Pricing
Log In Contact

Privacy Policy

Last updated: August 5, 2026

  • Terms Terms of Service
  • Privacy Privacy Policy
  • Cookies Cookie Policy
  • Usage Acceptable Use
  • DPA GDPR DPA
  • Subprocessors GDPR Subprocessors

Documents

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • GDPR DPA
  • GDPR Subprocessors

1. Introduction

JetEmail Pty Ltd ("JetEmail", "we", "us", or "our") is committed to protecting your privacy and handling your personal information in accordance with the Australian Privacy Act 1988 (Privacy Act), the Australian Privacy Principles (APPs), and the European General Data Protection Regulation (GDPR) where applicable.

This Privacy Policy explains how we collect, use, disclose, and manage your personal information when you use our email delivery services, visit our website, or interact with us in other ways.

Who This Policy Covers

Two different groups of people appear in this policy, and the rules are different for each:

  • Our customers are the businesses and individuals who hold a JetEmail account. We decide how their account, billing and support data is handled, and this policy describes that directly.
  • Our customers' contacts and email recipients are the people our customers store in the Marketing Suite or send mail to. We handle that data on our customer's instructions. If you received an email sent through JetEmail, or filled in a signup form powered by JetEmail, the business that contacted you controls that data, and their privacy policy applies to it. We explain our role in Section 2 and describe what we hold in Sections 4, 6 and 7.

JetEmail Pty Ltd

Australian Company Number: 641 539 166

Contact: legal@jetemail.com

2. Our Role: Controller and Processor

Our role depends on the data and the purpose, not on a single label.

  • We act as processor, or service provider, for the personal data our customers put into the Services: contacts, custom attributes, campaign content and recipient engagement data. We process it on their documented instructions under our Data Processing Agreement.
  • We act as controller, or business, for our customers' account, billing and support data, for our website, and for a limited set of purposes that are ours rather than our customers': security, fraud and abuse prevention, network and deliverability protection, complaint handling, service telemetry, and compliance with our own legal obligations.

Where we act as controller for security and abuse purposes, we may process data that also belongs to a customer's dataset. We keep that processing to what is necessary for those purposes.

We do not sell or share personal information for cross-context behavioural advertising, and we do not use our customers' contacts, campaign content or recipient engagement data to train machine learning models for use outside their account.

3. Information We Collect

Account Information

When you create an account with JetEmail, we collect:

  • Name and contact details (email address, phone number)
  • Business information (company name, website, industry)
  • Billing information (address, payment method details)
  • Account credentials (username, encrypted passwords)

Service Usage Data

When you use our email delivery services, we collect:

  • Email content and metadata (sender, recipients, subject lines, timestamps)
  • Delivery analytics (open rates, click rates, bounce rates)
  • API usage logs and technical data
  • Domain and DNS configuration information

Website and Technical Information

When you visit our website or use our services, we automatically collect:

  • IP addresses and device identifiers
  • Browser type, version, and settings
  • Operating system and device information
  • Website usage patterns and analytics
  • Cookies and similar tracking technologies
  • Signals used to detect fraudulent signups and account abuse, including device and browser characteristics

Communications

We collect information from your communications with us, including:

  • Support ticket content and correspondence
  • Feedback and survey responses
  • Marketing communication preferences

4. Marketing Suite Data

The Marketing Suite stores a contact database on behalf of our customers and records what happens to the campaigns they send. This is the data we hold, why we hold it, and how long it stays.

CategoryWhat it includesWhy we hold itRetention
Contact dataEmail address, name, status, tags, audience membership, custom attributesContact management, personalisation, delivery, suppressionLife of the account, then deleted under Section 13
Campaign and template contentSubject lines, HTML and text content, blocks, sender details, saved template versionsComposing and sending campaigns, reproducing what was sent, supportTemplates until you delete them; version history for the life of the account
Sent message archiveA reconstruction of an individual sent message, with sensitive merge values maskedSupport, dispute resolution, showing you what a recipient received30 days
AssetsUploaded images, filename, type, size, public URLHosting, campaign rendering, security and safety scanningUntil deleted or the account closes, plus cache and backup expiry
Form dataSubmitted fields, source page URL, consent wording shown, whether consent was given, user agent, timestampsAdding the contact, evidence of consent, abuse preventionConsent evidence for the life of the contact record; unconfirmed submissions 30 days
Abuse prevention dataPseudonymous signals derived from IP address and email using a keyed hash, rate limit events, honeypot hitsBlocking automated and fraudulent form submissions90 days, unless retained for an active investigation
Delivery dataRecipient, sender, subject, message ID, receiving server, MX, IP and SMTP responseDelivery, diagnostics, suppression, supportThe period published for your plan, and in no case longer than 12 months
Engagement dataOpens, clicks, destination URL, time, approximate location, email client, user agentCampaign reporting for the customer who sent the messageRecipient-level events up to 12 months; aggregate metrics up to 24 months
Workflow dataTrigger, custom event properties, merge snapshot, enrollment state, errorsRunning automations and troubleshooting themWhile the workflow is active, plus 12 months of event history
Unsubscribe and suppression evidenceEmail address snapshot, channel used, related campaign or message, timestampHonouring the request, preventing re-adding, demonstrating complianceRetained after contact deletion and after account closure
Domain and IP dataDomain names, DNS record state, sending pool or dedicated IP assignmentAuthentication, routing, reputation management, billingLife of the account plus an operational audit period

Suppression evidence is deliberately kept after a contact or account is deleted. Erasing it would allow an unsubscribe to be undone by a later import, which is the opposite of what the person asked for. We keep the minimum needed: the address, the channel, and when it happened.

5. How We Use Your Information

Service Delivery

  • Delivering email messages on your behalf
  • Storing and managing the contacts you add to the Marketing Suite
  • Providing email analytics and reporting
  • Managing your account and billing
  • Providing customer support

Service Improvement

  • Monitoring and improving service performance
  • Diagnosing faults and testing changes
  • Analyzing aggregated and de-identified usage patterns

We do this using account and platform telemetry. We do not mine customer contact databases or campaign content for product development, and we do not use them to train machine learning models for use outside the customer's account.

Legal and Security

  • Preventing fraud and abuse
  • Ensuring compliance with anti-spam laws
  • Protecting our systems, our network and other customers' deliverability
  • Meeting legal and regulatory obligations, including mandatory reporting

Marketing (with consent)

  • Sending service updates and announcements
  • Providing educational content and best practices
  • Promoting relevant features and services

6. Email Recipient Tracking

This section is about tracking in email sent by our customers through the Marketing Suite. It is separate from Section 15, which covers cookies on jetemail.com.

Where a customer enables open and click tracking on their sending domain:

  • Open tracking places a small invisible image in the message. When a mail client loads it, we record that the message was opened, when, and technical details available from the request.
  • Click tracking rewrites links so they pass through a tracking subdomain on the sender's own domain. When a link is clicked we record the destination, the time, and the same technical details, then redirect to the destination.
  • Those technical details can include the recipient and message identifier, IP address, an approximate location derived from it, device type, user agent and email client.

The customer who sent the message decides whether tracking is on and is responsible for giving recipients any notice and obtaining any consent required where they live. We carry out this processing on their instructions.

These measurements are estimates. Mailbox privacy features, image blocking, link prefetching, corporate security scanners, bots, relays and caching all distort them. An open or click record is not proof that a particular person read a particular message.

Turning tracking off stops open and click collection. It does not stop delivery logging, bounce and complaint processing, or the security telemetry we need to run the platform.

If you received a marketing email sent through JetEmail and want to know what was recorded about you or have it deleted, contact the business that sent it. They control that data. If you cannot reach them, write to legal@jetemail.com and we will pass the request on.

7. Signup Forms and Consent Records

Our customers can publish a JetEmail-hosted signup form or embed one on their own website. When someone submits a form we record, on the customer's behalf: the fields submitted, the page the submission came from, the exact consent wording displayed, whether a consent box was ticked, the browser user agent, the time, and pseudonymous signals derived from the submitter's IP address for abuse prevention. Where double opt-in is used, we store a hash of the confirmation token and a snapshot of the form as it was at the time, so the record stays meaningful after the form is edited.

The business that published the form is the entity collecting your data. Their identity and privacy policy should be shown on the form. We provide the form infrastructure and store the resulting record for them.

Consent evidence is kept because it is the proof that someone agreed to be contacted. Where the customer deletes the contact, we may keep a minimal record that consent was given and later withdrawn.

8. Automated Scanning and Safety

We use automated systems to keep the platform safe and deliverable. These systems process message content and uploaded files.

  • Outbound content and link scanning. We scan outgoing messages, attachments and links for spam characteristics, malware, phishing and policy violations, and may block a message on that basis.
  • Inbound filtering. For Inbound Email, we scan arriving mail for spam, phishing and malware in order to filter and quarantine it.
  • Merge value masking. When we archive a copy of a sent message, values that look sensitive are masked in the archive rather than stored in the clear.
  • Image safety scanning. Marketing Suite images are stored in Cloudflare R2 and served from public URLs through Cloudflare's network. Where enabled and technically eligible, images served through Cloudflare's cache are compared by Cloudflare against signatures of known child sexual abuse material. Cloudflare may block a match and may report matched images to the National Center for Missing and Exploited Children. Where we become aware of such material we may preserve records, restrict access, remove content, suspend the account and report it to the relevant authorities.
  • Fraud and abuse signals. We analyse signup, device, network and sending signals to detect fraudulent accounts and abuse.

Automated scanning is not a guarantee. It does not detect everything, it can produce false matches, and it is not a review or approval of anything you upload or send.

9. Legal Basis for Processing (GDPR)

For users in the European Union and the United Kingdom, we process personal data based on the following legal bases:

  • Contract Performance: Processing necessary to provide our email delivery services
  • Legitimate Interests: Service improvement, security, network protection and fraud prevention
  • Legal Obligation: Compliance with applicable laws and regulations
  • Consent: Marketing communications and optional features (where required)

Where we act as processor for a customer's contacts and recipients, the lawful basis for contacting those people is determined by that customer, not by us.

10. Information Sharing and Disclosure

Service Providers

We share information with trusted third-party service providers who assist us in delivering our services:

  • Cloud hosting, compute and infrastructure providers
  • Content delivery, DNS, object storage and network security providers
  • Payment processors
  • Analytics and monitoring services
  • Customer support platforms

A complete list of our subprocessors is available at: jetemail.com/legals/gdpr-subprocessors

Mailbox Providers and Feedback Loops

Delivering email necessarily discloses the message and its metadata to the recipient's mailbox provider. Mailbox providers also send us feedback, including spam complaints, which we use to apply suppressions and to report deliverability information back to the customer who sent the message.

Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes or government requests
  • Enforce our terms of service or policies
  • Protect our rights, property, or safety
  • Investigate potential violations or abuse
  • Make a mandatory report, including reports concerning child safety

Business Transfers

In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction, subject to appropriate safeguards.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

11. International Data Transfers

JetEmail is based in Australia. Personal information may be processed and stored in Australia, the United States and the European Union, and may transit the global networks of our infrastructure providers, including Cloudflare's edge network, which routes traffic through the location closest to the user.

The location of a specific dataset depends on the service and the plan. Details of where a particular category of data is stored are available on request at legal@jetemail.com.

For transfers to countries without adequate data protection laws, we implement appropriate safeguards including:

  • Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum where applicable
  • Adequacy decisions where available
  • Additional security measures as required

12. Data Security

We implement comprehensive security measures to protect your personal information, including:

Technical Safeguards

  • Encryption of data in transit and at rest
  • Secure authentication and access controls
  • Regular security monitoring and logging
  • Automated backup and recovery systems
  • Network security and firewall protection

Administrative Safeguards

  • Staff training on privacy and security
  • Confidentiality agreements for all personnel
  • Regular security assessments and audits
  • Incident response procedures
  • Restricted, logged access to abuse and child safety case data
  • Vendor security requirements

13. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law. Retention periods for Marketing Suite data are set out in the table in Section 4. Other periods are:

  • Account Information: For the duration of your account plus 7 years for tax and legal purposes
  • Outbound and Inbound message content: Held only as long as needed for delivery, filtering and diagnostics. Delivery logs and message data are retained for the period published for your plan on our pricing page, currently 30 days on free plans and 120 days on paid Outbound plans.
  • Aggregated Analytics: Up to 24 months for service improvement
  • Support Records: Up to 3 years for quality assurance
  • Suppression and unsubscribe evidence: Retained after the contact or account is deleted, so the request continues to be honoured
  • Security, abuse and complaint records: Retained for as long as needed for the investigation, and longer where required for a legal claim or a mandatory report

Deletion

When you delete a contact, an asset or your account, we remove the data from production systems on the schedule described in our Terms of Service. Two qualifications apply, and we would rather state them than imply an erasure we cannot deliver:

  • Copies held in encrypted backups and disaster recovery systems expire on their own cycle rather than being deleted individually. They are access-restricted and are not used for any other purpose.
  • Records we are required or reasonably need to keep, listed above, are retained, minimised and access-restricted rather than deleted.

Cached copies of public asset URLs held by content delivery networks and mailbox providers may persist for a period after deletion and are outside our direct control.

14. Your Privacy Rights

Australian Privacy Rights

Under the Australian Privacy Act, you have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete information
  • Make a complaint about privacy breaches
  • Request information about our privacy practices

GDPR Rights (EU and UK Users)

If you are in the European Union or the United Kingdom, you also have additional rights including:

  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain types of processing, including direct marketing
  • Right to Withdraw Consent: Withdraw consent for consent-based processing

United States State Privacy Rights

Residents of US states with comprehensive privacy laws may have rights to know, access, correct, delete, and to opt out of sale, sharing and certain profiling. We do not sell personal information or share it for cross-context behavioural advertising. Where we act as a service provider for a customer, we handle these requests through that customer.

If You Are a Recipient, Not a Customer

If your data reached us because a JetEmail customer added you as a contact or sent you an email, that customer decides what happens to it. Direct your request to them. If you cannot identify or reach them, contact us and we will forward your request to the relevant customer and tell you that we have done so. We may not be able to act on the data ourselves without their instruction, except where the law requires us to.

Exercising Your Rights

To exercise your privacy rights, please contact us at legal@jetemail.com. We will respond to your request within the timeframes required by applicable law (typically 30 days for GDPR requests and 30 days for Australian Privacy Act requests).

15. Cookies and Tracking on Our Website

This section is about jetemail.com. Tracking inside email sent by our customers is covered in Section 6, and it works differently.

We do not use cookies for analytics, advertising, profiling, or third-party tracking on jetemail.com. We use one first-party cookie, jetemail_aff, to attribute affiliate referrals so partners get credit when they send sign-ups our way. It stores only a short affiliate code and expires after 60 days.

Where consent is required (EU, EEA, UK, Switzerland), we show a banner asking you to accept or reject the affiliate cookie before it is set. We also store a strictly necessary jetemail_consent cookie to remember your choice so the banner does not reappear.

JetEmail-hosted pages that serve our customers, such as hosted signup forms and hosted unsubscribe pages, do not set advertising or analytics cookies. They may set a strictly necessary cookie or token to complete the action you started.

Full details, including how to change your choice at any time, are in our Cookie Policy.

16. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

17. Children's Privacy

JetEmail accounts are for businesses and adults. Our services are not intended for children, we do not knowingly collect personal information from children for our own purposes, and we will delete it promptly if we become aware that we have.

Signup forms and contact lists are different. Our customers publish forms and upload contacts, and we cannot tell how old a person who fills in a customer's form is. Our Terms of Service and Acceptable Use Policy prohibit customers from using the Services to knowingly collect personal information from, or market to, a child below the age at which consent can be given in their jurisdiction without verifiable parental consent.

If you believe a child's information has been collected through a form or list on our platform, contact legal@jetemail.com and we will investigate with the customer concerned.

18. Automated Decision-Making

We use automated systems to detect spam, fraud and abuse, and to protect deliverability. Those systems can block a message, pause a form, throttle sending or suspend an account without a person reviewing it first.

Where an automated decision materially affects you, you can ask for it to be reviewed by a person by writing to legal@jetemail.com. We will explain the decision to the extent we can without compromising the effectiveness of our abuse controls or the safety of any person, and we will restore service where the decision was wrong.

19. Data Breach Notification

In the event of a data breach that may result in serious harm to individuals, we will:

  • Contain the breach and begin assessing it immediately
  • Complete our assessment within 30 days, as required by the Australian Notifiable Data Breaches scheme, and usually much sooner
  • Notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable where the breach is an eligible data breach
  • Notify relevant EU or UK supervisory authorities within 72 hours where GDPR or UK GDPR requires it
  • Notify our customers without undue delay where the breach affects personal data we process on their behalf, so that they can meet their own notification obligations
  • Take immediate steps to contain and remedy the breach

20. Privacy Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Notify you via email or through our service dashboard
  • Update the "Last updated" date at the top of this policy
  • Provide additional notice for significant changes as required by law

21. Contact Information

If you have questions about this Privacy Policy or our privacy practices, please contact us:

General Privacy Inquiries

Email: legal@jetemail.com

Response time: Within 5 business days

Privacy Rights Requests

Email: legal@jetemail.com

Subject line: "Privacy Rights Request"

Response time: Within 30 days

Privacy Complaints

Email: legal@jetemail.com

Subject line: "Privacy Complaint"

We will investigate and respond within 30 days

External Complaint Options

Australia: Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au

EU: Your local Data Protection Authority

UK: Information Commissioner's Office (ICO)

JetEmail Pty Ltd

Australian Company Number: 641 539 166

Email: legal@jetemail.com

GDPR
Compliant

Features

  • Inbound Protection
  • Outbound SMTP
  • Email API
  • Marketing Suite
  • DMARC Monitoring
  • Email Delivery Speed
  • Pricing

Compare

  • vs Resend
  • vs Postmark
  • vs SMTP2GO
  • vs MailChannels
  • vs Mail Baby

Documentation

  • Getting Started
  • API Reference
  • Integrations
  • Status Page

Company

  • About Us
  • Blog
  • Affiliate Program
  • For Open Source
  • Case Studies
  • Legals
  • Report Abuse

© 2026 JetEmail Pty Ltd. All rights reserved. ABN 73 641 539 166

Dashboard Contact