Privacy Policy
Last updated October 1, 2026
This policy explains what Mailmize collects, why, and what it does not do. It is written to be read rather than to be survived.
Who runs this service
Mailmize is operated by Sawyer Higgins, a sole proprietorship based in Tennessee, at 133 Indian Lake Blvd, Hendersonville, TN 37075. Questions about this policy, or a request about your own data, go through the Support tab inside your account, or by post to the address above.
What is collected
Two separate things, and the difference matters:
1. Your account
- Your email address — it is how you sign in and how you are contacted about the account.
- Your name, if you choose to give one. It is optional and nothing depends on it.
- Your password, stored only as a salted hash. The password itself is never written down and cannot be recovered, only reset.
- Mailbox credentials for the mailboxes you connect — either an OAuth token issued by Microsoft, or an app password you supply. These are stored so the service can send on your behalf, and are used for nothing else.
- A record of what was sent — recipient, subject, time, result — so you have a history of your own sending and so daily limits can be enforced.
2. Your contacts
The contact lists you upload belong to you. They are stored so the service can send the emails you have set up, and they are never sold, rented, shared between accounts, merged into any wider list, or used to send anything on anyone else's behalf. Nobody else using this service can see them.
Because these are other people's details, you are responsible for having a lawful basis to hold and email them. That obligation is yours, not this service's, and it is set out in the Terms.
What is deliberately not collected
- No analytics. There is no Google Analytics, no Meta pixel, no advertising tag and no session recorder anywhere on this site.
- No third-party requests. The pages load no fonts, scripts, images or stylesheets from anyone else's server, so no third party ever sees your IP address through this site.
- No tracking pixels in your email. This service does not add open-tracking or click-tracking to the messages you send.
- No payment card details. Payments are handled entirely by Stripe. Card numbers never touch this service; it receives only a customer reference and whether a subscription is active.
- No selling of personal information, under any definition, ever.
Who your data is shared with
Only where it is needed to make the service work:
- Your email provider (Microsoft or Google) — the messages you send go through your own mailbox, which is the point of the service.
- Stripe — for subscription payments, if you are on a paid plan.
- Render — the hosting provider the service runs on.
Beyond that, personal information is disclosed only where the law requires it.
How long it is kept
Account data and contact lists are kept while your account is open. Delete a contact, a list or a campaign and it is removed. Ask for your account to be closed and everything in it is deleted, other than what has to be retained for tax and payment records.
Opt-out records are the deliberate exception: when someone unsubscribes, their address is kept on a suppression list so they cannot be emailed again by mistake. Keeping that record is what makes the opt-out permanent.
Your choices and rights
- See it — your contacts, send history and settings are all visible inside the app, and the send log can be exported as a CSV at any time.
- Correct it — anything about your account can be edited in Settings.
- Delete it — delete individual records in the app, or ask through the Support tab inside your account to have the whole account removed.
Depending on where you live you may have further rights over your personal information, including the right to a copy of it. Ask and it will be honoured, whether or not a particular law happens to apply to a business of this size.
Do Not Track
Some browsers send a “Do Not Track” signal. This service does not track visitors across websites in the first place, so there is nothing for the signal to switch off, and no behaviour changes when one is received.
Security
Traffic runs over HTTPS. Passwords are salted and hashed. Mailbox tokens are stored on an encrypted volume and used only to send your own mail. No system is perfectly secure, and anyone who tells you otherwise is selling something — but if a breach ever affects your data, you will be told what happened and when, not left to find out.
Children
This is a business tool and is not intended for anyone under 18. Accounts are not knowingly created for children, and information belonging to one would be deleted on discovery.
Changes
If this policy changes in a way that affects what is collected or who it goes to, account holders are emailed rather than being left to spot a new date at the top of a page.
