Privacy Policy

How YS Progress Inc. handles personal data: your customers’ mail on your instructions, and data about you under these rules, cookies included.

Version
v1.0
Effective
15 Sep 2026
History
no per-document change log yet
Previous versions
none — v1.0 is the first in force

Notes marked “In plain English” summarise a clause to help you read it. They are not part of the document; where a note and a clause differ, the clause governs.

This Privacy Policy explains how YS Progress Inc., a corporation registered in Canada (“YS Progress”, “we”, “us”), handles personal data in connection with Spoolway. We wear two hats, and this policy keeps them apart. For your customers’ email we are a processor — you decide, we execute, and the Data Processing Agreement governs. For data about you — the people who visit this site, create accounts and work in the panel — we are the controller, and this policy governs.

IN PLAIN ENGLISHYour customers’ mail: your rules. Data about you: these rules.
PART A — AS PROCESSORyour customers’ email, processed on your instructions

Recipient addresses, subjects, bodies, variables, attachments and delivery records pass through Spoolway because your applications send them. We process this data only under the DPA, on your instructions, and never for purposes of our own.

Message bodies and attachments are encrypted at rest and kept for the retention you set, up to your plan’s ceiling; a retention of zero deletes them as soon as a message reaches its final state. Message metadata — envelope, recipients, subjects and delivery records — is kept at least for your plan’s metadata retention period and deleted in monthly batches. Deleted data leaves our backups within 35 days.

Besides the messages themselves, a recipient can appear in the suppression list (addresses that must never be mailed again, kept so that promise holds), in per-address bounce counts that stop repeated sends to dead mailboxes, in verbatim responses from mail servers, in webhook deliveries to your endpoints (kept 14 days), in tracking records if you enable tracking, in error records from failed background jobs (kept 7 days), and in your account’s audit log when someone looks that person up or exports their data. Erasure removes or hashes the address wherever it is stored, except in failed-job records and backups, which expire on the schedules above.

Requests from recipients about this data belong with you, the controller. The panel’s search, suppression and audit tools, account erasure, and an owner’s tools to look up, export and erase one person’s data let you answer most of them yourself; for anything else, ask us and we help as the DPA describes.

We do not enrich, profile or sell your recipients’ data. We do not build a picture of a person across your Applications, we share recipient data only with our subprocessors or where the law requires it, and we do not use it to train models.

PART A2 — OPEN AND CLICK TRACKINGoff by default, per Application, your decision

Open and click tracking exists, and it is off by default. Nothing we send contains a tracking pixel, and no link in your mail is rewritten to pass through us, unless tracking is enabled on that Application. The rest of this section is what is true when it is.

It is enabled per Application, from your account, never account-wide and never by us. Enabling it means two things, stated plainly: a 1×1 image is added to the message so a fetch can be recorded, and links are rewritten to redirect through Spoolway. Both make us a processor of your recipients’ personal data — a pixel fetch and a redirect carry an IP address, which we store only as a keyed hash, and a user agent — on your instructions and under the DPA. You remain the controller and the lawful basis is yours to hold.

Three limits, kept by the code. An open is a fetch, not a read. Apple Mail Privacy Protection and several corporate gateways fetch every image before a person sees anything, so the Service labels it “pixel fetched” and never “opened”. Tracking data runs on its own retention clock, stamped from the message’s content retention so it never outlives the body, and it is deleted by the same erasure that deletes everything else. It is never joined to our own site analytics — the spw_cid cookie below describes how people use our pages, and it is not connected to who opened your mail. Switching tracking off stops the recording at once, for mail already sent as well.

PART B — AS CONTROLLERdata about you, the customer and visitor

What we collect

We collect:

  • Account and profile data: your name, email address, password (stored only as a hash), second-factor secrets and passkeys, the browsers you choose to trust, the accounts you belong to and your role in each, and the invitations you send or receive.
  • Billing data: your plan and payment history. Card details and billing addresses are collected and held by Stripe; we receive Stripe’s customer and subscription identifiers, amounts, taxes and invoice references.
  • Usage and security data: sign-ins, sign-outs and failed attempts with IP addresses, the audit log of actions in your account, API and SMTP usage, and technical logs.
  • Site analytics: the pages and product events our own first-party analytics records, described under Cookies and storage.
  • Correspondence: what you send us by email, through the contact form, or in the support chat on our public pages.
  • Abuse reports: if you report abuse, your email address and what you tell us.

We collect it from you, from your use of the Service and our site, and from Stripe.

Why we use it, and on what basis

We use personal data:

  • to create and run your account, provide the Service, bill you and support you — because it is necessary for the contract with you or your organisation;
  • to secure the Service, prevent and investigate fraud and abuse, keep audit records and enforce our Terms — in our legitimate interests in a safe and reliable service;
  • to understand how our site and panel are used and to improve them, with our own first-party analytics — in our legitimate interests;
  • to send you service, security and billing messages about your account — as part of the contract and in our legitimate interests;
  • to comply with tax, accounting and other legal obligations, and to establish, exercise or defend legal claims.

Where the law requires consent, we ask for it, and you can withdraw it at any time. In Canada, by creating an account or using the Service you consent to the collection, use and disclosure this policy describes, and you may withdraw that consent subject to legal and contractual restrictions.

We do not make decisions that produce legal or similarly significant effects about you solely by automated means. Automated protections such as rate limits and sign-in lockouts exist to keep the Service safe, and you can ask us to review one.

Cookies and storage

No third-party analytics or advertising trackers run on this site or in the panel. These are the cookies and browser storage we use:

  • spoolway-session — keeps you signed in and the site working; expires 2 hours after your last request.
  • XSRF-TOKEN — protects forms against cross-site request forgery; 2 hours.
  • remember_web_… — set only when you choose “Keep me signed in”; 30 days.
  • trusted_device — set only when you trust a browser after a second-factor check; 30 days from that moment.
  • spw_cid — our first-party analytics identifier, also used to remember your analytics-consent choice; up to 2 years, or less where your browser limits cookie lifetimes. It is not set when your browser sends Global Privacy Control or Do Not Track.
  • cw_conversation — set by the support chat on our public pages so a conversation survives a reload; 1 year. The chat does not load in the panel.
  • spoolway_docs_lang (local storage) — remembers the code language you picked in the docs, until you clear it.

spw_cid is a random identifier. Our analytics records the route of each page — never the full address, so a message id or a link token never lands in it — and a short list of product events, keeps them for 90 days, and links them to your user profile while you are signed in. It is not shared, not sold, and never joined to the contents of your mail, to your recipients, or to anything you send. A record of your analytics-consent choice is kept under a hash of that identifier (or of your session or IP address when there is none), so the choice can be honoured and shown to have been made.

Blocking these cookies in your browser can stop sign-in and forms from working.

Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only:

  • with service providers that process it for us — those on the Subprocessor list (Oracle Cloud for hosting and our own email, Cloudflare for network delivery and backups, Stripe for payments), and the AI model providers that may help draft replies in our support chat;
  • with professional advisers such as lawyers, accountants and auditors, under a duty of confidentiality;
  • with authorities, courts or other parties where the law requires it, or where it is necessary to protect our rights, our users or the public;
  • with a buyer, successor or investor, under confidentiality, as part of a merger, acquisition, financing or sale of all or part of our business;
  • with anyone else with your consent or at your direction — for example, with the other members of your account.

International transfers

We are based in Canada and store data about you primarily in Canada. Our service providers may process it in other countries, including the United States. Where the GDPR, the UK GDPR or Swiss law applies, transfers to us rely on the adequacy findings for Canada, and onward transfers rely on an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses. Personal data held by a service provider in another country is subject to the laws of that country, and may be accessible to its authorities.

How long we keep it

We keep personal data only as long as we need it for the purposes above:

  • Account and profile data: while you have a user profile. One profile can belong to several accounts, so it is not deleted when an account closes; ask us and we delete it, unless we must keep some of it for a reason below.
  • Sign-in and audit records: 12 months.
  • Site analytics events: 90 days. The spw_cid cookie: as set out above. Consent records: as long as needed to honour and demonstrate your choice.
  • Billing records: while the account exists. Stripe keeps its own payment records under its own policy.
  • Abuse reports: the reporter’s address and words are cleared 180 days after the report is closed.
  • Correspondence and technical logs: as long as needed to handle your request and keep the Service secure.
  • Backups: up to 35 days.

Security

We protect personal data with the measures described on the Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials safe.

Your rights and contact

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it or have it deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw a consent you gave. Canadian law gives you the right to access and correct your personal information and to withdraw consent.

To exercise a right, or to ask about this policy, write to [email protected]. We may need to verify who you are, and we answer within the time the law allows — normally one month under the GDPR and 30 days under PIPEDA, periods the law lets us extend. Some rights have exceptions, for example where we must keep data to meet a legal obligation.

For personal data we process as a processor for one of our customers, contact that customer: they decide how to answer, and we help them.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or, in the European Economic Area, the United Kingdom or Switzerland, to your data protection authority.

Marketing, children and changes

Marketing. We send you email about your account, the Service, security and billing as part of providing it. We send marketing email only with the consent the law requires, and every marketing email lets you unsubscribe.

Children. The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16; if you believe we have, write to us and we delete it.

Changes. We may update this policy. Its version and effective date are at the top of this page, and if a change materially affects how we handle your personal data, we tell account owners by email or in the panel before it takes effect.