MailMaker collects the information needed to operate and secure your workspace, process credits, run and reconcile provider tasks, and support you. Account results can contain sensitive credentials: retrieve them into a controlled destination, limit access, and remove copies when the approved purpose ends.
Scope of this policy
This Privacy Policy explains how MailMaker handles personal information when you visit MailMaker.io, create or use a workspace, purchase credits, submit account-creation tasks, use an API key, retrieve results, or contact support.
This policy covers information processed by MailMaker as the operator of the service. It does not replace the privacy terms of Gmail, Yahoo, Outlook, Proton, iCloud, payment processors, or other third-party services you choose to use with MailMaker.
Information you provide
We receive information you enter or submit to the service, including your name, email address, authentication details, organization or workspace information, support messages, task configuration, provider choice, quantity, and other fields required to operate an order.
When you purchase credits, payment information may be collected and processed by a payment provider. MailMaker may receive transaction identifiers, payment status, amount, currency, billing contact details, and limited fraud-prevention information, but payment-card handling depends on the checkout provider in use.
- Registration and workspace information
- Order and provider-task configuration
- Billing and transaction records
- Support and account-security communications
- Preferences and feedback you choose to provide
Task, API, and result data
MailMaker processes task identifiers, provider, requested quantity, timestamps, state changes, successful and failed counts, credit estimates and charges, error categories, API request metadata, and result-retrieval events to provide and reconcile the service.
Completed account results may include sensitive account credentials or recovery information. We process this data to deliver the requested service and make results available to the authorized workspace. You are responsible for retrieving results into an appropriate destination, restricting access, and deleting copies that are no longer required.
Do not send raw credentials through support email or place them in free-text fields unless a secure support process explicitly requests the minimum information necessary to resolve an issue.
Information collected automatically
When you use the website or application, systems may record IP address, browser and device information, operating system, referring page, pages or routes visited, timestamps, session events, request identifiers, authentication events, API usage, error logs, and security signals.
MailMaker may use essential cookies, local storage, or similar technologies to maintain login state, remember security or interface settings, prevent abuse, and keep the service functioning. Any non-essential analytics or measurement technology should be described through the interface or consent mechanism where required.
How information is used
We use information to operate the website and workspace, authenticate users, process purchases, estimate and reconcile credits, submit and monitor tasks, deliver results, provide support, investigate errors, prevent abuse, protect accounts, and comply with legal obligations.
We may also use task and product-usage information to understand reliability, improve workflows, plan capacity, and develop features. Where practical, product analysis should use aggregated or minimized records rather than raw account credentials.
- Provide and secure the service
- Process payments and maintain credit ledgers
- Operate, monitor, and reconcile tasks
- Respond to support and security requests
- Detect fraud, abuse, and policy violations
- Improve reliability and product experience
- Meet legal, accounting, and compliance obligations
Legal bases and your choices
Depending on your location, MailMaker may process personal information because it is necessary to perform a contract with you, because you have given consent, because processing is required by law, or because there is a legitimate interest in operating, securing, supporting, and improving the service that is not overridden by your rights.
You can choose not to provide optional information. Some registration, payment, task, and security information is necessary to create a workspace or deliver the requested service. You may also control certain browser storage through your browser, although disabling essential storage can prevent login or other features from working.
Retention and deletion
Retention depends on the category of information, the reason it was collected, security and fraud-prevention needs, billing and accounting obligations, unresolved disputes, and applicable law. Account and transaction records may be kept longer than transient technical logs or result files.
MailMaker aims to retain personal information only as long as reasonably necessary for the applicable purpose, then delete, de-identify, or restrict it. Backup copies may remain for a limited period before being overwritten. Security records may be retained when needed to investigate abuse or protect the service.
Customers control the copies they download, export, transmit to integrations, or store outside MailMaker. Deleting data from MailMaker does not remove copies already transferred to a customer-controlled system or a third party.
Security
MailMaker uses technical and organizational safeguards intended to protect information against unauthorized access, alteration, disclosure, and loss. Safeguards may include access controls, authentication, encryption in transit, monitoring, credential separation, and operational review.
No internet service or storage system can guarantee absolute security. Use a unique password, protect API keys, restrict result access, rotate exposed credentials, and notify hello@mailmaker.io promptly if you suspect unauthorized workspace activity or data exposure.
International processing
MailMaker, its infrastructure, and its service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws.
Where required, MailMaker will use an appropriate legal mechanism or contractual safeguard for cross-border transfers. You remain responsible for determining whether your use of third-party provider accounts or exported result data creates additional localization or transfer obligations for your organization.
Privacy rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, or to withdraw consent. You may also have a right to complain to a data-protection authority.
To make a request, email hello@mailmaker.io from the address associated with your workspace and describe the request. MailMaker may need to verify identity and authority before acting. Some information may be retained when required for security, fraud prevention, legal claims, accounting, or other lawful reasons.
Children's privacy
MailMaker is a business-oriented service and is not directed to children. You must be at least 18 years old to create an account or use the service. If you believe a child has provided personal information to MailMaker, contact hello@mailmaker.io so the situation can be reviewed.
Policy changes and contact
MailMaker may update this Privacy Policy as the service, providers, infrastructure, or legal requirements change. The updated date will appear at the top of the page. Material changes will be communicated through reasonable channels when required.
Questions, security reports, and privacy requests can be sent to hello@mailmaker.io. Include enough information to identify the relevant workspace or transaction, but do not include passwords, API secrets, recovery data, or exported credentials.