Privacy Policy & Data Protection
How eMailBase collects, uses, stores, and protects personal data — including strict compliance with the Google API Services User Data Policy.
Last updated: September 1, 2026
eMailBase (hereinafter referred to as "we", "us", "our") respects the privacy of customers, workspace users, email subscribers and website visitors. This privacy policy describes the types of information we process, the purposes for which we use it, our legal basis, your rights and the data protection measures within the scope of the service.
This policy should be read in conjunction with the Terms of Service, the Anti-spam Policy and the Data Processing Agreement (DPA).
1. Scope
This policy applies to:
- Visitors to emailbase.net website and related subdomains;
- Customers who register for and use the eMailBase platform, across all service plans;
- Sub-users are invited by customers to join the workspace;
- Subscribers receive emails (subscribers) whose data is put into the platform by customers.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable individual.
- Subscriber Data:Data that customers upload, sync, or collect through the platform about their email recipients.
- Workspace: The eMailBase workspace that customers use for campaign management, automation, and contacts.
- BYO (Bring Your Own): Sending infrastructure autonomy model — customers connect themselves to email sending providers (Amazon SES, SendGrid, Mailgun, SMTP, Gmail OAuth).
- Data Controller: The party that determines the purposes and means of processing personal data — typically the customer for Subscriber Data.
- Data Processor: Party that processes data on behalf of the Controller — eMailBase plays this role with respect to Subscriber Data.
3. Data we collect
We may collect and process the following groups of data:
3.1. Account information
Full name, email address, phone number (optional), company name, payment information and login information when you register or contact us.
3.2. Workspace configuration data
Configure sending providers (encrypted API keys), domain settings, automation settings, email templates, sending lists, and other settings in the workspace.
3.3. Technical Data and Activity Logs
IP address, browser type, operating system, visited pages, access times, workspace activity logs and technical diagnostic data necessary for security and service operation.
3.4. Customer-Generated Content
Email content, designs, images, attachments, and other marketing materials customers create in the workspace.
3.5. Subscriber Data
Information that customers put into the platform about email recipients, including but not limited to: email addresses, full names, custom fields, taxonomy tags, interaction history (opens, clicks, unsubscribes), and enrichment data from SocialEnrich (when customers enable this feature).
4. How We Use Data
We use collected data for the following purposes:
- Service provision: Create and maintain accounts, operate workspaces, handle campaigns, execute automation, coordinate email sending via customer-connected providers.
- System security: Detect and prevent unauthorized access, fraud, service abuse and security threats.
- Customer support: Respond to requests, handle technical problems and provide user instructions.
- Service Improvement: Analyze aggregate (non-personally identifiable) usage trends to improve features, performance and user experience.
- Legal compliance: Meet legal obligations, requests of competent authorities and resolve disputes.
- Service Communications: Send important account notifications, service updates, policy changes, and security information.
Commitment: eMailBase does not use customer Subscriber Data for eMailBase's own advertising or marketing purposes or to sell to third parties.
5. Legal basis for data processing
Depending on the type of data and applicable law, we rely on one or more of the following legal bases:
- Performance of contract: Processing necessary to provide services in accordance with the agreed Terms of Service.
- Consent: When you provide explicit consent for a specific purpose (for example, receiving marketing newsletters from eMailBase).
- Legitimate interests: When processing is necessary for legitimate business interests without undue prejudice to your rights (e.g. system security, aggregated analytics).
- Legal obligations: When we are required by law to retain or provide information.
6. BYO Model and Sending Provider Data
eMailBase operates under the BYO (Bring Your Own) model — customers connect to their own email provider. This means:
- API keys and sending provider credentials (Amazon SES, SendGrid, Mailgun, SMTP) are encrypted at rest and are only used to coordinate email delivery upon customer request.
- eMailBase does not have direct access to the sending provider's administrative account. We only use API keys within the scope of authorization granted by the customer.
- Email is sent from the customer's chosen provider's infrastructure, not from eMailBase's servers. Sending reputation (IP, domain name) belongs to the customer.
- Customers are responsible for complying with the terms of service of the sending provider they connect to.
7. Cookies & Tracking Technologies
The website and eMailBase platform use cookies and similar technologies for the following purposes:
- Necessary cookies: Maintains login sessions, security and basic platform functionality. These cookies cannot be disabled.
- Analytics cookies: Collect aggregate information about how users interact with the website to improve the experience (e.g. Google Analytics). You can refuse this group of cookies.
- Preference cookies: Remember interface preferences, language and personal settings.
You can manage cookies through your browser settings. Disabling some cookies may affect the functionality of the service.
8. Google API Services & Limited Use Requirements
eMailBase allows customers to connect Google accounts (Gmail, Google Workspace) via OAuth 2.0 protocol to send emails 1-on-1 from sales staff's personal mailboxes.
8.1. OAuth Scopes
When you connect your Google account, eMailBase only requests the minimum permissions necessary to perform email functionality, including:
- Permission to send emails on your behalf via the Gmail API;
- Permission to read basic profile information (name, email address) to show sender identification.
8.2. Compliance Commitments
eMailBase's use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including Limited Use requirements.
8.3. Limited Use Commitments
eMailBase is committed to complying with the following Usage Limit requirements for data received from Google APIs:
- Used only for user-visible features: Google data is only used to provide or improve features that users see and interact with directly in the eMailBase (sending emails from Gmail) app.
- Not used for advertising: Google data is not used to display advertising, including retargeting, personalization or interest advertising.
- No transfer to third parties: Google data is not transferred to third parties unless: (a) necessary to provide or improve user visibility, (b) to comply with law, or (c) in a merger/acquisition transaction on the condition that the recipient commits to equivalent compliance.
- Not used for AI/ML training: Google data is not used to train general machine learning or artificial intelligence models.
- Restricted reading of data by humans: eMailBase staff do not read your Google data unless: (a) you have explicitly agreed to view the specific data (e.g., technical support), (b) necessary for security reasons, or (c) required by law.
8.4. Revoking Access
You can revoke eMailBase's Google OAuth access at any time by:
- Disconnect your Google account in eMailBase sending server settings;
- Revoke access at Google app permissions management page.
After revocation, eMailBase will not be able to send email from that Google account and will delete the saved access token.
9. Data Sharing & Transfer
eMailBase does not sell, rent or trade your personal data to third parties for commercial purposes. We only share data in the following cases:
- Backend service providers: Partners who provide cloud infrastructure, payments, analytics, and technical support services needed to operate the platform. All are subject to appropriate security constraints.
- Email sending provider (BYO): When you send a campaign, recipient data is passed to the sending provider you connect yourself to (SES, SendGrid, Mailgun, Gmail). This is within the normal range of service operations.
- Legal requests: When there is a legal request from a competent state agency, court order or mandatory legal process.
- Protection of rights: When necessary to protect the rights, property or safety of eMailBase, its customers or the public.
- Corporate transactions: In the event of a merger, acquisition or asset sale, data may be transferred to the recipient provided the recipient commits to a comparable privacy policy.
10. International Data Transfers
eMailBase can process data at data centers in many geographical areas. When data is transferred outside the European Economic Area (EEA) or areas with equivalent regulations, we apply appropriate safeguards including:
- Standard Contractual Clauses (SCC) approved by the European Commission;
- Additional technical and organizational safeguards in accordance with data protection authority recommendations.
11. Data security
eMailBase applies reasonable technical and organizational measures to protect data, including:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest (drive encryption and sensitive data such as API keys).
- Access control: Decentralization according to the principle of least authority, multi-factor authentication for the administration system.
- Monitoring: Monitor access logs, detect anomalies and security alerts.
- Backup: Periodic backups with the ability to restore in case of failure.
Customers are also responsible for account security, using strong passwords, managing sub-user permissions, and protecting sending-provider credentials.
12. Data Retention & Deletion
We retain data for as long as necessary for the following purposes:
- Providing services under an effective contract;
- Comply with legal obligations (e.g. tax filings, accounting);
- Dispute resolution and agreement enforcement;
- Maintain security and prevent fraud.
When account is canceled or service ends:
- Customers have reasonable time (minimum 30 days) to export data before deletion;
- Workspace Data and Subscriber Data will be deleted or anonymized according to internal procedures;
- Minimum amounts of data may be retained if required by law.
13. Your Rights
Depending on the laws that apply in your area, you may have some or all of the following rights:
13.1. According to GDPR (European Union / United Kingdom)
- Access rights: Request a copy of the personal data we are processing about you.
- Right to edit: Request to correct inaccurate information or supplement missing information.
- Right to erasure: Request deletion of personal data in certain circumstances.
- Right to restriction of processing: Request to suspend data processing while a dispute is resolved.
- Right to data portability: Receive data in a structured, commonly used and machine-readable format.
- Right to object: Object to data processing based on legitimate interests.
- Right to complain: File a complaint with the data protection authority in your country of residence.
13.2. According to CCPA/CPRA (California, USA)
- Right to know: Request to know what personal data is collected, used and shared.
- Right to erasure: Request deletion of collected personal data.
- Right to refuse sale: eMailBase does not sell personal data. If this changes, we will provide an opt-out mechanism.
- Right to non-discrimination: You will not be discriminated against when exercising your privacy rights.
13.3. According to Decree 13/2023/ND-CP (Vietnam)
Data subjects in Vietnam have the right to know, consent, access, edit, delete, limit processing, object to processing and complain in accordance with the law on personal data protection.
To exercise any of the above rights, please contact hi@emailbase.net. We will respond within the legal time limit (normally 30 days).
14. Children's Privacy
eMailBase Services are not intended for use by persons under 16 years of age (or the minimum age according to local law). We do not knowingly collect personal data from children. If we discover that we have collected children's data, we will delete it immediately. Parents or guardians may contact hi@emailbase.net to request deletion.
15. Policy Changes & Contact
We may update this privacy policy from time to time to reflect changes in operations, technology or law. Any important changes will be notified via email or notification in the workspace before taking effect. The "Last Updated" date at the top of the page will be adjusted accordingly.
If you have questions, requests or complaints regarding the privacy policy, please contact:
- Email: hi@emailbase.net
- Subject: Specify "Privacy request" or "Security question"