1. Who we are
Refiremail is an email platform: an API for the email a product sends, and a campaign studio for the email a team writes, on one contact list. The service is run by the company to be named at legal review, whose registered office is to be published at legal review. In this policy, “we” and “us” mean that company.
Questions about this policy go to [email protected]. Complaints go to our grievance officer (section 9).
2. Our two roles
The Digital Personal Data Protection Act, 2023 (the DPDP Act) separates the business that decides why personal data is processed, the Data Fiduciary, from a business that processes it on the fiduciary’s behalf, a Data Processor. We are both, for different people:
- Fiduciary for people who visit this website, sign up for an account, use the dashboard or write to us. This policy covers that data.
- Processor for the people our customers email: their contacts, subscribers and recipients. The customer decides who is on its list and what they receive. Our data processing agreement covers that data.
If you received an email sent through Refiremail
The organisation in the From line is the Data Fiduciary for your address, not us. To stop its marketing email, use the unsubscribe link in any of its messages; you do not need an account. For anything else (a copy of your data, a correction, erasure), contact that organisation. If you cannot reach it, write to [email protected] with the sender’s address and we will pass your request on.
3. What we collect
On this website
This site sets no cookies, runs no analytics and loads no third-party scripts. Its fonts are served from our own domain. The server that hosts it may keep standard access logs (IP address, time, page requested and browser user agent) for security. We do not use them to profile visitors.
When you request early access
The early-access form on this site sends us your email address and whatever else you choose to fill in: your name, company, monthly sending volume and what you want to use Refiremail for, together with the page or button you came from. We use it only to contact you about access to Refiremail. The server may use your IP address to limit repeated submissions. We keep the request until you have access or ask us to delete it.
When you write to us
Your name, email address, company and whatever you put in the message. If you email us, it arrives in our mailbox. The contact form on this site is not switched on yet; once it is, it will send what you type to Refiremail’s own hosted-form endpoint, which stores it as a contact in our own account together with the time, IP address, browser user agent and referring page of the submission, as it does for every Refiremail form.
When you have an account
- Account details: your name, email address and password. The password is stored only as a scrypt hash, never in readable form.
- Sign-in sessions: the dashboard (not this website) sets one cookie,
rf_session, to keep you signed in. It is HttpOnly and expires after 30 days. We record the IP address and browser user agent of each session. - Audit log: who in your team did what and when, with IP address and user agent.
- API request logs: for each API call, the endpoint, status, time, IP address, user agent, and the request and response bodies with attachment content removed, each capped at 64 KiB.
- Billing details: legal name, billing address, GSTIN and the invoices we issue. Payments go through a payment provider; we do not receive or store full card numbers.
- Support conversations with you.
Data about other people that you send through Refiremail
Contacts and their properties, consent records, message content and attachments, delivery and engagement events (opens and clicks, with IP address and user agent), inbound email and form submissions belong to our customers. We process them only to provide the service, under the data processing agreement, and never for our own purposes.
4. Why we use it
- To run the service you signed up for: sending, receiving, storing and reporting on email.
- To send you service email: password resets, team invitations, invoices, security notices and changes to our terms. These are not marketing and carry no unsubscribe link.
- To keep the service safe: rate limits, abuse and fraud checks, and monitoring the bounce and complaint rates of the mail sent through us.
- To bill you and to meet tax and accounting law.
- To answer you when you write to us.
- To send you product news, only if you opt in. Every such email has an unsubscribe link, and opting out does not affect service email.
We process this data with your consent, given when you sign up or write to us, or for a legitimate use the DPDP Act allows, such as keeping tax invoices because the law requires it. You can withdraw consent at any time; that does not affect processing done before you withdrew it.
We do not sell personal data, and we do not use our customers’ contact lists for our own marketing.
5. Where it is stored
Refiremail is designed to keep data in India:
- Contacts and message content are stored in IndiaComing
- Mail is sent from the ap-south-1 (Mumbai) region
A statement marked Coming describes how the service is being set up, not what is in place today, and it is not yet a commitment. Before this policy takes effect it will list exactly which kinds of data stay in India: the database, backups, attachments and logs.
Some providers that help us run the service may process limited data outside India, for example DNS. They are listed with where they process data under sub-processors below. We will not transfer personal data to a country the Central Government has restricted under section 16 of the DPDP Act.
6. Sub-processors
These companies process personal data for us, only to run the service and under data protection terms. We will update this list, and email account owners, before we add or replace one.
| Company | What it does for us | Where |
|---|---|---|
| Amazon Web Services (Amazon SES) | Delivers the email sent through Refiremail: recipient addresses, message content and delivery events | ap-south-1 (Mumbai), India |
| Cloudflare | DNS for our domains, and the network our website is served through: every request to refiremail.com, including early-access form submissions, passes through Cloudflare, which sees the visitor’s IP address and the request | Cloudflare’s global network |
7. How long we keep it
These periods are the product’s defaults. If they change, this table changes with them.
| Data | Kept for |
|---|---|
| Sent email records and their content | 90 days after sending, then deleted |
| API request logs | The log retention period of your plan |
| Webhook delivery records | 30 days |
| Raw bounce and complaint notices from mailbox providers | 14 days |
| Consent records and the audit log | As long as the account exists. They are evidence, so nobody can edit them |
| Suppression list (addresses that bounced, complained or unsubscribed) | As long as the account exists, so those people are not emailed again |
| An account you delete | 30 days, during which you can restore it; then deleted |
| Tax invoices | As long as Indian tax law requires, even after the account is deleted |
| Backups | Deleted data leaves our backups as they expire, within 30 days |
| Early-access requests | Until you have access, or until you ask us to delete the request |
| Messages you send us | As long as we need them to help you and to keep a record of what we agreed |
8. Your rights
Under the DPDP Act you can:
- get a summary of the personal data we hold about you, what we do with it, and who we have shared it with (section 11);
- have it corrected, completed or updated, and have it erased once it is no longer needed for the purpose you gave it for, unless the law requires us to keep it (section 12);
- withdraw your consent at any time, as easily as you gave it (section 6);
- have a grievance handled by us, and if you are not satisfied, complain to the Data Protection Board of India (section 13);
- nominate someone to use these rights for you if you die or become unable to use them yourself (section 14).
To use any of them, write to [email protected] from the address on your account, or use the settings in your dashboard. We may ask you to confirm who you are. We will reply within the time the DPDP Rules allow.
If your request is about email a Refiremail customer sent you, it belongs with that customer (section 2).
9. Grievance officer
Our grievance officer answers questions and complaints about how we process personal data. Write to [email protected] with “Grievance” in the subject line.
- Name
- to be named at legal review
- [email protected]
- Postal address
- to be published at legal review
The same details are on our contact page.
10. Security
We protect personal data with reasonable security safeguards, as section 8(5) of the DPDP Act requires. These measures are part of how the product is built; the security page lists the rest:
- API keys stored only as SHA-256 hashes
- DKIM private keys encrypted at rest with AES-256-GCM
- Every tenant table is keyed by team, and the database refuses a reference that crosses teams
If a breach affects personal data we hold as a fiduciary, we will tell you and the Data Protection Board as section 8(6) of the DPDP Act requires.
11. Children
Refiremail is a service for businesses. You must be 18 or older to create an account. We do not knowingly process children’s personal data as a fiduciary; if you think we have, write to [email protected] and we will delete it.
A customer that emails children is responsible for getting verifiable consent from a parent or lawful guardian first, as section 9 of the DPDP Act requires.
12. Changes to this policy
We will post every change on this page with a new date. If a change affects how we use data you have already given us, we will email account owners before it takes effect.
This policy is a draft. It takes effect only after legal review, when the Draft label comes off this page.