Privacy Policy
Contents
- Who is responsible
- Controller and processor roles
- Data we collect
- Why we use it and on what legal basis
- AI processing and model training
- Payment data
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights
- Cookies
- Children
- Automated decision-making
- Changes
- Contact and complaints
1. Who is responsible
JC Establishment LLC (trading as CopperMailer): data controller
30 N Gould St, Ste N, Sheridan, WY 82801, United States
Privacy contact: privacy@coppermailer.com
We are a US company. Where we offer the Service to customers in the European Economic Area or the United Kingdom, we apply Regulation (EU) 2016/679 (GDPR) and the UK GDPR to that processing, and we act as a processor for mailbox content under the Data Processing Addendum. We also comply with applicable US federal and state privacy law, including the California Consumer Privacy Act where it applies to a resident of that state.
2. Controller and processor roles
We wear two hats, and it matters which one applies:
| Situation | Our role | Governed by |
|---|---|---|
| You visit our website, sign up, get invoiced, contact support, receive our release notes | Controller: we decide why and how | This Privacy Policy |
| We process the content of mailboxes you connect, including the personal data of the people who email you | Processor: we act only on your documented instructions | Data Processing Addendum; you are the controller |
If you emailed a company that uses CopperMailer and you want your data corrected or erased, please contact that company; they control the data. If you contact us instead, we will forward your request to them and tell you we have done so.
3. Data we collect
3.1 Account and billing data
Name, business name, work email address, telephone number (optional), postal or billing address, VAT number, country, job title (optional), workspace name, licence and unlocks owned, credit balance and ledger, invoices and purchase history, and the card brand, last four digits and expiry date returned to us by Stripe.
3.2 Customer Data (mailbox content)
When you connect a mailbox we process the email messages in it: sender and recipient addresses, subject lines, message bodies, attachments, headers, timestamps and thread structure, plus anything those messages happen to contain. We also store the knowledge sources you upload and the replies generated. We are a processor for all of this.
3.3 Usage and technical data
IP address, browser type and version, operating system, device type, pages viewed, referring URL, timestamps, feature usage counters, API call metadata, error traces, and audit-log entries (who did what, when, from where) in the application.
3.4 Support and communications
Messages you send us, support ticket history, call notes and, where you have opted in, whether you receive our release-note emails.
3.5 Data we do not collect
We do not knowingly collect special-category data (health, biometrics, religion, political opinions, trade-union membership, sexual orientation) about you as a customer, and we do not buy personal data from data brokers. Please do not send special-category data in support tickets. Mailbox content is a different matter: your customers may write anything to you, which is why the DPA and our security controls apply to it.
4. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service and your account | Account, usage, Customer Data | Performance of a contract: Art. 6(1)(b) |
| Billing, invoicing, tax and accounting records | Billing data | Contract: Art. 6(1)(b); legal obligation: Art. 6(1)(c) |
| Support, troubleshooting and service notices | Account, support, technical | Contract: Art. 6(1)(b) |
| Security, fraud and abuse prevention, audit logging | Technical, usage | Legitimate interests, Art. 6(1)(f): protecting our service and our customers |
| Product analytics and improvement (aggregated and pseudonymised) | Usage, technical | Legitimate interests, Art. 6(1)(f): improving a service you pay for |
| Release notes to people who asked for them | Contact | Consent: Art. 6(1)(a), withdrawable in one click at any time. We buy no lists, run no advertising and set no non-essential cookies, so no consent is collected for cookies. |
| Service emails to existing customers about similar features | Contact | Legitimate interests: Art. 6(1)(f), with an unsubscribe link in every message |
| Establishing, exercising or defending legal claims | As relevant | Legitimate interests: Art. 6(1)(f); legal obligation: Art. 6(1)(c) |
Where we rely on legitimate interests, we have carried out a balancing assessment and you may object at any time under clause 11.
5. AI processing and model training
- To generate a reply, the relevant message and the knowledge sources you supplied are sent to a large language model operated by us or by a contracted model provider listed in Annex B of the Data Processing Addendum.
- We do not use the content of your mailboxes to train shared, public or third-party models. We use commercial API terms with our model provider that prohibit training on data we submit. Retention at the provider is governed by that provider’s published API policy, which we link from Annex B of the Data Processing Addendum rather than restate in our own words.
- Tone matching (“Patina Engine”) produces a style profile that is confined to your workspace and never applied to another customer.
- We may use aggregated, de-identified statistics (reply volumes, latency, acceptance rates) which cannot be linked to an individual, to improve the Service.
- You can enable PII redaction so that detected phone numbers, card-like numbers and national identifiers are masked before content reaches a model provider.
- Storage and application processing can be pinned to our EU region on request before onboarding. Model inference currently runs against our provider’s endpoints and we cannot guarantee it stays inside the EEA; if EU-only inference is a hard requirement for you, tell us before you buy, because today we cannot offer it.
6. Payment data
Card payments are processed by Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA, and its EU affiliate Stripe Payments Europe Ltd, Dublin, Ireland. Card details are entered directly into Stripe-hosted fields and are never transmitted to or stored on CopperMailer systems. Stripe acts as an independent controller for payment and fraud-prevention purposes; see the Stripe Privacy Policy. We receive from Stripe only a customer token, the card brand, the last four digits, the expiry date, the country and the outcome of each charge. We are PCI DSS compliant by using Stripe’s hosted payment fields (SAQ A scope).
7. Who we share data with
- Sub-processors: hosting, email infrastructure, model providers, support tooling, analytics. The current list, with locations and purposes, is in Annex B of the Data Processing Addendum. Each is bound by a written data-processing agreement.
- Payment and tax providers: Stripe for payments; our accountants for statutory bookkeeping.
- Professional advisers: lawyers, auditors and insurers, under confidentiality.
- Authorities: where required by a valid legal obligation. We assess every request, refuse overbroad ones, and notify you unless legally prohibited.
- A successor: in a merger, acquisition or asset sale, subject to this policy continuing to apply and notice to you.
We never sell personal data and we never share it with advertising networks or data brokers. That is meant in the legal sense as well as the ordinary one: we do not “sell” or “share” personal information as those terms are defined by the California Consumer Privacy Act as amended, and we have not done so in the preceding 12 months. Every disclosure listed above is a service-provider or business-purpose disclosure under a written contract that forbids the recipient using the data for anything else.
8. International transfers
- Our default hosting region is the United States. Customers who need Customer Data stored at rest in the European Union can have their workspace provisioned in our EU region (Frankfurt, Germany) at no extra cost, but must ask before a mailbox is connected: a workspace cannot be moved between regions afterwards. This matches what the Security section says, and neither statement is marketing.
- Some sub-processors are established in the United States. Where personal data is transferred outside the European Economic Area we rely on the European Commission’s Standard Contractual Clauses (2021/914), supplemented by transfer impact assessments, encryption in transit and at rest, and, where applicable, the EU-US Data Privacy Framework certification of the recipient.
- You can request a copy of the safeguards in place by emailing privacy@coppermailer.com.
- Foundry customers can contractually restrict all processing, including model inference, to the EU.
9. How long we keep data
| Category | Retention |
|---|---|
| Account data | For the life of the account, then 30 days after closure |
| Credit ledger (what each credit was spent on) | For the life of the account, then deleted with account data; the underlying invoices follow the tax retention below |
| Customer Data (mailbox content, replies, knowledge sources) | Rolling 12 months, or until you delete it; in all cases deleted 30 days after the account is closed, and out of backups within 90 days. You can set a shorter period yourself at any time. |
| Audit logs | 12 months, on every licence. Retention is not sold as an upgrade. |
| Invoices, accounting and tax records | 7 years from the end of the relevant tax year (US statutory requirement) |
| Support tickets | 24 months from closure |
| Marketing contacts | Until consent is withdrawn, or 24 months of inactivity |
| Website server logs | 90 days |
| Free accounts that never make a purchase | Kept while in use; closed after 24 months of inactivity on 30 days’ notice, then deleted |
10. Security
TLS 1.2+ in transit, AES-256 at rest, encrypted backups, role-based access control, mandatory MFA on administrative accounts, least-privilege access, isolated per-tenant data, centralised audit logging and a documented incident-response plan. We have not yet commissioned an external penetration test and hold no third-party security certification; the Security section sets out exactly what is and is not in place, including the gaps.
10.1 If something goes wrong
If a personal data breach occurs, we notify affected customers without undue delay and within 72 hours of becoming aware of it, whether or not the law requires it in a particular case. Where we act as processor for mailbox content, that notice goes to you as controller so you can meet your own Article 33 deadline, and it includes what happened, which data and how many records are involved, what we have done and what we suggest you do. Where we are the controller, we notify the competent supervisory authority under Article 33 and, where the risk to individuals is high, the individuals themselves under Article 34. We do not wait for a full investigation before telling you that one is happening.
Card data is out of scope for any breach of ours by design: it never reaches our systems, because it is captured directly by Stripe.
11. Your rights
Where we are the controller you have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectify data that is inaccurate or incomplete;
- Erase data where the conditions of Article 17 are met;
- Restrict processing in the circumstances of Article 18;
- Data portability: receive data you gave us in a structured, machine-readable format;
- Object to processing based on legitimate interests, and to direct marketing at any time, absolutely;
- Withdraw consent at any time, without affecting processing already carried out;
- Complain to a supervisory authority.
Write to privacy@coppermailer.com. We reply within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask for proof of identity. Exercising these rights is free; we charge only for manifestly unfounded or excessive repeat requests.
If you are in the EEA or the UK, you may lodge a complaint with the supervisory authority where you live or work. Nothing here requires you to contact us first, though we would rather you did, because we can usually fix it faster.
11.1 California and other US state privacy rights
If you are a resident of California, and in substance also of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and the other states with comprehensive privacy statutes, you have the rights below in respect of data for which we are the business or controller. They sit alongside the rights above rather than replacing them, and we apply them to every US resident who asks, without checking which state you are in.
- Know and access. What categories of personal information we collected about you in the past 12 months, the sources, the purposes, the categories of recipient, and a copy of the specific pieces.
- Delete personal information we hold about you, subject to the exceptions in the statute, chiefly our legal duty to keep invoices and tax records for seven years.
- Correct inaccurate personal information.
- Opt out of sale, sharing and targeted advertising. There is nothing to opt out of: we do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. We have not done so in the preceding 12 months and we have no plans to start. We run no advertising pixels, no ad networks and no cross-site tracking.
- Limit the use of sensitive personal information. We do not collect sensitive personal information about our customers for any purpose that would trigger this right.
- Non-discrimination. Exercising any of these rights costs nothing, and never changes the price you pay, the credits you get or the service you receive. We operate no financial-incentive programme.
- Appeal. If we refuse a request, you may appeal by replying to our decision. A different person reviews it and answers within 45 days, with reasons. Where your state provides one, you may then complain to your Attorney General.
The categories of personal information in the tables in clause 3, collected for the purposes in clause 4 and disclosed for a business purpose only to the recipients in clause 7, are the complete picture; we do not maintain a separate, longer list somewhere else.
Requests go to privacy@coppermailer.com. We confirm receipt within 10 business days and answer within 45 days, extendable once by a further 45 where the request is complex, in which case we tell you before the first period runs out. An authorised agent may act for you if you give them written permission and we can verify it with you directly.
Global Privacy Control. We honour GPC and similar browser opt-out signals. In practice they change nothing here, because we set no advertising or tracking cookies to begin with; if that ever changes, the signal will be respected automatically and clause 12.5 will say so before the first such cookie is set.
12. Cookies
This website sets no cookies at all, which is why you have not seen a banner on it. The application sets strictly necessary cookies only: session, CSRF, load balancing, and two interface preferences you set yourself. We run no analytics, advertising or cross-site tracking cookies anywhere. The rest of this clause sets out every cookie, its purpose and its duration.
12.1 What cookies are
Cookies are small text files placed on your device by a website. Similar technologies (local storage, session storage and pixels) do comparable jobs, and this clause covers them too. We use them to keep you signed in, to keep the site secure, and (only if you agree) to understand how the site is used.
This website sets no cookies at all. There is no banner because there is nothing to consent to. Open your browser’s developer tools and check: the pages you are reading now are static HTML and one stylesheet, and they store nothing on your device. The cookies described in clause 12.3 belong to the CopperMailer application, which you reach only after signing in.
12.2 Your choices
- On this website: nothing is set, so there is nothing to choose. We do not run analytics here, and we do not load any third-party script.
- In the application: strictly necessary cookies are set without consent, because you cannot stay signed in without them. That is permitted by Article 5(3) of the ePrivacy Directive and equivalent rules.
- The application sets no analytics, advertising, retargeting or cross-site tracking cookies. If we ever add a non-essential cookie, we will ask for consent before setting it and update this clause first.
- You can delete any of these at any time in your browser. Deleting the session cookie signs you out; nothing else breaks.
12.3 Cookies we use
All of the following are set by the application at app.coppermailer.com after you sign in. None of them is set by the pages on this marketing site.
Strictly necessary: always active
| Name | Provider | Purpose | Duration |
|---|---|---|---|
cm_session | CopperMailer (first party) | Keeps you signed in to the application | Session, or 30 days if “remember me” is ticked |
cm_csrf | CopperMailer | Cross-site request forgery protection on forms | Session |
cm_lb | CopperMailer | Load-balancer affinity, keeps your requests on one server | Session |
__stripe_mid, __stripe_sid | Stripe | Fraud prevention on the payment page; required to take a card payment safely. Set by Stripe, on Stripe’s own checkout page, only when you are actually buying something. | 1 year / 30 minutes |
Preferences: strictly necessary, first party, no tracking
| Name | Provider | Purpose | Duration |
|---|---|---|---|
cm_theme | CopperMailer | Remembers light or dark interface preference. Set only when you change the setting yourself. | 12 months |
cm_lang | CopperMailer | Remembers interface language. Set only when you change the setting yourself. | 12 months |
Analytics and advertising
We set none. There is no analytics cookie, no advertising cookie, no retargeting pixel and no cross-site tracker anywhere on this website or in the application. This is not a promise about the future dressed up as a fact: it is what is deployed today, and clause 12.5 says what happens if it changes.
12.4 Controlling cookies in your browser
Every major browser lets you block or delete cookies: Chrome (Settings → Privacy and security → Third-party cookies), Firefox (Settings → Privacy & Security), Safari (Preferences → Privacy), Edge (Settings → Cookies and site permissions). Blocking strictly necessary cookies will stop you from signing in.
12.5 Changes to this clause
If we add a cookie we update this clause first. If the new cookie is anything other than strictly necessary, we will ask for your consent before setting it, and rejecting will be exactly as easy as accepting. The version and date at the top of this policy show the current version.
12.6 Cookie questions
Questions: privacy@coppermailer.com
JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States
13. Children
The Service is intended for business use by adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with data, contact privacy@coppermailer.com and we will delete it.
14. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The Service generates text automatically, but it does not decide anything about your rights, and you configure whether a human reviews output before it is sent.
15. Changes
We will update this policy when our practices change. Material changes are announced by email and in the application at least 30 days before they take effect. The version and date at the top always tell you what you are reading. This is version 1.1: it adds US state privacy rights, a 72-hour breach-notification commitment and a correction to how hosting regions are described. It gives you more than version 1.0 did and takes nothing away. Earlier versions are archived and available on request from privacy@coppermailer.com.
16. Contact and complaints
Privacy team: privacy@coppermailer.com · answered Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET)
Post: JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States
Two things we would rather state than let you discover. We have not appointed a Data Protection Officer, because our processing does not meet the Article 37 thresholds that would require one; the address above reaches the person who actually handles these requests, not a queue. We have not yet appointed an Article 27 representative in the European Union or the United Kingdom. We will appoint one before we market actively into the EEA, and until then EEA and UK data subjects can write to the address above, or to their own supervisory authority, and lose nothing by doing so: we answer within the statutory deadline either way.
If you are unhappy with how we have handled a request, say so in the same thread and ask for escalation. Someone who was not involved in the original decision reviews it and replies within 14 days. That is in addition to, and never a precondition of, your right to complain to a supervisory authority.