JustEmails
PricingSign inStart free trialStart free
Legal

Privacy Policy

This Privacy Policy describes how Velocity Digital Labs LLC (Company, we, us, or our) collects, uses, and protects your personal information when you use the JustEmails platform. We are committed to protecting your privacy and complying with the GDPR and other applicable data-protection laws.

Effective Last reviewed

1. Data We Collect

1.1 Account Information

When you create an account, we collect your name, email address, and password (stored as a cryptographic hash). If you subscribe, we collect billing information through our payment processor (Stripe).

1.2 Email Data

The Service processes and stores emails that you send and receive through your configured domains, including headers, body content, and attachments.

1.3 Domain Configuration Data

We store the domain names you add, DNS configuration records, and domain health check results.

1.4 Usage Data

We collect information about how you use the Service — login timestamps, feature usage, email-volume statistics, and storage consumption.

1.5 Technical Data

We automatically collect IP addresses, browser type and version, operating system, and device information when you access the Service.

1.6 Open and Click Data (Transactional API, optional)

If you send email through our Transactional API, you can switch on open and click tracking for those messages. It is off by default, and it is never applied to mail sent or received through your mailboxes (webmail, IMAP/SMTP clients, forwarding). When you switch it on, we add a small image to the HTML version of each message and route its links through justemails.app; the plain-text version is sent exactly as you wrote it. We then record when the image is loaded (an "open") and which link was followed (a "click"), with the time. We do not store the recipient's IP address or device information with these records, and neither the image nor the links set cookies. Opens are approximate: some mail apps and privacy features load images without the message being read, and others block them. The records are kept with the message's delivery history and are available only to you — in the dashboard, through the API, and to webhooks you configure. For the people you send to, we process this data on your behalf as described in our DPA; you decide whether to track them and are responsible for any notice or consent the law requires.

2. How We Use Your Data

We use the data we collect to:

  • Provide, operate, and maintain the Service
  • Process and deliver emails on your behalf
  • Manage your account and subscriptions
  • Provide customer support
  • Send service-related notifications (billing, security alerts)
  • Monitor and improve the security and performance of the Service
  • Detect and prevent spam, abuse, and fraud
  • Comply with legal obligations

We do not read, scan, or analyse the content of your emails for advertising purposes. Email content is processed only as necessary to provide the Service (spam filtering, virus scanning, delivery).

3. Legal Basis for Processing (GDPR)

Under the GDPR, we process your data based on the following legal bases:

  • Contract performance — processing necessary to provide the Service you have subscribed to.
  • Legitimate interests — processing necessary for security, fraud prevention, and service improvement.
  • Legal obligation — processing required to comply with applicable laws and regulations.
  • Consent — where we rely on your consent (e.g. marketing communications or optional analytics), you may withdraw it at any time.

4. Third-Party Service Providers

We share data with third-party service providers only as necessary to operate the Service. The full list — with locations — lives in the DPA. In summary:

  • Stripe — payment processing, under Stripe's privacy policy.
  • Railway + DigitalOcean — infrastructure hosting for the web app and mail server.
  • Cloudflare — DNS, CDN, and Turnstile bot protection.
  • JustAnalytics — first-party product analytics (our sibling product).

We do not sell, rent, or share your personal information with third parties for their marketing purposes.

5. Data Retention

We retain your data for as long as your account is active and as necessary to provide the Service. Specifically:

  • Account data — retained for the duration of your subscription and for 30 days after account termination to allow data export.
  • Email data — retained for the duration of your subscription. Deleted emails are permanently removed from our servers within 30 days.
  • Open and click records (Transactional API, only when you switch tracking on) — retained with the message's delivery history while your account is active, and deleted with your account.
  • Billing data — retained for up to 7 years as required by tax and accounting regulations.
  • Server logs — retained for up to 90 days for security and debugging purposes.

6. Your Rights (GDPR)

Under the GDPR and other applicable data-protection laws, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate personal data.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to restriction — request restriction of processing of your personal data.
  • Right to data portability — request a copy of your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact privacy@justemails.app. We respond within 30 days. Both data export and deletion are also available self-serve under Settings → Security.

7. Cookies and Similar Technologies

We use strictly necessary cookies to run the Service, and analytics and advertising technologies on our public website:

  • Session cookies — used to maintain your authenticated session. These expire when you log out or after the session timeout.
  • CSRF tokens — used to protect against cross-site request forgery attacks.
  • JustAnalytics — our own first-party analytics and error monitoring. In the UK, EEA and Switzerland the analytics runs cookieless — the visit is counted and nothing is stored on your device — and the error monitoring is not loaded at all, because it cannot run without storing an identifier. Elsewhere it stores a visitor identifier in your browser so repeat visits are not counted as new people. No cross-site tracking in either case.
  • Google Analytics, Google Ads and the Meta pixel — used on our public marketing pages to measure how people find us and whether advertising leads to sign-ups. These are third-party technologies and set their own cookies.

In the UK, EEA and Switzerland we set no analytics or advertising identifier on your device. Our own analytics runs cookieless there, and advertising storage is denied, so no advertising profile is built or stored. The Google and Meta tags still load in that restricted mode and may write a small amount of non-identifying technical data, such as the page that referred you. Because no identifier is stored, we do not ask for consent and show no cookie banner. Elsewhere analytics and advertising storage is on by default. If your browser sends a Global Privacy Control signal we honour it worldwide, regardless of region, and it overrides an earlier acceptance — no analytics loads at all.

We do not use the contents of your email for advertising, analytics or profiling. Message content is never sent to any advertising or analytics provider. The technologies above run on our marketing pages; they are not a means of reading your mail.

Full detail, including the purpose of each technology, is in our Cookie Policy.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • TLS 1.2+ encryption for all data in transit (HTTPS, IMAPS, SMTPS)
  • Encryption at rest for stored secrets and backups
  • Regular security audits and penetration testing
  • Access controls and principle of least privilege
  • Two-factor authentication (TOTP + WebAuthn passkeys) for user accounts
  • Automated threat detection and incident response

9. International Data Transfers

Your data may be transferred to and processed in countries other than your own. Where we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place — such as the EU Standard Contractual Clauses (SCCs, Module Two) approved by the European Commission, plus the UK IDTA Addendum for UK-origin transfers.

10. United States State Privacy Rights

This section applies to residents of US states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas and Oregon. Where these overlap with the GDPR rights in section 6, you may rely on whichever applies to you.

Notice at collection. What we collect and why is set out in sections 1 and 2. In CCPA terms these are: identifiers (name, email address, IP address), commercial information (subscription and billing records), internet activity (how you use the Service), and the contents of electronic communications you send and receive through the Service. We collect them to provide the Service, to bill for it, to secure it, and to market it.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA. We have not sold or shared personal information in the preceding twelve months, and we do not sell or share the personal information of anyone under 16.

Global Privacy Control. We honour the GPC browser signal as a valid opt-out. It applies wherever you are, not only in states that require it, and it overrides an earlier acceptance. You do not need to contact us for it to take effect.

Sensitive personal information. The contents of your email may contain information you consider sensitive. We process it only to deliver, store and display your mail as you have instructed — never to infer characteristics about you, and never for advertising. We do not use or disclose sensitive personal information for any purpose that would carry an opt-out right under the CCPA.

Your rights. Subject to verification, you may request: to know what we collect and why; access to a copy; correction of inaccurate information; deletion; and, where applicable, to opt out of sale, sharing or targeted advertising, and of profiling with legal or similarly significant effects. We do not carry out automated decision-making of that kind.

How to exercise them. Email privacy@justemails.app, or use the self-serve export and deletion tools under Settings → Security. We verify requests against the account email. An authorised agent may act for you with written permission. We respond within 45 days, and may extend once where the law allows, telling you if we do.

No retaliation. We will not deny you service, charge a different price, or provide a lesser standard of service because you exercised a privacy right.

Appeals. If we refuse a request and your state provides an appeal right, reply to our decision and we will reconsider and respond in writing. If we refuse again, you may complain to your state Attorney General.

11. Children's Privacy

The Service is not intended for children under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on the Service at least 30 days before the changes take effect. Prior versions are archived and available on request.

13. Contact Information

For privacy-related questions or to exercise your data rights, contact us at:

Velocity Digital Labs LLC
131 Continental Dr, Suite 305, Newark, DE 19713, United States
Delaware limited liability company, File No. 10509590
Email: privacy@justemails.app
Website: velocitydigitallabs.com

If you are in the EU and believe we have not adequately addressed your data-protection concerns, you have the right to lodge a complaint with your local Data Protection Authority.