Privacy Policy
Effective August 24, 2026 · Version v1.4.0-2026-08-24
Inventory Mailer is operated by Zonyx Labs LLC - Inventory Mailer Protected Series ("we," "us," or "our"), a protected series of Zonyx Labs LLC, a Florida limited liability company, located at 7901 4th St N, STE 300, St. Petersburg, FL 33702. This policy explains what data we collect, how we use it, who we share it with, and the rights you have. We keep it plain on purpose. The one idea that makes the rest make sense: for your own account we are the company you are dealing with, but for the people you email and the people who reach out to you, we are only handling that data on your behalf.
1. Two different roles
It matters which data we are talking about, because the law treats the two differently.
- Your account data (we are the controller). The information about you and your business that you give us to open and run your account. We decide how to handle it, and this policy governs it.
- Your contacts, recipients, and inquirers (we are the processor). The people you upload and email, and the people who contact you through your public item pages and showcases. You decide why and how that data is used; we only process it to provide the Service to you. Under the GDPR you are the data controller and we are your processor (see our Data Processing Addendum). You are responsible for having a lawful basis to email those people.
2. What we collect
When you sign up and use your account:
- Your name, email, company name, and the IP address of the signup request.
- A bot-protection check at signup and login (Cloudflare Turnstile), which sees your IP address and challenge response.
- Billing details handled by Stripe: your billing name and address and your payment method. Card numbers are held by Stripe, not by us.
- What you create and manage in the app: inventory, templates, campaigns, saved filters, team members, and audit logs of important changes.
- Support messages you send us, and basic, aggregate usage data about how the Service is used.
- Contact details a team member chooses to publish. A member can turn on a public contact card for themselves, which shows their name, title, a phone number they enter for this purpose, and, if they enable it, their sending address. It is off by default, each member controls their own, and an account owner or admin can switch someone else's off but cannot switch it on for them.
On behalf of you, as your processor:
- The contacts you import (such as names, email addresses, and any fields you add).
- The content of the email you compose and send.
- Engagement events on that email: opens, clicks, bounces, spam complaints, and unsubscribes.
- Inquiries submitted through your public item pages and showcases: the sender's name and email address, a phone number and message if they provide them, whether they ticked the box asking to hear from you, and a record of the item they were looking at and the campaign or showcase that brought them there.
Your public pages
Showcases and item pages are published to the open web, so anyone with the link can see what you put on them. We ask search engines not to index them, but that is a request to search engines and not a security control. Decide what belongs on a public page accordingly.
When someone submits the inquiry form on one of those pages, we check their IP address against a rate limit and a bot-protection challenge (Cloudflare Turnstile) to keep the form from being abused. We use the IP address for that check and do not store it on the inquiry. If they tick the box asking to hear from you, we add them to your contacts as subscribed, and that ticked box is the record of their consent. If they leave it unticked, they are not added. We never add an address that has previously unsubscribed, bounced, or filed a complaint.
The same thing, in the categories California law uses
California and several other states ask us to describe account data by category rather than by example. This is the same data listed above, sorted the way those laws sort it.
- Identifiers
- Your name, email address, account identifier, and the IP address of your requests.
- Commercial information
- Your plan, subscription status, billing history, and the add-ons you use.
- Financial information
- Billing name and address, and a payment method token. Card numbers are held by Stripe and never reach us.
- Professional information
- Your company name, the role you hold in your own account, and, if you turn on a public contact card for yourself, the name, title, phone number, and sending address you choose to publish on it.
- Internet activity
- Aggregate usage of the app, security and operational logs, and the bot-protection challenge result at signup and login.
- Not collected
- We do not collect sensitive personal information, precise geolocation, biometric data, government identifiers, or protected-classification data, and we do not build inferences or profiles about you.
- Sources
- You, your use of the Service, and the vendors that process on our behalf (payments and bot protection).
- Why we use it
- The business purposes in Section 3 below, and nothing else.
- Who we disclose it to
- Only the vendors on our Subprocessors page, for those same purposes, and where the law requires it.
- Sold or shared
- No. See Section 5.
- How long we keep it
- See Section 9.
3. How we use data
- To provide the Service: storing your inventory and contacts and sending the email you direct.
- To bill you, through Stripe.
- To keep the platform secure and protect against abuse, fraud, and spam.
- To maintain deliverability, including suppressing addresses that bounce or complain.
- To respond to your support requests and send you service-related notices.
- To meet legal obligations (for example CAN-SPAM, the GDPR, tax rules, and lawful requests).
We do not use the contacts or email content you upload to train AI models, and we do not use it for our own marketing.
4. Legal bases (GDPR)
For account data where the GDPR applies, we rely on:
- Contract: to provide the Service you signed up for and to bill you.
- Legitimate interests: to secure the platform, prevent abuse, and improve the Service, balanced against your rights.
- Legal obligation: to comply with the laws that apply to us.
For the contacts and recipients you process through the Service, the lawful basis is yours to establish and document as the controller.
5. We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are used under California law. We do not share your data with anyone outside the vendors on our Subprocessors page for their own marketing. We share data only with those subprocessors, to operate the Service, and when the law requires it or to protect rights and safety.
6. Subprocessors
We rely on a short list of vendors to run the Service (for hosting, the database, email delivery, payments, AI routing, and bot protection). Each one sees only the data it needs. They are listed, with what each receives and where it is hosted, on our Subprocessors page, and each is bound by its own data commitments. The AI assistant runs through a gateway configured for zero data retention at the model layer.
7. Recipients of your campaigns
When you send a campaign, the recipients are your contacts, not ours. We process their data on your behalf as a processor under GDPR Article 28. You are the controller responsible for having consent or another lawful basis to email them, and for honoring their requests. Every campaign we send includes a working unsubscribe link, your sender identity, and your postal address, and we suppress addresses that unsubscribe, bounce, or complain so they stay off your future sends.
8. Cookies and tracking
On this Service we use a session cookie to keep you signed in and the bot-protection check noted above. We do not use third-party advertising cookies on the app, and we do not track you across other sites. Because we do not sell or share personal information or serve targeted advertising, there is nothing for a browser opt-out preference signal such as Global Privacy Control to turn off. We honor those signals by having nothing to disable.
Our public website. On inventorymailer.com we use Vercel Web Analytics to count page views and see which pages people read. It sets no cookies, stores no identifier on your device, and cannot follow you to any other site: it derives a temporary, non-reversible hash per visit and discards it. We get totals, not people. This is why the site shows no cookie banner. There is nothing to consent to and nothing for you to turn off.
Separately, marketing email you send through the platform can include an open-tracking pixel and link rewrites so you can see engagement. That tracking is part of the campaigns you send to your recipients; every email carries an unsubscribe link, and recipients who opt out are suppressed.
9. Data retention
- Account and content data: kept while your account is active. Once we process an account deletion, the data is soft-deleted and recoverable for 30 days, then permanently purged.
- Inquiries from your public pages: kept with the rest of your account content, on the same terms, so the record of who asked about what survives for as long as you need it. Ask us to delete an individual inquiry and we do it within 45 days; deleting the account removes them on the schedule above.
- Suppression data: unsubscribes, bounces, and complaints are kept as long as needed to keep honoring opt-outs and to meet our legal obligations, even after other data is removed.
- Billing records: kept as long as required for tax and accounting purposes.
- Logs: security and operational logs are kept for about 90 days and then rotated out, except where a specific log is preserved for an open security or abuse investigation.
10. Security
The Service is hosted in the United States on infrastructure that is itself SOC 2 Type II certified (Supabase and Vercel). Every account is isolated from every other account at the database layer through row-level security. Connections are encrypted in transit. Payment card details are handled by Stripe, a PCI Level 1 provider, and never touch our servers. An audit history records important changes. No system is perfectly secure, but we take reasonable measures appropriate to the data we hold.
If a breach affects your account data, we will notify you without undue delay once we understand what happened, and in any case within 72 hours of becoming aware where the law sets that bound. Our notice will describe what we know, what it likely means for you, and what we are doing about it. Breaches affecting the contacts you process through the Service are covered by our Data Processing Addendum, where you are the controller and we notify you so you can meet your own obligations.
11. Your rights
Depending on where you live, you may have rights over your personal data. We honor them regardless of where you are.
- Access and portability: ask us and we will send you a copy of the account data we hold about you, and of your inventory, contacts, templates, and campaign records, in a common machine-readable format at no charge.
- Correction: you can correct your information in the app or ask us to.
- Deletion: ask us to close your account and we will delete your data, subject to the retention exceptions above. GDPR right-to-erasure and CCPA delete requests are honored within the statutory window.
- Restriction and objection: where the GDPR applies, you can ask us to restrict or stop certain processing.
- Opt out of sale, sharing, or profiling: there is nothing to opt out of. We do not sell or share personal information, we do not use it for targeted advertising, and we do not make decisions about you by automated means.
- No discrimination: we will not deny you service or charge you differently for exercising these rights.
To make a request, email support@inventorymailer.com, or write to us at 7901 4th St N, STE 300, St. Petersburg, FL 33702. We will verify the request against the account it concerns, which usually means confirming you control the account email. An authorized agent may make a request on your behalf with proof of authorization. We respond within 45 days, and will tell you if we need the one extension the applicable law allows.
If we say no, you can appeal. If we decline a request, our response will say why. You can appeal by replying to that response or by emailing support@inventorymailer.com with "appeal" in the subject. A person who was not involved in the original decision will review it, and we will tell you the outcome and our reasoning within 45 days. If we deny the appeal, we will also tell you how to raise it with your state attorney general.
If your request concerns someone whose data you uploaded as a controller, we will refer them to you and assist you as your processor, rather than answering on your behalf.
12. Where the Service is offered, and where data is processed
Inventory Mailer is offered to customers in the United States. It is operated from the United States, and both your account data and the contact data you process through it are stored in the United States. Some vendors route requests and run bot protection through global edge networks, and AI assistant requests are routed to a provider-dependent region; each one is listed on our Subprocessors page. We do not target or market the Service to people in the European Economic Area or the United Kingdom.
That is about where we sell, not about whose data you may hold. If your own contacts are in the EEA or the UK, you remain the controller of their data and you are responsible for the lawful basis and for any transfer mechanism your side requires. Our Data Processing Addendum is written for exactly that case: it incorporates the Standard Contractual Clauses and the UK addendum, with you as exporter and us as importer.
13. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will remove it.
14. Changes to this policy
We may update this policy. For material changes we will give notice in the app or by email. The version and effective date at the top always reflect the current policy.
Privacy questions or requests? Email support@inventorymailer.com.