Legal
Privacy Policy
Last updated: July 2026
This Privacy Policy describes how PostTo ("we", "us", "our") collects, uses, and protects personal data when you use the PostTo service ("Service"). PostTo is hosted in Europe and operated by Lindgaard.net (org. nr. 987 032 596), Norway.
1. Who is the data controller?
PostTo is the data controller for account holder data (the information you provide when you register and use the dashboard). For submission data collected through your endpoints, you are the data controller and PostTo is your data processor acting on your instructions. This processor relationship is governed by our Data Processing Agreement.
2. Data we collect
Account data
When you register, we collect your name and email address. If you subscribe to a paid plan, billing details (handled by Stripe — see sub-processors below) are collected.
Usage and log data
We collect server logs including IP addresses, browser user agents, and request metadata. This data is used for security, abuse prevention, and diagnostics. We do not sell this data.
Submission data
Your end-users' form submissions — including any personal data they submit — are stored encrypted at rest in our database. The retention period is set by your plan (7 days on Free, 30 on Starter, 90 on Pro, 365 on Scale). After the retention period expires, submission bodies (names, email addresses, messages, and all other field values) are automatically purged. Only non-personal metadata (status, timestamps, spam scores) is retained for analytics.
IP addresses from submissions
We record the IP address of the request that submitted the form for spam detection and abuse prevention. You may enable "privacy mode" on an endpoint to store a hashed/truncated IP address instead of the raw address.
3. How we use your data
We use the data we collect to:
- provide and operate the Service;
- route form submissions to your destination email and/or webhooks;
- detect and filter spam;
- enforce rate limits and quotas;
- send transactional notifications (delivery failures, bounces, AI entitlement changes);
- process payments and manage subscriptions;
- diagnose issues and improve the Service;
- comply with legal obligations.
We do not use your submission data to train AI models, sell to third parties, or serve advertising.
4. Legal basis for processing (GDPR)
For account holders in the EEA, our legal bases are:
- Contract — processing necessary to provide the Service you signed up for;
- Legitimate interests — security, spam/abuse prevention, and service improvement;
- Legal obligation — where required by applicable law;
- Consent — for optional features such as AI spam classification (see below).
5. Sub-processors
We use the following sub-processors to operate the Service. All sub-processors are contractually bound to appropriate data protection obligations.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Lettermint | Transactional email delivery | EU |
| Postmark (ActiveCampaign) | Backup transactional email delivery (only if our primary provider is unavailable) | USA (SCCs) |
| Stripe | Payment processing and billing | USA / EU (SCCs) |
| Anthropic opt-in only | AI spam classification (optional, per-endpoint) | USA (SCCs) |
| Plausible Analytics | Cookieless website analytics on our marketing pages | EU |
| Google (Google Ads) | Advertising conversion tracking on our marketing and sign-up pages | USA (SCCs) |
Anthropic (AI spam classification)
If you enable AI spam filtering on an endpoint, submission content (subject, message, sender name, sender email) is sent to Anthropic's API for classification. This is entirely opt-in and off by default. You must explicitly enable it per endpoint and acknowledge the sub-processor notice before activation. Anthropic does not use PostTo submission data to train its models under our API agreement.
Baseline spam filtering (honeypot and heuristics) is always on and entirely first-party — no data leaves our infrastructure.
Plausible Analytics (website analytics)
Our marketing pages (postto.dev outside the dashboard) use Plausible Analytics, a privacy-friendly analytics service hosted in the EU. Plausible does not use cookies, does not collect or store any personal data, and does not track visitors across websites or devices. It reports aggregate, anonymised traffic statistics (e.g. page views and referrers) that cannot be tied back to an individual. Plausible is not used on the authenticated dashboard.
When you successfully register, our server reports a "Signup" conversion event to Plausible so we can measure how many visitors become customers. This event is sent directly from our backend (not the browser) and includes only the request's IP address and browser user agent — the same non-identifying signal Plausible's script would otherwise collect — which Plausible uses transiently to de-duplicate visits and discards; it is not stored against your account.
Google Ads (advertising conversion tracking)
Our marketing pages and sign-up/login pages load Google's gtag.js tag to measure the performance of our Google Ads
campaigns. Unlike Plausible, this is a cookie-based, identifiable tracking mechanism: Google sets cookies in your browser (e.g.
_gcl_au) and, where you arrived via a Google Ads click, may associate your visit with that ad click for conversion
measurement. When you successfully create an account, a "Signup" conversion event is sent to Google from your browser on the next
page you load.
This tracking only runs on our public marketing pages and the login/registration screens — never on the authenticated dashboard or in connection with submission data.
6. Data retention
We retain different categories of data for different periods:
- Account data — retained while your account is active, and deleted within 30 days of account deletion.
- Submission bodies (PII) — automatically purged after the retention period set by your plan: 7 days (Free), 30 days (Starter), 90 days (Pro), 365 days (Scale). You may also purge data manually at any time from the dashboard.
- Submission metadata (status, spam scores, timestamps, non-PII) — retained for analytics and audit purposes for up to 12 months after purge.
- Audit logs — security-sensitive actions (secret rotation, destination changes) are retained for 12 months.
- Billing records — retained as required by applicable tax and accounting law (typically 7 years).
7. Data security
We implement appropriate technical and organisational measures to protect personal data:
- Submission content (fields, subject, message, sender name) is encrypted at rest using AES-256.
- Endpoint secrets and webhook secrets are stored encrypted and cannot be retrieved — only rotated.
- All data is transmitted over TLS.
- Access to production data is limited to authorised personnel.
8. Your rights (GDPR)
If you are located in the EEA, UK, or another jurisdiction with equivalent rights, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your personal data. You can delete your account and all associated data at any time from your account settings.
- Restriction — request that we restrict processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format. Submissions can be exported as CSV from the dashboard.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent (e.g. AI classification), you may withdraw it at any time by disabling the feature in the dashboard.
To exercise these rights, email us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In Norway, that is Datatilsynet.
9. Cookies and analytics
We use the following cookies:
- Session cookie — required to keep you logged in. This is a strictly necessary cookie.
- Appearance preference (
flux.appearance) — stores your dark/light mode preference inlocalStorage. No personal data. - Google Ads cookies (e.g.
_gcl_au) — set by Google'sgtag.json our marketing and sign-up/login pages to measure Google Ads campaign performance, including sign-up conversions. These are advertising cookies, not strictly necessary ones.
Our website analytics (Plausible) is cookieless — see above. Google Ads cookies are only set on our public marketing and authentication pages, never on the dashboard.
10. Data transfers
PostTo's primary infrastructure is located in Europe, and email delivery via Lettermint is hosted entirely within the EU. Where we use sub-processors based outside the EEA (Stripe, Anthropic, Google, and Postmark as a backup email provider), we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism to ensure adequate protection. Lettermint and Plausible Analytics are hosted entirely within the EU, so no transfer safeguard is required for that processing.
11. Children's privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.
12. Changes to this policy
We may update this Privacy Policy. We will notify registered users by email of material changes at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
For privacy-related questions or to exercise your rights:
Lindgaard.net
Org. nr. 987 032 596
Solstien 42, 8445 Melbu, Norway
Email: [email protected]
See also: Terms of Service · Data Processing Agreement