Sendy · Legal
Privacy policy
Last updated:
Sendy is operated by Stanley Masinde in Kenya. This policy explains how Sendy handles personal information when you use our website, sending console, and email API. Sendy sends application emails on behalf of its customers through Amazon Simple Email Service (Amazon SES).
Our role
We determine how account information is used to operate Sendy. For recipient information and email content submitted by customers, we process information on their instructions to provide email delivery. The customer determines why a message is sent, its content, and its recipients, and is responsible for providing their own privacy notice and a lawful basis for sending.
Information we process
- Account information: your name, email address, password hash, and account creation date.
- Access information: session token hashes and expiration times; API key hashes, labels, prefixes, creation dates, and revocation status; password-reset token hashes, expiry times, and which account a reset belongs to.
- Sending identities: domain names, DNS verification records, verification results, and identifiers connecting your account to an SES tenant.
- Email requests: sender and recipient addresses, subjects, plain-text or HTML message content, request identifiers, timestamps, sending attempts, status, errors, and SES message identifiers.
- Session information: browser user-agent, connection IP address, sign-in time, last activity, and expiry. We use these details to show active sessions and help you manage account access.
- Usage records: which account sent a message, when SES accepted it, and the associated sending region and tenant. These records support usage reporting and billing calculations.
Messages can contain personal information about recipients or other people. Include only information needed for the message and avoid submitting sensitive information unnecessarily.
How we use information
We use information to authenticate accounts, validate API requests, verify domains, queue and retry emails, submit messages to SES, report sending status and usage, resolve problems, and protect the service against abuse. We also use account contact information for service communications, including password-reset and password-changed emails, and to respond to requests.
Depending on the information and applicable law, processing is necessary to provide the service under our agreement, meet legal obligations, or pursue legitimate interests such as security and abuse prevention. Where consent is required for another purpose, we must obtain it before that processing.
Service providers and disclosure
Amazon Web Services processes sending identities, tenant information, and email data to verify domains and deliver messages through SES. Sendy also uses SES to send its own account emails, such as password-reset and password-changed notices. Messages also pass to recipients’ email providers. Our hosting and infrastructure providers process information needed to operate Sendy.
We may disclose information when required by law, to respond to a valid legal request, or to investigate abuse and protect rights and security. We do not sell personal information or recipient lists.
International processing
Sendy’s infrastructure, the configured AWS region, and recipients’ email providers can process information in countries other than your own. Where applicable law requires safeguards for these transfers, the operator must establish those safeguards. Contact the operator for the locations and transfer arrangements applicable to your account.
Storage and retention
Sendy stores email content and sending records in its database; messages are not automatically erased when SES accepts them. Revoking an API key or deleting a domain does not delete historical email or usage records. A password-reset record is stored until the link is used or a later reset request for that account replaces it.
We retain information as needed to operate the service, investigate sending problems, prevent abuse, maintain usage and billing records, and meet legal obligations. A fixed retention schedule and automatic deletion period have not yet been established. Request information about retention or deletion from the operator; some records may need to be kept for legal or accounting reasons.
Browser storage and security
The console uses an essential HttpOnly cookie to maintain your signed-in session. Browser JavaScript cannot read this session cookie. A separate request-verification token stays in memory to protect account actions against forged requests. An API key entered into the console stays in memory and clears when the tab reloads or you sign out. These features support authentication rather than advertising.
Passwords are hashed, and stored session tokens, API keys, and password-reset tokens are represented by hashes. The raw reset token appears only in the emailed link, in the fragment after #, so browsers do not send it to Sendy when the page loads. Email content must remain readable to process sending requests. No service can guarantee absolute security; protect your credentials and revoke compromised API keys promptly.
Your rights and requests
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of personal information, object to certain processing, and withdraw consent where processing relies on consent. We may need to verify your identity and may retain information where the law permits or requires it.
If you receive email from a Sendy customer, contact that sender first about your information, consent, or unsubscribe request. We can assist the customer with requests concerning information processed on their behalf. You can also complain to the relevant data protection authority; in Kenya this is the Office of the Data Protection Commissioner.
Contact and changes
For privacy questions or requests to access, correct, or delete information, contact Stanley Masinde in Kenya at [email protected].
We update this policy when our processing changes. The date above identifies the latest revision. Material changes affecting existing customers will be communicated through the service or their account email.