Privacy Policy
Last updated September 21, 2026
This policy explains how SentLedger handles personal information about our customers and their users ("Account Data") and about the people our customers send messages to ("Recipients").
Two roles
For Account Data, SentLedger is the controller. For Customer Data — including message content, recipient addresses and tracking events — SentLedger processes information on behalf of our customer, who decides what is sent and to whom. Recipients with questions about a specific message should contact the sender; we will assist our customers with those requests.
What we collect
- Account Data: name, email, workspace details, role, timezone, notification settings, billing contact and payment status (card details are handled by our payment processor, not stored by us).
- Customer Data: messages, files, templates, contacts, metadata our customers attach, and records of delivery and engagement.
- Tracking event data: time of an event, event type, a device category derived from the user agent, the user agent string, a truncated network prefix (for example 203.0.113.0/24) and a keyed hash used only for de-duplication. We do not store full IP addresses with tracking events, and we do not identify individuals or precise locations from them.
- Connected account tokens: OAuth tokens for Gmail or Microsoft 365, encrypted at rest, used only to send messages you request.
- Operational data: security logs, audit logs and error reports.
How we use it
To provide, secure and support the Service; to process payments; to prevent abuse; to communicate about your account; and to comply with law. We do not sell personal information, and we do not use Customer Data to advertise.
Sharing
We share information with service providers that help us run the Service — hosting and database (Railway, Supabase), email delivery (Resend), payments (Stripe) and error monitoring — under contracts that limit their use of it. We may disclose information if required by law or to protect people and the Service.
Retention
Customer Data is kept for the retention period of the customer's plan and settings, then deleted. Account Data is kept while the account is active and for a limited period afterwards for legal and accounting purposes.
Security
We use encryption in transit and at rest, workspace isolation enforced in the database, encrypted secrets, hashed API keys, role-based access and audit logging. See Security.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete or export your information, or to object to certain processing. Account holders can manage most of this in the app. Recipients can unsubscribe where a link is provided, or contact the sender. Contact privacy@sentledger.com for help.
International transfers
Our infrastructure is primarily located in the United States. Where required, we use appropriate safeguards for international transfers.
Children
The Service is not directed to children and we do not knowingly collect information from children.
Questions? Contact legal@sentledger.com.