Privacy Policy
Last updated: [DATE]
DearReach ("DearReach", "we", "us") provides a deliverability-first email platform. This policy explains what personal data we handle, why, and the choices available. It covers two distinct relationships:
- Customers, the people and businesses who hold a DearReach account and send email through us.
- Subscribers, the recipients whose contact details our customers upload and email. For subscriber data, our customer is the controller and DearReach is a processor acting on the customer's instructions.
1. Who is responsible for your data
The data controller for customer-account data is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For questions or to exercise your rights, contact [email protected]. If you are a subscriber and want your data changed or removed, contact the sender who emailed you; we act on their instructions, and every email includes a one-click unsubscribe.
2. Data we handle
Customer account data
- Identity and login: name, email, hashed password, authentication sessions.
- Workspace and sending configuration: company/branding details, sender profiles, sending domains, and the postal address anti-spam law requires in every footer.
- Billing: plan, subscription status, and a customer reference held by our payment processor. We do not store full card numbers, card data is handled directly by Stripe.
- Operational logs: request metadata, audit records of sensitive actions, and diagnostics needed to run the service securely.
Subscriber data (processed on our customers' behalf)
- Contact details our customers upload: email address, optional name, and custom fields.
- Consent and delivery records: how and when a subscriber joined, and per-campaign delivery, bounce, complaint, open, and click events.
- Suppression data: one-way hashes of addresses that have unsubscribed or complained, kept to prevent unlawful re-contact.
3. Why we handle it (legal bases)
| Purpose | Basis |
|---|---|
| Providing the account and sending service | Performance of a contract with the customer |
| Sending email to subscribers | The customer's instructions; the customer is responsible for a lawful basis to email each subscriber |
| Security, fraud prevention, abuse and reputation protection | Legitimate interests |
| Billing and tax records | Contract and legal obligation |
| Honouring unsubscribes and complaints (suppression) | Legal obligation and legitimate interests |
4. How email tracking works
Unless a customer turns it off for a campaign, emails may include an invisible open pixel and rewritten click links so the customer can see delivery and engagement. Customers can disable open tracking per campaign; unsubscribe, delivery, and bounce handling always remain active. We do not sell tracking data or build cross-site advertising profiles.
5. Sub-processors
We use a small set of vetted providers for email transmission, hosting, database, and payments. The current list and data-retention periods are on our Sub-processors & retention page.
6. Data retention
We keep customer-account data for the life of the account. When an account is deleted, it is scheduled for permanent erasure after a 30-day recovery window; after that, account and subscriber personal data are deleted. One-way suppression hashes are retained (currently up to three years) so people who unsubscribed or complained cannot be re-emailed, these hashes cannot be reversed into an email address. Billing records are kept as long as tax law requires.
7. International transfers
Our infrastructure and sub-processors may process data in [REGION(S)]. Where data leaves your region, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm exact regions and mechanisms with counsel.]
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. Customers can export and delete their data in the app. Subscribers should contact the sender who holds their data; we assist that sender as their processor. To make a request to us directly, email [email protected]. You may also complain to your local data protection authority.
9. Security
We enforce tenant isolation at the database level, restrict runtime database access, hash passwords and suppression data, verify inbound provider webhooks, and keep auditable records of sensitive and delivery actions.
10. Children
DearReach is not directed to children and is not intended for anyone under 16. We do not knowingly collect their data.
11. Changes
We will update this policy as the service evolves and post the new date here. Material changes are communicated to account holders.
12. Contact
[LEGAL ENTITY NAME], [ADDRESS] · [email protected]
© 2026 DearReach. This document is a draft template and does not constitute legal advice.