SendFable email marketing is live — start writing free. No credit card required.

sendfable

Privacy Policy

Effective date: July 25, 2026
Last updated: July 26, 2026
Document version: 2026-07-26

This Privacy Policy explains how personal information is handled for the SendFable service. SendFable is a service operated by iScream Studio INC ("we," "us"). It is incorporated into our Terms of Service.

1. Roles

  • For contact lists, campaign content, form submissions, and similar Customer Content, we generally act as a service provider / processor. The Customer decides why and to whom campaigns are sent and is responsible for lawful bases and notices to Recipients.
  • For account, billing, security, fraud/abuse, support, and platform operations data, we act as an independent controller / business for our own legitimate operational purposes.

We do not claim that SendFable is automatically subject to every privacy statute (for example GDPR, CCPA/CPRA, or CASL) for every Customer. Rights described below are offered as product practices and may also be required where a statute actually applies.

2. Information we collect

Account and workspace

  • Account information: name, email, password hash (we do not store plaintext passwords)
  • Authentication information: magic-link / verification tokens, session data
  • Workspace and team information: workspace name, roles, invitations, mailing address
  • Billing identifiers and subscription status via Stripe (not full card numbers)
  • Support messages and optional product-interest form submissions
  • Policy-acceptance records (policy versions, timestamp, source; IP and user-agent when collected)

Customer Content

  • Contact-list information you upload or collect (email, name, tags, segments, custom fields, status)
  • Campaign content, templates, sender identities, domain verification information
  • Signup-form and subscriber submissions
  • Uploaded images and files used in campaigns or branding

Usage, device, and security

  • Usage information: sends, quotas, plan enforcement, feature use
  • Device/browser information and logs needed to operate and secure the Service
  • Cookies described in Section 7 and on our Cookie disclosure
  • Open and click events for campaigns you send
  • Unsubscribe, bounce, and complaint events
  • Security and abuse signals (for example flags, holds, rate-limit metadata)

3. Sources

  • Users and Workspace administrators
  • Recipients interacting with campaigns or forms
  • Stripe
  • Amazon SES / AWS (delivery and feedback events)
  • Hosting and infrastructure providers
  • Support communications
  • Automated technical collection (logs, cookies, tracking pixels/links where enabled)

4. Purposes

  • Provide and operate the Service
  • Authenticate users and manage Workspaces
  • Deliver campaigns and process related events
  • Process billing and enforce plan limits
  • Provide campaign analytics (opens/clicks) to Customers
  • Process unsubscribes and suppress bounced/complained addresses
  • Prevent fraud and abuse; secure the platform
  • Provide support and respond to requests
  • Meet legal obligations and enforce Terms
  • Improve the product using aggregated or operational signals

5. Sharing and sale

We do not sell Customer contact lists or personal information. We do not share personal information for cross-context behavioral advertising. We share information with service providers / subprocessors as needed to run the Service, or when required by law, to protect rights and safety, or with your direction.

6. Categories of service providers / subprocessors

  • Amazon Web Services / Amazon SES — email delivery and related feedback (typically United States regions we configure)
  • Stripe — payments, invoices, Customer Portal, subscription state
  • Hosting / VPS provider — application hosting
  • PostgreSQL and Redis infrastructure — primary datastore and job/queue coordination
  • Email/mailbox provider — for SendFable support mailboxes (support@, privacy@, legal@, abuse@, security@)
  • Optional object storage (AWS S3) — encrypted off-host backups when enabled

Analytics: SendFable records first-party product funnel events when enabled (no advertising cookies). Optional Google Analytics 4 may be loaded when a measurement ID is configured by the operator; it is not required for the Service to function. We do not load Meta Pixel, PostHog, or Plausible by default. Campaign open/click tracking is first-party product functionality for Customers. Monitoring is primarily application health checks and operational logs.

7. Cookies

See the full Cookie disclosure. In short, SendFable uses first-party cookies that are necessary to run the Service (session / Auth.js cookies, CSRF protection, and a workspace-preference cookie). Optional GA4, when configured, may set analytics cookies from Google — enable only with an updated consent posture if your jurisdiction requires it. We do not set advertising cookies by default.

8. International processing

The Service is operated with infrastructure that may process data in the United States. If you access the Service from elsewhere, you understand that information may be processed in the U.S. and other locations where our providers operate.

9. Retention, deletion, and backups

  • You can export contacts as CSV from the app and delete a Workspace (OWNER) from settings, which removes associated contacts, campaigns, templates, and related Workspace data from the primary database subject to technical cascading deletes.
  • Backups (including encrypted off-host backups when enabled) age out on a fixed schedule and are not an interactive live copy of your Workspace.
  • Not everything can always be deleted immediately. Suppression records (including platform-wide hard-bounce and complaint suppressions), billing and tax records, fraud/security logs, policy-acceptance records, and information we must keep for legal compliance may be retained as needed to protect Recipients and operate the platform.

10. Data deletion and privacy-request instructions

  • Export: use in-app contact export where available.
  • Deletion: Workspace OWNER may delete the Workspace in settings, or email privacy@sendfable.com / use the contact form (topic: Privacy or data request).
  • Access / correction: same contact routes, including for Recipients who received email sent through SendFable.
  • We verify requests against the relevant account or other reasonable identity checks before acting, and aim to respond within 30 days (or sooner if required by applicable law).
  • Where an applicable law provides authorized-agent or appeal rights, include that information in your request and we will follow the process required for that law.

11. Children

The Service is not directed to children under 18, and we do not knowingly collect personal information from children for account registration.

12. Security

We use HTTPS/TLS in transit, access controls, role-based Workspace permissions, tenant isolation controls, backups, and operational monitoring as described on our Security page. No service can guarantee absolute security.

13. State privacy rights

Depending on your location and whether statutory thresholds apply, you may have rights to know, access, correct, delete, or appeal certain processing. We do not sell personal information. California or other state rights are described only to the extent they apply; contact privacy@sendfable.com to exercise a request. We will not discriminate against you for exercising rights that apply.

14. Policy updates

We may update this Policy and will revise the dates/version above. Material changes will be announced by email or in-app where practical before they take effect.

15. Contact

Privacy questions and requests: privacy@sendfable.com, or the contact form (topic: Privacy or data request). Operator: SendFable is a service operated by iScream Studio INC.