Email Bump provides marketing email, transactional email, automation, contact management, reporting, and related tools. This policy explains our data practices when you visit our website, create an account, or use the Email Bump service.
Scope and roles
This Privacy Policy applies to services operated under the Email Bump name. For account, billing, website, and product-usage information, Email Bump determines how that data is handled. For contacts, message content, and recipient activity that a customer submits to the service, the customer controls the data and Email Bump processes it to provide the service.
Customers are responsible for their own privacy notices, permissions, and lawful basis for collecting contact information and sending email.
Information we collect
Account and workspace information
We collect information such as your name, email address, authentication credentials, workspace and project details, team membership, sending-domain configuration, API keys, webhook settings, and communications with support. Passwords are stored in hashed form.
Customer content and contact data
Customers may upload or create contact records, lists, segments, templates, campaigns, automated flows, transactional messages, forms, and related profile attributes. Message content may contain personal information chosen by the customer.
Delivery and engagement information
We process sending, delivery, open, click, bounce, complaint, and unsubscribe events, along with timestamps and relevant request metadata. These events support reporting, deliverability, suppression, security, and list hygiene.
Billing, device, and usage information
Stripe processes payment-card details. Email Bump receives billing identifiers, subscription status, plan, and transaction-related information rather than full card numbers. We may also collect browser, device, IP address, session, log, and product-usage information. If product analytics is enabled, PostHog processes usage events and may receive account identifiers such as user ID, email, name, verification status, and active workspace ID.
Google user data
When you choose Join With Google or otherwise use Google sign-in, Email Bump requests only the openid, email, and profile scopes. We receive your Google account's unique identifier, email address, email-verification status, and display name.
We use this information solely to authenticate you, create or link your Email Bump account, populate basic account details, and create an initial workspace for a new user. The temporary OAuth access token is used to retrieve this basic profile during sign-in and is not stored by Email Bump.
Email Bump does not request access to Gmail messages, Google Contacts, Google Drive, Google Calendar, or other Google product content. We do not sell Google user data, use it for advertising, or use it to train generalized AI models.
We share Google user data only with service providers that help operate and secure Email Bump, when you direct us to, or when disclosure is legally required. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
- Provide, maintain, secure, and improve Email Bump.
- Authenticate users and manage accounts, workspaces, projects, and permissions.
- Send customer-directed marketing and transactional email.
- Process delivery and engagement events and maintain suppression lists.
- Provide reports, automation, support, migration, and deliverability guidance.
- Process subscriptions, prevent fraud and abuse, and enforce service limits.
- Comply with law and protect users, recipients, Email Bump, and the public.
Retention and security
We retain information while an account is active and as reasonably necessary to provide the service, maintain security and suppression records, resolve disputes, meet contractual and legal obligations, and enforce agreements. Retention periods vary by data type and operational need. Backups and logs may remain for a limited period after deletion.
We use administrative, technical, and organizational safeguards designed to protect data, including access controls, encrypted transport, server-side sessions, and credential protection. No method of storage or transmission is completely secure.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, or object to certain processing. Contact us to make a request. We may need to verify your identity and may retain information where legally permitted or required.
- Recipients can use the unsubscribe link in a marketing email.
- Account holders can update many account and contact fields in the product.
- You can request account deletion by emailing [email protected].
- You can manage or revoke Email Bump's Google connection from your Google Account permissions.
- You can control cookies through browser settings, although required session cookies are necessary to sign in.
International transfers
Email Bump and its service providers may process information in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers and require service providers to protect information consistently with this policy.
Children
Email Bump is a business service and is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information to the service.
Changes and contact
We may update this policy as the service or legal requirements change. We will update the effective date and provide additional notice when a material change requires it.
Questions, privacy requests, and complaints can be sent to [email protected].