Deliverably
Features FAQs About Contact Join waitlist
Join waitlist

Legal

Privacy Policy

Last updated: August 2026

Privacy Terms DPA Refunds Cookies Security

This Privacy Policy explains how Deliverably (“Deliverably,” “we,” “us,” or “our”) collects, uses, shares, and protects Personal Data. It also describes your rights and how to exercise them.

We aim to provide this notice in a concise, transparent, and accessible form, consistent with Articles 12–14 of the GDPR where those rules apply.

Contact: privacy@deliverably.co
Registered entity: Deliverably, incorporated in US.
Last updated: August 2026

Topics:

  • What data we collect
  • How we collect your data
  • How we use your data (and lawful bases)
  • AI and model training
  • How we store and retain your data
  • Sharing and subprocessors
  • International transfers
  • Marketing
  • Cookies
  • Your data protection rights
  • Automated decision-making
  • Children’s privacy
  • Third-party sites
  • Changes
  • Contact and supervisory authorities

1. About Deliverably

Deliverably provides an AI-assisted email deliverability platform, including tools for domain and IP monitoring (Radar), email content analysis (Clarity), subscriber list validation (Email Validation), and inbox placement / client preview testing (Inbox Testing), accessed primarily via our websites and the hosted console (for example, console.deliverably.co).

We serve business users. Additional modules may be offered as beta or “coming soon” features; this Policy covers Personal Data processed in connection with our Services generally.


2. Scope and roles

2.1 When we are a Data Controller

We act as a controller for Personal Data we process for our own purposes, including:

  • Account registration and authentication
  • Workspace administration and support
  • Billing and subscription management
  • Marketing communications about Deliverably (where permitted)
  • Security, fraud prevention, and product analytics for our sites and console
  • Improving and operating our Services

2.2 When we are a Data Processor

We act as a processor (or equivalent service provider) when customers upload or generate content for processing in the Services under their instructions, including for example:

  • Email addresses and list metadata submitted to Email Validation
  • Email HTML and related creative content submitted to Clarity or Inbox Testing
  • Domain, IP, DNS, DMARC, blacklist, and reputation-related data customers configure in Radar
  • Messages and artifacts captured for Inbox Testing seed / capture flows (headers, MIME content, placement results, preview outputs)

Where we are a processor, the customer’s privacy notice and instructions govern the underlying relationship with end users. End users of a customer’s mailing list or campaigns should contact that customer for data-rights requests relating to the customer’s mailing activities.

Business customers may request a Data Processing Addendum: see the DPA.

2.3 Who this Policy applies to

This Policy applies to Personal Data collected via our marketing sites, dashboards/console, support channels, and related communications. It does not override mandatory local law.


3. What data we collect

3.1 Account and workspace data

  • Name, email address, password (hashed) or SSO/OAuth identifiers
  • Workspace name, slug, plan, and entitlement/quota metadata
  • Role/membership information within a workspace (as features allow)

3.2 Billing data

  • Subscription plan and status
  • Stripe customer identifiers and billing portal activity
  • Payment card and detailed payment data are typically processed by Stripe as a payment processor; we receive limited billing metadata needed to provision the subscription

3.3 Usage and device data

  • IP address, browser/user agent, device type
  • Log data for security and reliability (timestamps, request paths, error codes)
  • Approximate product usage (feature access, job status) needed to operate quotas and support
  • Cookie and similar identifiers described in our Cookie Policy

3.4 Customer content (processor context)

Depending on features used:

Category Examples
Validation inputs Email addresses, batch names, validation results and flags
Creative content HTML emails, subjects, analysis scores, suggested fixes
Radar configuration Domains, IPs, monitor settings, alert channel configs, share-link tokens
Auth / reputation feeds DMARC aggregate report content routed to customer RUA mailboxes; Google Postmaster metrics; Microsoft SNDS metrics
Inbox testing Capture addresses, inbound message content, placement folder results, client preview artifacts

3.5 Integration credentials

  • Google OAuth tokens/scopes for Postmaster Tools (and sign-in, when used)
  • Microsoft SNDS automated access identifiers (for example, GUID) supplied by the customer
  • Alert destinations (email addresses, Slack webhook URLs, HTTPS webhook URLs)

3.6 Communications

  • Support requests and correspondence
  • Optional marketing preferences
  • Waitlist or contact-form submissions on our marketing site

4. How we collect your data

You directly provide most of the data we collect when you:

  • Create an account or sign in
  • Manage a workspace, billing, or integrations
  • Upload email lists, HTML creatives, domains/IPs, or related Customer Content
  • Contact us for support or sales
  • Join a waitlist or submit a form on our website
  • Use the site or console (technical and cookie data)

We may also receive data indirectly from:

  • Payment processors (Stripe)
  • Identity providers (for example, Google) when you choose to sign in or connect Postmaster
  • Reputation providers you connect (Google Postmaster, Microsoft SNDS)
  • Mailbox providers and reporters that send DMARC aggregate reports to addresses you configure with us
  • Analytics providers (for example, Google Analytics on the marketing site)

5. How we use your data

We collect and use Personal Data so that we can:

  1. Provide, operate, and secure the Services
  2. Create and manage accounts and workspaces
  3. Process validations, analyses, monitors, alerts, and inbox tests you request
  4. Connect third-party integrations you enable
  5. Process payments and manage subscriptions via Stripe
  6. Communicate service, security, and administrative messages
  7. Send marketing where we have a lawful basis / consent as required
  8. Monitor abuse, enforce acceptable use, and protect rights and safety
  9. Comply with law and respond to lawful requests
  10. Improve product quality, documentation, and customer experience (using aggregated or de-identified data where practical)

5.1 Lawful bases (GDPR / UK GDPR)

Where GDPR or UK GDPR applies to our controller processing:

Purpose Typical lawful basis
Provide accounts and paid Services Contract (Art. 6(1)(b))
Billing and tax records Contract and legal obligation
Security, fraud prevention, service logs Legitimate interests (Art. 6(1)(f))
Product analytics and improvement (B2B) Legitimate interests
Optional marketing emails Consent or other lawful basis where permitted for B2B
Non-essential analytics cookies Consent where required

For Customer Personal Data we process as a processor, the customer determines the lawful basis; we process under the customer’s documented instructions and our DPA.

5.2 Providing Personal Data

Providing account data (name, email, password or SSO) is required to enter a contract for the console. If you do not provide it, you cannot create or use an account. Providing Customer Content is optional per feature, but the relevant feature will not work without it.

5.3 Artificial intelligence and model training

Some features (notably Clarity) use AI systems to analyze content you submit in order to deliver that feature.

We do not use Customer Personal Data to train, fine-tune, or improve Deliverably’s own foundation or general-purpose AI models. See the DPA for processor terms. Details of security measures are in our Security Policy.


6. How we store your data

We securely store Personal Data primarily in the United States (AWS us-east-1), using access controls, encryption in transit, and other measures described in our Security Policy.

We retain Personal Data only as long as needed for the purposes above, including:

  • Account data — for the life of the account and a reasonable period thereafter for security, disputes, and legal retention
  • Billing records — as required by tax and accounting law (often up to 7 years)
  • Customer content — for the life of the workspace relationship unless deleted earlier by you or per product-specific limits
  • Inbox Testing artifacts — typically retained for about 24 hours, then expired/purged
  • DMARC raw inbound objects — typically deleted after about 30 days
  • Radar observation history — generally retained on the order of 90 days unless a longer monitoring history is configured
  • Validation batches and Clarity designs — while the workspace remains active, unless you delete them earlier
  • Logs — for a limited operational window (typically 30–90 days) unless needed longer for security investigations

When retention ends, we delete or anonymize data by removing it from active systems and allowing backup cycles to expire, subject to legal holds.


7. Sharing and subprocessors

We do not sell Personal Data.

We share Personal Data with:

  • Service providers / subprocessors that help us host, send email, process payments, analyze content, or provide infrastructure (for example: cloud hosting, Stripe, Google, Microsoft, email transport providers).
  • Integration partners you connect, to the extent necessary to operate the integration (for example, retrieving Postmaster metrics).
  • Professional advisors (legal, accounting) under confidentiality.
  • Authorities when required by law or to protect rights, safety, and security.
  • Successor entities in connection with a merger, acquisition, or asset transfer, subject to appropriate protections.

Alert webhooks you configure may receive incident payloads you choose to route — treat webhook URLs as secrets.


8. International transfers

We offer the Services globally. Primary hosting for the console and related workloads is in the United States (AWS us-east-1). Customer and account data may also be processed in the US and in other countries where our subprocessors operate (including the United States for providers such as AWS, Stripe, and Google).

Where we transfer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, we use the European Commission’s Standard Contractual Clauses (and UK/Swiss addenda as applicable), plus supplementary measures where appropriate. Details are in our DPA.


9. Marketing

We may send you information about Deliverably products and services that we think you will find useful, where permitted by law (for example, based on your consent or applicable B2B soft-opt-in rules).

You can opt out of marketing emails at any time by using the unsubscribe link in the message or emailing privacy@deliverably.co. Opting out of marketing does not stop service, billing, or security messages needed to operate your account.

We do not sell your Personal Data to third parties for their marketing.


10. Cookies

We use cookies and similar technologies as described in our Cookie Policy, including:

  • Authentication and session continuity
  • Security (for example, CSRF or abuse prevention)
  • Preferences (for example, theme)
  • Analytics (Google Analytics on the marketing site)

You can control many cookies through your browser settings. Disabling necessary cookies may prevent login or core features from working.


11. Your data protection rights

We want you to be fully aware of your rights. Depending on your location (including where GDPR/UK GDPR applies), you may be entitled to:

  • Right of access — request copies of your Personal Data
  • Right to rectification — request correction of inaccurate data or completion of incomplete data
  • Right to erasure — request deletion of your Personal Data, under certain conditions
  • Right to restrict processing — request that we restrict processing, under certain conditions
  • Right to object to processing — object to certain processing (including processing based on legitimate interests), under certain conditions
  • Right to data portability — request that we transfer data you provided to you or another organization, under certain conditions
  • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing
  • Right to lodge a complaint — with a supervisory authority (see Section 15)

If you make a request, we will respond within one month (or as otherwise required by law). We may need to verify your identity. We generally do not charge a fee unless a request is manifestly unfounded or excessive.

How to exercise: email privacy@deliverably.co.

If we process your data only as a processor for a Deliverably customer, we will direct you to that customer or assist them per our contract.

California and other US state rights

If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information, and to limit use of sensitive personal information where applicable. Deliverably does not sell personal information and does not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We will not discriminate against you for exercising privacy rights.


12. Automated decision-making

We do not use Personal Data to make solely automated decisions that produce legal or similarly significant effects about individuals (GDPR Article 22).

Product features may generate scores, statuses, or recommendations (for example, validation status, Radar findings, Clarity suggestions, inbox placement labels). These tools assist business users; they do not by themselves create legal effects about individuals in the sense of Article 22. Customers remain responsible for how they act on results.


13. Children’s privacy

The Services are for business use and are not directed to children under 16 (or under 13 where that is the applicable threshold). We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data, contact privacy@deliverably.co.


14. Privacy policies of other websites

Our sites may contain links to other websites or integrate third-party APIs (for example Google, Microsoft, Stripe). This Privacy Policy applies only to Deliverably. If you click a third-party link or use a third-party service, you should read their privacy policy. We are not responsible for third-party practices.


15. Changes to this Policy

We keep this Privacy Policy under regular review and place updates on this page (and at docs/legal/privacy-policy.md while in draft). For material changes, we will provide additional notice as required by law (for example, email or in-product notice).


16. Contact us

If you have questions about this Policy, the data we hold about you, or you wish to exercise your rights:

Email: privacy@deliverably.co
Legal: legal@deliverably.co

How to contact a supervisory authority

If you are in the EEA/UK and believe we have not addressed your concern, you may lodge a complaint with your local data protection supervisory authority. For example, in the UK you may contact the Information Commissioner’s Office (ICO): https://ico.org.uk/. EEA residents may find their authority via the European Data Protection Board.


© 2026 Deliverably. All rights reserved.

© 2026 Deliverably. All rights reserved. legal@deliverably.co

For legal inquiries, contact legal@deliverably.co. Privacy requests: privacy@deliverably.co.

Deliverability process made simple.

Features Privacy Terms Cookies Legal Contact