Privacy Policy
Last Updated: [DATE]
1. Introduction
This Privacy Policy explains how Destinatarium ("Destinatarium", "we", "our", or "us") collects, uses, stores, protects, and discloses information when you access or use our Services.
Our Services include:
- Transactional email delivery
- SMTP relay services
- Email APIs
- Webhooks
- Analytics and reporting
- Open tracking
- Click tracking
- Shared IP infrastructure
- Dedicated IP services
- Websites, dashboards, and support systems
2. Scope
This Privacy Policy applies to information collected through:
- The Destinatarium website
- Customer dashboards
- APIs
- SMTP services
- Webhooks
- Tracking features
- Customer support interactions
- Billing and account management systems
3. Information We Collect
3.1 Account Information
- Name
- Email address
- Company name
- Account credentials
- Billing information
- Subscription details
- Support communications
3.2 Service Data
Encrypted Data
- Sender email addresses
- Recipient email addresses
- Message subject lines
- Message bodies
- Email attachments
Non-Encrypted Operational Data
- Message headers
- Delivery events
- Bounce events
- Open tracking events
- Click tracking events
- Authentication results
- Technical metadata
- Queue information
- Message identifiers
3.3 Technical Information
- IP addresses
- Browser information
- Device information
- Operating system information
- Network information
- Access logs
- Authentication logs
- API usage logs
- SMTP activity logs
4. How We Use Information
- Provide and maintain the Services
- Deliver email messages
- Authenticate domains
- Generate analytics and reporting
- Monitor service performance
- Detect abuse and fraud
- Protect infrastructure and sender reputation
- Process payments
- Provide customer support
- Improve Services
- Comply with legal obligations
- Enforce our policies
5. Tracking Features
Destinatarium may provide open tracking and click tracking features. These features are optional and controlled by Customers.
Customers are solely responsible for:
- Determining whether tracking features are appropriate for their use case
- Obtaining any legally required consent
- Complying with applicable privacy laws and regulations
Tracking data may include:
- Event timestamps
- IP addresses
- User-agent information
- Link interaction events
6. Data Retention
| Plan | Retention Period |
|---|---|
| Free | 48 Hours |
| Starter | 7 Days |
| Growth | 30 Days |
| Enterprise | Contractual |
Retention periods may change over time. Destinatarium is not intended to function as a backup or archival service. Customers remain responsible for maintaining their own backups.
7. Encryption and Security
Destinatarium implements technical and organizational measures designed to protect customer information.
- Encryption at rest
- Encryption in transit
- Access controls
- Authentication mechanisms
- Infrastructure monitoring
- Abuse detection systems
- Security logging
Although reasonable safeguards are implemented, no system can guarantee absolute security.
8. Sharing of Information
Destinatarium does not sell personal data.
Service Providers
Information may be shared with hosting providers, infrastructure providers, payment processors, monitoring providers, and security providers.
Legal Compliance
Information may be disclosed when required by law, court order, government authority, regulatory obligation, or legal process.
Business Transactions
Information may be transferred as part of a merger, acquisition, corporate restructuring, sale of assets, or formation of successor entities.
9. Third-Party Providers
Current providers may include:
- Paddle
- Contabo
- Amazon Web Services (AWS)
Providers may change over time without prior notice.
10. International Data Transfers
Information may be processed, transferred, stored, or accessed in countries other than the country in which it was originally collected.
11. Customer Responsibilities and Data Roles
Customer
The Customer generally acts as the Data Controller and determines the purpose and legal basis for processing recipient information.
Destinatarium
Destinatarium generally acts as a Data Processor or service provider, processing information on behalf of the Customer.
12. Legal Bases for Processing
Where applicable, processing may be based on:
- Performance of a contract
- Legitimate interests
- Legal obligations
- Consent
- Protection of legitimate business interests
13. Your Rights
Depending on applicable law, individuals may have rights including:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Data portability
14. Abuse Detection and Security Monitoring
To protect the Services, Destinatarium may process:
- Message metadata
- Authentication results
- Reputation indicators
- Abuse signals
- Security events
- Technical logs
System activity may be monitored to detect fraud, prevent abuse, protect infrastructure, preserve service availability, and maintain sender reputation.
15. Children's Privacy
The Services are not intended for individuals under eighteen (18) years of age.
16. Changes to This Privacy Policy
Destinatarium may modify this Privacy Policy from time to time. Updated versions become effective upon publication.
17. Contact Information
For privacy-related inquiries:
privacy@destinatarium.com
18. Relationship With Other Policies
This Privacy Policy should be read together with:
- Terms of Service
- Acceptable Use Policy
- Data Processing Agreement (where applicable)
- Data Retention Policy
- Other applicable service policies