Privacy Policy
Last updated: March 3, 2026
ThunkMail ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email marketing platform.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Customer" means any person or entity that creates a ThunkMail account.
- "Subscriber" means any individual whose personal data is included in a Customer's contact list on ThunkMail.
- "Services" means the ThunkMail email marketing platform and all associated features.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Password (stored securely using industry-standard hashing)
- Name (if provided)
- Profile picture (if uploaded)
- Billing information (processed securely by Stripe; we do not store card details)
Usage Data
We automatically collect information about how you interact with our platform, including:
- Pages visited and features used
- Campaign sending activity and performance metrics
- Device type, browser, and operating system
- IP address and approximate location
- Date and time of access
Contact Data (Subscriber Data)
When you upload or manage contacts through our platform, we store the contact information you provide (such as email addresses, names, and custom fields) on your behalf. You are the Data Controller for your contact lists; ThunkMail acts as the Data Processor. See our Data Processing Addendum for details.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our email marketing services
- Process your campaigns and deliver emails on your behalf
- Process payments and manage your subscription
- Send you account-related communications (confirmations, security alerts, support)
- Monitor platform health, including bounce rates and complaint rates
- Detect and prevent fraud, abuse, and violations of our Terms of Service and Acceptable Use Policy
- Comply with legal obligations
- Provide customer support
4. How We Collect Your Information
We collect information through:
- Direct collection — Information you provide when creating an account, uploading contacts, or contacting support
- Automated collection — Usage data collected through cookies and server logs when you use our platform
- Third-party services — Information received from authentication providers (e.g., Google OAuth)
5. Third-Party Services
We use the following third-party services to operate our platform:
- Supabase — Authentication and database hosting (Privacy Policy)
- Amazon Web Services (AWS SES) — Email delivery (Privacy Policy)
- Stripe — Payment processing (Privacy Policy)
- Vercel — Application hosting (Privacy Policy)
Each of these providers maintains their own privacy policies. We have agreements in place with each sub-processor to ensure adequate data protection. See our Data Processing Addendum for the full list of sub-processors.
6. Data Storage and Security
Your data is stored on servers located in the United States. We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest
- Access controls and role-based permissions
- Regular security monitoring and incident response procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. International Data Transfers
ThunkMail is based in the United States. If you access our services from outside the United States, your personal data will be transferred to and processed in the United States.
For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate transfer mechanisms recognized by applicable authorities.
8. Data Retention
We retain your account information for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.
Campaign analytics and sending logs may be retained in anonymized form for platform improvement purposes.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Correction — Request that we correct inaccurate or incomplete data
- Deletion — Request that we delete your personal data
- Restriction — Request that we restrict the processing of your data
- Portability — Request a copy of your data in a portable format
- Objection — Object to certain types of processing
- Withdrawal of consent — Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at privacy@thunkmail.com. We will respond to your request within 30 days.
10. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights, including:
- Right to know — You may request that we disclose the categories and specific pieces of personal information we have collected about you
- Right to delete — You may request the deletion of your personal information
- Right to opt out of sale — We do not sell your personal information to third parties
- Right to non-discrimination — We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact us at privacy@thunkmail.com.
11. Email Communications and Opting Out
We may send you the following types of emails:
- Transactional emails — Account confirmations, password resets, security alerts, and billing notifications. These are necessary for the operation of your account and cannot be opted out of.
- Service updates — Important changes to our platform, terms, or policies. These are sent infrequently and only when necessary.
- Product updates — New features, tips, and platform news. You can opt out of these at any time through your account settings or by clicking the unsubscribe link in the email.
12. Protecting Subscriber Data
Your subscribers' data is your responsibility as the Data Controller. ThunkMail processes this data solely on your behalf and according to your instructions. We will:
- Not use your subscriber data for our own marketing purposes
- Not sell, rent, or share your subscriber data with third parties for their own purposes
- Process subscriber data only as necessary to provide our email delivery services
- Delete subscriber data when you remove it from your account or when your account is terminated
13. Cookies
We use essential cookies to maintain your session and authentication state. We do not use third-party tracking or advertising cookies. For detailed information, please see our Cookie Policy.
14. Links to Other Websites
Our platform and marketing pages may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We encourage you to read the privacy policies of any third-party sites you visit.
15. Merger or Acquisition
In the event that ThunkMail is involved in a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email or prominent notice on our platform before your personal data becomes subject to a different privacy policy.
16. Children's Privacy
ThunkMail is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our platform. We will update the "Last updated" date at the top of this page. Your continued use of ThunkMail after changes take effect constitutes acceptance of the revised policy.
18. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us at: