Privacy Policy
This Privacy Policy explains what information SendHQ collects, how we use it, and the choices you have.
Last updated: October 5, 2026
1. Information we collect
- Account information — your name, email address, and password (stored as a salted hash) when you create an account.
- Domain information — the domains you add to your workspace and the DNS records used to verify them.
- Email metadata — sender, recipient, subject, and status of messages sent and received through the Service. Message bodies are stored to power your inbox and outbox.
- Usage data — API requests, volume, and delivery events (delivery, bounce, complaint) used to power deliverability insights.
- Product and operational analytics — we collect page views, button and link clicks, scroll depth, sections viewed, errors, acquisition attribution (campaign parameters such as utm_source, the referring site, the landing page, and the last ad click), and account lifecycle events such as signup, checkout, payment outcomes, domain setup, API-key creation, and email-send outcomes. Each event records your IP address, the approximate location derived from it (country, region, city, time zone and network provider), and your device, operating system, browser (including whether it is an in-app browser such as Facebook's or Instagram's), and preferred language. Once you are signed in, analytics events are associated with your account, and the analytics profile holds your account email address and name, and your last known location and device. For email-send outcomes, analytics additionally records the sending (From) address and domain, the message subject, whether the message carried attachments and how many, its approximate size, and whether it was transactional or marketing. For failed payments, it records the payment provider's decline reason and the issuing country and network of the card (never the card number). Analytics excludes message bodies, the addresses of your recipients, passwords, API keys and other credentials.
- Error diagnostics — limited technical information about browser errors may be processed to help us identify and fix reliability issues. We configure error monitoring not to send default personally identifiable information.
- Support information — the reply email, query, category, and optional attachment you submit through our contact form. Contact content is delivered by email and is not added to SendHQ workspace storage.
2. Google Sign-In and Google user data
If you choose to sign in with Google, SendHQ requests only the non-sensitive openid, userinfo.email, and userinfo.profile scopes. Google provides your account identifier, email address, name, and profile image. SendHQ uses this data only to create or identify your SendHQ account, authenticate you, display your profile, secure your session, and provide account support.
SendHQ does not request or access Gmail messages, Google contacts, Google Drive files, calendars, or other sensitive or restricted Google user data. Google Sign-In data is not used to send email through SendHQ, is not sold, is not used for advertising, and is not shared except with infrastructure providers strictly as necessary to operate authentication and the Service. You may request deletion of your SendHQ account and associated Google Sign-In data by contacting us at postmaster@sendhq.cc.
3. How we use information
We use the information above to operate and improve the Service, to send and receive email on your behalf, to enforce usage limits, to detect abuse, and to provide support. We do not sell your personal information.
4. Email content
Email sent and received through the Service is processed and stored to provide the inbox, outbox, and deliverability features. Content is stored in your isolated workspace and is accessible only to you.
5. Sharing and subprocessors
We share data with subprocessors strictly to provide and improve the Service — for example, a mail transport provider (such as Amazon SES) to deliver email, infrastructure providers to host the platform, and a product-analytics provider (Mixpanel) that receives the events described above, a session-replay provider (Microsoft Clarity) that receives masked usage recordings, and advertising platforms (Meta and Google) that receive ad-conversion events. Subprocessors are bound by data-protection obligations.
6. Cookies
We use a session cookie to keep you signed in, short-lived cookies for security (such as OAuth state), and first-party analytics cookies scoped to *.sendhq.cc so they work on both this site and the app: a visitor identifier (sendhq_visitor_id) that measures navigation funnels, a first-touch attribution record (sendhq_attribution), and a last-ad-click record (sendhq_paid_touch). They expire after one year. Analytics requests go first to SendHQ and are forwarded to our product-analytics provider together with the IP address, location and device details described above. Session replay and heatmaps run through Microsoft Clarity, loaded by our own first-party script. We also use advertising pixels from Meta (Facebook and Instagram) and Google, which set their own cookies (such as _fbp and _fbc) to measure which ads lead to signups and purchases; we additionally report signups and first purchases to Meta from our servers, with your email address and account identifier hashed.
7. Data retention and deletion
We retain account and email data for as long as your account is active. You may request deletion of your account and associated data by contacting us. Some records may be retained where required by law.
8. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details below.
9. Security
We use industry-standard safeguards, including transport encryption (TLS) and hashed credentials. No method of transmission or storage is 100% secure, but we work to protect your data.
10. Contact
For privacy questions or requests, email postmaster@sendhq.cc.
This document is a general template and may be updated as the Service evolves. It does not constitute legal advice.