under an attested consent basis (a legal-claims/compliance retention, e.g. GDPR Art. 17(3)(e) and CASL record-keeping).


Part B — If you have an account with us or visit our website

For customer and visitor data we are the data controller.

What we collect

  • Account data: name, email address, and a password (stored only as a cryptographic hash). We verify your email address before activating the account.
  • Session data: when you sign in we record the session's IP address and browser user-agent, and set a first-party session cookie (see Cookies below).
  • Organization and vetting data: because we operate shared email infrastructure, every sending account is reviewed before it may send. The vetting questionnaire collects your company name, website, industry, physical mailing address, a description of how your contact lists were built, your opt-in method, and expected sending volume. Approval, rejection, or suspension decisions and their reasons are recorded.
  • Consent attestations: each list import requires a signed statement of the list's origin and consent basis; we record the statement, the submitting user, and the IP address it was submitted from. These are compliance records and are retained indefinitely, including after account closure.
  • Billing data: payment is handled by Stripe. We send Stripe your email address and an internal account reference; card details are entered directly with Stripe and never touch our servers. We store only Stripe's customer/subscription identifiers and subscription status.
  • Content you upload: contact lists (CSV files), email templates, and campaign content. Recipient data inside these is covered by Part A.
  • Operational logs: administrative actions affecting your account (vetting decisions, sending-limit overrides, support impersonation of your session) are written to an append-only audit log.
PurposeDataLegal basis (GDPR/UK GDPR, where applicable)
Providing the service (accounts, campaigns, sending)account, contentContract (Art. 6(1)(b))
Vetting senders, enforcing anti-abuse guardrails, protecting shared IP reputationvetting data, sending statistics, audit logsLegitimate interests (Art. 6(1)(f)) — ours and all customers' interest in deliverable, lawful email
Billingbilling dataContract; legal obligation (tax/accounting)
Anti-spam law compliance (consent attestations, suppression, send-proof records)attestations, suppressions, send recordsLegal obligation (Art. 6(1)(c)); legitimate interests
Transactional service email (verification, security, billing notices)account emailContract

We do not use customer data for advertising and do not sell it.

Cookies

The application sets only first-party, strictly-necessary authentication cookies (session token and related state from our auth layer). There are no analytics cookies, no advertising cookies, and no third-party trackers on the application. Because no non-essential cookies are set, no cookie-consent banner is currently required.


Sub-processors and service providers

ProviderRoleData touchedLocation
OVH (dedicated server)Hosting for the entire platform: application, database, mail server, uploaded filesAll platform data[CONFIRM: OVH data center, Beauharnois, Québec, Canada — IP 192.99.45.69]
CloudflareDNS and reverse proxy for the application domainVisitor/customer web traffic metadata (IPs, requests) in transitGlobal network
StripePayment processing (customers only)Customer billing dataStripe's infrastructure (US/global); Stripe acts under its own privacy terms
Spamhaus (DQS)IP-reputation monitoring of our own sending IPNo personal data — queries concern our server IP only

Our outbound mail server (Mailcow/Postfix) is self-hosted on our own OVH server — email sending does not involve a third-party email service provider.

Where your data lives

All platform data (database, uploaded files, mail queues) is stored on a single dedicated server operated for us by OVH in [CONFIRM: Canada (Beauharnois, Québec)]. Database backups are encrypted (AES-256) before leaving the server and stored off-site in Cloudflare R2 object storage [CONFIRM R2 bucket region/jurisdiction — bucket predates this project]; Cloudflare cannot read them. For visitors and customers in the EEA/UK: Canada benefits from a European Commission adequacy decision for data subject to PIPEDA; where adequacy does not apply to a given transfer, we rely on Standard Contractual Clauses (see our Data Processing Addendum). [OPERATOR: confirm EU/UK customers are in scope for the current release — see GAP-REPORT.md.]

How long we keep data

DataRetention
Account and organization dataLife of the account + [PERIOD — operator to set] after closure
Contact lists and campaign contentUntil you delete them or your account closes (subject to the compliance carve-outs below)
Suppression lists (unsubscribes, complaints, hard bounces)Indefinitely — kept so opt-outs keep working; survives account closure
Consent attestations and per-send consent recordsIndefinitely — anti-spam compliance evidence; survives account closure
Raw bounce (DSN) and complaint (ARF) reports90 days, then the raw content is deleted; structured records are kept [pending operator ratification]
Delivery/engagement event logEvent rows kept for statistics; IP and user-agent deleted after 90 days [pending operator ratification]
Uploaded CSV files on diskDeleted when the import finishes (completes or fails); on-screen preview rows deleted with it
Audit logsIndefinitely (operational compliance record)
Session recordsDeleted within 7 days of session expiry

Security

Honest summary of what is actually in place: TLS on all public endpoints; passwords stored as cryptographic hashes; per-tenant data isolation enforced in the data-access layer; mail-relay credentials encrypted at the application layer (AES-256-GCM); tracking and unsubscribe links signed with HMAC so they cannot be forged or enumerated; secrets held outside the codebase with restricted file permissions; administrative access to customer accounts is audit-logged. We do not currently claim full-disk encryption at rest or independent security certifications. No system is perfectly secure; we will notify affected parties of personal-data breaches as required by applicable law.

Your rights

Depending on where you live (EEA/UK — GDPR/UK GDPR; Canada — PIPEDA and provincial law; elsewhere — local equivalents), you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, to object to processing based on legitimate interests, and to withdraw consent. To exercise them, email [email protected]. We respond within one month (GDPR) or 30 days (PIPEDA), extendable as the law allows. Recipients of customer email: see Part A — your request usually belongs with the sender, but we will route and assist regardless.

You also have the right to complain to a supervisory authority — for the EEA your local data protection authority; for the UK the ICO; for Canada the Office of the Privacy Commissioner of Canada [and the CAI if Québec's Law 25 applies — operator to confirm jurisdiction].

Children

The platform is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16 (or the applicable local age). Customers are prohibited from using the platform to email children's lists.

Automated decision-making

Sending accounts are subject to automated deliverability guardrails (e.g. a campaign pauses automatically if bounce or complaint rates exceed thresholds, and an account can be automatically suspended for sustained abuse signals). These decisions affect customer accounts, not recipients, and every automated suspension can be reviewed by a human on request.

Changes to this policy

We will post updates here with a new "last updated" date, and notify account holders by email of material changes before they take effect.

Contact

[OPERATOR LEGAL ENTITY NAME], [REGISTERED ADDRESS] — [email protected] [If GDPR applies and no EU establishment exists: EU/UK representative details or a statement of Art. 27 analysis — operator decision.]