Privacy Policy
Effective date: [CONFIRM: EFFECTIVE DATE]
This policy explains how rate.email processes personal data. It covers two separate roles. For traffic to the rating API, the customer (the shop or website operator who holds an API key) is the controller and rate.email acts as processor. For visitors to the rate.email website and for account holders, rate.email is the controller. Both roles are described below.
1. Controller identity and contact
Controller (for the website and for account data):
- Firm name: @lbajsarowicz Łukasz Bajsarowicz
- Legal form: sole trader (jednoosobowa działalność gospodarcza), registered in CEIDG (Central Register and Information on Economic Activity, Poland)
- NIP: 9111960653
- REGON: 021046365
- Address for correspondence: ul. Hoża 86, lok. 410, 00-682 Warszawa, Poland
- Business registered since: 2017-01-04, per CEIDG
- Registration status: Aktywny (active), per CEIDG
- Contact email: [email protected]
No data protection officer is appointed. Data protection questions go to the contact email above.
2. Scope: two processing relationships
2.1 API traffic (rate.email as processor)
When a customer's shop or website calls the rate.email API to rate an email address, the customer decides why and how the address is checked. Under GDPR Article 28, the customer is the controller of that end-user data and rate.email is the processor. The terms for this relationship are in data-processing-agreement.md, not in this policy. This policy still lists, for transparency, what rate.email receives and does with it as a processor.
2.2 Website visitors and account holders (rate.email as controller)
For people who visit the rate.email marketing site, sign up for an account, or manage billing, rate.email is the controller. The rest of this policy is written from that role, with section 3 also covering the processor-role data for completeness.
3. What data is processed, for what purpose, and on what legal basis
| Activity | Data categories | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| API rating request (processor role) | Email address submitted by the customer's end user, or in privacy mode a SHA-256 hash of the local part plus the plaintext domain; requester API key; requesting IP address; Origin header; user agent |
Return a deliverability/risk score for the submitted address | Performed on the customer's instructions under the DPA; the customer's own legal basis toward its end user applies. Article 6(1)(b) or (f) as between rate.email and the customer under the service contract. |
| Account creation and API key management | Name, email address, billing identifiers, usage history | Provide the service, issue and manage API keys, respond to support requests | Article 6(1)(b), contract |
| Security and abuse prevention | Request metadata (IP address, timestamps, rate-limit counters, hashed API keys), Turnstile challenge results where enabled | Detect and block abuse, enforce quotas, protect the service and other customers | Article 6(1)(f), legitimate interest |
| Billing | Name, billing address, transaction identifiers, invoice data (handled by Polar.sh as merchant of record; see section 5) | Process payment, issue invoices, comply with tax law | Article 6(1)(b) contract, and Article 6(1)(c) legal obligation for tax and accounting records |
| Website analytics cookies | Pseudonymous identifiers, page interaction events, routed through a first-party Google Analytics 4 gateway | Understand website usage, improve the service | Article 6(1)(a), consent. Not set before consent is given. |
| Account correspondence | Google Workspace mailbox contents for support and account emails | Operate the account relationship | Article 6(1)(b), contract, and Article 6(1)(f) for routine service correspondence |
4. Categories of data subjects
- End users of a customer's shop or website whose email address is submitted to the API (processor role, customer is controller).
- Visitors to the rate.email website.
- Account holders and their nominated contacts (customer role, controller relationship with rate.email).
5. Recipients and processors, with countries and transfer mechanisms
| Recipient | Role | Data involved | Country / region | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. (Workers, KV, D1, Analytics Engine, Turnstile) | Sub-processor / infrastructure processor | All API request data in transit and cache; hashed address and domain in KV; abuse-signal data | Cloudflare's network is global edge; data-at-rest location depends on the product and account configuration. [CONFIRM: whether the account is configured for EU-only data residency, or defaults to global edge processing] | Standard Contractual Clauses under Cloudflare's Data Processing Addendum. Cloudflare self-certifies to the EU-U.S. Data Privacy Framework where the underlying entity is US-based; confirm current status at the time of publication. [CONFIRM: current DPF certification status for the specific Cloudflare entity processing this data] |
| Polar.sh | Merchant of record, payment and billing processor | Name, billing address, payment metadata (never full card data; card data is handled by Polar's own payment processor) | [CONFIRM: Polar.sh's country of establishment / domicile]. Polar holds an EU One-Stop-Shop (OSS) VAT number and issues VAT-compliant invoices for EU sales. | [CONFIRM: transfer mechanism used by Polar for any data leaving the EEA, e.g. SCCs or DPF, per Polar's own privacy policy and DPA at the time of publication] |
| Deliverability verification provider (Verifalia or Clearout) | Sub-processor, paid slow-path only | Plaintext email address, only for customers on the paid tier who request deliverability verification | Verifalia: Italy (EU). Clearout: [CONFIRM: Clearout's country of establishment]. Provider choice is [CONFIRM: Verifalia vs Clearout, or both, not yet finalised per architecture notes]. | If Verifalia: intra-EU, no transfer mechanism needed. If Clearout or another non-EU provider: [CONFIRM: SCCs or other mechanism per that provider's DPA]. |
| Google LLC / Google Ireland Limited (Google Analytics 4) | Processor, website analytics, consent-gated | Pseudonymous website usage data, only after cookie consent, routed through a first-party server-side gateway | United States (Google LLC) and/or EU (Google Ireland Limited depending on configuration) | Google self-certifies to the EU-U.S. Data Privacy Framework. [CONFIRM: current DPF certification status for the specific Google entity, and whether IP anonymisation / consent mode is configured] |
| Google Workspace | Processor, account and support email | Account correspondence content | [CONFIRM: data location configured for the Workspace tenant] | Google Workspace's own Data Processing Amendment; Google self-certifies to the EU-U.S. Data Privacy Framework. [CONFIRM: current status at publication] |
No personal data is sold. No recipient outside this table receives personal data as a matter of course.
6. Retention
| Data | Retention period | Notes |
|---|---|---|
| Per-address rating result | 7 days | Cached in Cloudflare KV, keyed by SHA-256 hash of the normalized address. The plaintext address is never stored at rest by rate.email; it exists only in transit during the request and, briefly, in server memory while the score is computed. |
| Per-domain rating result | 7 days | Cached in KV, keyed by domain. |
| Request logs (hashed address) | 30 days | Address is hashed before it is written to any log. IP address and other request metadata may also be hashed or truncated; see the security measures annex in the DPA for detail. |
| Billing records | Per statutory retention period under Polish tax and accounting law | [CONFIRM: exact statutory period, generally 5 years from the end of the tax year for VAT records under Polish law; confirm with an accountant before publication] |
| Account data | Until the account is deleted, plus any period required to resolve open disputes or comply with law | Deletion requests are honoured per section 8. |
7. Data subject rights
Any data subject (website visitor, account holder, or a customer's end user for the processor-role data) has the right to:
- Access their personal data (Article 15).
- Rectify inaccurate data (Article 16).
- Erasure, subject to legal retention obligations (Article 17).
- Restriction of processing in defined cases (Article 18).
- Data portability, where processing is based on consent or contract and carried out by automated means (Article 20).
- Object to processing based on legitimate interest (Article 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)).
For end users of a customer's API integration, the request should first go to that customer, since the customer is the controller of that data. If the customer cannot be identified or does not respond, contact rate.email at the address in section 1.
To exercise a right, write to the contact email in section 1. A response is provided within one month of a verified request, extendable by two further months for complex requests, per Article 12(3).
8. Right to lodge a complaint
Every data subject has the right to lodge a complaint with the Polish supervisory authority:
Urząd Ochrony Danych Osobowych (UODO) ul. Stanisława Moniuszki 1A 00-014 Warszawa, Poland Email: [email protected] Phone: +48 22 531 03 00
A data subject resident in another EU/EEA member state may instead lodge a complaint with their own national supervisory authority.
9. Cookies
The rate.email website sets no analytics or advertising cookie before consent is obtained through the cookie banner. Strictly necessary cookies (session, security, load balancing) may be set without consent, per Article 6(1)(f) and the ePrivacy exemption for cookies necessary to provide a requested service.
After consent, Google Analytics 4 is loaded through a first-party server-side gateway rather than loading Google's script directly from the browser, so cookies are set under the rate.email domain. Consent can be withdrawn at any time from the cookie settings link in the website footer. Withdrawing consent stops new analytics cookies from being set; it does not retroactively delete data already sent.
[CONFIRM: exact list of cookie names, purposes, and durations set by the GA4 first-party gateway, to be added once the gateway is implemented]
10. Children
The service is a B2B API and a business website. It is not directed at children, and account holders must be adults acting for a business or professional purpose. rate.email does not knowingly collect personal data from children. If a parent or guardian believes a child's data has been submitted, contact the address in section 1 for erasure.
11. Changes to this policy
This policy may be updated to reflect changes in the service, in applicable law, or in the list of processors. Material changes are announced on the website or by email to account holders. The effective date at the top of this document indicates the last update.
12. Effective date
[CONFIRM: EFFECTIVE DATE, to be set on first publication after legal review]