Subprocessors
KAPTIVA SOLUTIONS LLC uses the third parties below to process personal data on our behalf in providing mailQA. Each is bound by a contract that limits it to our instructions, requires it to keep the data confidential and secure, and, where data leaves the EEA, the United Kingdom or Switzerland, includes the transfer safeguards described in the Privacy Policy.
Current subprocessors
| Provider | What it does for mailQA | Data involved | Location |
|---|---|---|---|
| Stripe, Inc. | Payments, subscriptions, invoices and the billing portal | Name, email address, billing address and payment details, entered directly with Stripe; subscription status | United States |
| Resend | Sends our transactional email: verification, password resets, invitations | The recipient's email address and the contents of those emails | United States |
| Plausible Insights OÜ | Website traffic analytics | The page visited, the referrer, and the browser type and country of the visitor. No cookies; the IP address is not stored. | Estonia (EU) |
| Google LLC | Measures which of our ads lead to a subscription (Google Ads conversion tracking) | That a subscription started, what it bills, and a SHA-256 hash of the billing email address — hashed in the visitor's browser, so the address itself is never sent. Nothing is sent from the EEA, the United Kingdom or Switzerland. | United States |
| LinkedIn (LinkedIn Ireland Unlimited Company in the EEA, the United Kingdom and Switzerland; LinkedIn Corporation elsewhere) | Measures which of our ads lead to a signup or a subscription (LinkedIn Conversions API) | That an account was created, or that a subscription started and what it bills; when; and a SHA-256 hash of the account's or the billing email address — hashed on our server, so the address itself is never sent. Sent from our server for every signup and subscription, wherever the visitor is; no LinkedIn script or cookie on our pages. | Ireland (EU) and United States |
| Sentry (Functional Software, Inc.) | Error reporting | Technical details of a failed request: stack trace, request path, user and organization identifiers. Credentials and message contents are removed before a report is sent. | United States |
| PostHog, Inc. | Session replay and usage analytics for the dashboard | Which pages were visited and where the visitor clicked and scrolled, as a recording of the page's layout. Every piece of text, every field and every attribute that could hold text is masked in the browser before anything is sent, and the pane that shows a message is left out entirely, so a recording never contains mail. A signed-in session carries the user and organization identifiers, never the email address or name. Nothing is stored in the visitor's browser. | United States |
Infrastructure
The Service — its servers, database, the object store holding raw messages and attachments, and the database backups — runs on infrastructure leased from a cloud hosting provider. Every kind of Service data is held there, encrypted in transit. The provider's identity and the region of the data centre are available on request at legal@mailqa.io, and this page is updated when either changes.
Changes to this list
We update this page when we add or replace a subprocessor. Where a new subprocessor will handle Customer Content, we will announce it at least 14 days before it starts, by email to organization owners or in the dashboard, so that you can raise an objection with us at legal@mailqa.io. If we cannot resolve a reasonable objection, you may cancel your subscription and receive a pro-rata refund of any prepaid fees for the period after cancellation.