Legal
Privacy Policy
This policy explains what we collect, why we collect it, who processes it on our behalf and how you and your contacts can exercise your rights.
Last updated: August 10, 2026
Data we collect from customers
- Account data: name, email address, password hash, team membership and role.
- Billing data: plan, usage counters and invoice history. Card details are handled by our payment processor — we never store card numbers.
- Sending configuration: verified domains, DNS verification status, sender names and reply-to addresses.
- Product usage: pages visited in the app, actions taken, and error diagnostics used to fix bugs.
Data you upload about your contacts
When you import contacts you decide what we store: email address, name, tags and any custom fields you add. We process this data only to deliver the campaigns and automations you configure and to produce your reporting. We never email your contacts on our own behalf, sell your lists, or use them to enrich anyone else's data.
Engagement events (delivered, opened, clicked, bounced, complained, unsubscribed) are recorded per contact so you can measure results and keep your list clean. Opens are tracked with a small image; clicks are tracked by wrapping links.
Legal bases
- Performance of a contract: operating your account and sending the campaigns you request.
- Legitimate interests: securing the platform, preventing abuse and protecting shared sending reputation.
- Legal obligation: retaining unsubscribe and complaint records required by bulk-sender and anti-spam law.
Subprocessors
We use a small set of vendors to run the service: cloud hosting and database providers for application data, an email delivery provider for outbound sending and feedback notifications, and a payment processor for subscriptions. Each is bound by contract to process data only on our instructions and with appropriate safeguards. A current list is available on request.
Retention
- Contacts and campaigns: kept while your account is active; deleted within 60 days of cancellation.
- Engagement events: retained up to 24 months, then aggregated into totals.
- Suppression records (unsubscribes, hard bounces, complaints): kept indefinitely — deleting them would let a previously opted-out address be emailed again.
- Invoices and tax records: retained as required by law.
Security
Data is encrypted in transit and at rest. Access to production data is limited to personnel who need it, and every account's records are isolated at the database level so one customer can never read another's contacts or reporting. We recommend enabling a strong, unique password and reviewing your team's roles regularly.
Your rights
You may access, correct, export or delete your account data from within the app, or by writing to us. If you are a recipient of an email sent through wepamail, use the unsubscribe link in that message to manage your preferences, or contact the sender directly — they control the list you are on. We will forward requests we cannot action ourselves to the relevant sender.
To make a request, email support@wepamail.com. We respond within 30 days.
Cookies
We use strictly necessary cookies and local storage to keep you signed in and remember interface preferences. We do not use advertising cookies on the application.
Children
The service is not directed to children and we do not knowingly collect data from anyone under 16.
Changes
We will announce material changes to this policy in the app or by email before they take effect, and update the date at the top of this page.
Questions about this document? Write to support@wepamail.com.
