Your customers' data, treated like it's radioactive.
An email platform holds the most valuable asset a store owns: its audience. Here is, concretely, how we protect it - no vague "bank-level security" hand-waving.
EU data residency
GDPR ART. 44Subscriber data is stored and processed in EU data centers. No transatlantic guesswork about which legal framework applies to your customer data this quarter.
Right to access & erasure
GDPR ART. 15 / 17One API call exports everything the platform knows about a subscriber - profile, events, sessions, queue history. One call erases it, across every table, verifiably. Data subject requests become a two-minute task, not a project.
Consent, recorded properly
EPRIVACYDouble opt-in flows, consent logs with source and timestamp, and a consent gate on website tracking. When someone asks "when did I sign up for this?", you have the answer on file.
Secrets encrypted at rest
VAULTIntegration credentials and API keys are stored in an encrypted vault with keys held outside the database. API keys are hashed - we can't read them back, and neither can anyone else.
Tenant isolation, enforced by the database
ROW-LEVEL SECURITYEvery table carries row-level security policies. Account separation isn't an application convention that a bug can bypass - it's enforced at the database layer on every single query.
Signed, non-enumerable links
HMAC-SHA256Unsubscribe and mirror-page links carry cryptographic signatures. Nobody can unsubscribe your customers by guessing IDs, and web versions of emails expire after 180 days.
Scoped, revocable API access
LEAST PRIVILEGEAPI keys carry granular scopes - a dashboard integration gets read-only access, a sync job gets exactly the write scope it needs. Revoke any key instantly, see when each was last used.
Honest analytics
BOT FILTERINGSecurity scanners and prefetch bots inflate open rates on most platforms. We detect and exclude known scanners and prefetchers from open and click stats.
EU hosted email marketing, in practice.
"EU hosted" is easy to claim and rarely specified, so here is what it means on this platform: subscriber data, consent logs, campaign content and event history live in EU data centers, and the GDPR tooling is part of the product rather than a support ticket. For a store selling to European customers, that removes the data-transfer questions before your DPO asks them.
- Subscriber data at rest in the EU - not mirrored to US regions
- Double opt-in, consent logs with source and timestamp, consent-gated tracking
- Access and erasure requests handled with built-in export and deletion tooling
- A data processing agreement ready for your records
Compliance questions, answered.
GDPR compliance is a property of how you use a tool, but the tool decides how easy it is. Here the requirements are built in: EU data residency, double opt-in, consent logs with source and timestamp, consent-gated website tracking, data export for access requests and erasure tooling for deletion requests, plus a data processing agreement for your records.
In EU data centers. Subscriber data, consent records, campaign content and event history are stored at rest in the EU and are not mirrored to US regions.
Double opt-in is available on forms and enforced for API-created subscribers when enabled: new signups are held as pending until they click the confirmation link. The confirmation email is customisable with your own template and a confirm link merge tag.
Questions your DPO will ask?
We have written answers.
Get our security overview and data processing agreement before you commit.