Privacy

Privacy Policy

Last updated 1 August 2026. WillItInbox is the controller for account and website data and a processor for customer-submitted email data.

Controller and contact

Akash Soni, an individual operating WillItInbox from India, acts as data controller for account, security, billing, and website data. Contact [email protected] for privacy questions. Customers act as controllers for personal data they submit for validation, testing, or monitoring; WillItInbox processes that data under the Data Processing Agreement.

Data we process

  • Account and authentication data: email address, account identifiers, login provider, verification status, hashed session and security metadata, plan, and usage.
  • Customer content: test messages and headers, uploaded recipient lists, validation evidence, reports, monitored domains, DMARC aggregate and optional forensic data, TLS reports, webhook payloads, and support communications.
  • Technical data: IP and user-agent hashes, security and audit events, API key names and prefixes, device/browser information, essential cookies, and cookie-free Cloudflare Web Analytics performance and usage metrics.
  • Billing data: plan, transaction, subscription, credit, and invoice records. Payment details are processed by Dodo Payments; WillItInbox does not store full card details.
  • With consent, Google Analytics processes sanitized page routes, referrer and campaign attribution, device/browser information, coarse location, and engagement metrics. Query strings, route tokens, customer emails, tested domains, uploaded lists, and report contents are not sent.

Purposes and legal bases

  • Contractual necessity (GDPR Art. 6(1)(b)): provide accounts, deliverability tests, validation, monitoring, reports, support, billing, and requested exports.
  • Consent (Art. 6(1)(a)): optional Google Analytics measurement, marketing attribution, and non-essential storage. Consent can be rejected or changed at any time through Cookie settings.
  • Legitimate interests (Art. 6(1)(f)): secure the service, prevent fraud and abuse, debug failures, and measure reliability through cookie-free Cloudflare Web Analytics, balanced against individual rights.
  • Legal obligation (Art. 6(1)(c)): retain required tax, accounting, dispute, and compliance records.

Processors and recipients

  • OVH US LLC dba OVHcloud hosts the frontend origin, API, PostgreSQL, Redis, SMTP receiver, workers, and encrypted backups. Primary hosting and backups are in Vint Hill, Virginia, USA.
  • Cloudflare, Inc. provides authoritative DNS, proxy/CDN, edge security, Email Routing, and cookie-free Web Analytics/Browser Insights. Cloudflare processes data globally.
  • Google LLC provides consent-gated website analytics. Advertising storage, advertising personalization, Google Signals, query strings, and sensitive route values are disabled.
  • SMTP2GO provides transactional account email using automatic/global routing. Its fixed account storage region is confirmed in manually executed customer documentation.
  • Dodo Payments acts as Merchant of Record and an independent controller for checkout, payments, tax, fraud prevention, and invoices. Google processes sign-in data when you choose Google OAuth.
  • Customer-configured webhook, mailbox, SMTP, and provider integrations receive only the data needed for the customer-requested workflow.

Retention

  • Raw inbound email bodies and completed deliverability test sessions are deleted after 24 hours by default. Derived sandbox data follows the plan-specific windows on the Data Retention page.
  • Bulk-upload artifacts use a 24-hour job TTL. Account and product records remain while the account is active or needed to provide the service.
  • Never-verified accounts and accounts whose plan expired without a later login are erased after a 30-day grace period.
  • OVHcloud backup snapshots are retained for 24 hours and use provider-managed encryption at rest.
  • When an account is erased, access credentials and non-financial personal data are deleted. A random, unlinkable tombstone and anonymized financial records remain only where needed for legal, tax, fraud, or accounting obligations.

Your rights

  • Subject to applicable law, you may request access, correction, erasure, restriction, objection, and a portable copy of your data, and withdraw consent without affecting earlier lawful processing.
  • Signed-in users can export or erase their account from Account → Security. You may also contact [email protected]. We may verify identity before acting and normally respond within one month.
  • You may complain to the data-protection authority where you live or work, or where you believe an infringement occurred.

International transfers

  • Providers may process data outside the EEA. Where an adequacy decision does not apply, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures where required.
  • Customers may request information about the safeguards and relevant transfer documentation from [email protected].

See also Data Retention, Security, and the DPA.