Privacy policy

Effective date: July 2026 • Transparent Data Processor & Privacy Standards

At MailBlaster, protecting user confidentiality and recipient database integrity is fundamental to our architecture. This privacy policy explains what information we collect, how we interact with trusted sub-processors, data retention limits, and your explicit privacy rights.

Personal account and workspace data collected

When you create a MailBlaster tenant workspace, we collect essential registration and billing identifier details necessary to provision your account and verify institutional identity:

  • Profile & identifier details: Your full name, work email address, phone number with country code, business or physical street address, and organization workspace name.
  • Media assets: Custom avatar photos or corporate brand logo images uploaded to customize your sender settings.
  • System telemetry & access logs: Standard timestamped login IP records, API execution logs, and verification status history required to maintain account security and prevent unauthorized access.

Uploaded contact lists and customer data protection

Strict Data Processor Guarantee: Your Lists Belong Solely to You

We maintain an explicit, unconditional distinction between our SaaS operational records and your uploaded recipient contact databases. Every subscriber email address, name, custom field, tag, or CSV file uploaded into MailBlaster constitutes Customer Data.

MailBlaster functions purely as a Data Processor acting strictly on your instructions to format, queue, and dispatch your broadcast email campaigns. We will NEVER mine, sell, share, rent, monetize, or send external promotional marketing to your uploaded contact lists. Your recipient data is processed exclusively on your behalf.

Third-party processors and infrastructure integrations

To provide high-reliability broadcast infrastructure, MailBlaster transmits specific operational payloads to vetted third-party sub-processors under rigorous confidentiality agreements:

Resend Email Delivery

Recipient email addresses, message headers, and body HTML are transmitted over secure TLS to Resend solely for high-deliverability transport, SMTP authentication, and bounce/open diagnostic tracking.

Stripe & PayPal Payments

Subscription upgrades are tokenized and handled entirely within secure PCI-DSS compliant environments at Stripe and PayPal. MailBlaster never stores complete credit card numbers locally.

Data retention periods and database purging

We retain your user profile, active domain configurations, and contact lists for the active duration of your MailBlaster subscription so you can analyze campaign analytics and retain sender reputation history:

  • Active accounts: Contact lists and broadcast engagement stats are preserved until explicitly deleted by you in your dashboard.
  • Cancelled or closed accounts: When you voluntarily close your workspace, subscriber databases and uploaded contact CSV files are scheduled for automatic, unrecoverable system deletion within 30 days.
  • Encrypted backups: Routine system-wide security snapshots rotate on a fixed 60-day cycle, ensuring deleted records are fully cleared across all archival storage.

User rights to access, export, and delete data

In alignment with international data sovereignty frameworks (including GDPR, UK DPA, and California CCPA), you maintain complete authority over your personal identifiers and subscriber repositories:

Access and Data Portability: You can download and export all your contacts, subscriber files, and broadcast performance reports directly from your workspace dashboard at any time in industry-standard CSV formats.

Right to Erasure (Account Deletion): You hold the immediate right to request total account erasure and workspace purging directly through your profile Settings tab or by contacting our data protection staff.

Cookie usage and authentication tokens

MailBlaster utilizes minimal, strictly necessary functional web cookies and security tokens to operate our web interface reliably:

  • Session & security tokens: We deploy NextAuth session cookies to verify authenticated dashboard logins and prevent cross-site request forgery (CSRF).
  • Anti-bot protection: We utilize Cloudflare Turnstile human verification tokens during registration to protect our platform from automated spam bot registrations.
  • Zero advertising cookies: We do NOT embed third-party advertising network tracking cookies, behavioral profiling trackers, or retargeting ad scripts across our application.

© 2026 MailBlaster Platform. All rights reserved.