Privacy Policy

Last updated 30 August 2026

This policy explains what MyNewsletter does with two different kinds of data: information about you as a customer, and the contact data you upload to send campaigns. They are treated differently, and the distinction matters.

1. Who we are

MyNewsletter provides email campaign software. For the contact data you upload we act as a processor — you decide what is collected and why, and we process it on your instructions. For your own account details we act as a controller.

Questions about this policy go to hello@mynewsletter.com.

2. Data we collect about you

  • Account details: your name, email address, and a hashed password. We never store your password in a readable form.
  • Configuration: sender identity, sending limits, and the domains you send from.
  • Billing details, handled by our payment provider. We do not see or store full card numbers.
  • Operational logs: sign-in times and error records, kept so we can debug and secure the service.

3. Contact data you upload

When you import a CSV, the contact records in it are stored so campaigns can be sent and measured. You remain responsible for having a lawful basis to hold and email those people.

  • We do not sell, rent, share or license your contact data to anyone.
  • We do not email your contacts on our own behalf, ever.
  • We do not use your contact data to train models or build any cross-customer product.
  • Contact data is only accessed by staff when you ask us for support, or where access is strictly necessary to keep the service running.

4. Tracking inside the emails you send

If you enable open or click tracking, campaigns you send will include a tracking pixel and rewritten links. That records opens, clicks, the approximate time, and the requesting user agent and IP address.

This tracking is yours, applied to your campaigns, and the resulting events are stored against your account. You can switch either off per campaign. Where your recipients are in a jurisdiction that requires consent for this, obtaining it is your responsibility.

5. Subprocessors

We use a small number of third parties to run the service. Each is bound by contract to protect the data they handle:

  • Zoho ZeptoMail — delivering the emails you send.
  • Amazon Web Services — database and application hosting.
  • A payment provider — subscription billing.

On self-hosted deployments you run the infrastructure and choose your own providers, so this list does not apply.

6. Where data is stored and for how long

Data is stored in the region of the database you or we provision. Contact data and campaign events are retained for as long as your account is active. On cancellation, data is deleted within 30 days unless you ask us to remove it sooner or the law requires us to keep it longer.

Suppression records — addresses that unsubscribed, bounced or reported spam — are retained after deletion of the underlying contact, because keeping them is what stops that person being emailed again by mistake.

7. Security

  • All traffic is encrypted in transit with TLS.
  • Passwords are hashed with scrypt and a per-user salt.
  • Sessions use signed, HTTP-only cookies.
  • Database access is restricted to the application, over an encrypted connection.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to processing, or to complain to a supervisory authority. Email us and we will action it.

If one of your contacts exercises those rights, they should contact you directly, since you are the controller of that data. We will help you respond.

9. Changes

If we make a material change to this policy, we will tell you by email before it takes effect. The date at the top always reflects the current version.