Legal
Last updated 2026-07-06
1. Overview
JustSMTP Inc. ("JustSMTP", "we", "us") operates an SMTP relay for transactional email on top of Amazon SES. This policy explains what data we collect from you and the messages you send through us, why we collect it, and how long we keep it.
2. What we collect
We collect and process the following categories of data:
- Account data — your email address, hashed password or OAuth identifier, and billing contact information.
- Sending domain data — domains you verify with us, and the DNS records (SPF, DKIM, DMARC) associated with them.
- Credential metadata — labels, creation dates, and last-used timestamps for SMTP credential pairs. Credential passwords are stored only as salted hashes; the plaintext is shown once and never persisted in retrievable form.
- Message metadata and activity logs — sender, recipient, subject line, timestamp, size, and the SMTP/SES response for each relay attempt (sent, deferred, bounced, or dropped).
- Billing data — plan tier, usage against your monthly limit, and invoice history. Card details are handled by our payment processor; we do not store full card numbers.
3. What we do not collect
We do not retain the bodies or attachments of messages you relay through us. Message content passes through our relay to Amazon SES for delivery and is not persisted afterward, beyond the subject line captured in your activity log for troubleshooting and deliverability purposes.
4. How we use this data
We use collected data to operate the relay (authentication, domain verification, delivery, and logging), to meter usage against your plan, to detect abuse and protect sending reputation, to provide support, and to send you account and billing notices. We do not sell your data or the data of the recipients you send to.
5. Sub-processors
We rely on Amazon Web Services (SES, and underlying infrastructure) to deliver mail on your behalf, and a payment processor to handle billing. These sub-processors receive only the data necessary to perform their function and are bound by their own data protection commitments.
6. Retention
Account and domain data is retained for as long as your account is active. Activity log retention follows your plan tier (7, 30, or 90 days, or as agreed for Enterprise) and is automatically purged after that window. Billing records are retained as required by applicable tax and accounting law.
7. Your rights
You can access, export, or delete most account data directly from your dashboard. To request deletion of your account and associated data, or to exercise data subject rights available under your local law (including GDPR or CCPA where applicable), contact us at privacy@justsmtp.com.
8. Security
Data is encrypted in transit and at rest. Access to production systems and logs is limited to personnel who need it to operate the service and is logged and reviewed.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page and, where appropriate, by email.
10. Contact
Questions about this policy can be sent to privacy@justsmtp.com.