Last updated: May 27, 2026
This Privacy Policy explains how SmartMailing ("SmartMailing," "we," "us") collects, uses, stores, and protects personal data when you visit smartmailing.io, create an account, or use our email-marketing platform.
SmartMailing is operated by Ionuț-Săndel Badiu, sole proprietor (Einzelunternehmen, Gewerbeschein) based at Nordbahnstraße 13/11, 1020 Vienna, Austria. GISA-Zahl: 39386489. Kleinunternehmer gemäß §6 Abs 1 Z 27 UStG (no UID-Nummer). Full legal notice available in our Impressum. We are the data controller for personal data of platform users and the data processor for the subscriber data our customers upload (see Section 9 below).
We collect and process the following categories of personal data:
When you create an account: email address, name, hashed password (managed by our authentication provider; we never see your plaintext password), and account creation / last sign-in timestamps.
Brand names, logo files, brand colors, fonts, website URLs you ask us to extract, footer text, social links, and any other content you enter to configure your brand.
The email templates, web landing pages, transactional emails, and campaign content you create using the platform, including AI-generated content based on your inputs.
When you use SmartMailing to manage your own mailing lists, you upload personal data of your subscribers (email address, name, language, custom fields, consent records, opt-in source, IP at signup). We process this data on your instructions as a processor — see Section 9.
The recipient addresses, subject lines, rendered email HTML, and delivery events (sent, delivered, opened, clicked, bounced, complained) for emails sent via the platform, including timestamps and IP-derived metadata from our delivery provider.
If you purchase a paid plan, our payment processor (Stripe) collects billing name, address, card details (we never see card numbers), and transaction history. We store only billing-related identifiers and amounts on our side.
IP address (truncated to /24 where stored long-term), browser user agent, referrer, request paths, error logs. We retain this for security, debugging, and abuse prevention.
If you use AI features (e.g. generating email content from your website), we store the prompts you submit and the responses you receive, linked to your project, so you can revisit and refine them.
Each processing activity relies on one of the following bases:
We rely on the following third-party processors to deliver the service. Each one is bound by a Data Processing Agreement, and where any data is transferred outside the European Economic Area (EEA), the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) and supplementary measures.
| Processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Switzerland (AWS eu-central-2, Zurich) | EU adequacy decision (no SCCs needed) |
| Resend | Email sending (transactional + campaign), webhook delivery | United States | SCCs + supplementary measures |
| OpenAI | AI content generation (when you use AI features). API submissions are not used to train OpenAI's models. | United States | SCCs; OpenAI Enterprise DPA |
| Anthropic | AI content generation (alternative model provider) | United States | SCCs |
| Stripe | Payment processing and subscription billing | Ireland (EU) / United States | SCCs for any US transfers; Stripe DPA |
| Cloudflare | DNS, CDN, AI Gateway, hosted-form custom domains | Global edge network | SCCs |
| Vercel | Next.js application hosting and edge delivery | United States / Global edge network | SCCs |
| Hostinger | VPS hosting for the website-extraction worker that fetches public content (logos, images, colors, text) from URLs you provide during brand setup. Processing is transient — extracted brand assets are returned to and stored in Supabase; the VPS does not retain content long-term. | United States | SCCs + supplementary measures |
We update this list when we add or change processors. Material changes are communicated to platform users in advance where reasonable.
Where personal data is transferred outside the EEA — primarily to the United States via our sub-processors above — we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) supplemented by technical and organizational measures (TLS in transit, encryption at rest, strict access controls). For more information about a specific transfer, contact [email protected].
We retain personal data only as long as needed for the purpose for which it was collected:
Under the GDPR you have the following rights regarding your personal data. To exercise any of these, contact [email protected]. We respond within one month (extendable by two months for complex requests).
SmartMailing uses AI services (currently OpenAI and Anthropic) to generate email copy from inputs you provide. This is content generation, not automated decision-making about you within the meaning of Article 22 GDPR — no significant legal or similar decisions are made automatically. You remain in control of any content before it is sent.
Inputs you submit to AI features are sent to the provider via API. The providers we use do not train their models on API-submitted data by default. We do not retain your inputs with the AI providers beyond what is needed to complete the request.
SmartMailing uses only essential cookies and browser-storage entries required to operate the service:
We do not currently use third-party analytics, advertising cookies, or trackers that would require a consent banner under the ePrivacy Directive. If this changes, we will deploy a compliant cookie consent banner before any such cookies are set.
Emails sent through SmartMailing may include tracking pixels and rewritten links that allow our customers to measure open and click rates. This is configured by each customer and disclosed in their own privacy policy and email footers (every email contains a one-click unsubscribe link).
When you (the customer) upload subscriber data to SmartMailing — through the API, hosted subscribe forms, manual add, or CSV import — you are the data controller for those subscribers, and SmartMailing acts as your data processor.
We process subscriber data only on your documented instructions: storing it, segmenting it, sending the emails you compose, recording consent and delivery events. We do not use subscriber data for our own purposes, do not sell it, and do not contact subscribers ourselves (except for transactional emails you trigger, such as the double-opt-in confirmation).
The terms of this processor relationship are set out in our Data Processing Agreement, available at smartmailing.io/legal/dpa. By using the platform you accept the DPA. Subscribers who want to exercise their rights should contact you (the controller); we will assist you in responding.
We use industry-standard technical and organizational measures to protect personal data: TLS 1.2+ for all network traffic, encryption at rest for stored data, role-based access controls, row-level security in our database to enforce strict isolation between customers, signed and authenticated webhooks, regular security review of our code, and timely patching for known vulnerabilities in our dependencies.
In the event of a personal-data breach affecting your data, we will notify the relevant supervisory authority within 72 hours and inform affected users where required by Articles 33–34 GDPR.
SmartMailing is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will delete it.
We may update this policy from time to time to reflect changes in processing, processors, or applicable law. Material changes will be communicated to platform users via email at least 14 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.
For any privacy-related question or to exercise any of the rights listed in Section 6, contact us at [email protected]. We aim to respond within five business days and within one month for formal data-protection requests.
If you are not satisfied with our response, you may lodge a complaint with your local data protection authority. The competent authority for SmartMailing is the Austrian Datenschutzbehörde (DSB) — dsb.gv.at.