Privacy Policy
testmail.app | Last updated: 24 September 2026 (see change log)

Your privacy is important to us. We may use or need your email address, phone number, and similar contact details to operate your account and keep it secure. We never sell or otherwise monetize your personal information, and we respect your browser's opt-out and Do Not Track settings. This Privacy Policy ("Policy") details our privacy practices and how you can exercise your rights under this Policy and the privacy legislation applicable in your jurisdiction. Details on everything we collect, why, and your rights are below.

Information We Collect and Store

We collect, store, and use a few types of information. We only collect information that we need to provide and improve our services. We collect basic personal information like names and email addresses to identify you and communicate with you. We may use or need your email address, phone number, or similar contact details to verify your identity, secure your account, and communicate with you. When you subscribe to any paid tier of our service, we collect additional personal information for billing purposes like company names, billing addresses, and payment methods. We do not store your payment card data ourselves; all sensitive billing information like credit card numbers is passed to and stored by Stripe, our Payment Card Industry (PCI) Standard compliant third-party payment processor.

We collect technical information like which browser, device, IP address, and operating system you use to facilitate troubleshooting, bug discovery, crash reporting, and other diagnostic activities. We also collect information about how you interact with our website like your referral source, which pages you viewed, and whether you encountered any errors, to facilitate product development, analytics, and personalization.

We never intentionally collect what we consider to be sensitive information, which includes race or ethnic origin, political opinions, religious beliefs, medical conditions, passport numbers, or other similar data.

Test Email Data

We receive emails sent to your test inboxes as the core function of our service. The contents of these emails are controlled by you and your systems; you are responsible for the data you send to your test inboxes, and we recommend not sending real personal data of third parties to test inboxes. Where test emails contain personal data, we act as a processor on your behalf.

Communications

We use your contact information, such as your email address and phone number (if provided), for relevant communications with you regarding our services such as account, billing, and security notifications and occasional product updates or announcements. You may choose to stop receiving communications, except for certain important billing notifications, by signing in and reviewing your notification preferences or by contacting us.

Keeping Your Data Safe

We take security very seriously. We have strict access controls on your data that ensure only select employees can review service data for valid business needs such as providing customer service and evaluating service performance and use. We do everything we can within commercially acceptable means, including utilizing firewalls, cryptographic techniques, nondisclosure agreements, and other standard measures, to protect your personal information from loss or theft, as well as unauthorized access, disclosure, copying, use or modification.

If we become aware of a data breach affecting your personal information, we will notify you and the relevant supervisory authorities without undue delay, in accordance with applicable law.

Your Responsibilities

When you sign up at testmail.app, we verify your identity by sending a code (and link) via email and SMS or phone call (if applicable). For your protection, you should make sure that your email accounts and your phones (if applicable) are secure and accessible to you only. The security of your account depends in part on how secure your emails and phones (if applicable) are.

Your Rights

You have the right to request access to personal information we hold about you, request that we correct, update, or delete your personal information, request a copy of your personal information in a portable format (data portability), request that we restrict processing of your personal information, object to our processing of your personal information, revoke consent to being contacted by email or any other means of communication, and opt out of any and all marketing communications. To exercise any of these rights, please contact us through the contact information below. We will respond to your request within one month. You also have the right to lodge a complaint with your local data protection supervisory authority.

US State Privacy Rights

We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar US state privacy laws. Residents of California and other states with comprehensive privacy laws have the right to know what personal information we collect (described above), to access, correct, and delete it, and to non-discrimination for exercising these rights. We respect browser-based opt-out signals, including Global Privacy Control (GPC) and Do Not Track settings. To exercise your rights, contact us using the details below.

Automated Decision-Making

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

Children's Privacy

Our services are not directed at, and we do not knowingly collect personal information from, anyone under the age of 16. If you believe a child has provided us with personal information, please contact us and we will delete it.

International Transfers (GDPR)

We handle the personal data of users in the EEA, the UK, and Switzerland in accordance with the GDPR. Our services are managed by our team in Canada. As the European Commission considers Canada's data protection laws adequate (see adequacy decisions and PIPEDA), your personal information may be legally transferred from the EEA to Canada.

We use third-party service providers for the networking, infrastructure, and software services necessary to deliver our services to you. These third-party providers may process and store your personal data outside of the EEA, the UK, and Switzerland, including in Canada and the US. We rely on adequacy decisions when data is sent to Canada, and on the EU-US Data Privacy Framework (and its UK and Swiss extensions) and/or Standard Contractual Clauses when data is sent to the US, to ensure that your personal information is lawfully transferred under EU, UK, and Swiss law.

Sub-processors (GDPR)

Our third-party sub-processors may have access to your personal information only to perform specific tasks on our behalf. They are obligated to not disclose or use your information for any other purpose and to maintain GDPR-compliant privacy practices.

EntityLocationPurpose
Amazon Web Services, Inc.USACloud Infrastructure
Google LLCUSACloud Infrastructure
Microsoft CorporationUSACloud Infrastructure
Cloudflare, Inc.USANetworking
Datadog, Inc.USAInfrastructure Monitoring
CrowdStrike Holdings, Inc.USALog Analytics, Security
Stripe, Inc.USAPayment Processing
Slack Technologies, LLC (Salesforce)USACommunication
Help Scout PBCUSACustomer Support
Nolt Software Inc.CanadaCustomer Feedback Management
PostHog Inc.USALog Analytics
FullStory Inc.USALog Analytics
Cookies

We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit so we can understand how you use our site and serve you content based on preferences you have specified.

We respect your browser's opt-out settings: if your browser sends a Do Not Track or Global Privacy Control signal, we honor it. If you do not wish to accept cookies from us, you can also instruct your browser to refuse cookies from our website, with the understanding that we may be unable to provide you with some of your desired services without them.

Governing Law

This Policy is governed by the laws of Canada. Any disputes arising from or relating to this Policy will be subject to the jurisdiction of the courts of Canada.

Changes to our Privacy Policy

At our discretion, we may update our privacy policy. Any changes will be reflected here, so we encourage you to visit this page regularly. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and personal information.

Contact Us

If you have any questions or concerns, please contact us through our or send an email to [email protected]


Change Log
We are fully transparent about any changes we make: they are detailed here.
24 September 2026

Updates to subprocessors: removed Sentry and Typeform, added Nolt, PostHog, and FullStory.

8 July 2026

Replaced Privacy Shield references with the EU-US Data Privacy Framework and Standard Contractual Clauses; added test email data, US state privacy rights, automated decision-making, children's privacy, breach notification, and governing law sections; expanded user rights; added Do Not Track / Global Privacy Control support; added GDPR compliance statement; clarified that payment card data is stored by our payment processor, not by us; corrected sub-processor names and locations.

25 Jan 2023

Updates to subprocessors: removed Twilio and Humio, added CrowdStrike.

18 May 2020

Added clarifying language related to GDPR, added change log section, added sub-processors, updated contact information, and added opt-in notifications for future privacy policy updates.

31 Jan 2020

Added Your Rights section.