# Privacy Policy _Last updated: v6.0.0_ This document describes what data this Bulk Email SaaS Platform collects, how it's used, and how it's protected. This is a template for whoever operates a deployment of this software to adapt — replace placeholder sections with your own organization's specifics before publishing it to your customers. ## What Data Is Collected **Company Admins & Users** (people who log into the platform): - Name, email address, hashed password - Login activity (timestamps, IP addresses) — used for security (rate-limiting, audit logging) and troubleshooting - Two-factor authentication secret, if enabled (encrypted at rest) **Contacts** (the people companies using this platform send email to): - Name, email, company, mobile, designation, city, state, country, website, notes — whatever fields a Company Admin/User chooses to fill in when adding or importing a contact - Consent source and timestamp (how/when they were added), and opt-in confirmation status if double opt-in is enabled - Email engagement data: opens, clicks, and unsubscribe status, associated with individual sends **Campaign Data**: - Email subject/body content, send history, delivery/bounce status ## How Data Is Used - Contact data is used solely to send the email campaigns a Company Admin/User creates through the platform. - Engagement data (opens/clicks) is used to show campaign performance back to the company that sent the campaign. - Login/activity data is used for account security and, where legally required, to investigate misuse. ## Data Sharing - Contact and campaign data belonging to one company is never visible to another company using this platform (see multi-tenant isolation in `SECURITY.md`). - Data is not sold or shared with third parties, beyond the SMTP provider a company configures to actually deliver its own emails, and (if configured) an external service a company sets up webhooks with for bounce/complaint handling. ## Data Retention - Contact and campaign data is retained until a Company Admin/User deletes it, or the company's account is closed. - [Operator note: this platform does not currently auto-purge old queue/history rows or inactive contacts — if you need a specific retention/deletion policy for compliance reasons, implement it before publishing this section as final, and describe it here.] ## Recipient Rights (Unsubscribe & Suppression) - Every campaign email includes a working unsubscribe link. Clicking it immediately and permanently stops that address from receiving future campaigns from that company. - Bounced or complained-about addresses are automatically suppressed from future sends. - [Operator note: if you operate in a jurisdiction with a formal "right to be forgotten" / data subject access request process (e.g. GDPR), document your specific process here — this platform does not yet include a fully automated self-service data-export/erasure tool; see the product roadmap for planned work in this area.] ## Security See `SECURITY.md` for the technical measures protecting this data (encryption, access control, audit logging, etc.). ## Contact [Operator note: replace this with your organization's actual privacy contact — e.g. a dedicated privacy@ email address, or a link to your company's general contact page.]