Legal
Privacy Policy
Effective: 17 July 2026
PostMTA Inc. ("PostMTA", "we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard data in compliance with GDPR, UK GDPR, and CCPA.
1. Information We Collect
1.1 Information You Provide
- Account registration: name, email address, company name, job title, phone number
- Payment information: processed and tokenised by Stripe — we never store card numbers or bank details
- Email content & metadata: subject lines, from/to addresses, message body, headers, engagement events (opens, clicks, bounces, complaints)
- Support communications: tickets, chat transcripts, and any files you upload when requesting help
1.2 Information Collected Automatically
- IP address, browser type, operating system, and device identifiers
- Pages visited, referring URLs, and interaction events on our marketing site and dashboard
- Email delivery events (sent, delivered, bounced, complained) — associated with your sending domain
2. Purpose & Lawful Basis for Processing (GDPR)
| Purpose | Lawful Basis | Data Categories |
|---|---|---|
| Provide email delivery services | Contract (Art. 6(1)(b)) | Account info, email content/metadata, API keys |
| Billing and subscription management | Contract (Art. 6(1)(b)) | Payment tokens (Stripe), usage records |
| Customer support | Legitimate interests (Art. 6(1)(f)) — our interests in resolving issues | Support tickets, account history |
| Security, fraud detection, abuse prevention | Legitimate interests (Art. 6(1)(f)) | IP logs, API call records, engagement events |
| Marketing emails (product updates, tips) | Consent (Art. 6(1)(a)) — you can withdraw at any time | Email address, name |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) — you may object at any time | Aggregated, anonymised usage data |
3. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with the following trusted sub-processors, each acting only on our instructions:
| Sub-processor | Purpose | Data Shared |
|---|---|---|
| Supabase (PostgreSQL) | Primary data store — account records, email metadata, usage logs | Account info, email metadata, support tickets |
| Stripe | Payment processing and subscription management | Payment tokens only — no card data |
| AWS / GCP | Cloud infrastructure hosting (your choice of region) | Email content/metadata stored in your selected region |
| Mailgun / Amazon SES | Optional upstream MTA relay (EU regions) | Email content/metadata for relay only |
| Plausible Analytics | Privacy-first website analytics (no cookies, GDPR-compliant) | Anonymous page-view data |
Any new sub-processor will be listed in our DPA and notified 30 days in advance.
4. Retention Periods
- Account data: Duration of your subscription + 90 days after closure
- Email metadata & delivery events: 13 months from the event date
- Billing records: 7 years (tax and accounting obligations)
- Support tickets: 3 years after resolution
- Marketing consent records: Until you withdraw consent + 2 years
After account closure, all personal data is deleted within 30 days except billing records retained under legal obligation.
5. Your Rights
Depending on your jurisdiction, you may have the following rights. To exercise any of them, email privacy@netwit.ca. We respond within 30 days.
- Access (GDPR Art. 15): Receive a copy of all personal data we hold about you
- Rectification (Art. 16): Correct inaccurate or incomplete data
- Erasure ("Right to be Forgotten", Art. 17): Delete your data, where no legal obligation prevents it
- Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON)
- Objection (Art. 21): Object to processing based on legitimate interests; we will cease unless we have a compelling legal basis
- Restriction (Art. 18): Request we restrict processing during a dispute
- Withdraw consent: At any time, for consent-based processing — this does not affect lawfulness prior to withdrawal
6. Data Processing Agreement (DPA)
We offer a signed DPA for customers subject to GDPR or UK GDPR. It includes:
- Data Processing Addendum incorporating Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA) for UK transfers
- Full list of sub-processors with their processing locations and security certifications
- Audit rights: provide SOC 2 Type II report upon request
- Data breach notification within 72 hours of becoming aware
Request a DPA by emailing privacy@netwit.ca with your company details and VAT/tax ID if applicable.
7. Data Security
We implement a defence-in-depth security model:
- TLS 1.3 in transit; AES-256 encryption at rest
- MFA enforced on all dashboard accounts
- API keys are hashed — we never store plaintext keys
- Annual third-party penetration testing (SOC 2 Type II report available under NDA)
- Role-based access control (RBAC); least-privilege principle
- Infrastructure DDoS protection via Cloudflare
8. California Consumer Privacy Act (CCPA) Rights
California residents have additional rights under the CCPA (as amended by CPRA):
- Right to Know: What personal information is collected, its business purpose, and third parties involved
- Right to Delete: Request deletion of personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information (we do not sell or share your data)
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
We do not sell personal information and have not done so in the preceding 12 months. To submit a verified CCPA request, contact privacy@netwit.ca.
9. Changes to This Policy
We will notify you of material changes via email at least 30 days before they take effect. Non-material changes (e.g., updating sub-processor details) will be reflected in the "Effective" date at the top of this page.
10. Contact
PostMTA Inc.
Data Protection Officer
123 Mail Street, Suite 400
San Francisco, CA 94107
USA