Privacy Policy
Last updated: June 14, 2026
Sendaloft ("we," "our," or "us") is an email deliverability platform that helps you send emails that land in the Primary inbox. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service at sendaloft.com.
1. Information We Collect
Account Information
When you create a Sendaloft account, we collect your name, email address, and a hashed version of your password. We never store passwords in plain text.
SMTP Credentials
To send emails on your behalf, we collect your SMTP server credentials (host, port, username, and password). SMTP passwords are encrypted at rest using AES-256-GCM encryption and are only decrypted momentarily during the email sending process. We never log, export, or share your SMTP credentials.
Email Content & Metadata
We store the emails you compose and send through Sendaloft, including recipients, subject lines, body content, and sending timestamps. This data is associated with your account and used to provide the service, including delivery tracking and analytics.
Tracking Data
When you send an email through Sendaloft, we may embed a tracking pixel and rewrite links to track opens and clicks. We collect the timestamp and general event type (open or click) for each tracked interaction. We do not collect the recipient's IP address, browser fingerprint, or geolocation.
Usage Data
We automatically collect basic usage data such as pages visited within the application, feature usage patterns, and error logs. This data helps us improve the service and troubleshoot issues.
2. How We Use Your Information
We use the information we collect for the following purposes:
Providing the Service: Sending emails through your connected SMTP accounts, tracking delivery and engagement metrics, performing inbox placement tests, and monitoring DNS health for your sending domains.
Account Management: Authenticating your identity, managing your subscription, and communicating with you about your account, including service updates and security notices.
Service Improvement: Analyzing aggregate usage patterns to improve our deliverability algorithms, user interface, and overall product experience. We do not use your email content to train machine learning models.
Security: Detecting and preventing fraud, abuse, and unauthorized access to the service.
3. Data Storage & Security
Your data is stored on servers provided by Vercel (application hosting) and Neon (PostgreSQL database), both of which maintain SOC 2 Type II compliance. All data is encrypted in transit using TLS 1.2+ and sensitive fields (SMTP passwords) are encrypted at rest using AES-256-GCM.
We implement industry-standard security measures including secure password hashing with bcrypt (12 rounds), HTTPS-only access, server-side session management with signed JWTs, and environment-level access controls for sensitive configuration.
While we take reasonable precautions to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
4. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes.
We share data only with the infrastructure providers necessary to operate the service:
Infrastructure Providers
Vercel (hosting and serverless functions), Neon (database), and your configured SMTP provider (to send emails on your behalf). These providers process data solely to deliver their services and are bound by their own privacy policies.
Legal Requirements
We may disclose your information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Email Recipient Privacy
Sendaloft processes the email addresses and names of the people you send emails to. We treat recipient data with the same care as your own personal data.
We do not use recipient email addresses or data for any purpose other than delivering your emails, tracking engagement you have opted into, and performing inbox placement tests you initiate.
We do not build recipient profiles, sell recipient lists, or send any communications to your recipients on our own behalf.
You are responsible for ensuring you have the appropriate consent or legal basis to email the recipients you add to Sendaloft, in compliance with applicable laws such as CAN-SPAM, GDPR, and CASL.
6. Data Retention
We retain your account data, sent emails, and tracking data for as long as your account is active. If you delete your account, we will delete your personal data, SMTP credentials, and email content within 30 days. Some anonymized, aggregate data (such as total emails sent across all users) may be retained indefinitely for analytics.
Server logs containing IP addresses and request metadata are retained for up to 90 days for security and debugging purposes, after which they are automatically purged.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access & Portability
You can request a copy of your personal data at any time by contacting us. We will provide your data in a structured, machine-readable format within 30 days.
Correction
You can update your account information (name, email) directly within the application. For other corrections, contact us.
Deletion
You can request deletion of your account and all associated data by contacting us at team@sendaloft.com. We will process your request within 30 days.
Objection & Restriction
You can object to certain processing activities or request that we restrict processing of your data. We will honor valid requests unless we have a compelling legitimate interest.
8. Cookies & Local Storage
Sendaloft uses a session cookie to keep you signed in. This is a strictly necessary cookie required for the service to function. We do not use advertising cookies, third-party tracking cookies, or analytics cookies.
We may use browser local storage to save user interface preferences (such as sidebar state). This data never leaves your browser.
9. Children's Privacy
Sendaloft is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
10. International Data Transfers
Sendaloft is operated from the United States. If you access the service from outside the US, your data will be transferred to and processed in the United States. By using the service, you consent to this transfer. We rely on our infrastructure providers' data processing agreements and standard contractual clauses to ensure adequate data protection for international transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice within the application at least 14 days before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.
12. Contact
If you have questions about this Privacy Policy or wish to exercise any of your data rights, contact us at team@sendaloft.com or through our contact form at sendaloft.com/contact.