Legal
Privacy Policy
Last updated: August 4, 2026
1. What we collect
We collect information needed to provide Automizely, including:
- account information such as name, email address, password hash, and email verification status;
- contact data you upload or import, such as names, email addresses, phone numbers, push subscriptions, custom fields, consent flags, and unsubscribe state;
- credentials and configuration for the third-party accounts you connect, such as store, marketplace, REST, and message-provider keys, which are stored encrypted;
- campaign records such as message content, audience selection, send status per recipient, opens, clicks, bounces, failures, and survey responses;
- content you create and publish, such as landing pages, blog posts, social posts, and their view counts;
- automation definitions and run logs, including the payloads and step results of each run;
- API token metadata, such as token prefix and last-used time;
- technical logs such as IP address, timestamps, request metadata, and error logs.
2. How we use information
We use information to operate the service, authenticate users, send verification and reset emails, deliver and track the campaigns you send, publish the content you create, run the automations you configure, show you analytics for your own account, prevent abuse, improve reliability, and comply with legal obligations.
3. Emails and notifications
We send transactional emails for your account, such as email verification and password reset. Campaigns you send are delivered through the provider account you connect, using your own credentials and sending reputation, and we process the resulting engagement records so you can report on them. Recipients of your campaigns can unsubscribe through the link included in a send, which sets their unsubscribe state in your contact list.
4. Your role and ours
For your account data, we decide how information is handled. For the contact data you upload or import, you decide: you choose which contacts to add, what to send them, and on what legal basis. You are responsible for having the right to contact those people and for honouring their consent and unsubscribe choices, which the service records and applies to future sends.
5. Cookies and local storage
We use essential cookies and local storage for sign-in, security, and saved preferences. See the Cookie Policy for more detail.
6. Service providers and connected accounts
We may use service providers for hosting, databases, transactional email delivery, and security. These providers process information only as needed to provide their services to us.
Separately, when you connect a third-party account — a store, a marketplace, a REST endpoint, or a message provider such as SendGrid, Twilio, or a web-push service — the service acts on your behalf against that account using the credentials you supply. Data sent to or read from a connected account is governed by your agreement with that provider, not by this policy.
7. Data sharing
We do not sell personal information. We may disclose information if required by law, to protect rights and security, or as part of a business transfer such as merger, acquisition, or reorganization.
8. Data retention
We keep account, contact, campaign, content, automation, and security records for as long as needed to provide the service, resolve issues, comply with obligations, and maintain abuse-prevention records. Users may request deletion of account data by contacting us. Deleting a connection removes its stored credentials from our database.
9. Your choices
You can edit or delete contacts, connections, campaigns, content, and automations in your account. You can reject optional cookies in the cookie banner. You can contact us to request access, correction, deletion, or portability where applicable.
10. Security
We use reasonable administrative, technical, and organizational safeguards, including password hashing, email verification, rate limits, hashed API tokens, encryption of connected third-party credentials at rest, and blocking of requests to private network addresses. Credentials for connected accounts are never returned to the browser; only a masked prefix is shown. No system is completely secure.
11. International use
The service may be operated from, and data may be processed in, countries other than where you live. By using the service, you understand that information may be transferred and processed in those locations.
12. Children
The service is not intended for children under 13, and we do not knowingly collect information from children.
13. Contact
Privacy questions or requests can be sent to [email protected].