Privacy Policy.
This policy explains what personal data SendCanyon, Inc. ("SendCanyon", "we", "us") collects, why we collect it, who we share it with, and the choices and rights you have. It covers our website, application, and APIs (together, the "Service"). Questions to [email protected].
Last updated
On this page
Privacy Policy
1. Our two roles: controller and processor
SendCanyon handles personal data in two distinct capacities, and your rights differ depending on which applies.
- As a controller for data about our own users and site visitors — your account details, billing information, usage of the Service, and communications with us. This policy governs that data directly.
- As a processor for data our customers upload — the contacts, email addresses, and message content a workspace imports and sends through the Service. For that data, the customer (the workspace owner) is the controller, we process it only on their instructions under our Data Processing Addendum, and requests concerning it should go to the customer who uploaded it. If you contact us directly about data a customer holds, we will forward your request to them and support their response.
2. Data we collect
Data you provide
- Account data: name, email address, password (stored hashed), workspace name, and role. If you sign in with Google or Microsoft, also that account's ID (see Section 4 for Google).
- Billing data: plan, billing address, and tax ID where applicable. Card details go directly to our payment processor (Stripe) and never touch our servers.
- Connected mailbox credentials: OAuth tokens or SMTP/IMAP credentials for mailboxes you connect. These are encrypted at rest and decrypted only in memory when a mailbox sends or is read. For Google mailboxes see Section 4.
- Customer content (as processor): contact lists, custom fields, email templates, sequences, and the content of messages sent and received through connected mailboxes.
- Communications: support requests, feedback, and survey responses.
Data collected automatically
- Usage data: pages viewed, features used, actions taken (e.g. campaign launched), timestamps, and API request metadata.
- Device data: IP address, browser type, operating system, and screen dimensions.
- Sign-in data: the IP address you sign in and work from, and the approximate location (country and city) we derive from it on our own servers without a third-party lookup. Kept for account security, such as spotting a sign-in from somewhere unexpected.
- Security records: failed sign-in attempts (the email address entered, IP address, approximate location and browser) to protect accounts from password guessing, and a record of when you accepted our Terms and this policy, which versions, and from which IP address.
- Email event data: delivery, bounce, open, click, reply, and unsubscribe events for messages sent through the Service.
- Free tools: when you use a free tool on our website or in the app, we keep a record of each use: your IP address, the country we derive from it, your browser type, the page you used it on and the page that brought you there, the time, and, if you are signed in, your account and workspace. We use it to enforce the free allowance, to stop abuse and for usage analytics. Most tools also keep what you entered and the result they gave you. The template checker is the exception: the email you check is processed in memory to score it and then discarded, never stored or logged, and we keep only its score. Where a tool has an AI step, what you entered and the tool's result are sent to our AI writing-assistance subprocessor (Section 5) to produce that part of the answer.
- Cookies: see Section 9.
3. Why we process it (and our legal bases)
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Providing the Service | Authentication, sending campaigns, warmup, analytics | Contract performance |
| Billing | Subscriptions, invoices, tax compliance | Contract performance; legal obligation |
| Security & abuse prevention | Fraud detection, rate limiting, enforcing our Acceptable Use Policy | Legitimate interests |
| Service communications | Verification emails, DNS alerts, warmup completion, limit warnings | Contract performance |
| Product improvement | Aggregated feature-usage analysis, debugging | Legitimate interests |
| Marketing to you | Product updates and newsletters (opt-out any time) | Consent / legitimate interests |
| Legal compliance | Responding to lawful requests, tax and accounting records | Legal obligation |
We do not sell personal data, and we do not use customer content (your contacts or message bodies) for advertising or to train generalized models.
4. Google user data
SendCanyon asks Google for data in two separate places, each with its own permission screen. We access only what is listed here, only for the purpose stated, and only while you keep the connection.
Sign in with Google
- Scopes:
openid,email,profile. - What we receive: your Google account ID, email address, whether Google has verified that address, your name, and, for Google Workspace accounts, your organisation's domain.
- Why: to create your SendCanyon account or sign you in to it, and to confirm the address is yours. We store the account ID, email address and name on your SendCanyon account. We do not store Google sign-in tokens: the token Google returns is checked and discarded during sign-in.
Connecting a Gmail or Google Workspace mailbox
- Scopes:
https://mail.google.com/(withopenidandemailto identify the mailbox). Gmail's SMTP and IMAP servers accept no narrower scope. - Sending: we send the campaign emails and Inbox replies you write, from the mailbox you connected, when you schedule or send them.
- Reading: to detect replies to your campaigns, we check the mailbox's inbox for new messages about once a minute. For each new message we keep the sender, recipient, subject, date, message identifiers and the first 500 characters of text, and show replies in your SendCanyon Inbox and analytics. To attribute a reply to the right campaign email, we may look up the headers of that email in the mailbox's Sent folder.
- Warmup (only if you turn it on): the mailbox exchanges warmup emails with other mailboxes connected to SendCanyon, replies to them, and marks warmup emails it receives as read.
- What we store: only the OAuth refresh token, encrypted at rest with AES-256-GCM. We do not store your Google password.
Limited Use
SendCanyon's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide the features described above, which you see and control in the app.
- We do not sell Google user data, use it for advertising, transfer it to data brokers or information resellers, or use it to decide creditworthiness or for lending.
- We do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models. SendCanyon's AI features receive only the text you type or paste into them; no Gmail content is sent to them automatically.
- No person at SendCanyon reads your Google user data unless you ask us to and agree to it for a specific support request, it is necessary for security (such as investigating abuse), it is required to comply with law, or it is aggregated and anonymised for internal operations.
- We transfer Google user data to others only to provide these features (for example, our hosting provider in Section 5), for security, to comply with law, or as part of a merger, acquisition or sale of assets with notice to you.
Retention, disconnection and deletion
- Removing a Google mailbox revokes SendCanyon's access at Google and deletes the stored token immediately. Messages already captured stay in your workspace until you delete them or the workspace.
- Deleting a workspace or your account revokes and deletes the tokens of every Google mailbox in the workspaces deleted with it. Workspace content, including captured replies, is deleted within 90 days (Section 7).
- Disconnecting Google sign-in in Settings → Account removes the stored Google account ID. Deleting your account erases your name, email and Google account ID.
- You can also withdraw access at any time from your Google Account at myaccount.google.com/permissions. Once access is withdrawn, the mailbox stops sending and reading.
5. Who we share data with
We share personal data only with service providers who process it for us under contract (subprocessors), with parties you direct us to share with (e.g. your connected email provider), in a corporate transaction with notice, or where the law requires it. Our current subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Infrastructure hosting (application, database, queue) | Customer-selected region |
| Amazon Web Services (SES) | Email delivery for customers who connect SES | Customer-selected region |
| Stripe, Inc. | Payment processing and invoicing | United States |
| Google LLC | Mailbox connectivity for Gmail/Google Workspace senders | United States / global |
| Microsoft Corporation | Mailbox connectivity for Microsoft 365 senders | United States / global |
| OpenAI, L.L.C. | AI writing-assistance features and the AI step of free tools (prompt content only, on request) | United States |
| Postmark (ActiveCampaign, LLC) | Transactional system emails (verification, alerts) | United States |
We update this table when subprocessors change and, for customers with a DPA, provide advance notice of additions with a right to object.
6. International transfers
Where personal data originating in the EEA, UK, or Switzerland is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with the receiving party, together with technical measures including encryption in transit and at rest. A copy of the relevant clauses is available on request to [email protected].
7. Retention
- Account data: kept while your account is active and deleted or anonymized within 90 days of account closure, except where law requires longer (e.g. invoices for tax purposes, typically 7–10 years).
- Customer content: kept while the workspace is active; deleted within 90 days of workspace deletion. Workspace owners can delete contacts, campaigns, and messages at any time from the dashboard or API.
- Suppression records: retained even after related contact records are deleted, because they exist to prevent future unwanted email — deleting them would defeat their purpose.
- Email event data: retained for the life of the workspace for analytics and deliverability protection.
- Sign-in data: deleted 90 days after it was last seen, and immediately when you delete your account. Failed sign-in attempts are deleted after 90 days.
- Free tool usage: the IP address, country, browser type, referring page, what you entered and the result are deleted 90 days after each use; the time, the tool and any score are kept as anonymous usage counts.
- Backups: encrypted backups roll off within 35 days of deletion from production.
8. Your rights (GDPR, CCPA, and similar laws)
Depending on where you live, you may have the right to access, correct, delete, export (data portability), restrict or object to processing of your personal data, withdraw consent, and lodge a complaint with a supervisory authority. California residents additionally have the right to know what categories of personal information we collect and disclose, the right to deletion and correction, and the right not to be discriminated against for exercising these rights — and because we do not sell or share personal information as defined by the CCPA/CPRA, there is nothing to opt out of.
To exercise any right, email [email protected] from the address associated with your account (or provide equivalent verification). We respond within 30 days (GDPR) or 45 days (CCPA). Remember the two-roles distinction in Section 1: for data uploaded by one of our customers, your request will be routed to that customer as controller.
10. Security
We encrypt data in transit (TLS) and at rest, apply application-level encryption to mailbox credentials and webhook secrets, hash passwords with a modern algorithm, scope every query to its workspace, log administrative access, and restrict production access to personnel who need it. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authorities as the law requires (including within 72 hours under GDPR where feasible).
11. Children
The Service is for business use and not directed to anyone under 16. We do not knowingly collect data from children; if you believe we have, contact [email protected] and we will delete it.
12. Changes and contact
We will post any changes to this policy here and update the date above; material changes will be announced by email or in-app notice at least 14 days before they take effect. Contact: [email protected], or SendCanyon, Inc., [registered address to be inserted before launch]. EU/UK representatives, where required, will be listed here once appointed.
Send from your own domains. Follow the law where your recipients live.