01Scope
This Privacy Policy describes how PostZeno ("PostZeno", "we", "us") collects, uses, and protects personal data in connection with the PostZeno email delivery service available at postzeno.com.
It applies to:
- Visitors to our marketing website
- Customers who register an account or purchase credits
- Recipients of emails sent through our platform (limited to processing on behalf of our customers)
We comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable Chinese personal information laws (PIPL).
02Data We Collect
2.1 Account information
- Email address (required to create an account)
- Hashed password (we never store passwords in plaintext)
- Optional profile information you choose to provide
2.2 Billing information
- For purchases, we use a third-party payment processor. The processor collects your card or bank details directly; we only receive an order ID, payment status, and the email address you used at checkout.
- We do not store your full credit card number, CVV, or bank account number.
2.3 Service usage data
- API request metadata: timestamp, endpoint, IP address, response code
- Email send logs: sender domain, recipient address, subject, status, timestamps
- Email content (body, attachments) is processed transiently for delivery and not retained beyond what is needed for queueing and bounce handling, unless explicitly enabled by the customer for debugging.
2.4 Recipient data
When our customers send emails through PostZeno, we process recipient email addresses and message content as a data processor on their behalf. Recipients should contact the sending company (the data controller) for access or deletion requests.
03How We Use Your Data
- To provide, operate, and maintain the email delivery service
- To authenticate accounts and prevent fraud or abuse
- To process payments and issue receipts
- To send service notifications (security alerts, billing confirmations, important changes)
- To improve product features through aggregated, de-identified analytics
- To comply with legal obligations and respond to lawful requests
We do not sell personal data. We do not use customer email content for advertising or to train machine-learning models.
05Data Retention
| Data Type | Retention |
|---|---|
| Account record | Until account deletion |
| Email send metadata (logs) | 7 to 90 days based on plan, then anonymized |
| Email body and attachments | Discarded after successful delivery; retained up to 72h for retry |
| Billing records | 7 years (legal requirement) |
| Inbound mail (Inbox) | Until user deletes |
06Security
- TLS 1.2+ encryption in transit for all API, SMTP, and dashboard traffic
- Passwords hashed using bcrypt with per-user salts
- Database encryption at rest on managed disks
- Principle-of-least-privilege internal access with audit logging
- Regular dependency scanning and security patching
While we work hard to protect your data, no system is impenetrable. If you suspect unauthorized access to your account, contact [email protected] immediately.
07Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data ("right to be forgotten")
- Export your data in a portable format
- Object to certain processing activities
- Withdraw consent at any time
To exercise any of these rights, email [email protected]. We respond within 30 days.
09Contact
For privacy-related questions or requests, contact our Data Protection team:
01适用范围
本《隐私政策》说明 PostZeno("PostZeno"、"我们")在 postzeno.com 提供邮件投递服务过程中如何收集、使用和保护个人数据。
适用于:
- 访问我们官网的访客
- 注册账户或购买额度的客户
- 通过本平台收到邮件的收件人(仅限代客户处理)
我们遵守欧盟《通用数据保护条例》(GDPR)、美国《加州消费者隐私法案》(CCPA)以及中国《个人信息保护法》(PIPL)。
02数据收集
2.1 账户信息
- 邮箱地址(创建账户必需)
- 哈希后的密码(我们不会以明文形式存储密码)
- 您主动提供的可选资料
2.2 账单信息
- 购买时我们使用第三方支付服务商。支付服务商直接收集您的银行卡或银行账号信息;我们仅获得订单 ID、支付状态和您在结账时使用的邮箱。
- 我们 不会 存储您的完整信用卡号、CVV 或银行账号。
2.3 服务使用数据
- API 请求元数据:时间戳、端点、IP 地址、响应码
- 邮件发送日志:发件域名、收件地址、主题、状态、时间戳
- 邮件正文与附件仅在投递所需的时间内短暂处理,除非客户为调试目的明确开启保留。
2.4 收件人数据
当客户通过 PostZeno 发送邮件时,我们作为客户的 数据处理者 处理收件人邮箱与邮件内容。收件人如需访问或删除数据,应直接联系发送方公司(数据控制者)。
03数据使用
- 提供、运营和维护邮件投递服务
- 账户身份验证,防止欺诈与滥用
- 处理付款并开具收据
- 发送服务通知(安全提醒、账单确认、重要变更)
- 通过聚合、去标识化的分析改进产品
- 履行法律义务,响应合法请求
我们 不会 出售个人数据。我们 不会 将客户邮件内容用于广告投放或训练机器学习模型。
05数据保留
| 数据类型 | 保留期 |
|---|---|
| 账户记录 | 账户删除前 |
| 邮件发送元数据(日志) | 按套餐 7 至 90 天,之后匿名化 |
| 邮件正文与附件 | 投递成功后即丢弃;为重试最多保留 72 小时 |
| 账单记录 | 7 年(法定要求) |
| 收件箱邮件 | 用户删除前 |
06安全措施
- 所有 API、SMTP、控制台流量采用 TLS 1.2+ 传输加密
- 密码使用 bcrypt 加每用户 salt 哈希
- 数据库存储于加密磁盘
- 内部访问遵循最小权限原则并记录审计日志
- 定期依赖扫描与安全补丁更新
尽管我们竭力保护您的数据,但没有任何系统是绝对安全的。如怀疑账户遭未授权访问,请立即联系 [email protected]。
07您的权利
根据所在地区法律,您可能享有以下权利:
- 访问权 — 获取我们保存的您的个人数据
- 更正权 — 更正不准确的数据
- 删除权("被遗忘权")— 删除账户与相关数据
- 数据可携权 — 以可携带的格式导出您的数据
- 反对权 — 对特定处理活动表示反对
- 随时 撤回同意
如需行使上述权利,请发送邮件至 [email protected]。我们将在 30 天内响应。
09联系我们
如有隐私相关问题或请求,请联系我们的数据保护团队: