Legal

Privacy policy

What we hold, why we hold it, and how to get it back or get rid of it.

Last updated

Draft, pending legal review. Posthaste is in private testing and these terms have not yet been reviewed by a solicitor. They describe how we actually intend to operate, but they are not a substitute for the reviewed version that will replace them before general availability. Questions in the meantime: get in touch.

Two different roles

This distinction runs through everything below, so it comes first.

For your personal data — the account holder’s name, email, billing details — we are the controller. We decide why and how it is processed, and this policy governs it.

For the personal data inside the messages you send — your recipients’ addresses and message content — we are a processor acting on your instructions. You are the controller. That relationship is governed by the data processing addendum, not by this policy.

Who we are

Posthaste — the service operated under that name. For data protection enquiries, including any request to access, correct or delete your data: [email protected].

What we collect about you

We do not use third-party advertising or analytics trackers on this site, and there is no tracking pixel in the mail you send unless you add one yourself.

Why, and on what legal basis

To provide the service
Performance of our contract with you.
To bill you
Performance of our contract, and our legal obligation to keep tax records.
To protect the platform
Our legitimate interest in preventing abuse and in maintaining the deliverability of infrastructure shared by every customer.
To send service notices
Our legitimate interest in telling you about outages, security issues and changes that affect your sending. These are not marketing and you cannot unsubscribe from them while holding an account.

How long we keep it

Account details
For as long as the account is open, then 90 days after closure.
Message bodies
Kept only as long as needed to deliver and to handle a bounce — 30 days, then deleted. They are stored separately from delivery records for exactly this reason.
Delivery records
By plan: 30 days on Free, 90 days on Starter, 1 year on Growth, 2 years on Scale. These contain recipient addresses and the receiving server’s responses.
Suppression list
Retained while the account is open. Deleting a suppression entry would mean sending again to an address that bounced or complained, which is the harm the list exists to prevent.
Security and access logs
12 months.

Who else sees it

Only the providers we need to run the service — hosting, payments and the like. They are listed individually, with what each one processes and where, on the sub-processors page.

There is one unavoidable disclosure inherent to email: to deliver a message we transmit it to the recipient’s mail server, which is operated by whoever the recipient chose. That is what sending an email is.

We do not sell personal data, and we have never been asked to.

Where it is processed

Our infrastructure is hosted in the European Union. Where a provider processes data outside the UK or EEA, that transfer is covered by the appropriate safeguards — standard contractual clauses or an adequacy decision — as noted per provider on the sub-processors page.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to processing based on legitimate interests. You can also ask for it in a portable format.

Email [email protected] and we will respond within one month. There is no charge. If you are unhappy with how we have handled a request you can complain to your local data protection authority.

One limit worth stating plainly: we cannot delete an entry from the suppression list on request from the account holder, because doing so would cause us to send again to an address that bounced or complained. If you are a recipient asking about your own address, get in touch and we will deal with it directly.

Cookies

This marketing site sets no cookies at all — no analytics, no advertising, nothing to consent to. The application sets a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. They are essential to the service and are not used for tracking.

Security

The measures we actually take — database-enforced tenant isolation, encrypted signing keys, hashed API secrets, an append-only delivery record — are described on the security page rather than summarised as “industry-standard” here.

Changes

If we change this policy materially we will email account holders before it takes effect. The date at the top always reflects the current version.