RichSMTP · Privacy Policy
richsmtp.com and the RichSMTP service are operated by RNS STAR LLC, 99 Wall Street #112, New York, NY 10005, United States ("we", "us", "our"). This policy explains how we handle information when you visit our website, open an account, or send mail through our services. It forms part of our Terms and Conditions.
1. The two roles we play
We are an email infrastructure provider, so we handle two very different kinds of personal data, under two different legal roles. The distinction runs through this whole policy:
- Your data: we are the controller. Your name, email address, company, billing details, login credentials, verification documents, support messages and how you use the dashboard and API. We decide how this is handled, and this policy governs it.
- Your recipients' data: we are the processor. The addresses you send to, the contents of those messages, and the delivery events they generate. You are the controller of that data. We process it only to deliver your mail, protect the platform and recipients, and meet our legal obligations, and only on your instructions. Your own privacy notice, not this one, governs your relationship with your recipients.
2. Information we collect
2.1 Information you give us
- Name, company name, email address and, where you provide it, phone number, website and postal address.
- Billing details. Card data is entered on our payment processor's hosted checkout. We never receive or store your full card number. We receive the card brand, last four digits, country and the outcome of the charge.
- Account credentials. Passwords are stored only as salted hashes and cannot be recovered by anyone, including us.
- Sending domains and the DNS records you configure for SPF, DKIM, DMARC and tracking.
- Verification material we request under the Terms: proof of identity or business registration, evidence of domain and website ownership, samples of intended mail, your privacy notice and recipient consent records.
- The content of enquiries, appeals and support requests you send us.
2.2 Information we collect automatically
- Website access logs. When you visit richsmtp.com our web server records your IP address, the time, the page requested, the response status, the referring page and your browser's user agent. That is all the website collects: it sets no cookies, stores nothing in your browser, and loads no analytics, advertising or social-media tags (see section 8).
- Service logs. When you use an account: authentication events, API and SMTP request volume, endpoints used, rate-limit and screening activity.
We keep these for security, abuse prevention, billing accuracy and troubleshooting.
2.3 Data you send us about your recipients
To deliver mail we necessarily process sender and recipient addresses, subject lines and headers, message bodies and attachments, and the resulting delivery, bounce, complaint, unsubscribe, open and click events.
We do not read, analyse or mine your message content for advertising, profiling or model training. Content is processed to deliver the message, to give you delivery analytics and a short message history, to investigate complaints and abuse reports, and to run the automated and human abuse screening described in our Acceptable Use & Anti-Spam Policy. Nothing else. Message bodies are deleted seven days after the final delivery attempt; see section 6.
3. Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the Services and operating your account | Performance of a contract |
| Taking payment, invoicing, renewals and refunds | Performance of a contract |
| Verifying who you are and what you intend to send | Performance of a contract; legitimate interests in preventing abuse |
| Support, appeals and responding to enquiries | Performance of a contract; legitimate interests |
| Screening outbound mail; preventing spam, phishing, fraud and card testing; rate limiting; enforcing the Acceptable Use & Anti-Spam Policy | Legitimate interests in protecting recipients, the platform, our sending reputation and other customers |
| Investigating complaints and abuse reports, and cooperating with mailbox providers, blocklist operators and authorities | Legitimate interests; legal obligation |
| Keeping the website secure and working (access logs) | Legitimate interests |
| Service, security and billing notices | Performance of a contract; legal obligation |
| Product and marketing email to prospects | Consent, withdrawable at any time |
| Tax, accounting and regulatory records | Legal obligation |
| Establishing or defending legal claims | Legitimate interests |
Service messages about your account, billing, security, enforcement and material changes are not marketing, and cannot be opted out of while you hold an account.
We do not sell personal information, and we do not share it with advertisers.
4. Who we share it with
We share personal data only with the following, and only as needed:
- Stripe: payment processing. Stripe receives your billing and card details directly and handles them as a controller under its own policy.
- Our own infrastructure: servers we operate in datacentres in the United States, Europe and Asia, and the network, transit and mail-delivery providers those servers depend on.
- Receiving mail servers: delivering your mail necessarily discloses it to the recipient's mail provider. That is the service.
- Mailbox providers, blocklist operators and anti-abuse organisations: when we investigate or answer a complaint, request the removal of a block, or stop abuse, we may disclose the sender's identity, contact details, domains, message samples, headers and sending history to the provider or organisation concerned.
- Professional advisers, regulators and law enforcement: where we are legally required to disclose, where a complainant pursues a legal claim, or where we need to establish, exercise or defend a legal claim.
- An acquirer: if the business is merged, acquired or sold, subject to this policy continuing to apply. We will notify you.
The richsmtp.com website serves its fonts, images and scripts from our own server, so a visit discloses nothing to third parties. Sub-processors are bound to confidentiality and to security obligations no weaker than ours. We update this list before adding a new category of processor.
5. International transfers
We operate infrastructure in the United States, Europe and Asia, so your data and your recipients' data may be processed in any of them. Where data leaves the UK or EEA we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, and apply the protections in this policy wherever the data is held.
6. How long we keep it
- Message content (bodies and attachments): deleted 7 days after the final delivery attempt. Mail rejected by our screening is deleted within 30 days.
- Delivery logs and analytics (addresses, subjects, headers, events): up to 90 days.
- Suppression records (unsubscribes, hard bounces, complaints): kept for the life of the account and after closure. Deleting one would cause a sender to mail someone who asked not to be mailed.
- Enforcement and abuse evidence (message samples, headers, complaint reports, consent records you supplied, account details, logs): 24 months after the matter is closed or the account is terminated, longer if a claim is pending.
- Verification documents: for the life of the account, then 24 months.
- Account data: for the life of the account, then 90 days after closure so it can be exported or restored.
- Billing records: 7 years, as tax and accounting law requires.
- Website access logs: up to 60 days.
- Service and security logs: up to 12 months.
- Support correspondence: up to 2 years.
- Aggregated statistics that identify nobody: indefinitely.
7. Security
We operate our own infrastructure, so security is our responsibility rather than a vendor's. Our measures include:
- TLS on every connection to our websites, API and dashboard, with HTTP redirected to HTTPS, and TLS-only SMTP submission.
- Opportunistic TLS on outbound mail wherever the receiving server offers it.
- Passwords stored as salted hashes, never in plain text and never recoverable.
- Administrative access restricted to the people who operate the platform, over key-based SSH from restricted networks, with credentials held in server-side configuration and never in source control.
- Firewalled infrastructure with monitored service health, automatic certificate renewal, replicated databases and regular backups.
- Rate limiting on sign-up and checkout, to stop automated abuse and card testing.
No system is perfectly secure, and we do not claim otherwise. If we learn of a breach affecting your data we will notify you without undue delay. If you believe you have found a vulnerability, email support@richsmtp.com; we will respond within one business day and will not pursue anyone who reports a genuine issue in good faith without accessing others' data.
8. Cookies and tracking
The richsmtp.com website sets no cookies, uses no local or session storage, and loads no analytics, advertising, pixel or social-media tags. There is nothing to accept or refuse.
If you sign in to a RichSMTP account, we use a strictly necessary session cookie to keep you signed in and may use preference cookies to remember dashboard settings. They are not used for analytics or advertising. The Cookie Policy has the details, and we will update it and this policy before any tag is added to the website.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on it.
If you are in the EEA, the UK or Switzerland these are your rights under the GDPR and UK GDPR, and you may also lodge a complaint with your local supervisory authority.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to access and delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information, and we do not collect sensitive personal information. We will not discriminate against you for exercising any of these rights.
To exercise any right, email support@richsmtp.com from the address on your account. We respond within 30 days and do not charge. We may ask you to verify your identity first. Some data cannot be deleted on request: suppression records, enforcement evidence and records the law requires us to keep.
If you are a recipient of mail sent through our platform and want your data accessed or deleted, the sender is the controller and holds it. Contact them, or write to us and we will pass the request on. If you want a sender to stop mailing you, tell us who it is and we will add you to that sender's suppression list, whether or not you have used their unsubscribe link. To report unwanted mail, write to abuse@richsmtp.com.
10. Children
The Services are for business use by adults and are not directed at children. We do not knowingly collect personal information from anyone under 18, and will delete it promptly if we learn we have.
11. Data processing addendum
If you need a data processing addendum covering our role as your processor, including the Standard Contractual Clauses and our sub-processor list, request one from support@richsmtp.com.
12. Changes to this policy
We may update this policy. Material changes are posted here with a revised effective date and, where significant, emailed to the address on your account before they take effect.
13. Contact
RNS STAR LLC, 99 Wall Street #112, New York, NY 10005, United States.
- Privacy enquiries and data-subject requests: support@richsmtp.com
- Report abuse or unwanted mail: abuse@richsmtp.com
- Mailbox providers and blocklist operators: postmaster@richsmtp.com
Effective 5 October 2026 · Version 1.0 · RNS STAR LLC, 99 Wall Street #112, New York, NY 10005, United States