Privacy Policy

Last updated: 24 June 2026

1. Who we are

This Privacy Policy explains how Sendcheck Ltd ("sendcheck.io", "we", "us", or "our"), a company registered in England and Wales under company number 17297971, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, collects, uses, and protects your personal data when you use the sendcheck.io website and service (the "Service").

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and other applicable data protection laws, Sendcheck Ltd is the data controller of the personal data described in this policy, except where we act as a processor on your behalf (see Section 6).

If you have any questions about this policy or how we handle your data, contact us at hello@sendcheck.io.

2. The data we collect

We collect and process the following categories of personal data:

2.1 Account and profile data

When you create an account, we collect:

  • Your name
  • Your email address
  • A unique scanning address we generate for you
  • Your password (stored only in a securely hashed form — we never see or store it in plain text)
  • Your marketing preferences (whether you have opted in to receive product updates)

2.2 Email content you submit for scanning

The core function of the Service is to analyse marketing emails. When you submit an email to be scanned — either by pasting its content or by sending it to your unique scanning address — we receive and process:

  • The full content of that email (subject line, body, HTML, links, images, and any other content it contains)
  • The technical headers of emails sent to your scanning address (used for deliverability and authentication checks)
  • The analysis and results we generate from it

Important: emails you submit may contain personal data relating to other people — for example, your own subscribers' names or email addresses in personalisation fields or merge tags. Please read Section 7 carefully, as you are responsible for that data.

2.3 Payment and billing data

When you purchase a paid plan, payment is processed by our payment provider, Stripe. We do not collect or store your full card details. We receive and store from Stripe:

  • Your billing country
  • A Stripe customer reference
  • Your subscription status, plan, and renewal information

2.4 Marketing and attribution data

If you arrive at our site via a marketing link, we may capture attribution parameters (such as UTM source, medium, and campaign) and your referrer, to understand how people find us.

2.5 Usage and analytics data

We may collect information about how you use the Service — such as pages visited, features used, and scan history — to operate, secure, and improve the Service. We use third-party analytics tools, including Google Analytics, to help us understand how the Service is used and to improve it. Where required by law, we request your consent before setting non-essential analytics cookies (see Section 11).

2.6 Technical data

We automatically collect limited technical data necessary to deliver and secure the Service, such as your IP address, browser type, and device information, primarily through our hosting and infrastructure providers.

3. How and why we use your data (lawful bases)

We process your personal data on the following lawful bases under the UK/EU GDPR:

What we use it forLawful basis
Creating and managing your accountPerformance of a contract
Providing the scanning and analysis servicePerformance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Sending essential service emails (confirmations, security, account notices)Performance of a contract / legitimate interests
Sending marketing emails (where you have opted in)Consent
Understanding how the Service is found and used, and improving itLegitimate interests
Securing the Service and preventing abuse or fraudLegitimate interests
Complying with legal and tax obligationsLegal obligation

Where we rely on consent (for example, marketing emails or certain analytics), you may withdraw it at any time. Where we rely on legitimate interests, you have the right to object (see Section 9).

4. How long we keep your data (retention)

We keep personal data only for as long as necessary:

  • Scanned email content and scan results: retained for 12 months from the date of each scan, to power your scan history, after which it is automatically deleted. You may delete individual scans at any time before then.
  • Account and profile data: retained for as long as your account is active. If you close your account, we delete your account data within 90 days, except where we are legally required to keep certain records.
  • Payment and transaction records: retained for 6 years to comply with UK tax and accounting law (HMRC requirements), regardless of account closure.
  • Marketing and attribution data: retained for as long as your account is active, or until you withdraw marketing consent.

You can request deletion of your data at any time (see Section 9). We provide tools within the Service to delete individual scans and to close and delete your account.

5. Who we share your data with

We do not sell your personal data. We share it only with the trusted service providers ("sub-processors") that we rely on to operate the Service, and only as necessary for them to perform their function. Our sub-processors include:

ProviderPurposeData involved
SupabaseDatabase and authenticationAccount data, scan records
VercelApplication hosting and infrastructureTechnical data, all data in transit
MailgunReceiving emails sent to your scanning address; sending service and account emailsEmail content and headers, your email address
AnthropicAI-powered analysis of your email contentThe email content you submit for scanning
PostmarkSpam-filter scoring of emails sent for scanningThe email content of scanned emails
StripePayment processing and subscription managementBilling data, email
Google AnalyticsUsage analyticsUsage and technical data

Each of these providers processes data under their own terms and applicable data protection safeguards. We may also disclose data where required by law, to enforce our terms, or to protect our rights, users, or the public.

If our business is sold or transferred, your data may be transferred as part of that transaction, subject to this policy.

6. When we act as a processor

For most personal data (your account, your usage), we are the controller.

However, in relation to the personal data of third parties contained within the emails you submit (for example, your subscribers' details in personalisation fields), we act as a processor on your behalf. You are the controller of that data. We process it solely to provide the scanning service to you, in accordance with this policy and our Terms of Service, and we do not use it for any other purpose.

7. Your responsibilities for third-party data

Because the emails you submit may contain other people's personal data, you confirm that you have a lawful basis to share that data with us for the purpose of scanning, and that doing so does not breach any law or any obligation you owe to those individuals.

You are responsible for ensuring that your use of the Service complies with all data protection laws applicable to you and to the data you submit. We rely on this confirmation, and you agree to indemnify us in respect of any claim arising from your failure to have a lawful basis for the third-party data you submit (see our Terms of Service).

We recommend you avoid submitting more personal data than is necessary, and that you do not submit special category data (such as health, racial, or biometric data) through the Service.

8. International data transfers

We are based in the United Kingdom, and our customers are worldwide. Some of our sub-processors may process data outside the UK or European Economic Area. Where data is transferred internationally, we rely on appropriate safeguards recognised under UK and EU data protection law (such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or adequacy decisions) to ensure your data remains protected.

9. Your rights

Under the UK/EU GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to our legal retention obligations
  • Restrict or object to our processing in certain circumstances
  • Data portability — receive your data in a portable format
  • Withdraw consent at any time, where we rely on consent
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, contact us at hello@sendcheck.io. We will respond within the timeframes required by law (usually one month).

If you are in the UK, you may also complain to the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you may complain to your local data protection authority.

10. Security

We take the security of your data seriously and use appropriate technical and organisational measures to protect it, including encryption in transit, hashed password storage, access controls, and reputable infrastructure providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Cookies and similar technologies

We use cookies and similar technologies that are necessary to operate the Service (for example, to keep you logged in). If we introduce non-essential cookies (such as analytics or marketing cookies), we will request your consent where required and provide a means to manage your preferences.

12. Children

The Service is not directed at children and is intended for use by businesses and professionals. We do not knowingly collect data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact us

For any privacy-related questions or requests, contact us at:

Sendcheck Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
hello@sendcheck.io