EmailFig handles two kinds of personal data: yours, as our customer, and your subscribers', which you bring to the service. This policy covers both. For a shorter summary aimed at EU/UK data protection questions specifically (legal basis, subprocessors, transfer safeguards, and how to request a Data Processing Addendum), see our GDPR page.
What this covers
For the data you give us about yourself (your account, your billing details, how you use the app), EmailFig is the data controller. For the data you upload about your subscribers (addresses, names, custom fields, and what happens to the emails you send them), you are the controller and EmailFig is your processor: we handle that data only to provide the service, on your instructions. This policy describes both roles; our Terms of Service require you to have permission for every address you upload.
Data about you
We collect what the service needs to run:
- Account data: your email address and name. Sign-in is passwordless: a code to your inbox, or Google sign-in if you connect it, in which case Google tells us your address and name and nothing more.
- Billing data: handled by Stripe, our payment processor. Card numbers never touch our servers; we keep the subscription state and invoice history your account page shows you.
- Usage data: product analytics about how the app is used (pages visited, features exercised), which we use to find what's broken or confusing. Our marketing pages, blog, and help centre separately use Google Analytics for traffic analytics: pageviews and referrers, configured without ad personalization or remarketing. We don't buy third-party data about you or track you across other sites.
Your subscribers' data
When you upload contacts or someone joins through one of your signup forms, we store the data you've chosen to collect: address, name, custom fields, tags, and the consent record (when and how each person signed up, including double opt-in confirmations). When you send, we record what the reports need: deliveries, bounces, opens, clicks, unsubscribes, and complaints.
We use this data to run your sending and for nothing else. We don't sell it, rent it, use it to build profiles, or let one account see another's lists. Unsubscribes are honored immediately and permanently: an address that opts out is suppressed across every path that could mail it.
Legal basis for processing
Where the GDPR applies, we rely on the following legal bases:
- Contract: processing your account and billing data, and processing your subscriber data on your instructions, is necessary to provide the service you signed up for.
- Legitimate interests: securing the service, diagnosing and fixing problems, and preventing abuse that would put every customer's deliverability at risk. We balance this against your rights, and you can object at any time (see Your rights).
- Legal obligation: where we're required to keep or disclose records, such as billing records for tax purposes.
- Consent: where your subscribers give it directly to you (e.g. checking a box on a signup form), which is a matter between you and them; EmailFig processes that data as your processor under the contract basis above.
Who we share it with
Data leaves EmailFig only for the infrastructure that runs it: Amazon Web Services hosts the service and delivers email (if you bring your own AWS account, sending runs through yours instead), Stripe processes payments, PostHog runs our product analytics, Cloudflare protects our public forms from bots, and Google Analytics measures traffic on our marketing pages, blog, and help centre. Each provider processes data only to do its job for us. The full list, with what each one sees and where it runs, is on our GDPR page.
Beyond that, we disclose data only when the law requires it, and we'll tell you first unless we're legally barred from doing so. If EmailFig is ever acquired, this policy continues to apply to your data until you're told otherwise with notice to opt out.
International transfers
EmailFig is based in Canada, and our infrastructure runs primarily in the United States. If you or your subscribers are in the European Economic Area, the UK, or another region with its own transfer rules, your data is processed outside that region. Where that requires a safeguard, each of our subprocessors is either certified under the EU-U.S. Data Privacy Framework or covered by Standard Contractual Clauses. See the per-subprocessor breakdown on our GDPR page.
Cookies
We set the cookies the app needs: a session cookie to keep you signed in and security cookies that protect forms from abuse. Our analytics run without advertising cookies, and we don't use third-party advertising trackers anywhere. Our Cookie Policy lists every cookie by name, what sets it, and how to control it.
Retention & deletion
We keep your data while your account is open, so your history and reports keep working. When you close your account there's a 30-day window in which you can change your mind; after that your account data and your subscriber data are deleted. Uploaded import files and generated exports are bounded separately and removed within 30 days regardless of account status, since they can hold a whole list in one file that can't be edited person by person. Suppression records (the list of addresses that opted out) may be retained longer, because honoring an opt-out requires remembering it.
Your rights
You can access, export, correct, and delete your own account data directly from the app: your account details in settings, your lists and reports as CSV exports, and account closure is self-serve. Where the GDPR, UK GDPR, or a similar law applies to you, you additionally have the right to restrict or object to processing, to data portability, and to lodge a complaint with your local data protection supervisory authority. To exercise a right this page doesn't cover as a self-serve action, write to contact@emailfig.com and we'll respond within the time the applicable law requires.
For your subscribers, you're the controller, so their requests go to you, and the app gives you the tools to answer them, including per-contact export and a permanent erasure action distinct from delete. If a subscriber contacts us directly, we'll point them to you and help you comply.
Children's privacy
EmailFig is not directed at children, and you must be at least 16 to create an account (see our Terms of Service). We don't knowingly collect account data from anyone under that age. If you believe a child has created an account, write to contact@emailfig.com and we'll remove it.
If something goes wrong
If we become aware of a breach affecting your personal data, we'll notify you without undue delay, describe what happened and what we're doing about it, and notify the relevant supervisory authority where the law requires it. For your subscriber data, we'll notify you as our customer so you can meet your own notification obligations as the controller.
Changes & contact
We may update this policy as the product and the law evolve. For material changes we'll email the address on your account before the new policy takes effect, and the dates at the top of this page will always tell you what you're reading.
Questions, or a request this page doesn't answer? Write to contact@emailfig.com. A human replies.