Draft — the operator’s details have not been provided yet. This document is not offered for acceptance.
Operator: Not yet provided
Contact: Not yet provided
Operator and contact
The operator identified on this document is responsible for the personal information it handles to operate Stampwing. Contact that operator for privacy questions, access, correction, deletion, or complaints. Do not include passwords, API secrets, full payment-card numbers, or unnecessary message content.
Information used to provide the service
Stampwing processes account details, domain configuration, email addresses, message content, delivery events, credential metadata, usage, and security reports to provide and protect transactional email. API secrets are hashed. Message storage uses encryption and restricted access.
We preserve your account identity, acceptance time, document versions and copies, signup notice and action wording, and document language as evidence of your agreement. These records are separate from message history and may be retained after account closure for contract administration, disputes, and legal obligations. We do not collect a separate IP address or device fingerprint for this acceptance record.
Waitlist and optional updates
Joining the early-access waitlist stores your email, signup time, and the wording and time of your consent to early-access and launch updates. It does not create an account or send email automatically. Access is restricted to the operator. You can request removal through the contact form. Account creation does not subscribe you to marketing.
Resources and tools
Resource views, engaged reads, downloads, and tool uses are counted as daily totals without visitor identifiers, IP addresses, search queries, pasted headers, or checked domains in those counters. These counters honor browser Do Not Track and Global Privacy Control signals. A resource path may be remembered in this tab and saved with a waitlist signup.
The email-header analyzer runs in your browser. The domain checker sends the requested domain and optional DKIM selector to our server and Cloudflare’s public DNS resolver without storing those inputs in the application database. Infrastructure providers may retain operational logs under their own settings.
Retention and deletion
Message history, content retention, and storage allowances depend on the selected plan and are disclosed on the pricing page. Backups expire on the deployment’s configured schedule. Unresolved delivery, security, and abuse investigations may require restricted evidence preservation. Billing and agreement records remain separate from message history.
Account deletion disables active credentials and sending and follows a controlled removal process. Preservation exceptions must be recorded and access restricted. Contact the operator for the applicable retention schedule or a deletion request.
Screening and staff access
Messages may be checked for dangerous links, malware, recipient flooding, and sending-policy violations before delivery. Hashed recipient signals help detect abuse across accounts without sharing customer activity. Staff content access is limited to authorized operational or abuse investigations and is audited.
Service providers and locations
Depending on the deployment, service providers include Clerk for authentication, Stripe for payments, AWS for email and private storage, Railway for hosting and Postgres, Cloudflare for DNS, and Google Web Risk for threat checks. Stripe collects payment-card details; Stampwing does not store them. Providers may process information outside Québec. The operator must assess and document applicable safeguards and arrangements for the deployment.
Optional AI assistance has a separate disclosure and consent step before information is sent to its provider. Agreement to the service terms does not grant blanket permission for unrelated uses of your information.