Privacy Policy
This policy explains what personal data KAPTIVA SOLUTIONS LLC ("KAPTIVA", "we", "us") collects
when you use mailQA — the website at mailqa.io, the dashboard, the SMTP listeners, the REST API
and the @mailqa/client SDK (together, the "Service") — why we collect it, whom we share it
with, and the rights you have over it.
Two kinds of data
mailQA handles data in two different roles, and the difference matters for whom to ask about it.
- Account data is what we collect about you and your organization in order to run the Service. For account data we are the data controller: we decide why and how it is processed, and this policy describes that.
- Customer Content is the email your application sends to mailQA, and everything in it. Your organization decides what to send to mailQA, so for Customer Content we act as a processor on your organization's instructions, and your organization is responsible for having a lawful basis to capture it. If you are an individual whose email ended up in a mailQA inbox, the organization running the test is the controller of that data. Contact them first; we will assist them with your request.
Account data we collect
| Data | Source | Why we collect it |
|---|---|---|
| Name, email address and password | You, at signup or when you accept an invitation | To identify you, sign you in and send you account email: verification, password resets, invitations. Passwords are stored only as a salted hash. |
| Organization name and subdomain, plan and limits, members and their roles | You, at signup and in settings | To operate your organization and route mail to its inboxes |
| SMTP credentials and API keys | Generated by the Service | To authenticate your application. API keys are stored hashed. The SMTP password is stored encrypted so the dashboard can show it to you again. |
| Billing status: Stripe customer and subscription identifiers, plan, subscription state, renewal date | Stripe, after checkout | To know which plan applies and whether the subscription is active. We never receive or store card numbers. Payment details are entered on pages hosted by Stripe. |
| Usage counters: messages received this month, inbox counts | The Service | To enforce plan limits and show usage in the dashboard |
| Technical data: IP address, user agent, request path, timestamps, error reports | Your browser or client, automatically | Security, rate limiting, abuse prevention and debugging |
| Dashboard usage: pages visited, clicks and scrolling, and a recording of the page's layout with every piece of text masked | Your browser, automatically, while you use mailqa.io | To find and fix the places where the dashboard is confusing or broken. How the recording is masked is described under Cookies and local storage, below. |
| Support correspondence | You, when you write to us | To answer you |
Customer Content
When mail reaches mailQA we store the raw message and parse it: sender and recipients, subject, plain-text and HTML bodies, headers, attachments, links and verification codes extracted from the body, and the SPF, DKIM and DMARC results. All of it is visible to every member of your organization, and through the API to anyone holding one of its API keys.
We use Customer Content only to provide the Service: to store it, parse it, index it for search, render it safely in the dashboard and return it through the API. We do not use it for advertising, analytics or product research, we do not use it to train any model, and we do not share it with anyone except the infrastructure providers that store it on our behalf (see Subprocessors). Recordings of dashboard sessions never contain it: the pane that shows a message is left out of the recording, and every other piece of text on the page is masked before anything leaves your browser (see PostHog, under Cookies and local storage). Our staff open it only to resolve a support request you raise, to investigate suspected abuse or a security incident, or where the law requires.
Customer Content is retained for your plan's retention window — between 7 and 90 days, as shown on the pricing page — and then deleted automatically, attachments and raw source included. You can delete a message, empty an inbox or delete an inbox sooner, and those deletions are permanent.
Mail addressed to real people. The SMTP sink captures every message your application hands it, including mail addressed to real users if you point a staging or production environment at it, and that mail may contain their personal data. Sending it to mailQA is your organization's decision, and your organization is responsible for the notice and lawful basis that decision requires. We recommend using test accounts and synthetic data wherever possible.
How we use account data
- To provide the Service: authenticating you, running your organization, capturing and showing mail, enforcing plan limits.
- To bill you, through Stripe.
- To send transactional email: verification, password resets, invitations, and notices about your account, your subscription or changes to our terms. We do not send marketing email without your consent.
- To keep the Service secure: rate limiting, detecting abuse and unauthorised access, investigating incidents.
- To support you when you contact us.
- To understand how the dashboard is used and to improve it: which pages are visited and where people click, including masked recordings of dashboard sessions as described under Cookies and local storage. Never for advertising.
- To measure which of our ads lead to signups and subscriptions: when you create an account, and when your organization's subscription starts, a SHA-256 hash of an email address is sent to LinkedIn, as described under Whom we share data with.
- To comply with legal obligations and to enforce our terms.
Legal bases
Where data-protection law requires a legal basis for processing (the EEA, the United Kingdom, Switzerland and similar jurisdictions), we rely on:
- Performance of a contract — providing the Service you signed up for, and billing for it.
- Legitimate interests — securing the Service, preventing abuse, keeping it reliable, communicating with you about your account, and measuring which of our advertisements lead to signups and subscriptions. We balance these interests against your rights.
- Legal obligation — keeping tax and accounting records, and responding to lawful requests.
- Consent, where we ask for it. You may withdraw consent at any time.
Whom we share data with
We share personal data only with:
- Service providers that process it on our behalf under contracts that bind them to our instructions and to confidentiality. They are listed, with what each does and where it operates, on the Subprocessors page.
- Your organization. Your name and email address are visible to the other members of any organization you belong to, and its owners and admins can see and remove your membership.
- Authorities, when we are legally required to, or when disclosure is necessary to protect the rights, safety or property of KAPTIVA, our users or the public.
- A successor, if KAPTIVA is involved in a merger, acquisition or sale of assets. This policy continues to apply to the transferred data, and we will notify you of the change.
We do not sell personal data. The only data we share with advertising platforms is the conversion measurement described here and under Cookies and local storage: a hash of an email address, never the address itself, sent so that we can tell which of our ads lead to signups and subscriptions. We do not use it to build advertising audiences.
LinkedIn. We advertise mailQA on LinkedIn, and our server reports two events to LinkedIn's Conversions API. When you create an account — with a password, or with Google or GitHub — it sends a record that an account was created, when, and a SHA-256 hash of its email address. When a subscription starts, the free trial included, it sends a record that a subscription started, when, what the plan bills per period, and a SHA-256 hash of the billing email address. Each address is normalised and hashed on our server, before anything is transmitted: LinkedIn receives only that hash, never the address, and compares it against hashes of the addresses on its members' accounts to tell us whether the signup or subscription followed one of our ads. Nothing else about your account is sent, and nothing about the mail you capture is sent at any point. This applies wherever you are, the EEA, the United Kingdom and Switzerland included. LinkedIn has no script on our pages and sets no cookie. Accounts created by accepting an invitation are not reported. LinkedIn's handling of this data is described in LinkedIn's privacy policy.
International transfers
KAPTIVA is a United States company. Personal data may be processed in the United States and in the countries where our subprocessors operate. Where we transfer personal data out of the EEA, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK addendum where it applies, or on another transfer mechanism the law recognises, together with the safeguards described under Security. A copy of the clauses that apply to your data is available on request at legal@mailqa.io, as is a data processing agreement for customers who need one.
Data retention
| Data | Kept for |
|---|---|
| Customer Content | Your plan's retention window (7 to 90 days), then deleted automatically; sooner if you delete it |
| Account and organization data | For as long as your account exists. To delete your account or organization, email support@mailqa.io from the account's address; we complete deletion within 30 days, except for records we are required to keep. |
| Billing records | For as long as tax and accounting law requires, typically seven years, held by Stripe and in our own records |
| Server logs and error reports | No more than 90 days |
| Database backups | 14 days, after which a backup expires. Data deleted from the live database leaves every backup within that window. |
| Support correspondence | Up to two years after the request is closed |
Security
- Traffic to the website, dashboard and API is encrypted with TLS. The SMTP listeners support STARTTLS, and the submission port requires authentication.
- Passwords are hashed with argon2. API keys, and the one-time tokens in verification, reset and invitation links, are stored as SHA-256 hashes. SMTP passwords are encrypted with AES-256-GCM.
- Every request is scoped to the organization behind its credential. No request can name another organization's data, and an identifier from another organization answers as if it did not exist.
- Rendered email is sanitised on the server and displayed in a sandboxed frame on a separate origin, with remote images blocked, so a captured message cannot run code in the dashboard or reach your session.
- Attachments are served through short-lived signed links.
- Error reports are scrubbed of credentials and message contents before they leave our systems.
- Access to production systems is limited to the people who operate the Service.
If you believe you have found a security vulnerability, email security@mailqa.io. We will acknowledge your report and keep you informed while we address it.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent. You can change your name and password and manage your organization from the dashboard. For anything else, email legal@mailqa.io. We respond within 30 days, or within the period the applicable law sets, and we may need to verify your identity first. You also have the right to complain to the data-protection authority where you live.
California residents. Under the CCPA and CPRA you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, and not to be treated differently for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. Requests go to the address above; you may use an authorised agent.
People whose mail was captured. If your email address appeared in a message captured by a mailQA customer, that customer controls the data. Contact them. If you cannot identify them, contact us and we will help route your request within the limits of our role as a processor.
Cookies and local storage
mailQA uses the storage that is strictly necessary to run the Service, plus an advertising measurement tag, a cookieless analytics script and a session replay script, all described below. It sets no analytics cookies and does not show a cookie banner: the analytics and the replay store nothing in your browser, and in the EEA, the United Kingdom and Switzerland the advertising tag runs without setting any cookie at all.
| Name | Kind | Purpose | Lifetime |
|---|---|---|---|
mailqa_session |
Cookie, strictly necessary | Keeps you signed in to the dashboard. Set only for mailqa.io, marked HttpOnly and Secure. | 30 days, or until you sign out |
mailqa-theme |
Browser local storage | Remembers whether you chose light or dark mode in the dashboard | Until you clear it |
_gcl_au, _gcl_aw |
Cookie, advertising measurement | Set by Google Ads so that a subscription can be attributed to the ad that led to it. Not set in the EEA, the UK or Switzerland. | 90 days |
Google Ads. We advertise mailQA on Google, and every page loads Google's tag (gtag.js) so
that we can tell which ads lead to a subscription. We do not use it for personalised advertising
or remarketing, and we run no analytics on it. In the EEA, the United Kingdom and Switzerland the
tag is loaded with Google's consent mode set to "denied": it sets no cookies, sends no advertising
identifiers, and sends none of the data described in the next paragraph, and Google reports only
aggregate, modelled conversion counts for those regions. Elsewhere it sets the cookies listed
above. Google's handling of this data is described in
Google's own privacy policy.
Enhanced conversions. When a subscription starts, the tag also reports the billing email address recorded for it, so that the subscription can still be matched to the ad that led to it when no cookie is available. The address is normalised and hashed with SHA-256 by the tag, in your browser, before anything is transmitted: Google receives only that hash, never the address, and compares it against hashes of the addresses on its own accounts. Nothing else about your account is sent, and nothing about the mail you capture is sent at any point. As above, none of this happens in the EEA, the United Kingdom or Switzerland, where consent for it is set to "denied".
Plausible Analytics. We count visits with Plausible, hosted in the European Union by Plausible Insights OÜ. It sets no cookies and stores no personal data: it records the page visited, the referrer, and the browser type and country derived from the request. The IP address is used only to count a visitor once per day and is never stored. Plausible's data policy describes the measurement in full.
PostHog. On every page of mailqa.io we record how the page is used — the pages visited, clicks and scrolling, and a recording of the page's layout — with PostHog, Inc., hosted in the United States, so that we can find and fix the places where the dashboard is confusing or broken. The recording is masked in your browser before anything is sent: every piece of text on the page, every field and every attribute that could hold text is replaced with placeholders, images and embedded frames are left out, and the pane that shows a message is left out entirely, so a recording never contains mail, an address, a name or anything you typed. Network activity appears only as request paths with their query strings removed, never their contents, and browser console output is not captured. While you are signed in the recording is linked to your account by its identifier, not by your email address or name; otherwise it is anonymous. PostHog stores nothing in your browser — no cookie and no local storage — so each page load is a new recording. PostHog's own handling of this data is described in PostHog's privacy policy.
Pages hosted by Stripe — checkout and the billing portal — set Stripe's own cookies, which are covered by Stripe's privacy policy.
Children
The Service is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy. Material changes will be announced by email to organization owners or in the dashboard before they take effect. The date at the top of this page identifies the version in force.
Contact
KAPTIVA SOLUTIONS LLC, operator of mailQA.
- Privacy and legal: legal@mailqa.io
- Support and account deletion: support@mailqa.io
- Security reports: security@mailqa.io