Privacy Policy
Last updated: February 12, 2026
1. Introduction
Top Software, Inc. (“TopMail,” “we,” “us,” or “our”) operates the TopMail email marketing platform. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our website and services (collectively, the “Service”).
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, password, and billing information. If you connect a third-party integration (e.g., Shopify, HubSpot, Salesforce), we collect the OAuth tokens and integration data necessary to provide those features.
2.2 Contact & Subscriber Data
You may upload or sync contact lists containing names, email addresses, and other subscriber information. You are the data controller for your subscriber data; we process it on your behalf as a data processor.
2.3 Email Content
We store the email campaigns, templates, and automations you create so we can send them on your behalf. We do not use the content of your emails for advertising or sell it to third parties.
2.4 Usage & Analytics Data
We collect information about how you interact with the Service, including pages visited, features used, browser type, IP address, and device information. We use analytics tools (such as PostHog) to understand usage patterns and improve the Service.
2.5 Email Engagement Data
We track email opens, clicks, bounces, complaints, and unsubscribes for campaigns sent through our platform. This data is used to provide you with campaign analytics and to maintain sending reputation.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To send emails on your behalf through Amazon SES
- To process payments and manage your subscription
- To send you transactional communications (e.g., account confirmations, billing receipts, security alerts)
- To monitor and enforce our Acceptable Use Policy and prevent abuse
- To comply with legal obligations, including CAN-SPAM, GDPR, and other applicable laws
4. Data Processing & Sub-processors
We use the following categories of sub-processors to deliver the Service:
- Cloud infrastructure: Amazon Web Services (AWS), Vercel
- Email delivery: Amazon Simple Email Service (SES)
- Database: Supabase (PostgreSQL)
- Payment processing: Stripe
- Analytics: PostHog
Each sub-processor is contractually bound to protect your data and process it only as needed to provide their respective services.
5. Data Retention
We retain your account data for as long as your account is active. When you delete your account, we delete your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records). Email engagement data (opens, clicks) is retained for the lifetime of the associated campaign.
6. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability — receive your data in a structured, machine-readable format
- Opt out of the sale of personal information (we do not sell personal information)
To exercise any of these rights, contact us at privacy@topmail.so.
7. Your Subscribers' Rights
As a TopMail user, you are the data controller for your subscribers. You are responsible for obtaining proper consent to email your contacts and for honoring unsubscribe requests. We provide tools (unsubscribe links, preference centers) to help you comply with CAN-SPAM, GDPR, and other applicable laws. If a subscriber contacts us directly with a data rights request, we will direct them to you and notify you of the request.
8. Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. Despite these measures, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Cookies
We use essential cookies for authentication and session management. We may also use analytics cookies to understand how the Service is used. You can control cookie preferences through your browser settings.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at privacy@topmail.so.
Top Software, Inc.