1. What we collect
When you use MariMail, we collect the information you give us directly:
- Account details — name, work email, company, role.
- Workspace data — vessels, contacts, lists, campaigns you upload or create.
- Sending accounts — the email inboxes you connect for sending campaigns.
- Billing information — processed through our payments provider; card numbers never touch our servers.
We also collect operational data automatically: IP, browser, timestamps of your actions, and delivery/engagement events for the emails you send through us (opens, clicks, bounces, replies).
2. How we use it
- To run your workspace — matching vessels to contacts, scheduling ETA-triggered sends, showing analytics.
- To keep your account secure — detecting abuse, preventing account takeover.
- To improve the product — anonymised, aggregated usage patterns.
- To bill you — through Stripe.
- To reach you about the service — critical account or security notices only. Marketing emails are opt-in.
3. Third-party data sources
MariMail enriches vessel and contact data through third-party contact enrichment providers and our internal Maribiz index. When you unlock a contact from those sources, we retain the unlocked fields so we don’t re-pay the source for the same person — this benefits every workspace on the platform.
4. Where your data lives
Data is stored in encrypted PostgreSQL databases hosted in the US and EU regions. Backups are retained for 30 days. Redis is used for ephemeral queueing (delivery jobs, rate limits) and does not hold long-term personal data.
5. Sharing
We do not sell your data. We share it only with subprocessors that make MariMail work — email deliverability providers, payments, analytics, error tracking. A full subprocessor list is available on request at [email protected].
6. Your rights
Under GDPR, UK GDPR, and comparable laws, you can access, correct, export, or delete your personal data. Email [email protected] and we’ll respond within 30 days.
7. Retention
Workspace data is kept for the life of your subscription plus 30 days for restore purposes. After that it is permanently deleted. Aggregated, non-identifying metrics may be retained longer.
8. Contact
Questions about this policy? Reach us at [email protected].
