Privacy policy
What we collect, why we collect it, and what you can do about it.
This policy explains how Mailkoo handles personal data — both the data of the person who holds the account, and the subscriber data uploaded into it. It is written to be read, not to be survived.
The two kinds of data
There are two different kinds of personal data here, and they are treated differently.
- Account data is about you: your name, email address, password hash, billing details, IP address and the log of what you did in the application. We are the controller of this data.
- Subscriber data is about the people on your lists: whatever fields you upload or collect, plus the delivery, open and click events generated when you send to them. You are the controller of this data. We process it on your instructions.
How data reaches us
We collect account data when you create an account, buy a plan, or use the application. We collect subscriber data only because you put it there — by import, by API, or through a signup form you published.
We also record technical information automatically: request logs, error traces, and the events needed to send and track email. Cookies are used for the session, your language and theme choice, and — only where enabled — analytics.
What the data is used for
Account data is used to run the service: to authenticate you, to bill you, to enforce plan limits, to send service notices, and to answer support requests. Subscriber data is used only to do what you asked — to deliver the campaigns and automations you send, and to report on what happened to them.
We do not sell personal data, and we do not use subscriber data to train models or build audience products.
Who else sees it
Data is shared with the third parties needed to run the service: your chosen sending provider, the payment gateway that processes your subscription, and the infrastructure this installation runs on. Which sending provider receives your subscriber data is your choice — it is the one configured on your account.
We disclose data to authorities only where legally compelled, and only to the extent compelled.
How long it is kept
Account data is kept for as long as the account exists, and for as long afterwards as tax and accounting rules require for the billing records.
Subscriber data is kept until you delete it, or until the account is deleted. Tracking and log data is pruned on a rolling schedule. Deleting a list, a campaign or the account removes the associated data from the live system.
Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing.
For account data, most of this is self-service: your profile, your export and your account deletion are all in the application. For subscriber data, the request should go to the account holder who uploaded it — they are the controller — and we will support them in answering it.
Unsubscribes and suppression
Every marketing email sent through Mailkoo carries an unsubscribe link, and an unsubscribe is honoured immediately and permanently for that list. Sending to a subscriber who has unsubscribed, hard-bounced or filed a complaint is blocked by the system, not merely discouraged.
International transfers
Where data is transferred outside your own country, it is because your sending provider, payment gateway or hosting is located there. Choosing providers in a particular region is under your control.
Children
The service is not directed at children, and accounts may not be created by anyone under the age required by their local law to consent to processing.
Changes and contact
If this policy changes in a way that materially affects you, the change is announced in the application before it takes effect. The date at the top of this page always reflects the current version.
Questions about this policy, or a request about your data, can be sent through the contact page.