Privacy Policy
Last updated 28 September 2026
YourMail is a trading name of Mather Software Ltd ("we", "us"). This describes what we do with personal data. It covers two different relationships, and the distinction matters: data about you as our customer, where we decide what happens to it, and data inside the messages you send, where you decide and we only act on your instructions.
Who we are
The controller of your personal data is Mather Software Ltd, a company registered in England and Wales with company number 17443861. Registered office: 31 Mill Fold Gardens, Littleborough, England, OL15 8SA. We are registered with the Information Commissioner's Office under number ZC256628. For anything about your personal data, email conor@mathersoftware.com. We have not appointed a data protection officer; that address reaches the person responsible.
Two roles, not one
- We are the controller of your account data — your name and email address, your billing details, the domains you add, your API request logs, your support requests. We decide why and how that is processed, and this policy governs it.
- We are your processor for everything inside the messages you send: recipient addresses, subject lines, message bodies and attachments. You decide what goes in them; we transmit and store them under your instructions. The Data Processing Agreement and section 5 of the Terms of Service govern that relationship; if you are wondering what happens to your own recipients' data, that is where to look.
What we collect, and where it comes from
- Account. Your name, email address and authentication details, held by our identity provider (Clerk). If you sign up with Google, Clerk receives your name and email address from Google. We never see or store your password.
- Sign-up location check. When you create an account we ask Clerk for the approximate location — country and city — it derives from the IP address of your sign-up session. We use it only to decide whether a new account can start sending to any recipient straight away or is first held for a person to review. We do not store the IP address, and the location is not written to your account record; it appears only in the internal sign-up notification we receive.
- Bot protection. The sign-up form runs Cloudflare Turnstile (loaded by Clerk), which checks signals from your browser and IP address to tell people from automated sign-ups.
- Billing. If you subscribe, Stripe holds your payment details and we hold a customer reference, your plan, and whether the last payment succeeded. We never receive your card number. We do hold the card fingerprint Stripe gives us — a code derived from the card that cannot be used to make a payment and does not reveal the number. Because it is the same code for the same card across different accounts, we use it for one purpose only: to notice when a new account is paying with a card that belongs to an account we have already suspended for abuse. A match slows that account’s sending for 24 hours and alerts us; it never closes an account on its own.
- Usage. Message counts, delivery outcomes, and a log of API requests — endpoint, status, method, user agent — kept so you can debug your own integration. Recipient addresses appearing in error messages in that log are redacted before it is written.
- Support requests. When you raise a ticket from the dashboard we keep your email address, the subject and message thread, and the context you were in (the page, your plan, and the message or domain concerned, if any). A copy is emailed to us so we can answer it.
- Website analytics. The public pages (not the dashboard) use Vercel Web Analytics, which counts page views, referrers, and the country, browser, operating system and device type of visitors. It uses no cookies and does not build a profile of you; we only ever see aggregated figures.
- Errors and performance. When the website or dashboard hits an error, Sentry receives a report of it — the error, the page, your browser and the steps that led to it — and it also receives performance traces (how long pages and requests took). Its session replay feature is not enabled.
- Network. When someone clicks an unsubscribe link we derive a short-lived, non-reversible bucket value from the requesting IP address in order to rate-limit abuse. The address itself is not stored.
There is no advertising tracker anywhere on this site, and no analytics script on any dashboard page — the dashboard displays plaintext API keys.
Why we process it, and our lawful basis
- Running your account, sending your mail, support, billing you — contract: we need this data to provide the service you signed up for.
- The sign-up location check, bot protection, the card fingerprint match and other abuse controls — legitimate interests: preventing fraud and abuse, and protecting the sending reputation every customer shares.
- Error reports and performance traces — legitimate interests: finding and fixing faults and keeping the service fast.
- Website analytics — legitimate interests: understanding, in aggregate, which public pages are read so we can improve them.
- Keeping financial records and answering lawful requests — legal obligation.
Where we rely on legitimate interests we have weighed them against your rights and limited the processing to what those aims actually require. You can object to it at any time (see “Your rights”). We do not currently rely on consent for any processing.
Do you have to give us this data? Your name, email address and, for a paid plan, payment details are needed to enter into and perform our contract — without them we cannot open an account. The rest is collected automatically as you use the service.
Automated decisions
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. Some automated checks — the sign-up location check, bounce and complaint thresholds, and the abuse signals described in the Acceptable Use Policy — can hold back or slow an account's sending. An account held for review is looked at by a person, and you can always ask us to review one by emailing conor@mathersoftware.com.
Who else processes it
We use the following processors. Each is bound by a data-processing agreement, and we will give notice before adding a new one. The same list is the sub-processor list in our Data Processing Agreement.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Email delivery (SES) and attachment storage | London, UK (eu-west-2) |
| Convex | Application database — message records and account data | United States; storage region not yet confirmed in writing |
| Clerk | Authentication and user accounts, including the approximate location (country and city) it derives from the IP address of your sign-up session | United States |
| Cloudflare | Bot protection on sign-up (Turnstile, loaded by Clerk) | United States, with processing worldwide |
| Vercel | Dashboard and website hosting, and cookieless, aggregated web analytics on the public pages (Vercel Web Analytics) | United States, with edge delivery worldwide |
| Stripe | Payment processing and subscription billing | United States and Ireland |
| Sentry | Error reporting and performance tracing for the website and dashboard | Germany (Sentry EU data region); US-headquartered provider |
Beyond those, we share personal data only with professional advisers (such as our accountants and lawyers) under a duty of confidence, with authorities where the law requires it, and with a buyer of the business if it is ever sold. We do not sell personal data.
International transfers
Several of the providers above are based in, or process data in, the United States. Where a US provider is certified under the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”), the transfer relies on the UK's adequacy regulations for it. Otherwise it relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement. Transfers to the EU (for example Sentry's EU data region) rely on the UK's adequacy regulations for the EEA. You can ask us for a copy of the relevant safeguards at conor@mathersoftware.com.
How long we keep it
- Message bodies and attachments are kept for as long as you choose. The retention setting in your dashboard offers indefinite, 365, 90 or 30 days; when a window is set, an automated job strips bodies and attachments past it while keeping the delivery record so your statistics stay intact.
- API request logs are deleted after 30 days, on a fixed schedule that your retention setting does not change. That is why recipient addresses in them are redacted.
- Account data, delivery records and support tickets are kept while your account is open and deleted from our database when you delete it, which you can do yourself. Residual copies in our providers' logs and backups are removed within a further 30 days.
- Financial records (invoices, payments, the customer reference) are kept for six years from the end of the financial year they relate to, as UK tax and company law requires.
- Internal notifications — the sign-up notification carrying the location check, and copies of support tickets — are kept in our mailbox for up to 24 months.
- Error reports and performance traces are kept by Sentry for up to 90 days. Website analytics are held by Vercel only in aggregated form.
- An account we suspend for abuse is the exception. We keep its records — including the card fingerprint above, after the account is closed — for as long as we need them to answer a chargeback, a regulator or a law-enforcement request, and to stop the same actor signing straight back up, and in any case no longer than six years. Self-serve deletion is refused while that case is open; erasure still happens, it just goes through a person.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased;
- restrict how we process it;
- receive it in a portable, machine-readable format;
- object to processing we carry out on the basis of legitimate interests; and
- withdraw consent at any time, where we rely on consent (we currently do not).
Two of those you do not have to ask us for:
- Export — the settings page produces a JSON file of your account, domains, suppression list, webhooks, usage, a log of rolled API keys and removed domains, and message metadata, on demand.
- Erasure — the same page deletes your account outright, including every message, your sending identities and your login. If we have suspended the account for abuse, that button is refused while the case is open and you should email us instead; the right is not removed, only the self-serve route to it.
For anything else, email conor@mathersoftware.com. We will respond within one month. If you are the recipient of a message sent by one of our customers, that customer is the controller of your data; contact them first, and we will help them respond.
If you are unhappy with how we have handled your data you have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put it right first.
Security
API keys are stored only as SHA-256 hashes and shown to you exactly once. Every query is scoped to your account. Webhook deliveries are signed so you can verify they came from us. More detail, including what we do not yet claim, is on the security page.
Changes to this policy
If we change this policy in a way that matters, we will email the address on your account before the change takes effect. The date at the top shows when it was last updated.
Contact
Mather Software Ltd, a company registered in England and Wales with company number 17443861, whose registered office is at 31 Mill Fold Gardens, Littleborough, England, OL15 8SA. ICO registration ZC256628. Data protection enquiries: conor@mathersoftware.com.