Legal
Privacy Policy
Last updated: August 7, 2026
This policy explains what personal data SendCanyon, Inc. ("SendCanyon", "we", "us") collects, why we collect it, who we share it with, and the choices and rights you have. It covers our website, application, and APIs (together, the "Service"). Questions to privacy@sendcanyon.com.
1. Our two roles: controller and processor
SendCanyon handles personal data in two distinct capacities, and your rights differ depending on which applies.
- As a controller for data about our own users and site visitors — your account details, billing information, usage of the Service, and communications with us. This policy governs that data directly.
- As a processor for data our customers upload — the contacts, email addresses, and message content a workspace imports and sends through the Service. For that data, the customer (the workspace owner) is the controller, we process it only on their instructions under our Data Processing Addendum, and requests concerning it should go to the customer who uploaded it. If you contact us directly about data a customer holds, we will forward your request to them and support their response.
2. Data we collect
Data you provide
- Account data: name, email address, password (stored hashed), workspace name, and role.
- Billing data: plan, billing address, and tax ID where applicable. Card details go directly to our payment processor (Stripe) and never touch our servers.
- Connected mailbox credentials: OAuth tokens or SMTP/IMAP credentials for mailboxes you connect. These are encrypted at rest and decrypted only in memory at send time.
- Customer content (as processor): contact lists, custom fields, email templates, sequences, and the content of messages sent and received through connected mailboxes.
- Communications: support requests, feedback, and survey responses.
Data collected automatically
- Usage data: pages viewed, features used, actions taken (e.g. campaign launched), timestamps, and API request metadata.
- Device data: IP address, browser type, operating system, and screen dimensions.
- Email event data: delivery, bounce, open, click, reply, and unsubscribe events for messages sent through the Service.
- Cookies: see Section 8.
3. Why we process it (and our legal bases)
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Providing the Service | Authentication, sending campaigns, warmup, analytics | Contract performance |
| Billing | Subscriptions, invoices, tax compliance | Contract performance; legal obligation |
| Security & abuse prevention | Fraud detection, rate limiting, enforcing our Acceptable Use Policy | Legitimate interests |
| Service communications | Verification emails, DNS alerts, warmup completion, limit warnings | Contract performance |
| Product improvement | Aggregated feature-usage analysis, debugging | Legitimate interests |
| Marketing to you | Product updates and newsletters (opt-out any time) | Consent / legitimate interests |
| Legal compliance | Responding to lawful requests, tax and accounting records | Legal obligation |
We do not sell personal data, and we do not use customer content (your contacts or message bodies) for advertising or to train generalized models.
4. Who we share data with
We share personal data only with service providers who process it for us under contract (subprocessors), with parties you direct us to share with (e.g. your connected email provider), in a corporate transaction with notice, or where the law requires it. Our current subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Infrastructure hosting (application, database, queue) | Customer-selected region |
| Amazon Web Services (SES) | Email delivery for customers who connect SES | Customer-selected region |
| Stripe, Inc. | Payment processing and invoicing | United States |
| Google LLC | Mailbox connectivity for Gmail/Google Workspace senders | United States / global |
| Microsoft Corporation | Mailbox connectivity for Microsoft 365 senders | United States / global |
| OpenAI, L.L.C. | AI writing-assistance features (prompt content only, on request) | United States |
| Postmark (ActiveCampaign, LLC) | Transactional system emails (verification, alerts) | United States |
We update this table when subprocessors change and, for customers with a DPA, provide advance notice of additions with a right to object.
5. International transfers
Where personal data originating in the EEA, UK, or Switzerland is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with the receiving party, together with technical measures including encryption in transit and at rest. A copy of the relevant clauses is available on request to privacy@sendcanyon.com.
6. Retention
- Account data: kept while your account is active and deleted or anonymized within 90 days of account closure, except where law requires longer (e.g. invoices for tax purposes, typically 7–10 years).
- Customer content: kept while the workspace is active; deleted within 90 days of workspace deletion. Workspace owners can delete contacts, campaigns, and messages at any time from the dashboard or API.
- Suppression records: retained even after related contact records are deleted, because they exist to prevent future unwanted email — deleting them would defeat their purpose.
- Email event data: retained for the life of the workspace for analytics and deliverability protection.
- Backups: encrypted backups roll off within 35 days of deletion from production.
7. Your rights (GDPR, CCPA, and similar laws)
Depending on where you live, you may have the right to access, correct, delete, export (data portability), restrict or object to processing of your personal data, withdraw consent, and lodge a complaint with a supervisory authority. California residents additionally have the right to know what categories of personal information we collect and disclose, the right to deletion and correction, and the right not to be discriminated against for exercising these rights — and because we do not sell or share personal information as defined by the CCPA/CPRA, there is nothing to opt out of.
To exercise any right, email privacy@sendcanyon.com from the address associated with your account (or provide equivalent verification). We respond within 30 days (GDPR) or 45 days (CCPA). Remember the two-roles distinction in Section 1: for data uploaded by one of our customers, your request will be routed to that customer as controller.
8. Cookies
The application uses strictly necessary cookies only: a session cookie for authentication and a CSRF token. The marketing site uses no third-party advertising or cross-site tracking cookies. If we ever add analytics cookies that require consent, we will ask first rather than assume.
9. Security
We encrypt data in transit (TLS) and at rest, apply application-level encryption to mailbox credentials and webhook secrets, hash passwords with a modern algorithm, scope every query to its workspace, log administrative access, and restrict production access to personnel who need it. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authorities as the law requires (including within 72 hours under GDPR where feasible).
10. Children
The Service is for business use and not directed to anyone under 16. We do not knowingly collect data from children; if you believe we have, contact privacy@sendcanyon.com and we will delete it.
11. Changes and contact
We will post any changes to this policy here and update the date above; material changes will be announced by email or in-app notice at least 14 days before they take effect. Contact: privacy@sendcanyon.com, or SendCanyon, Inc., [registered address to be inserted before launch]. EU/UK representatives, where required, will be listed here once appointed.