Skip to content
Cu CopperMailer
How it works Product Pricing Docs Security Company Legal Polski Sign in Request access
Home/Privacy Policy

Privacy Policy

Effective date: 3 August 2026 · Version 1.1 · Previous version 1.0 of 29 July 2026
This policy explains how JC Establishment LLC handles personal data. It covers our website, our own business correspondence and the CopperMailer application.

Contents

  1. Who is responsible
  2. Controller and processor roles
  3. Data we collect
  4. Why we use it and on what legal basis
  5. AI processing and model training
  6. Payment data
  7. Who we share data with
  8. International transfers
  9. How long we keep data
  10. Security
  11. Your rights
  12. Cookies
  13. Children
  14. Automated decision-making
  15. Changes
  16. Contact and complaints

1. Who is responsible

JC Establishment LLC (trading as CopperMailer): data controller
30 N Gould St, Ste N, Sheridan, WY 82801, United States
Privacy contact: privacy@coppermailer.com

We are a US company. Where we offer the Service to customers in the European Economic Area or the United Kingdom, we apply Regulation (EU) 2016/679 (GDPR) and the UK GDPR to that processing, and we act as a processor for mailbox content under the Data Processing Addendum. We also comply with applicable US federal and state privacy law, including the California Consumer Privacy Act where it applies to a resident of that state.

2. Controller and processor roles

We wear two hats, and it matters which one applies:

SituationOur roleGoverned by
You visit our website, sign up, get invoiced, contact support, receive our release notesController: we decide why and howThis Privacy Policy
We process the content of mailboxes you connect, including the personal data of the people who email youProcessor: we act only on your documented instructionsData Processing Addendum; you are the controller

If you emailed a company that uses CopperMailer and you want your data corrected or erased, please contact that company; they control the data. If you contact us instead, we will forward your request to them and tell you we have done so.

3. Data we collect

3.1 Account and billing data

Name, business name, work email address, telephone number (optional), postal or billing address, VAT number, country, job title (optional), workspace name, licence and unlocks owned, credit balance and ledger, invoices and purchase history, and the card brand, last four digits and expiry date returned to us by Stripe.

3.2 Customer Data (mailbox content)

When you connect a mailbox we process the email messages in it: sender and recipient addresses, subject lines, message bodies, attachments, headers, timestamps and thread structure, plus anything those messages happen to contain. We also store the knowledge sources you upload and the replies generated. We are a processor for all of this.

3.3 Usage and technical data

IP address, browser type and version, operating system, device type, pages viewed, referring URL, timestamps, feature usage counters, API call metadata, error traces, and audit-log entries (who did what, when, from where) in the application.

3.4 Support and communications

Messages you send us, support ticket history, call notes and, where you have opted in, whether you receive our release-note emails.

3.5 Data we do not collect

We do not knowingly collect special-category data (health, biometrics, religion, political opinions, trade-union membership, sexual orientation) about you as a customer, and we do not buy personal data from data brokers. Please do not send special-category data in support tickets. Mailbox content is a different matter: your customers may write anything to you, which is why the DPA and our security controls apply to it.

4. Why we use it and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Providing the Service and your accountAccount, usage, Customer DataPerformance of a contract: Art. 6(1)(b)
Billing, invoicing, tax and accounting recordsBilling dataContract: Art. 6(1)(b); legal obligation: Art. 6(1)(c)
Support, troubleshooting and service noticesAccount, support, technicalContract: Art. 6(1)(b)
Security, fraud and abuse prevention, audit loggingTechnical, usageLegitimate interests, Art. 6(1)(f): protecting our service and our customers
Product analytics and improvement (aggregated and pseudonymised)Usage, technicalLegitimate interests, Art. 6(1)(f): improving a service you pay for
Release notes to people who asked for themContactConsent: Art. 6(1)(a), withdrawable in one click at any time. We buy no lists, run no advertising and set no non-essential cookies, so no consent is collected for cookies.
Service emails to existing customers about similar featuresContactLegitimate interests: Art. 6(1)(f), with an unsubscribe link in every message
Establishing, exercising or defending legal claimsAs relevantLegitimate interests: Art. 6(1)(f); legal obligation: Art. 6(1)(c)

Where we rely on legitimate interests, we have carried out a balancing assessment and you may object at any time under clause 11.

5. AI processing and model training

  1. To generate a reply, the relevant message and the knowledge sources you supplied are sent to a large language model operated by us or by a contracted model provider listed in Annex B of the Data Processing Addendum.
  2. We do not use the content of your mailboxes to train shared, public or third-party models. We use commercial API terms with our model provider that prohibit training on data we submit. Retention at the provider is governed by that provider’s published API policy, which we link from Annex B of the Data Processing Addendum rather than restate in our own words.
  3. Tone matching (“Patina Engine”) produces a style profile that is confined to your workspace and never applied to another customer.
  4. We may use aggregated, de-identified statistics (reply volumes, latency, acceptance rates) which cannot be linked to an individual, to improve the Service.
  5. You can enable PII redaction so that detected phone numbers, card-like numbers and national identifiers are masked before content reaches a model provider.
  6. Storage and application processing can be pinned to our EU region on request before onboarding. Model inference currently runs against our provider’s endpoints and we cannot guarantee it stays inside the EEA; if EU-only inference is a hard requirement for you, tell us before you buy, because today we cannot offer it.

6. Payment data

Card payments are processed by Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA, and its EU affiliate Stripe Payments Europe Ltd, Dublin, Ireland. Card details are entered directly into Stripe-hosted fields and are never transmitted to or stored on CopperMailer systems. Stripe acts as an independent controller for payment and fraud-prevention purposes; see the Stripe Privacy Policy. We receive from Stripe only a customer token, the card brand, the last four digits, the expiry date, the country and the outcome of each charge. We are PCI DSS compliant by using Stripe’s hosted payment fields (SAQ A scope).

7. Who we share data with

  • Sub-processors: hosting, email infrastructure, model providers, support tooling, analytics. The current list, with locations and purposes, is in Annex B of the Data Processing Addendum. Each is bound by a written data-processing agreement.
  • Payment and tax providers: Stripe for payments; our accountants for statutory bookkeeping.
  • Professional advisers: lawyers, auditors and insurers, under confidentiality.
  • Authorities: where required by a valid legal obligation. We assess every request, refuse overbroad ones, and notify you unless legally prohibited.
  • A successor: in a merger, acquisition or asset sale, subject to this policy continuing to apply and notice to you.

We never sell personal data and we never share it with advertising networks or data brokers. That is meant in the legal sense as well as the ordinary one: we do not “sell” or “share” personal information as those terms are defined by the California Consumer Privacy Act as amended, and we have not done so in the preceding 12 months. Every disclosure listed above is a service-provider or business-purpose disclosure under a written contract that forbids the recipient using the data for anything else.

8. International transfers

  1. Our default hosting region is the United States. Customers who need Customer Data stored at rest in the European Union can have their workspace provisioned in our EU region (Frankfurt, Germany) at no extra cost, but must ask before a mailbox is connected: a workspace cannot be moved between regions afterwards. This matches what the Security section says, and neither statement is marketing.
  2. Some sub-processors are established in the United States. Where personal data is transferred outside the European Economic Area we rely on the European Commission’s Standard Contractual Clauses (2021/914), supplemented by transfer impact assessments, encryption in transit and at rest, and, where applicable, the EU-US Data Privacy Framework certification of the recipient.
  3. You can request a copy of the safeguards in place by emailing privacy@coppermailer.com.
  4. Foundry customers can contractually restrict all processing, including model inference, to the EU.

9. How long we keep data

CategoryRetention
Account dataFor the life of the account, then 30 days after closure
Credit ledger (what each credit was spent on)For the life of the account, then deleted with account data; the underlying invoices follow the tax retention below
Customer Data (mailbox content, replies, knowledge sources)Rolling 12 months, or until you delete it; in all cases deleted 30 days after the account is closed, and out of backups within 90 days. You can set a shorter period yourself at any time.
Audit logs12 months, on every licence. Retention is not sold as an upgrade.
Invoices, accounting and tax records7 years from the end of the relevant tax year (US statutory requirement)
Support tickets24 months from closure
Marketing contactsUntil consent is withdrawn, or 24 months of inactivity
Website server logs90 days
Free accounts that never make a purchaseKept while in use; closed after 24 months of inactivity on 30 days’ notice, then deleted

10. Security

TLS 1.2+ in transit, AES-256 at rest, encrypted backups, role-based access control, mandatory MFA on administrative accounts, least-privilege access, isolated per-tenant data, centralised audit logging and a documented incident-response plan. We have not yet commissioned an external penetration test and hold no third-party security certification; the Security section sets out exactly what is and is not in place, including the gaps.

10.1 If something goes wrong

If a personal data breach occurs, we notify affected customers without undue delay and within 72 hours of becoming aware of it, whether or not the law requires it in a particular case. Where we act as processor for mailbox content, that notice goes to you as controller so you can meet your own Article 33 deadline, and it includes what happened, which data and how many records are involved, what we have done and what we suggest you do. Where we are the controller, we notify the competent supervisory authority under Article 33 and, where the risk to individuals is high, the individuals themselves under Article 34. We do not wait for a full investigation before telling you that one is happening.

Card data is out of scope for any breach of ours by design: it never reaches our systems, because it is captured directly by Stripe.

11. Your rights

Where we are the controller you have the right to:

  • Access the personal data we hold about you and receive a copy;
  • Rectify data that is inaccurate or incomplete;
  • Erase data where the conditions of Article 17 are met;
  • Restrict processing in the circumstances of Article 18;
  • Data portability: receive data you gave us in a structured, machine-readable format;
  • Object to processing based on legitimate interests, and to direct marketing at any time, absolutely;
  • Withdraw consent at any time, without affecting processing already carried out;
  • Complain to a supervisory authority.

Write to privacy@coppermailer.com. We reply within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask for proof of identity. Exercising these rights is free; we charge only for manifestly unfounded or excessive repeat requests.

If you are in the EEA or the UK, you may lodge a complaint with the supervisory authority where you live or work. Nothing here requires you to contact us first, though we would rather you did, because we can usually fix it faster.

11.1 California and other US state privacy rights

If you are a resident of California, and in substance also of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and the other states with comprehensive privacy statutes, you have the rights below in respect of data for which we are the business or controller. They sit alongside the rights above rather than replacing them, and we apply them to every US resident who asks, without checking which state you are in.

  • Know and access. What categories of personal information we collected about you in the past 12 months, the sources, the purposes, the categories of recipient, and a copy of the specific pieces.
  • Delete personal information we hold about you, subject to the exceptions in the statute, chiefly our legal duty to keep invoices and tax records for seven years.
  • Correct inaccurate personal information.
  • Opt out of sale, sharing and targeted advertising. There is nothing to opt out of: we do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. We have not done so in the preceding 12 months and we have no plans to start. We run no advertising pixels, no ad networks and no cross-site tracking.
  • Limit the use of sensitive personal information. We do not collect sensitive personal information about our customers for any purpose that would trigger this right.
  • Non-discrimination. Exercising any of these rights costs nothing, and never changes the price you pay, the credits you get or the service you receive. We operate no financial-incentive programme.
  • Appeal. If we refuse a request, you may appeal by replying to our decision. A different person reviews it and answers within 45 days, with reasons. Where your state provides one, you may then complain to your Attorney General.

The categories of personal information in the tables in clause 3, collected for the purposes in clause 4 and disclosed for a business purpose only to the recipients in clause 7, are the complete picture; we do not maintain a separate, longer list somewhere else.

Requests go to privacy@coppermailer.com. We confirm receipt within 10 business days and answer within 45 days, extendable once by a further 45 where the request is complex, in which case we tell you before the first period runs out. An authorised agent may act for you if you give them written permission and we can verify it with you directly.

Global Privacy Control. We honour GPC and similar browser opt-out signals. In practice they change nothing here, because we set no advertising or tracking cookies to begin with; if that ever changes, the signal will be respected automatically and clause 12.5 will say so before the first such cookie is set.

12. Cookies

This website sets no cookies at all, which is why you have not seen a banner on it. The application sets strictly necessary cookies only: session, CSRF, load balancing, and two interface preferences you set yourself. We run no analytics, advertising or cross-site tracking cookies anywhere. The rest of this clause sets out every cookie, its purpose and its duration.

12.1 What cookies are

Cookies are small text files placed on your device by a website. Similar technologies (local storage, session storage and pixels) do comparable jobs, and this clause covers them too. We use them to keep you signed in, to keep the site secure, and (only if you agree) to understand how the site is used.

This website sets no cookies at all. There is no banner because there is nothing to consent to. Open your browser’s developer tools and check: the pages you are reading now are static HTML and one stylesheet, and they store nothing on your device. The cookies described in clause 12.3 belong to the CopperMailer application, which you reach only after signing in.

12.2 Your choices

  1. On this website: nothing is set, so there is nothing to choose. We do not run analytics here, and we do not load any third-party script.
  2. In the application: strictly necessary cookies are set without consent, because you cannot stay signed in without them. That is permitted by Article 5(3) of the ePrivacy Directive and equivalent rules.
  3. The application sets no analytics, advertising, retargeting or cross-site tracking cookies. If we ever add a non-essential cookie, we will ask for consent before setting it and update this clause first.
  4. You can delete any of these at any time in your browser. Deleting the session cookie signs you out; nothing else breaks.

12.3 Cookies we use

All of the following are set by the application at app.coppermailer.com after you sign in. None of them is set by the pages on this marketing site.

Strictly necessary: always active

NameProviderPurposeDuration
cm_sessionCopperMailer (first party)Keeps you signed in to the applicationSession, or 30 days if “remember me” is ticked
cm_csrfCopperMailerCross-site request forgery protection on formsSession
cm_lbCopperMailerLoad-balancer affinity, keeps your requests on one serverSession
__stripe_mid, __stripe_sidStripeFraud prevention on the payment page; required to take a card payment safely. Set by Stripe, on Stripe’s own checkout page, only when you are actually buying something.1 year / 30 minutes

Preferences: strictly necessary, first party, no tracking

NameProviderPurposeDuration
cm_themeCopperMailerRemembers light or dark interface preference. Set only when you change the setting yourself.12 months
cm_langCopperMailerRemembers interface language. Set only when you change the setting yourself.12 months

Analytics and advertising

We set none. There is no analytics cookie, no advertising cookie, no retargeting pixel and no cross-site tracker anywhere on this website or in the application. This is not a promise about the future dressed up as a fact: it is what is deployed today, and clause 12.5 says what happens if it changes.

12.4 Controlling cookies in your browser

Every major browser lets you block or delete cookies: Chrome (Settings → Privacy and security → Third-party cookies), Firefox (Settings → Privacy & Security), Safari (Preferences → Privacy), Edge (Settings → Cookies and site permissions). Blocking strictly necessary cookies will stop you from signing in.

12.5 Changes to this clause

If we add a cookie we update this clause first. If the new cookie is anything other than strictly necessary, we will ask for your consent before setting it, and rejecting will be exactly as easy as accepting. The version and date at the top of this policy show the current version.

12.6 Cookie questions

Questions: privacy@coppermailer.com
JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States

13. Children

The Service is intended for business use by adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with data, contact privacy@coppermailer.com and we will delete it.

14. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The Service generates text automatically, but it does not decide anything about your rights, and you configure whether a human reviews output before it is sent.

15. Changes

We will update this policy when our practices change. Material changes are announced by email and in the application at least 30 days before they take effect. The version and date at the top always tell you what you are reading. This is version 1.1: it adds US state privacy rights, a 72-hour breach-notification commitment and a correction to how hosting regions are described. It gives you more than version 1.0 did and takes nothing away. Earlier versions are archived and available on request from privacy@coppermailer.com.

16. Contact and complaints

Privacy team: privacy@coppermailer.com · answered Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET)
Post: JC Establishment LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States

Two things we would rather state than let you discover. We have not appointed a Data Protection Officer, because our processing does not meet the Article 37 thresholds that would require one; the address above reaches the person who actually handles these requests, not a queue. We have not yet appointed an Article 27 representative in the European Union or the United Kingdom. We will appoint one before we market actively into the EEA, and until then EEA and UK data subjects can write to the address above, or to their own supervisory authority, and lose nothing by doing so: we answer within the statutory deadline either way.

If you are unhappy with how we have handled a request, say so in the same thread and ask for escalation. Someone who was not involved in the original decision reviews it and replies within 14 days. That is in addition to, and never a precondition of, your right to complain to a supervisory authority.

Cu CopperMailer

Customer-service software for shared support inboxes: it answers the mail your own customers send you. Licensed software, sold as one-time purchases and delivered to your account in seconds. It replies to messages already in your mailbox and has no way to start a conversation.

Business address

JC Establishment LLC
trading as CopperMailer
30 N Gould St, Ste N
Sheridan, WY 82801
United States
support@coppermailer.com
Registered in
State of Wyoming, United States
Business activity
Publisher and licensor of its own customer-service software (SaaS). Merchant category 5734 – computer software.
VisaMastercardAmerican ExpressDiscoverApple PayGoogle Pay

Card payments processed by Stripe. Prices are quoted in USD; where a local payment method settles in another currency – PLN for customers in Poland, for example – the exact amount is shown before you confirm.

Product

  • How it works
  • The interface
  • Features
  • API & documentation
  • Pricing
  • How credits work
  • Security

Legal & payments

  • Merchant information
  • Payments
  • Terms of Service
  • Privacy Policy
  • Return & Refund Policy
  • Acceptable Use Policy
  • Cookie Policy
  • Data Processing Addendum
  • Sub-processors
  • All legal documents

Company

  • Request an account
  • Sign in
  • About us
  • Company details
  • Contact & support
  • Support hours
  • Informacje po polsku
  • Billing enquiries
  • Report abuse
  • Security disclosure

JC Establishment LLC, a limited liability company organised under the laws of the State of Wyoming, United States, trading as CopperMailer, is the seller, the invoicing entity and the merchant of record for every purchase made on this site. Business address: 30 N Gould St, Ste N, Sheridan, WY 82801, United States. Customer service: support@coppermailer.com, Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET).

What we sell: licences and usage of our own cloud-hosted customer-service software, which drafts replies to email that our customers’ own correspondents have sent them. Software publishing, merchant category 5734; NAICS 511210, PKD 58.29.Z. Everything here is our own product, sold by us to the person who uses it, delivered digitally and immediately; no physical goods, no third-party sales and no money handled on anyone else’s behalf. See Business classification.

All prices are quoted, charged and refunded in United States dollars. Every purchase is a single charge that appears on your statement as JC Establishment – the legal name of the company behind CopperMailer, so you recognise it when it lands. There are no subscriptions, no renewals, no automatic top-ups and no handling or processing fees. Access is delivered digitally and applied to your account immediately on payment; no physical goods are sold or shipped. Card payments are processed by Stripe on Stripe-hosted fields, and CopperMailer never receives or stores full card numbers.

Terms of Service · Privacy Policy · Return & Refund Policy · Payments · Acceptable Use Policy · Cookie Policy · Business classification · Company details · Information for payment providers · Informacje dla klientów z Polski
Customer service: support@coppermailer.com · Billing and refunds: billing@coppermailer.com · Monday to Friday, 09:00 to 17:00 Mountain Time (17:00 to 01:00 CET)

© 2026 JC Establishment LLC. All rights reserved. CopperMailer is a trading name of JC Establishment LLC, a Wyoming limited liability company