Privacy Policy
How Splitsoft handles personal data. Where you (the Customer) use the Service to send email to your own contacts, we act as a processor on your behalf and our Data Processing Addendum applies. Where we hold data about you (billing, login), we act as a controller and this Policy applies directly.
1. Who we are
Splitsoft, Inc. (Delaware, USA) operates email.splitsoft.com and the underlying email-sending platform. Contact: privacy@splitsoft.com.
2. Data we hold as a controller (about you, the Customer)
- Account data — name, business email, hashed password (NextAuth), session cookies.
- Billing data — company name, billing address, tax ID, last-4 of payment method, invoice history. Card details are stored at Stripe; we never see the PAN.
- Operational data — admin-panel audit log, IP address of admin logins, user-agent, support tickets.
3. Data we process as a processor (on your behalf)
When you use the Service to send Messages, we process the following on your behalf, governed by our DPA:
- Recipient identifiers — email addresses, optional name and merge fields you upload to lists.
- Message content — subject, headers, HTML and text bodies, attachments.
- Delivery metadata — timestamps, SMTP responses, bounce codes, open and click events (when tracking is enabled by you), suppression-list entries.
We are not the controller of this data. You are. You are responsible for having a lawful basis to send to each Recipient and for honoring Recipient rights under applicable law. We will support you with the data export and deletion endpoints described in Section 8.
4. Legal bases (where GDPR / UK GDPR applies)
- Contract — to deliver the Service you signed up for (account, billing, Message delivery).
- Legitimate interest — to operate, secure, and improve the Service; to detect abuse and fraud; to maintain deliverability of shared IPs; to keep audit logs.
- Consent — for any optional analytics or marketing email we send to you about Splitsoft itself. You can withdraw consent at any time.
- Legal obligation — tax, accounting, and lawful requests from competent authorities.
5. Retention
| Data | Retention | Why |
|---|---|---|
| Message bodies (HTML, text, attachments) | 30 days | Bounce diagnosis, support, deliverability investigation. |
| Message metadata (envelope, timestamps, SMTP codes, opens/clicks) | 13 months | Year-over-year deliverability trends, fraud and abuse review. |
| Suppression-list entries (bounces, complaints, unsubscribes) | Lifetime of account | To prevent re-sending to addresses that have bounced or complained. |
| Account and billing records (invoices, payment history) | Indefinite, as required by tax law (typically 7–10 years) | Statutory record-keeping under US/EU/UK rules. |
| Admin audit log | 2 years | Security investigation. |
| Encrypted backups (Postgres, MariaDB) | 35 days, then purged | Disaster recovery; deletion in production propagates within this window. |
6. Sub-processors
We use the following sub-processors. We notify Customers of changes at least 30 days in advance via email and via the published list at this URL.
- Vultr Holdings, LLC (USA) — primary compute, block storage, and BYOIP custody for the production stack.
- Stripe, Inc. (USA) — payment processing and invoicing.
- Cloudflare, Inc. (USA) — DNS, edge TLS termination for the marketing site, DDoS protection.
- An S3-compatible backup provider (region matched to your data residency election) — encrypted off-site backups of Postgres and MariaDB volumes. Specific provider listed in the DPA.
7. Data residency
By default, all production data sits on Vultr infrastructure in the United States. EU residency (Frankfurt) becomes available with milestone M9 of our roadmap. We do not transfer Customer Data outside the elected region except for encrypted, off-region backups, which are encrypted with keys held in the production region.
8. Your rights and how to exercise them
Where you are a natural person whose personal data we hold as a controller (e.g. you are the Splitsoft account holder), you may exercise the following rights subject to applicable law:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion, subject to retention obligations above.
- Portability — receive a machine-readable export.
- Objection / restriction — object to processing based on legitimate interest.
Authenticated Customers can self-serve via the data endpoints in the admin panel: /api/data-export (download), /api/data-erasure (delete), /api/data-portability (machine-readable handoff). Anyone may also email privacy@splitsoft.com; we respond within 30 days.
Where you are a Recipient (you received an email sent through us by one of our Customers), Splitsoft is not the controller of your data. We will route your request to the relevant Customer; you may identify the Customer from the unsubscribe footer of the email you received.
9. Cookies
The marketing site (email.splitsoft.com) sets no analytics or advertising cookies. The admin panel sets a single first-party session cookie issued by NextAuth (next-auth.session-token), strictly necessary to keep you logged in. We do not embed third-party trackers.
10. Security
Our technical and organizational measures are described on our security page. We will notify affected Customers of a confirmed personal-data breach without undue delay and in any event within 72 hours of becoming aware, as required by Art. 33 GDPR and our DPA.
11. Children
The Service is not directed at children under 16 and we do not knowingly process their personal data.
12. Changes
We will post material changes to this Policy at least 30 days before they take effect, and notify the account email of record. Historic versions are archived on request.
13. Contact and complaints
Questions: privacy@splitsoft.com. EU/UK users have the right to lodge a complaint with their local supervisory authority. Our EU representative under Art. 27 GDPR will be appointed before EU launch (M9). [REVIEW: appoint Art. 27 rep before EU GA.]