01Who we are
SadaSend is a sole proprietorship registered in Pakistan, at Model Town, Daska 51010, Pakistan. SadaSend is a registered trademark.
SadaSend provides a transactional email API. When you send email through us, you are the data controller for your recipients’ personal data and SadaSend is your data processor. When you use our website and dashboard, we are the controller for your own account data.
For any privacy question, including requests to access or delete data, contact us through our official privacy channel upon public launch.
02What we collect
- Account data — your name, email address, company name, and authentication credentials. Passwords are hashed; we never store them in a readable form.
- Billing data — handled by our payment processor. We store a customer reference and your plan, never full card numbers.
- Sending domain data — the domains you verify, their DNS records, and the DKIM key pairs we generate for them.
- Email content and metadata — the messages you send, their recipients, subjects, headers, bodies, attachments, and the delivery events they generate.
- Usage and diagnostic data — API requests, error traces, and aggregate volume statistics.
03How long we keep email content
Message bodies and delivery logs are retained according to your plan. This is a product limit and a privacy control at the same time — shorter retention means less of your recipients’ data sitting on our systems.
| Plan | Message bodies and logs | Delivery events |
|---|---|---|
| Free | 1 day | 30 days |
| Pro | 7 days | 90 days |
| Scale | 30 days | 90 days |
04Suppression lists are kept longer, on purpose
When an address hard-bounces, marks your mail as spam, or unsubscribes, we record it on your account-wide suppression list and keep it for the life of your account. Deleting that record would allow the same address to be emailed again, which is precisely the harm the suppression exists to prevent.
A suppression record contains the address, the reason, and a timestamp. Nothing else.
05Subprocessors
We use a small number of third parties to run the service — for delivery, storage, payments and monitoring. Each is bound by a data processing agreement, and none of them receives more of your data than the job requires.
The current list, naming each subprocessor and what it processes, is available on request upon public launch. We will send it to any customer or prospective customer, and we will tell you before we add one.
06Why we are allowed to process it
For your account data — your email address, your organisation, what you do in the dashboard — we rely on the contract between us: we cannot run the service you signed up for without it. For security logging, abuse investigation and keeping a suppression list, we rely on legitimate interests, and the interest is one you share: an account that cannot be investigated is an account whose sending reputation everyone else pays for.
For your recipients’ data you are the controller and we are your processor. We process it on your instructions to deliver the mail you asked us to send, and for nothing else — see “What we do not do”.
Where we ask for consent, such as optional analytics, refusing costs you nothing and changes nothing about the service.
07Decisions made without a person
Two of them, and both can affect your account materially, so they are written here rather than discovered.
We measure every account’s complaint and bounce rate over a rolling window. Above the published thresholds the account is throttled automatically — slowed, not stopped, because cutting a customer’s password resets because their marketing list has a problem is the worse outcome. Further above, sending is suspended.
Neither decision is final and neither is made by a person, which is exactly why you can ask for one. Open a support ticket and a human reviews it, and a pause set by our staff is by definition a person already looking. The thresholds are published on our terms page, and the rates we measured are in your dashboard — so the input to the decision is visible to you at the same time it is visible to us.
08Where data is processed
Our primary infrastructure runs in the United States, and we operate from Pakistan. If you are in the UK or the EEA, that means your data is transferred outside it — we rely on the UK and EU Standard Contractual Clauses for those transfers, and we will sign them with you on request.
If you require EU data residency, contact us before you build on the service — we would rather tell you honestly that it is not available yet than have you discover it during a compliance review.
09What we do not do
And when we do look at a message body — because you asked us to, or during an abuse investigation, or under legal compulsion — you can see that we did. Every access is listed in your dashboard under Data access: who opened it, when, and why. You do not have to take this section on trust.
- We do not sell your data, or your recipients’ data, to anyone.
- We do not use the content of the email you send to train machine learning models.
- We do not read your message bodies except when you explicitly ask us to help debug a specific message, or where we are legally compelled.
- We do not add tracking pixels or rewrite your links unless you turn on open and click tracking yourself.
10Open and click tracking, if you turn it on
Both are off on every account until you switch them on, and switching them on is a decision about your recipients rather than about you — so it is worth knowing exactly what changes.
With open tracking on, a 1×1 transparent image is added to the end of your HTML. When a mail client loads it, we record that the message was opened and when. With click tracking on, links in your HTML are rewritten to pass through a redirect on our tracking domain, which records that the link was followed and to where, then sends the recipient to your original URL.
We record the event, its time, and for a click the destination. **We do not store the recipient’s IP address or user agent**, so neither is available to us, to you, or to anyone who asks us for it.
Two exceptions are deliberate. The one-click unsubscribe link is never rewritten — it is the one action that must not gain a hop. And links containing template variables are left alone, because the address is not known until the message renders.
An open is a ceiling, not a count. Several mailbox providers fetch images on the recipient’s behalf, whether or not anyone looked, so the figure over-reports and we say so where we show it rather than only here.
Turning either off stops the recording immediately, including for mail already sitting in an inbox — the check happens when the pixel or link is reached, not when the message was sent.
11Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, and to lodge a complaint with a supervisory authority.
You can export your account data and delete your account from the dashboard at any time. Deleting an account removes message content within 30 days, with the exception of suppression records and any data we must keep for tax or legal reasons.
12Cookies
The marketing site loads four third-party tools. Two set no cookies: one counts page views without recording personal data, and one is a tag container that sets nothing by itself.
Two do set cookies. One is an analytics tool that sets `_ga` and `_ga_*` to recognise a returning visitor. The other records how pages are used, including a replay of mouse movement, scrolling and clicks, with text input masked by default.
Neither runs on the dashboard, on onboarding, or on any page behind sign-in. They are switched off by path before they load, so a session replay cannot cover your message log, your recipients or your suppression list.
We do not currently ask for consent before setting those two, and if you are in a jurisdiction that requires it you should treat that as a gap on our side rather than an exemption. You can block both with any content blocker. Each is named in the subprocessor list above, available on request, and we will name any further tag that sets cookies before it goes live.
The dashboard sets a single session cookie required to keep you signed in.
13Age
SadaSend is a tool for people building software, and it is not for children. You must be at least 16 to hold an account, or older where your country sets a higher age for agreeing to terms. We do not knowingly collect data from anyone younger; if you believe we have, tell us and we will delete it.
14Changes to this policy
If we make a material change we will email account holders at least 30 days before it takes effect. The date at the top of this page always reflects the current version.