Legal

Privacy Policy

Last updated: August 7, 2026

This policy explains what personal data SendCanyon, Inc. ("SendCanyon", "we", "us") collects, why we collect it, who we share it with, and the choices and rights you have. It covers our website, application, and APIs (together, the "Service"). Questions to privacy@sendcanyon.com.

1. Our two roles: controller and processor

SendCanyon handles personal data in two distinct capacities, and your rights differ depending on which applies.

  • As a controller for data about our own users and site visitors — your account details, billing information, usage of the Service, and communications with us. This policy governs that data directly.
  • As a processor for data our customers upload — the contacts, email addresses, and message content a workspace imports and sends through the Service. For that data, the customer (the workspace owner) is the controller, we process it only on their instructions under our Data Processing Addendum, and requests concerning it should go to the customer who uploaded it. If you contact us directly about data a customer holds, we will forward your request to them and support their response.

2. Data we collect

Data you provide

  • Account data: name, email address, password (stored hashed), workspace name, and role.
  • Billing data: plan, billing address, and tax ID where applicable. Card details go directly to our payment processor (Stripe) and never touch our servers.
  • Connected mailbox credentials: OAuth tokens or SMTP/IMAP credentials for mailboxes you connect. These are encrypted at rest and decrypted only in memory at send time.
  • Customer content (as processor): contact lists, custom fields, email templates, sequences, and the content of messages sent and received through connected mailboxes.
  • Communications: support requests, feedback, and survey responses.

Data collected automatically

  • Usage data: pages viewed, features used, actions taken (e.g. campaign launched), timestamps, and API request metadata.
  • Device data: IP address, browser type, operating system, and screen dimensions.
  • Email event data: delivery, bounce, open, click, reply, and unsubscribe events for messages sent through the Service.
  • Cookies: see Section 8.

3. Why we process it (and our legal bases)

PurposeExamplesLegal basis (GDPR)
Providing the ServiceAuthentication, sending campaigns, warmup, analyticsContract performance
BillingSubscriptions, invoices, tax complianceContract performance; legal obligation
Security & abuse preventionFraud detection, rate limiting, enforcing our Acceptable Use PolicyLegitimate interests
Service communicationsVerification emails, DNS alerts, warmup completion, limit warningsContract performance
Product improvementAggregated feature-usage analysis, debuggingLegitimate interests
Marketing to youProduct updates and newsletters (opt-out any time)Consent / legitimate interests
Legal complianceResponding to lawful requests, tax and accounting recordsLegal obligation

We do not sell personal data, and we do not use customer content (your contacts or message bodies) for advertising or to train generalized models.

4. Who we share data with

We share personal data only with service providers who process it for us under contract (subprocessors), with parties you direct us to share with (e.g. your connected email provider), in a corporate transaction with notice, or where the law requires it. Our current subprocessors:

SubprocessorPurposeLocation
Hostinger International Ltd.Infrastructure hosting (application, database, queue)Customer-selected region
Amazon Web Services (SES)Email delivery for customers who connect SESCustomer-selected region
Stripe, Inc.Payment processing and invoicingUnited States
Google LLCMailbox connectivity for Gmail/Google Workspace sendersUnited States / global
Microsoft CorporationMailbox connectivity for Microsoft 365 sendersUnited States / global
OpenAI, L.L.C.AI writing-assistance features (prompt content only, on request)United States
Postmark (ActiveCampaign, LLC)Transactional system emails (verification, alerts)United States

We update this table when subprocessors change and, for customers with a DPA, provide advance notice of additions with a right to object.

5. International transfers

Where personal data originating in the EEA, UK, or Switzerland is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with the receiving party, together with technical measures including encryption in transit and at rest. A copy of the relevant clauses is available on request to privacy@sendcanyon.com.

6. Retention

  • Account data: kept while your account is active and deleted or anonymized within 90 days of account closure, except where law requires longer (e.g. invoices for tax purposes, typically 7–10 years).
  • Customer content: kept while the workspace is active; deleted within 90 days of workspace deletion. Workspace owners can delete contacts, campaigns, and messages at any time from the dashboard or API.
  • Suppression records: retained even after related contact records are deleted, because they exist to prevent future unwanted email — deleting them would defeat their purpose.
  • Email event data: retained for the life of the workspace for analytics and deliverability protection.
  • Backups: encrypted backups roll off within 35 days of deletion from production.

7. Your rights (GDPR, CCPA, and similar laws)

Depending on where you live, you may have the right to access, correct, delete, export (data portability), restrict or object to processing of your personal data, withdraw consent, and lodge a complaint with a supervisory authority. California residents additionally have the right to know what categories of personal information we collect and disclose, the right to deletion and correction, and the right not to be discriminated against for exercising these rights — and because we do not sell or share personal information as defined by the CCPA/CPRA, there is nothing to opt out of.

To exercise any right, email privacy@sendcanyon.com from the address associated with your account (or provide equivalent verification). We respond within 30 days (GDPR) or 45 days (CCPA). Remember the two-roles distinction in Section 1: for data uploaded by one of our customers, your request will be routed to that customer as controller.

8. Cookies

The application uses strictly necessary cookies only: a session cookie for authentication and a CSRF token. The marketing site uses no third-party advertising or cross-site tracking cookies. If we ever add analytics cookies that require consent, we will ask first rather than assume.

9. Security

We encrypt data in transit (TLS) and at rest, apply application-level encryption to mailbox credentials and webhook secrets, hash passwords with a modern algorithm, scope every query to its workspace, log administrative access, and restrict production access to personnel who need it. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authorities as the law requires (including within 72 hours under GDPR where feasible).

10. Children

The Service is for business use and not directed to anyone under 16. We do not knowingly collect data from children; if you believe we have, contact privacy@sendcanyon.com and we will delete it.

11. Changes and contact

We will post any changes to this policy here and update the date above; material changes will be announced by email or in-app notice at least 14 days before they take effect. Contact: privacy@sendcanyon.com, or SendCanyon, Inc., [registered address to be inserted before launch]. EU/UK representatives, where required, will be listed here once appointed.