Privacy Policy

Last updated August 16, 2026

This Privacy Policy explains how SpringMail (“SpringMail,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you visit our websites, create an account, or use our outbound email Service.

By using the Service, you acknowledge this Policy. Related documents: Terms of Service, Acceptable Use Policy, and Security.

1. Who we are

The controller (or business) responsible for personal information described here is:

SpringMail
SpringMail, 1111B S Governors Ave STE 39124, Dover, DE 19904, USA
support@springmail.ai

2. Information we collect

We collect information in these categories:

  • Account and workspace data: name, email address, authentication identifiers, workspace name, team invitations, and role settings.
  • Billing data: processed by Stripe. We store customer, subscription, and payment status identifiers. We do not store full card numbers.
  • Customer Content: contact lists and lead records you upload or sync, campaign subjects and bodies, domain and inbox configuration, and related metadata needed to send and track mail.
  • Mailbox connection data: OAuth tokens and related identifiers for Google Workspace or Microsoft 365 (and operational secrets such as DNS provider tokens), stored and used to send and manage mail on your behalf. We do not ask for mailbox passwords for the supported OAuth path.
  • Usage and deliverability data: product logs, security events, send status, bounce and health signals, and similar telemetry.
  • Support and sales communications: messages you send to us (including contact and enterprise inquiry forms).
  • Device and site data: IP address, browser type, pages viewed, and cookies or similar technologies needed for sessions, security, and basic analytics.

If you use the Service to process personal data about your recipients or prospects, you act as the controller (or “business”) for that data. SpringMail acts as a processor (or “service provider”) on your instructions, except where we process data for our own account, security, billing, or legal purposes.

3. How we use information

We use information to:

  • Provide, operate, and improve the Service
  • Authenticate users and secure accounts and infrastructure
  • Send campaign and warmup mail as you configure
  • Process payments, credits, and marketplace purchases
  • Enforce Terms, Acceptable Use, and bounce or abuse limits
  • Honor unsubscribes and maintain suppression records
  • Provide support and respond to requests
  • Send service and account notices (and product updates you opt into)
  • Comply with law and protect rights, safety, and the Service

4. Legal bases (EEA/UK where applicable)

Where GDPR or UK GDPR applies, we rely on one or more of: performance of a contract; legitimate interests (securing and improving the Service, preventing abuse); consent where required; and legal obligation.

5. Sharing

We do not sell personal information. We share information with:

  • Service providers / subprocessors that help us run the Service (for example hosting, databases, authentication, payment processing, email infrastructure, DNS, and error monitoring when enabled)
  • Mailbox and DNS providers you connect (Google, Microsoft, Cloudflare, AWS, GCP, and similar) as needed to provide the features you use
  • Professional advisors and authorities when required by law or to protect rights and safety
  • A successor in a merger, acquisition, or asset sale, subject to this Policy or equivalent protections

Workspace admins can access Customer Content in their organization. If you invite teammates, they may see data according to their role.

6. International transfers

We may process information in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.

7. Retention

We retain account and operational data while your workspace is active and as needed for billing, security, dispute resolution, and legal obligations. Suppression and unsubscribe records are kept as long as needed to honor opt-outs. You may request deletion of your account; some records may remain where retention is required or permitted by law.

8. Your choices and rights

  • Recipients of campaign email can unsubscribe via the link in each message or our unsubscribe page.
  • Account holders can update profile and workspace settings in the product, and may request access, correction, or deletion by emailing support@springmail.ai.
  • Depending on your location, you may have rights to object, restrict processing, portability, or lodge a complaint with a supervisory authority.

We will not discriminate against you for exercising privacy rights where that is prohibited by law (for example under CCPA/CPRA for eligible California residents).

9. Cookies and sessions

We use cookies and similar technologies for authentication, security, preference storage, and basic analytics. You can control cookies in your browser; disabling them may break login or core features.

10. Security

We use industry-standard controls including encryption in transit, access controls, and secret management for operational credentials. No method of transmission or storage is 100% secure. See our Security page for a plain-language summary.

11. Children

The Service is not directed to children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact support@springmail.ai.

12. Changes

We may update this Policy from time to time. We will post the revised version with a new “Last updated” date. Material changes may also be communicated by email or in-product notice.

13. Contact

Privacy questions or requests: support@springmail.ai.

SpringMail
SpringMail, 1111B S Governors Ave STE 39124, Dover, DE 19904, USA

This document is an operational baseline for launch. Have qualified counsel review it for your entity and markets before high-volume public acquisition.

Privacy Policy · SpringMail