Legal
Privacy policy
Mint Mail is a sending platform, so personal data reaches us in two very different ways: the details of the person who signs up, and the contact lists that person sends to. This policy keeps those apart, because our obligations — and yours — are not the same in each case.
- Last updated
- 3 August 2026
- Effective
- 3 August 2026
1.Who we are
Mint Mail is operated by Revenize LTD (“Revenize”, “we”, “us”), registered at 20 Warburton Road, Flat 18, London, E8 3FY, under company number 17064965.
For any question about this policy, or to exercise the rights described in section 9, write to [email protected].
2.The two roles we play, and why the difference matters
For your own account, we are the controller. Your name, your sign-in details, your billing history and how you use the product are ours to decide about, and this policy is the notice for them.
For the contacts you upload and send to, we are the processor. You decide who is on your list, why you are allowed to mail them, what you send and when. We act on your instructions and do not use your contacts for our own purposes — we never mail them on our own behalf, never sell or share their details, and never merge them into any other customer’s data.
The practical consequence: if one of your contacts asks to see or delete the data held about them, that request belongs to you as the controller. Write to us and we will help you answer it, but we will not act on it unilaterally, because we have no way to verify a request about a list we do not own.
3.What we hold about you (as controller)
Account and identity
Your email address, your name, and a profile picture if you sign in with Google. If you use a password we store only a hash of it, never the password itself. If you sign in with Google we receive your email address, name and picture from Google, and nothing else — we request no access to your Gmail, Drive or Contacts.
Organisation and team
Your organisation’s name, the members you invite, their roles, and an audit trail of significant actions taken in the workspace (who invited whom, who changed a role, who deleted a campaign).
Billing
Your prepaid balance and the ledger of top-ups and deductions. Card details are handled entirely by Stripe and never reach our servers — we store Stripe’s reference for a payment, not the payment instrument.
Technical and security logs
Session records, sign-in events and application logs, kept so we can investigate abuse, debug failures and answer “who did this?” about an account.
Marketing site analytics
We run Google Analytics on the public pages only — this one, the landing page, pricing and deliverability. It is deliberately not loaded inside the signed-in application, and not on the per-recipient links in the email we send, because those URLs identify an individual and we will not hand them to an analytics provider.
Our lawful bases are performance of a contract (running the account you asked for), legitimate interests (securing the service, preventing abuse, understanding how the public site is used) and legal obligation (tax and accounting records).
4.What we process for you (as processor)
When you import a list or send a campaign, we process the following on your behalf. You are responsible for having a lawful basis to give it to us — see section 4 of the terms of service.
Contact records
Email address, first and last name, subscription status, any custom fields you define, and the consent evidence you record against each contact — where they came from and when they opted in.
Sending and delivery data
Which messages were sent to whom and when, and what the receiving mail server said back: delivered, bounced (with the diagnostic the server returned), or marked as spam.
Engagement events, including IP address
When a recipient opens a message or clicks a link, we record the event, the link and the browser’s user-agent string. The user-agent is what lets us tell a real reader from a security gateway or a chat app’s link preview, which fetch every URL in a message — without that the open and click figures would be fiction.
Suppression data
Addresses that unsubscribed, hard-bounced or complained are recorded so they are never mailed again. This list is retained even after a contact is deleted: forgetting that someone opted out is how they get mailed a second time, which is the harm the record exists to prevent.
5.Cookies
The signed-in application sets a small number of strictly necessary cookies: a session cookie that keeps you logged in, and cookies used to protect sign-in forms against cross-site request forgery and to return you to the page you came from. These cannot be switched off without breaking sign-in, and we do not ask for consent to set them.
6.Where the data lives, and international transfers
Email is sent through Amazon SES in the AWSus-east-1region, in the United States. That is the only sending region we operate. If you are in the UK or the EU, this means contact data you upload is transferred to and processed in the United States.
Our application servers and database are hosted in Europe.
Transfers out of the UK/EEA rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, as incorporated into our subprocessors’ terms.
7.Subprocessors
We use the following providers to run the service. Each is bound by contract to process data only on our instructions.
Amazon Web Services (AWS)
Email delivery through SES, in us-east-1, plus the storage and queueing behind it. Processes contact email addresses and message content.
Stripe
Payment processing for balance top-ups. Processes your billing details as an independent controller for its own compliance purposes; it never receives your contact lists.
Two separate, unrelated uses: “Sign in with Google” if you choose it, and Google Postmaster Tools, which reports Gmail’s aggregate view of a sending domain’s reputation. Postmaster data is aggregate and statistical — it identifies no individual recipient.
Hosting provider
Contabo, in Germany, — the servers running the application and its database.
8.How long we keep things
Contact and engagement data is kept for as long as your account is open, because it is your data and deleting it would break the reporting and suppression you depend on. When you delete a contact, its record and engagement history are removed; the suppression entry survives, for the reason given in section 4.
When you close your workspace we delete its data.
9.Your rights
If you are in the UK or the EEA you have the right to access a copy of your personal data, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent you may withdraw it at any time. Similar rights apply under several US state privacy laws.
Exercise any of them by writing to [email protected]. We answer within one month. There is no self-service export or erasure screen yet, so these requests are handled by a human — we would rather say so than imply a button that does not exist.
If you are a recipient of email sent through Mint Mail rather than a customer of ours, the sender is the controller of your data. Every message carries an unsubscribe link that works immediately; beyond that, direct your request to whoever sent it, and we will help them answer.
You may also complain to a supervisory authority — in the UK, the Information Commissioner’s Office.
10.Security
Passwords are stored as argon2id hashes. Sessions can be revoked across every device at once, and changing a password does so automatically. Each customer sends inside their own isolated tenant, and every database query in the application is scoped to a single organisation so one customer’s data cannot be read by another.
No system is perfectly secure. If you believe you have found a vulnerability, tell us at [email protected] and we will not pursue you for reporting it in good faith.
11.Children
Mint Mail is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, tell us and we will delete it.
12.Changes to this policy
We update this page when what we do changes. The date at the top always reflects the current version, and we will email account owners before any change that materially reduces the protection described here.
Questions about this document? [email protected]. See also our terms of service.