Privacy Policy
1. Introduction & Scope
Centimailer ("we", "our", or "platform") provides email campaign infrastructure, recipient list segmentation, and cold outreach tooling. We value your privacy and are committed to maintaining the confidentiality of your workspace data, sending identities, and recipient contact information.
This Privacy Policy outlines the categories of data we collect, how that information is utilized, our zero-sale policy regarding customer data, and your privacy rights under applicable data protection regulations including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect
We adhere to the principle of data minimization, collecting only the information required to securely provide our services:
- Account Information: When you register a workspace, we collect your chosen username, email address, and a cryptographically salted password hash (bcrypt). We do not store plaintext passwords.
- Campaign & Outreach Data: We store email subjects, message body HTML/text, sender identities, and recipient contact lists (including uploaded CSV data and custom personalization variables such as
{{first_name}}or company name) for the sole purpose of dispatching campaigns on your behalf. - Technical & Operational Logs: To safeguard server integrity, mitigate DDoS attacks, and enforce rate limits, our infrastructure logs server request timestamps, Cloudflare Turnstile challenge outcomes, and IP addresses. These logs are retained strictly for operational security and are never sold or combined with external tracking databases.
Our Absolute Commitment: Centimailer never sells, rents, monetizes, or shares your contact lists or campaign content with third-party advertisers, data brokers, or external marketing entities under any circumstances.
3. Multi-Tenant Recipient Isolation
All contacts, lists, and recipient events in Centimailer are strictly isolated by your workspace tenant ID. No other platform user or organization can access, view, or dispatch emails to your contacts. When you delete a list or contact, that record is permanently purged from your active workspace database.
4. Open Tracking & Privacy Architecture
Centimailer includes built-in email open tracking designed with privacy in mind. Tracking utilizes a lightweight 1×1 transparent GIF loaded via a unique cryptographic token.
- Open tracking does not install third-party tracking cookies or execute client-side tracking JavaScript on recipient devices.
- Open tracking does not perform cross-site behavioral profiling or device fingerprinting.
- Open tracking is completely optional: senders can uncheck open tracking at any time in the campaign composer to send completely raw, tracking-free plain emails.
5. Payment Processing & Financial Privacy
Centimailer does not collect, store, or process raw credit card numbers or banking passwords on its servers.
- Cryptocurrency Payments: Processed via NOWPayments. Transactions occur directly on the respective blockchain network (Bitcoin, Ethereum, USDT, LTC, etc.). Centimailer never has access to your private keys, seed phrases, or external wallet software.
- Card & PayPal Payments: Handled securely through PayPal's PCI-DSS compliant checkout gateways. Payment authentication tokens are exchanged via encrypted webhooks without Centimailer retaining Primary Account Numbers (PANs).
6. Cookies & Session Security
We use strictly necessary session cookies (specifically cm_platform_token) configured with HttpOnly, Secure, and SameSite=Lax security attributes. These cookies exist exclusively to authenticate your browser session and protect against Cross-Site Request Forgery (CSRF). We do not deploy advertising, tracking, or marketing cookies.
7. Data Subject Rights (GDPR & CCPA)
Depending on your location, you hold the following rights regarding your personal data:
- Right of Access: You can review and export your sender identities, audience lists, and campaign logs directly from your workspace.
- Right to Rectification: You can modify your sender details, templates, and contact lists at any time.
- Right to Erasure ("Right to be Forgotten"): You may request complete deletion of your account and all associated campaign data by contacting our team.
- Right to Restrict Processing: You may toggle tracking off or pause campaigns at your discretion.
8. Data Retention & Security Measures
All data in transit is encrypted using Transport Layer Security (TLS 1.3). Database queries utilize parameterized statements to eliminate SQL injection vulnerabilities. Operational campaign event logs are archived or purged according to workspace lifecycle needs.
9. Contact Our Privacy Team
If you have questions regarding this Privacy Policy or wish to exercise your data subject rights, please open a ticket under Support in your dashboard or contact us at privacy@centimailer.com.