Two different roles
This distinction runs through everything below, so it comes first.
For your personal data — the account holder’s name, email, billing details — we are the controller. We decide why and how it is processed, and this policy governs it.
For the personal data inside the messages you send — your recipients’ addresses and message content — we are a processor acting on your instructions. You are the controller. That relationship is governed by the data processing addendum, not by this policy.
Who we are
Posthaste — the service operated under that name. For data protection enquiries, including any request to access, correct or delete your data: [email protected].
What we collect about you
- Account data — name, email address, password hash, and the organisation name if you give one.
- Billing data — plan, billing address and tax details. Card details are handled by our payment processor and never reach our servers.
- Usage data — API requests, sending volumes, error rates, and the IP addresses requests come from.
- Support correspondence — what you write to us and what we write back.
We do not use third-party advertising or analytics trackers on this site, and there is no tracking pixel in the mail you send unless you add one yourself.
Why, and on what legal basis
- To provide the service
- Performance of our contract with you.
- To bill you
- Performance of our contract, and our legal obligation to keep tax records.
- To protect the platform
- Our legitimate interest in preventing abuse and in maintaining the deliverability of infrastructure shared by every customer.
- To send service notices
- Our legitimate interest in telling you about outages, security issues and changes that affect your sending. These are not marketing and you cannot unsubscribe from them while holding an account.
How long we keep it
- Account details
- For as long as the account is open, then 90 days after closure.
- Message bodies
- Kept only as long as needed to deliver and to handle a bounce — 30 days, then deleted. They are stored separately from delivery records for exactly this reason.
- Delivery records
- By plan: 30 days on Free, 90 days on Starter, 1 year on Growth, 2 years on Scale. These contain recipient addresses and the receiving server’s responses.
- Suppression list
- Retained while the account is open. Deleting a suppression entry would mean sending again to an address that bounced or complained, which is the harm the list exists to prevent.
- Security and access logs
- 12 months.
Who else sees it
Only the providers we need to run the service — hosting, payments and the like. They are listed individually, with what each one processes and where, on the sub-processors page.
There is one unavoidable disclosure inherent to email: to deliver a message we transmit it to the recipient’s mail server, which is operated by whoever the recipient chose. That is what sending an email is.
We do not sell personal data, and we have never been asked to.
Where it is processed
Our infrastructure is hosted in the European Union. Where a provider processes data outside the UK or EEA, that transfer is covered by the appropriate safeguards — standard contractual clauses or an adequacy decision — as noted per provider on the sub-processors page.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to processing based on legitimate interests. You can also ask for it in a portable format.
Email [email protected] and we will respond within one month. There is no charge. If you are unhappy with how we have handled a request you can complain to your local data protection authority.
One limit worth stating plainly: we cannot delete an entry from the suppression list on request from the account holder, because doing so would cause us to send again to an address that bounced or complained. If you are a recipient asking about your own address, get in touch and we will deal with it directly.
Cookies
This marketing site sets no cookies at all — no analytics, no advertising, nothing to consent to. The application sets a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. They are essential to the service and are not used for tracking.
Security
The measures we actually take — database-enforced tenant isolation, encrypted signing keys, hashed API secrets, an append-only delivery record — are described on the security page rather than summarised as “industry-standard” here.
Changes
If we change this policy materially we will email account holders before it takes effect. The date at the top always reflects the current version.