← Back to Home

Privacy Policy

Last updated: January 27, 2026

1. Introduction

Modular Mail ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Email Content Management System service ("Service"). By using the Service, you consent to the data practices described in this policy.

This policy applies to all users of the Service, including visitors, registered users, and paying subscribers. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly when you:

  • Create an Account: Name, email address, password, and workspace information
  • Subscribe: Billing information (processed by Stripe), company name, and billing address
  • Use the Service: Email templates, campaigns, content, images, and other data you create or upload
  • Contact Support: Messages, attachments, and any information you provide in support communications
  • Participate in Surveys: Feedback, opinions, and any other information you choose to provide

2.2 Automatically Collected Information

When you access the Service, we automatically collect:

  • Usage Data: Pages viewed, features used, time spent, clicks, and interaction patterns
  • Device Information: Browser type, operating system, device type, and screen resolution
  • Log Data: IP address, access times, referring URLs, and error logs
  • Cookies and Similar Technologies: Session identifiers, preferences, and authentication tokens

2.3 Information from Third Parties

We may receive information from:

  • Payment Processor (Stripe): Payment status, transaction details, and billing information
  • Analytics Providers: Aggregated usage statistics and performance metrics

3. How We Use Your Information

We use the collected information for the following purposes:

  • Provide the Service: Create and manage your account, process subscriptions, and enable core functionality
  • Process Payments: Handle billing, invoicing, and subscription management through Stripe
  • Improve the Service: Analyze usage patterns, identify bugs, and develop new features
  • Customer Support: Respond to inquiries, troubleshoot issues, and provide technical assistance
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Communications: Send transactional emails (account notifications, billing updates), service announcements, and optional marketing communications
  • Legal Compliance: Comply with legal obligations, enforce our Terms of Service, and protect our rights
  • Analytics: Understand how users interact with the Service to optimize performance and user experience

4. Legal Basis for Processing (UK GDPR)

We process personal data under the following legal bases:

  • Contract Performance: Processing necessary to provide the Service you've subscribed to
  • Legitimate Interests: Improving the Service, preventing fraud, and ensuring security
  • Legal Obligation: Complying with tax, accounting, and other legal requirements
  • Consent: Marketing communications (you may withdraw consent at any time)

5. How We Share Your Information

We do not sell or rent your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We share information with trusted third-party service providers who assist in operating our Service:

  • Stripe: Payment processing and subscription management (subject to Stripe's Privacy Policy)
  • Cloud Hosting: Infrastructure providers that host our servers and databases
  • Email Service: Transactional email delivery for account notifications and system messages
  • Analytics Tools: Usage analytics and performance monitoring (with anonymized or aggregated data where possible)

All service providers are contractually obligated to protect your data and use it only for the specified purposes.

5.2 Workspace Members

If you are part of a team workspace, other workspace members may have access to templates, campaigns, and content you create within that workspace, based on their permission levels.

5.3 Legal Requirements

We may disclose information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:

  • Comply with legal obligations or valid legal processes
  • Protect the rights, property, or safety of Modular Mail, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our Terms of Service

5.4 Business Transfers

If Modular Mail is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.

6. Data Storage and Security

6.1 Data Storage

Your data is stored on secure servers. While we use servers that may be located in various jurisdictions, we ensure all data processing complies with UK GDPR standards through appropriate safeguards and data transfer agreements.

6.2 Security Measures

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure password hashing using modern cryptographic algorithms
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Monitoring for suspicious activity and unauthorized access

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:

  • Active Accounts: Account and usage data retained while your account is active
  • Cancelled Accounts: Grace period of 30 days after cancellation for data recovery, then data is deleted
  • Billing Records: Retained for 7 years to comply with UK tax and accounting regulations
  • Legal Requirements: Certain data may be retained longer if required by law or to resolve disputes

You may request deletion of your data at any time by contacting us, subject to legal retention requirements.

8. Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Request that we limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format or request transfer to another service
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent: Withdraw consent for processing based on consent (e.g., marketing emails)
  • Right to Lodge a Complaint: File a complaint with the Information Commissioner's Office (ICO) if you believe we've violated your privacy rights

To exercise any of these rights, please contact us at support@modular-mail.com. We will respond to your request within 30 days.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and collect usage data:

  • Essential Cookies: Required for authentication, security, and core functionality (cannot be disabled)
  • Analytics Cookies: Help us understand how users interact with the Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Service.

10. Third-Party Links

The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

12. Marketing Communications

We may send you marketing communications about new features, updates, and offers if you have consented to receive them. You can opt out of marketing emails at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your communication preferences in your account settings
  • Contacting us at support@modular-mail.com

Note that you cannot opt out of transactional emails (e.g., account notifications, billing updates, password resets) that are necessary for the operation of the Service.

13. International Data Transfers

Your information may be transferred to and processed in countries other than the United Kingdom. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the UK ICO
  • Service providers with adequate data protection certifications
  • Transfer mechanisms that comply with UK GDPR requirements

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by email or through a prominent notice on the Service at least 30 days before the changes take effect.

The "Last updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

15. Data Controller Information

For the purposes of UK GDPR, the data controller is Modular Mail. We are responsible for ensuring that your personal data is processed in accordance with applicable data protection laws.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: support@modular-mail.com

For data protection inquiries or to exercise your GDPR rights, you may also contact us using the email above with the subject line "Data Protection Request."

Supervisory Authority: If you are not satisfied with our response or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: https://ico.org.uk