Privacy Policy
How mailkube collects, uses, and protects your personal data.
Effective date: September 20, 2026
1. Introduction
Welcome to mailkube.
mailkube (“us”, “we”, or “our”) operates https://mailkube.com and its subdomains (hereinafter referred to as “Service”).
Our Privacy Policy governs your visit to our website and your use of the customer dashboard, and explains how we collect, safeguard, and disclose information that results from your use of our Service.
We use your data to provide and improve the Service. Unless otherwise defined in this Privacy Policy, the terms used here have the same meanings as in our Terms of Service.
Our Terms of Service (“Terms”) govern all use of our Service and, together with this Privacy Policy, constitute your agreement with us.
2. Definitions
SERVICE means the web pages mailkube operates at mailkube.com and its subdomains, including the customer dashboard, the sign-in service, and the documentation, together with the email sending services operated by mailkube, as defined in the Terms of Service.
PERSONAL DATA means any information relating to an identified or identifiable natural person. A person is identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier such as an IP address or a device identifier. It does not matter whether the information that makes them identifiable is held by us or by someone else.
USAGE DATA is data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
COOKIES are information stored in, or read from, your terminal equipment (your computer, phone, or other device). The term covers cookies and the technologies used alongside them, including local storage and device identifiers.
DATA CONTROLLER means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purpose of this Privacy Policy, mailkube is the Data Controller of your data. This policy covers the data we hold about you as an account holder, a team user, or a visitor to our website. Where you upload or send contact and audience data through the Service, you are the controller of that data and we act as your processor, on the terms of our Data Processing Addendum. Separately from that processor role, we act as a controller of a narrow set of data about email recipients, for the purpose of protecting the security, integrity, and sending reputation of the Service; that processing is described in our notice for email recipients. If you applied for a job with us, the personal data in your application is covered by our candidate privacy notice instead of by this policy.
DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person, public authority, agency, or other body which processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
DATA SUBJECT is the identified or identifiable natural person to whom Personal Data relates.
THE USER is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
3. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our Service to you.
4. Types of Data Collected
Personal Data
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Address, state, province, ZIP/postal code, city
- Cookies and Usage Data
We may use your Personal Data to contact you with service updates, billing notices, or other information relevant to your account. You may opt out of non-essential communications by following the unsubscribe link in any such email.
Usage Data
We may also collect information that your browser sends whenever you visit our Service or when you access the Service through a mobile device (“Usage Data”).
This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
When you access the Service with a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers, and other diagnostic data.
Early access waitlist
Signing up for the Service is currently by invitation. If you join the waitlist through the form on our website, we collect what you type into it: your full name, your email address, your company name, which is optional, the domain you intend to send from, the volume of email you expect to send, and a short description of what you plan to send. We also record which language the form was displayed in and which page you opened it from, so that anything we write to you is written in the right language.
Two of those entries are checked automatically before your entry is stored. We ask a public DNS resolver operated by Cloudflare whether the domain you typed exists, which involves no personal data of yours. We then send your email address to Bouncer, which tells us whether it is deliverable and returns nothing else about you; the Analytics section below sets out what that involves.
This section applies to you whether or not you already hold an account with us, and whether or not we go on to offer you one. It is this policy that covers your entry, not our candidate privacy notice, which is about job applications only.
We use what you send us to decide who to invite and when. Access is gated so that we can pace how quickly new senders join and look at who they are before they start sending on infrastructure they share with other customers. Our legal basis is Article 6(1)(b) GDPR: holding your entry and assessing it when invitations go out is a step taken at your own request before entering into a contract.
Your entry is filed as a ticket in Jira Service Management, which is hosted by Atlassian and covered by the Standard Contractual Clauses we have concluded with Atlassian, as set out in the Transfer of Data section below. We raise that ticket under our own account rather than in your name, so Atlassian creates no customer record for you and sends you no notification about it.
We do not write to you to tell you we are not inviting you. An invitation is the only thing we send, and entries are assessed when a batch of invitations goes out. Where we decide not to invite you, we record that decision against your entry and keep it for as long as we keep the entry itself, so that we do not assess the same application twice. Our legal basis for keeping that record is Article 6(1)(f) GDPR: we have a legitimate interest in not repeating an assessment we have already made. You can ask us to delete your entry, and that decision with it, at any time.
So that joining a second time does not open a second ticket, we keep a short marker for seven days after an entry. It records when the entry was made and the reference of the ticket it created. It is filed under a one-way fingerprint of your email address rather than under the address itself, so the marker holds no address that can be read back out of it, and it expires on its own once the seven days are up.
We keep your entry until we invite you, until you ask to come off the list, or for twenty-four months from the date you join, whichever comes first, and then delete it. To come off the list at any time, write to privacy@mailkube.com, quoting the reference the form showed you if you still have it. We do not share your entry with anyone beyond what is described in this Policy.
Contacting us through our website
If you write to us through the contact form on our website, we collect what you type into it: your name, your email address, the subject line you choose, and your message. This section applies to you whether or not you hold an account with us.
We use what you send us to answer you and to keep a record of the exchange. Our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in responding to people who write to us, and in being able to show afterwards what was said.
Your message is filed as a ticket in Jira Service Management, which is hosted by Atlassian and covered by the Standard Contractual Clauses we have concluded with Atlassian, as set out in the Transfer of Data section below. Unlike a waitlist entry, we raise that ticket in your name, so Atlassian creates a customer record for you and may notify you as the ticket progresses.
We keep your message for twelve months from the date you send it, and then delete it. We do not share it with anyone beyond what is described in this Policy.
5. Use of Data
mailkube uses the data described above for the purposes below. Each purpose names the legal basis we rely on under Article 6 GDPR.
- To provide the Service and run your account. Creating and maintaining your organization, signing you in, provisioning your sending domains, and transmitting the email you ask us to send. Our legal basis is Article 6(1)(b) GDPR: this is the contract between us.
- To bill you and to enforce that contract, including collection. Our legal basis is Article 6(1)(b) GDPR, and Article 6(1)(c) GDPR where tax or accounting law requires us to keep the record for a fixed period.
- To send you notices about your account and your subscription, including changes to the Service, expiry, and renewal. Our legal basis is Article 6(1)(b) GDPR: the contract requires us to give you these.
- To provide customer support. Our legal basis is Article 6(1)(b) GDPR where your request concerns the Service you hold, and Article 6(1)(f) GDPR otherwise: we have a legitimate interest in answering people who write to us, and in being able to show afterwards what was said.
- To keep the Service working and secure. This covers detecting and fixing technical faults, and detecting and preventing abuse of infrastructure that customers share. Our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in protecting the Service, the customers who share it, and the people who receive mail sent through it.
- To understand how the Service is used and to improve it. Where we do this with the analytics and session-replay tools named in the Analytics section, our legal basis is Article 6(1)(a) GDPR, consent, which you give or refuse in the cookie banner and can withdraw at any time. Where we do it from our own server-side records, without reading anything stored on your device, our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in knowing which parts of the Service are used and where they fail.
- To meet our own legal obligations, including answering lawful requests from public authorities and keeping the records the law requires us to keep. Our legal basis is Article 6(1)(c) GDPR.
- To establish, exercise, or defend legal claims. Our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in being able to bring or answer a claim within the period a claim can be brought.
- To send you product news about our own similar products and services, such as new features and product updates. Our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in telling existing customers what the Service they already use can do. For electronic mail, we rely on the rule for existing customers in Article 13(2) of Directive 2002/58/EC, as transposed where you are located: we obtained your email address from you when you signed up for the Service, we use it for our own similar products and services only, every such email carries an unsubscribe link, and you may object at any time, free of charge, from the moment we collect your address onwards. We honor an opt-out within 24 hours. Opting out of product news does not stop the notices about your account and your subscription described above, which the contract requires us to send.
6. Retention of Data
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
For data processed as part of the Service, we apply the following retention periods, measured against our production systems. After an organization is deleted, its data is erased within 90 days. After a domain is deleted, its data is erased within 90 days. After a subscription lapses, data is retained for the period defined by your plan, up to a maximum of 90 days, after which it is erased. That period is currently 45 days on every plan, and 45 days also applies where a plan defines no period. Invoices and billing records are retained for the period required by tax law and are not erased under this policy. Residual copies may persist in routine backups after erasure from production systems and are overwritten in the ordinary course of the backup cycle. The full retention schedule for data we process on a customer’s behalf, including the rolling analytics window, is in Section 11 of the Data Processing Addendum.
Usage Data is held in two places and we do not set one period across both, so here are the criteria we apply instead. In the analytics tools named in the Analytics section, it is kept for the retention window configured in each tool and is deleted by that tool when the window expires. In our own server-side records, it is kept for as long as it is needed to run, secure, and debug the Service, and a record needed for an open investigation into a fault or a suspected abuse is kept until that investigation closes. Where the law fixes a minimum period, we keep the record for that minimum. We do not extend either period because the data might one day be useful.
7. Transfer of Data
Customer and recipient data processed in the Service is stored at rest in the European Union, and our operational access to it is from within the European Union. Two things cross that boundary in normal operation: connection details such as IP addresses, which our content-delivery provider handles at the location nearest the person concerned, and anything put into a support request or a waitlist entry, which goes to our support-ticketing provider, whether or not the person writing is a customer. Both are covered by Standard Contractual Clauses, and Section 8 of our Data Processing Addendum sets out the detail.
The address-deliverability check described in the Analytics section does not cross that boundary. Bouncer is established in Poland and processes within the European Union, so no transfer mechanism is needed for it.
mailkube is operated by Mail Tactic Corporation, which is incorporated in the United States (Delaware). Where you are established in the European Economic Area, the United Kingdom, or Switzerland, providing the Service to you therefore involves a transfer of personal data to a company in a third country. That transfer is governed by the Standard Contractual Clauses, and where applicable by the UK Addendum to those clauses or by the clauses as modified for Swiss transfers, as set out in Section 8 of our Data Processing Addendum.
Separately, some of our sub-processors are established in a third country or have a parent entity in one (OVH, Cloudflare, Sentry, and Atlassian, which provide infrastructure hosting, our public edge and content delivery, error monitoring, and support ticketing on our behalf). Those transfers are governed by Standard Contractual Clauses concluded between us and each sub-processor. The full list, and what each one does, is on our sub-processors page.
We also use our own analytics and security tools that involve transfers to US-linked providers: Google (Google Analytics 4 and Firebase), Amplitude, and Cloudflare Turnstile, which protects our forms and our registration page from automated abuse. We act as controller for these tools rather than engaging them as sub-processors of customer data, and each transfer is covered by appropriate safeguards (Standard Contractual Clauses or the provider’s own transfer mechanism). Cloudflare appears twice in this section for two different reasons: it is the sub-processor that runs our public edge and content delivery, and it is separately the provider of the bot protection described in the Analytics section, which we use as controller in our own right. The same Standard Contractual Clauses cover both. See the Analytics section for what each tool does and how consent applies.
Our public service-status page is hosted by Atlassian on Statuspage. When you open that page, your browser fetches the current status directly from Atlassian, which therefore receives your IP address and request metadata. That connection is separate from the support-ticketing role described above, and it is covered by the same Standard Contractual Clauses concluded between us and Atlassian.
Separately, payments are processed by Stripe, whose contracting entity is Stripe, LLC in the United States. Stripe acts partly on our instructions and partly as an independent controller of payment data, and that transfer is covered by the Standard Contractual Clauses in Stripe’s data processing agreement. See the Payments section.
You can ask us for a copy of the Standard Contractual Clauses referred to anywhere in this policy, including those we have concluded with the sub-processors named above. Write to privacy@mailkube.com and we will send them to you. We may first remove commercial terms and any information that has nothing to do with data protection.
mailkube will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. No transfer of your Personal Data will take place to an organisation or country unless there are adequate controls in place, including the security of your data and other personal information.
8. Disclosure of Data
We may disclose personal information that we collect, or that you provide:
Disclosure for Law Enforcement
Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.
Where we receive such a request, we will, unless we are legally prohibited from doing so, notify you, challenge requests that are overbroad or unlawful where that is reasonably possible, and disclose only the minimum required. We do not disclose personal data to any public authority in the absence of a valid and binding legal obligation, and we have not created any facility that would give a public authority direct access to personal data. The same commitments apply to data we process on a customer’s behalf, as set out in Section 8 of our Data Processing Addendum.
Other cases
We may also disclose your information:
- To contractors, service providers, and other third parties we use to support our business
- To fulfill the purpose for which you provide it
- To a buyer or successor, and to their professional advisers during due diligence, in connection with a merger, acquisition, reorganisation, financing, insolvency, or a sale of all or substantially all of our assets. The Assignment section of our Terms of Service governs what happens to your agreement with us in that situation, and we will require any recipient of personal data to continue to protect it in accordance with this Policy
- With your consent in any other cases
9. Security of Data
The security of your data is important to us. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
10. Your Data Protection Rights Under GDPR
If you are a resident of the European Union (EU) or European Economic Area (EEA), you have certain data protection rights covered by GDPR.
We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us at privacy@mailkube.com.
In certain circumstances, you have the following data protection rights:
- The right to access, update, or delete the information we hold on you
- The right of rectification. You have the right to have your information rectified if it is inaccurate or incomplete
- The right to object to our processing of your Personal Data
- The right of restriction. You have the right to request that we restrict the processing of your personal information
- The right to data portability. You have the right to receive a copy of your Personal Data in a structured, machine-readable, and commonly used format
- The right to withdraw consent at any time where we rely on your consent to process your personal information
- The right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We take decisions of that kind, and the next paragraphs say what they are and what you can do about them
Automated decisions about sending
Some enforcement decisions are taken by software alone, with no person involved at the point the decision is made. They are taken about the sending behaviour of an account, and they can affect you directly where you hold the account in your own name rather than through a company.
What we weigh. The rate at which the mail you send is rejected by receiving servers, separated into permanent and temporary failures and measured only once a domain has sent enough mail for a rate to mean anything, so a small number of failures on a small send does not trigger anything. Failed authentication attempts against your SMTP credentials. Bounces that indicate a message was malformed or its identifiers were forged. Attempts to send to more recipients in one message than your plan allows. The verdict of the scan we run over outbound message content for links known to be malicious. And, for a permanent shutdown at the apex, the number of sending domains beneath that apex that have already been suspended. Our Acceptable Use Policy publishes the floors we apply and states that they are floors rather than a safe harbour. We do not publish the measurement periods or the exact triggers, because a threshold we publish in full is one that can be sent just underneath.
What can happen. Your sending can be throttled. A sending domain can be suspended. After a repeated suspension a sending domain can be blocked permanently, and where enough domains beneath the same apex have been suspended, the apex itself can be blocked permanently, which stops every subdomain under it and locks the creation of new ones. Your account can be suspended or terminated. Separately, the IP address you connect from can be blocked temporarily.
What you can do. Any permanent action is reviewed by a person and not by an automated process if you ask, and you can put forward your own account of the facts and ask us to reconsider. The route to do that is in the Acceptable Use Policy and survives losing access to the dashboard. You can also ask us to explain how a decision about you was reached.
Please note that we may ask you to verify your identity before responding to such requests. Please also note that we may not be able to provide the Service without some necessary data.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the EEA.
11. Your Data Protection Rights Under CalOPPA
CalOPPA is the first state law in the United States to require commercial websites and online services to post a privacy policy.
According to CalOPPA, we agree to the following:
- Users can visit our site anonymously
- Our Privacy Policy link includes the word “Privacy” and can be found on this page
- Users will be notified of any privacy policy changes on this page
- Users are able to change their name from the profile page of their mailkube dashboard, and to change any other personal information we hold about them by contacting us at privacy@mailkube.com
12. Your Data Protection Rights Under CCPA
If you are a California resident, you are entitled to learn what data we collect about you, ask to delete your data, and request that it not be sold. To exercise your data protection rights, you can ask us:
a) What personal information we have about you, including:
- The categories of personal information we have collected
- The categories of sources from which we collect it
- The business or commercial purpose for collecting it
- The categories of third parties with whom we share it
- The specific pieces of personal information we have collected about you
You are entitled to make this request up to two times in any rolling twelve-month period.
b) To delete your personal information. We will delete the personal information we hold about you and direct any service providers to do the same, except where we are permitted or required to retain it. We retain invoices and billing records for the period required by tax law, and we retain bounce suppression entries for as long as the associated sending domain remains configured, because they exist to stop us mailing an address that has already rejected mail. If you choose to delete your personal information, you may not be able to use certain functions that require it to operate.
c) To correct your personal information. You may ask us to correct personal information you believe is inaccurate.
d) To stop selling or sharing your personal information. We do not sell or share your personal information, as those terms are defined in the CCPA, and we do not rent it. “Share” includes disclosure for cross-context behavioural advertising.
e) To limit our use of sensitive personal information. We do not collect or process sensitive personal information for purposes that would give rise to this right.
f) Not to be discriminated against. We will not deny you goods or services, charge you a different price, or provide a different level of service because you exercised any of these rights.
You may use an authorised agent to make a request on your behalf. We may ask the agent to provide proof of your authorisation, and may ask you to verify your identity directly.
To exercise your California data protection rights, please contact us at privacy@mailkube.com.
Where we process personal information on a customer’s behalf as their service provider, requests about that information should be directed to that customer, and we will forward any request we receive. The terms of that processing are in our Data Processing Addendum.
13. Service Providers
We may employ third-party companies and individuals to facilitate our Service (“Service Providers”), provide the Service on our behalf, perform Service-related services, or assist us in analysing how our Service is used.
Where these third parties act as our processors, they have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. The sub-processors that process data on our behalf are listed on our sub-processors page. Some third parties named in this policy are not sub-processors of customer data: Stripe processes payment and billing data, partly on our instructions and partly as an independent controller, as described in the Payments section, and the analytics and security tools described in the Analytics section are ones we use as controller in our own right.
14. Analytics
We use analytics and error-monitoring tools to understand how our Service is used and to keep it reliable. Non-essential analytics and session replay only run after you consent, and you can withdraw consent at any time.
Google Analytics 4
Google Analytics 4 is a web analytics service offered by Google that reports on how visitors use our website. It is loaded through Google Consent Mode: analytics storage stays denied by default and is only enabled once you accept analytics cookies. This data may be shared with other Google services.
You can also opt out by installing the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout.
For more information on Google’s privacy practices, please visit: https://policies.google.com/privacy.
Amplitude
Amplitude is a product analytics service provided by Amplitude, Inc. We use it only in the app dashboard, and only to measure how you, as the account holder, use the dashboard so we can improve the product experience. It is limited to your own account identity and usage; it does not process your customers’ or recipients’ data. Amplitude runs only after you consent and can be switched off by withdrawing consent.
You can review Amplitude’s privacy practices at: https://amplitude.com/privacy.
Firebase (Google)
Firebase, and specifically its Firestore database, is a Google service we use in the app dashboard to deliver realtime change notifications, so that a counter or a list updates as soon as the underlying record does. The documents it carries hold only internal record identifiers and counters. They never carry message content, recipient data, or personal details. When you are logged in, your browser connects directly to Google’s servers to receive these notifications, and Google therefore receives connection data including your IP address and device signals as the recipient of that connection. The realtime channel itself stores nothing on your device and reads nothing already stored there. Signing the dashboard in to it does store a token on your device, and that token is exempt from consent because it does one job only, authenticating you to the service you asked for. The transfer is covered by Google’s standard contractual safeguards.
For more information on Google’s privacy practices, please visit: https://policies.google.com/privacy.
Error monitoring (Sentry)
We use Sentry to capture technical error diagnostics so we can detect and fix problems. Basic error capture is essential to operating the Service reliably and is always active. Optional session replay, which records a masked reconstruction of a dashboard session to help us diagnose errors, is non-essential and only runs after you consent; when enabled, it masks text and blocks media so that content is not captured.
You can review Sentry’s privacy practices at: https://sentry.io/privacy/.
Cloudflare Turnstile
We use Cloudflare Turnstile to protect our contact, careers, job-application, signup, and waitlist forms, and the registration page on our sign-in service, from spam and automated abuse. Until August 2026 this role was filled by Google reCAPTCHA Enterprise, which we no longer use anywhere.
Turnstile receives your IP address, the technical fingerprint of your browser’s connection, your browser’s user-agent string, and the identifier of the form you are using. It sets no cookies and stores nothing on your device.
It is treated as essential and is always active rather than being consent-gated, and the reasons are these. Protecting a form from unbounded automated submission is strictly necessary to the service you asked us for, and securing the site is a purpose that needs no consent in its own right. The signals it receives serve one purpose, telling a person from an automated script, and are not used for advertising, for profiling you, or for anything unrelated to that. And Cloudflare already operates the network our website and sign-in service are served through, so it already receives the same connection data on every page you load: Turnstile does not send your data anywhere it was not already going. Nothing loads until you start filling a form in, so a visit that does not involve a form reaches Cloudflare’s challenge service not at all.
One thing is worth stating plainly rather than leaving you to find it. Cloudflare acts on our instructions when it protects our forms, but it also uses what it learns to improve its own bot-detection service, and for that limited purpose it decides how the data is used. We are satisfied that this stays inside the same security purpose rather than becoming a separate one, which is what our assessment of this choice turns on. You can read Cloudflare’s account of it in its Turnstile privacy addendum.
Email address verification (Bouncer)
We use Bouncer to check whether an email address can actually receive mail. It runs in three places: when you join the early access waitlist, and at each of the two steps of the signup form once your invitation code has been checked. The signup form checks the address twice because the two steps are independent requests and the address can change between them.
Bouncer receives the email address and nothing else. It returns whether the address is deliverable and whether it belongs to a disposable or throwaway provider. It returns nothing about who you are. If it does not answer, or answers that it could not tell, we accept the address.
We keep that answer at our own network edge for up to twenty-four hours, filed under a one-way fingerprint of the address rather than under the address itself, so that checking the same address twice does not send it twice. The stored answer holds no address that can be read back out of it, and it expires on its own.
Our legal basis is Article 6(1)(f) GDPR: we have a legitimate interest in not building a waitlist and a set of accounts around addresses that cannot receive the mail we would send to them, and in not sending invitation codes and password-setup links into the void. The check tells us one thing about an address you gave us yourself, and nothing about you.
Bouncer is operated by Bouncer Sp. z o.o., established in Wrocław, Poland. It acts as our processor, it processes within the European Union, and your address is not transferred outside it. It is not a sub-processor of customer data and does not appear on our sub-processors page, because the addresses we send it are our own, given to us by the person concerned, and never data we hold on a customer’s behalf.
For more detail on which of these set cookies or similar technologies, and how to change your choice, see our Cookie Policy.
15. Payments
We provide paid products and services within the Service. Mail Tactic Corporation is the seller of record for those purchases, and payment processing is handled by Stripe. We do not store or collect your payment card details. You enter them on Stripe’s own checkout page and they do not pass through our systems.
We do hold your billing information: your organization or business name, your billing email address, your billing address, and your tax identifier where you give one, together with the invoices and payment records we keep to meet our tax and accounting obligations. We send that billing information to Stripe so that it can take the payment and calculate any tax due.
Stripe acts in two capacities at once. It carries out payment instructions on our behalf and on our instructions. It separately processes the same payment data as an independent controller, for fraud prevention, anti-money-laundering screening, its obligations to banks and card networks, and its own regulatory duties. That second capacity is governed by its own privacy policy rather than by ours.
Our payment processor is:
Stripe
Stripe, LLC, in the United States, processes payments for our transactions. Their Privacy Policy can be viewed at: https://stripe.com/privacy.
16. Links to Other Sites
Our Service may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
17. Children’s Privacy
Our Service is not intended for use by children under the age of 18.
We do not knowingly collect personally identifiable information from children under 18. If you become aware that a child has provided us with Personal Data, please contact us at privacy@mailkube.com. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
18. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service prior to the change becoming effective, and will update the effective date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
19. Contact
The Service is operated by Mail Tactic Corporation (“mailkube”).
If you have any questions about this Privacy Policy, please contact us at privacy@mailkube.com.
Mail Tactic Corporation has appointed Prighter EU Rep GmbH, Vienna, Austria, as its representative in the European Union pursuant to Article 27 GDPR, as the point of contact for data subjects and supervisory authorities on matters relating to the processing of personal data. The representative may be addressed in addition to or instead of Mail Tactic Corporation, which remains reachable at privacy@mailkube.com. Contact details are on our EU Representation page.