Legal
Privacy Policy
The short version: we collect the minimum an email API needs to work, we never store your email bodies after sending, and we never sell data to anyone. The details follow.
1. Who we are
PennyPost is operated by Pockadot LLC, a limited liability company organized in the State of Washington, USA. For anything privacy-related, write to dev@pockadot.com.
We handle data in two roles. For our customers' account data, we decide how it is used. For the recipient data our customers send through the API, we process it on the customer's behalf: the customer decides who gets emailed and why.
2. What we collect
Account data (about you, our customer)
- Your email address and sign-in identifiers.
- Billing details, handled by Stripe. We never see or store your full card number.
- Your sending domains and their verification status.
Sending data (processed on your behalf)
- Recipient email addresses and message metadata: subjects, message IDs, timestamps, and delivery events (delivered, bounced, complained, suppressed).
- Email content is not stored after sending. Message bodies pass through our systems to be delivered and are never written to storage.
Website
This website sets no advertising or tracking cookies. The customer dashboard uses only the strictly necessary cookies required to keep you signed in.
3. Why we collect it
- To run the service: deliver your email, show you logs, manage suppressions.
- To protect deliverability: monitor bounce and complaint rates and enforce our acceptable use policy, with reasons always given.
- To bill you: meter usage and process subscription payments.
- To meet legal obligations and respond to lawful requests.
We do not sell personal data, and we do not use your data or your recipients' data for advertising.
4. How long we keep it
| Data | Retention |
|---|---|
| Email bodies | Never stored. Processed in transit only. |
| Delivery logs and events | 30 days, then deleted. |
| Aggregate statistics (counts and rates, no personal data) | Kept indefinitely to operate the service. |
| Suppression list entries | Kept while your account is active, so we never re-email someone who bounced or complained. |
| Account and billing records | Life of the account, plus what tax and accounting law requires. |
5. Subprocessors
We use two third-party processors to run PennyPost:
- Amazon Web Services (AWS): infrastructure and email delivery via Amazon SES, in the US East (N. Virginia) region, us-east-1. Data is processed in the United States.
- Stripe: payment processing and subscription billing.
We share data with them only as needed to provide the service. We will update this list here before adding a subprocessor.
6. Your rights
You can ask us what data we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Send data requests to dev@pockadot.com and we will respond promptly.
If you received an email sent through PennyPost, the sender controls their recipient list, so start with the unsubscribe link or the sender. If a sender is abusing the service, report it to us at dev@pockadot.com; cold email and purchased lists are banned here, and reports have consequences.
7. Security
Data is encrypted in transit, access is restricted to what operating the service requires, and API keys are stored hashed. No provider can promise perfect security, so if a breach ever affects your data we will notify you without undue delay.
8. Changes to this policy
The current version always lives at this page, with its effective date at the top. For material changes we will notify account holders by email before the change takes effect.
9. Contact
Privacy questions and data requests: dev@pockadot.com.