Skip to content

Legal

Privacy Policy

Last updated: July 2026

This Privacy Policy describes how PostTo ("we", "us", "our") collects, uses, and protects personal data when you use the PostTo service ("Service"). PostTo is hosted in Europe and operated by Lindgaard.net (org. nr. 987 032 596), Norway.

1. Who is the data controller?

PostTo is the data controller for account holder data (the information you provide when you register and use the dashboard). For submission data collected through your endpoints, you are the data controller and PostTo is your data processor acting on your instructions. This processor relationship is governed by our Data Processing Agreement.

2. Data we collect

Account data

When you register, we collect your name and email address. If you subscribe to a paid plan, billing details (handled by Stripe — see sub-processors below) are collected.

Usage and log data

We collect server logs including IP addresses, browser user agents, and request metadata. This data is used for security, abuse prevention, and diagnostics. We do not sell this data.

Submission data

Your end-users' form submissions — including any personal data they submit — are stored encrypted at rest in our database. The retention period is set by your plan (7 days on Free, 30 on Starter, 90 on Pro, 365 on Scale). After the retention period expires, submission bodies (names, email addresses, messages, and all other field values) are automatically purged. Only non-personal metadata (status, timestamps, spam scores) is retained for analytics.

IP addresses from submissions

We record the IP address of the request that submitted the form for spam detection and abuse prevention. You may enable "privacy mode" on an endpoint to store a hashed/truncated IP address instead of the raw address.

3. How we use your data

We use the data we collect to:

We do not use your submission data to train AI models, sell to third parties, or serve advertising.

4. Legal basis for processing (GDPR)

For account holders in the EEA, our legal bases are:

5. Sub-processors

We use the following sub-processors to operate the Service. All sub-processors are contractually bound to appropriate data protection obligations.

Sub-processor Purpose Data location
Lettermint Transactional email delivery EU
Postmark (ActiveCampaign) Backup transactional email delivery (only if our primary provider is unavailable) USA (SCCs)
Stripe Payment processing and billing USA / EU (SCCs)
Anthropic opt-in only AI spam classification (optional, per-endpoint) USA (SCCs)
Plausible Analytics Cookieless website analytics on our marketing pages EU
Google (Google Ads) Advertising conversion tracking on our marketing and sign-up pages USA (SCCs)

Anthropic (AI spam classification)

If you enable AI spam filtering on an endpoint, submission content (subject, message, sender name, sender email) is sent to Anthropic's API for classification. This is entirely opt-in and off by default. You must explicitly enable it per endpoint and acknowledge the sub-processor notice before activation. Anthropic does not use PostTo submission data to train its models under our API agreement.

Baseline spam filtering (honeypot and heuristics) is always on and entirely first-party — no data leaves our infrastructure.

Plausible Analytics (website analytics)

Our marketing pages (postto.dev outside the dashboard) use Plausible Analytics, a privacy-friendly analytics service hosted in the EU. Plausible does not use cookies, does not collect or store any personal data, and does not track visitors across websites or devices. It reports aggregate, anonymised traffic statistics (e.g. page views and referrers) that cannot be tied back to an individual. Plausible is not used on the authenticated dashboard.

When you successfully register, our server reports a "Signup" conversion event to Plausible so we can measure how many visitors become customers. This event is sent directly from our backend (not the browser) and includes only the request's IP address and browser user agent — the same non-identifying signal Plausible's script would otherwise collect — which Plausible uses transiently to de-duplicate visits and discards; it is not stored against your account.

Google Ads (advertising conversion tracking)

Our marketing pages and sign-up/login pages load Google's gtag.js tag to measure the performance of our Google Ads campaigns. Unlike Plausible, this is a cookie-based, identifiable tracking mechanism: Google sets cookies in your browser (e.g. _gcl_au) and, where you arrived via a Google Ads click, may associate your visit with that ad click for conversion measurement. When you successfully create an account, a "Signup" conversion event is sent to Google from your browser on the next page you load.

This tracking only runs on our public marketing pages and the login/registration screens — never on the authenticated dashboard or in connection with submission data.

6. Data retention

We retain different categories of data for different periods:

7. Data security

We implement appropriate technical and organisational measures to protect personal data:

8. Your rights (GDPR)

If you are located in the EEA, UK, or another jurisdiction with equivalent rights, you have the right to:

To exercise these rights, email us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In Norway, that is Datatilsynet.

9. Cookies and analytics

We use the following cookies:

Our website analytics (Plausible) is cookieless — see above. Google Ads cookies are only set on our public marketing and authentication pages, never on the dashboard.

10. Data transfers

PostTo's primary infrastructure is located in Europe, and email delivery via Lettermint is hosted entirely within the EU. Where we use sub-processors based outside the EEA (Stripe, Anthropic, Google, and Postmark as a backup email provider), we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism to ensure adequate protection. Lettermint and Plausible Analytics are hosted entirely within the EU, so no transfer safeguard is required for that processing.

11. Children's privacy

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.

12. Changes to this policy

We may update this Privacy Policy. We will notify registered users by email of material changes at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For privacy-related questions or to exercise your rights:

Lindgaard.net
Org. nr. 987 032 596
Solstien 42, 8445 Melbu, Norway
Email: [email protected]


See also: Terms of Service · Data Processing Agreement