TrekMail — Privacy Policy
Effective Date: January 29, 2026
Last Updated: September 4, 2026
Summary of Our Privacy Practices
This summary provides an overview of how TrekGuider Inc. ("TrekMail," "we," or "us") handles your data when you use the TrekMail.net email hosting, file storage, and related services. For full legal details, please read the complete Privacy Policy below.
-
What We Collect: Account credentials, domain configurations, email and Drive data you choose to process through the Services, payment data (via Stripe or other payment providers), technical usage logs, and support tickets.
- Specific Feature Data: If you use features like "Bring Your Own SMTP" (including per-domain SMTP routing), "Migration," Connected Accounts (external mailboxes you link, such as Gmail or Outlook), Drive, Account Drive, public links, large attachment links, Calendar, Contacts, or Shared Mailboxes, we process the data and configuration needed to provide those features.
- Why We Collect It: To operate the service, route emails, process payments, prevent abuse (spam/fraud), and comply with legal obligations.
- No Sale of Customer Content: We do not sell Customer Content or disclose it to third parties for their independent marketing. Limited account, transaction, device, and campaign information may be processed by service providers for the purposes described in this Policy.
- Your Rights: Depending on applicable law, you may have rights to access, correct, delete, or export covered personal data. Current customers can submit requests through the TrekMail dashboard.
- Security: We use administrative, technical, and organizational safeguards designed to protect information, though no system is impenetrable.
1. Introduction
1.1. Purpose and Identity
This Privacy Policy ("Policy") describes how TrekGuider Inc., a Delaware corporation ("TrekMail," "we," "us," or "our"), collects, uses, stores, discloses, and protects personal data when you use our websites, applications, APIs, dashboards, and related services (collectively, the "Service"). It is a privacy notice and does not itself seek or obtain consent.
By accessing or using the Service, you acknowledge that you have received this Policy. Where applicable law requires consent for a particular activity, consent is requested separately in the manner presented for that activity. Use of the Service is governed by our Terms of Service.
1.2. HIPAA and Sensitive Data Disclaimer
Unless you have entered into a separate Business Associate Agreement (BAA) with TrekMail: The Service is not intended for the storage or transmission of "Protected Health Information" (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA), or other highly sensitive data subject to strict regulatory compliance (e.g., PCI-DSS card data, GLBA financial data). You acknowledge that TrekMail is not a Business Associate or subcontractor under HIPAA, and you agree not to use the Service to process PHI.
2. Privacy Roles: Controller vs. Processor
Depending on how you use TrekMail, we may process data as either a Controller or a Processor (or similar terms under applicable law).
A. When TrekMail is a Controller
We act as a Controller when we process information for our own business purposes, such as:
- Creating and administering accounts;
- Billing and payments;
- Customer support and communications;
- Preventing fraud, abuse, and security incidents;
- Improving and operating the Services;
- Measuring the performance of our websites and advertising campaigns;
- Complying with legal obligations.
B. When TrekMail is a Processor (Customer Content)
When a customer uses TrekMail to send, receive, upload, store, route, migrate, share, or otherwise process email, files, and related content through the Services, TrekMail typically acts as a Processor (or "Service Provider" under certain U.S. state privacy laws) with respect to that Customer Content, and processes such data only on the customer's documented instructions (as reflected in the customer's configuration, use of the Services, and support requests).
Customer Content may include email message content (including attachments), message headers, addressing and routing information, mailbox data, shared mailbox (team inbox) content and membership configuration, calendar and event data (including CalDAV data), contact and address book data (including CardDAV data), Drive files, folder names and paths, file metadata, public link settings, sharing metadata, and related service metadata (e.g., delivery events, storage usage, download activity, abuse-prevention signals, and diagnostic logs generated to operate the Services).
Contractual Data Processing Terms
If you are a business customer and TrekMail processes Customer Content on your behalf, the following terms apply where required by applicable law and form part of the agreement between you and TrekMail (the "DPA Terms"):
- Subject matter and duration. TrekMail processes Customer Content solely to provide, secure, and maintain the Services for the duration of the customer's subscription and any post-termination period required to complete exports, resolve support issues, comply with legal obligations, or enforce our agreements.
- Data and data subjects. Processing may concern the categories of Customer Content described above and personal data relating to the customer, its authorized users, mailbox users, senders, recipients, contacts, calendar participants, file recipients, and other persons whose information the customer submits to or processes through the Services. Processing operations may include collection, transmission, routing, storage, retrieval, organization, synchronization, disclosure at the customer's direction, restriction, and deletion.
-
Purpose limitation / instructions. TrekMail will process Customer Content only:
- to provide the Services as configured by the customer (including routing/forwarding/migration features), and
- as otherwise documented by the customer through use of the Services and support requests, and
- as required by applicable law.
- Confidentiality. TrekMail restricts access to Customer Content to authorized personnel and contractors who are bound by confidentiality obligations.
- Security measures. TrekMail maintains appropriate technical and organizational measures designed to protect Customer Content against unauthorized access, disclosure, alteration, or loss (including access controls and measures intended to protect sensitive configuration data such as SMTP and migration credentials).
- Subprocessors. TrekMail may use Subprocessors to help provide the Services (e.g., infrastructure hosting, object storage, monitoring, payments). TrekMail remains responsible for its Subprocessors' performance of their obligations with respect to Customer Content and will impose contractual data protection obligations on Subprocessors consistent with this Policy.
-
Assistance. Taking into account the nature of the processing and the information available, TrekMail will provide reasonable assistance to the customer for:
- responding to data subject requests relating to Customer Content (where applicable), and
- supporting security and privacy obligations (e.g., incident information reasonably needed by the customer), subject to legal and security restrictions.
- Information and review. Upon a reasonable support request, TrekMail will provide information reasonably available to it concerning these DPA Terms and may satisfy an audit or review request through relevant documentation, summaries, or other proportionate means, subject to confidentiality, security, privilege, and protection of other customers' information.
- Incident notification. TrekMail will notify the customer of a confirmed personal data breach affecting Customer Content without undue delay after becoming aware of it, and will share information reasonably necessary to support the customer's compliance obligations, to the extent available.
- Return or deletion. Upon termination of the Services, TrekMail will make Customer Content available for export via available tools (where applicable) and, thereafter, will delete or de-identify Customer Content within a reasonable period, except to the extent retention is required by law or necessary for security, dispute resolution, or enforcement.
- International transfers. TrekMail uses infrastructure and subprocessors in multiple jurisdictions to provide the Services. Where Customer Content or related data is transferred outside the EEA/UK, TrekMail will use appropriate transfer safeguards recognized under applicable law (such as Standard Contractual Clauses and/or the UK Addendum/UK IDTA, as applicable).
These DPA Terms are incorporated into the Terms of Service for business customers to the extent TrekMail processes Customer Content on their behalf. Questions about these terms may be submitted through a support ticket from within the TrekMail dashboard.
3. Information We Collect
We collect information in three main ways: (1) information you provide, (2) information collected automatically, and (3) information from third parties.
A. Information You Provide
Account and Profile Information:
- Name or username;
- Organization/company name;
- Authentication credentials (passwords, 2FA tokens).
Billing and Transaction Information:
- Billing address and transaction records;
- Payment status and invoices/receipts metadata (processed primarily by our payment providers; see Section 6).
Domain and Mailbox Configuration:
- Domains you add and related DNS verification records;
- Mailbox names, aliases, routing rules, forwarding configurations, and administrative settings.
Drive and File Storage Data:
If you use TrekMail Drive, Account Drive, shared folders, public links, or large attachment links, we process information necessary to provide and secure those features, including:
- Files you upload or store through the Services;
- File and folder names, paths, sizes, file types, ownership, sharing state, and storage usage;
- Public link settings such as expiry, download limits, revocation status, and download counts;
- Upload, download, deletion, restoration, and quota-related operational records;
- Large attachment link metadata when email attachments are routed through Drive instead of being sent as standard attachments.
Calendar and Contacts Data:
If you use the Calendar or Contacts features (including via Webmail or supported CalDAV/CardDAV clients), we process the information necessary to provide and synchronize those features, including:
- Calendar entries you create or import, such as event titles, descriptions, dates and times, locations, attendees, reminders, and recurrence rules;
- Contact and address book entries you create, import, or export, such as names, email addresses, phone numbers, organizations, and related fields;
- Synchronization, sharing, and operational metadata needed to keep this data available across the Services and any connected clients.
- Note: Calendar and Contacts data may include personal data of third parties (for example, people you invite to events or save as contacts). You are responsible for having an appropriate legal basis to provide such data and for using these features in compliance with applicable law.
Shared Mailboxes (Team Inboxes):
If you use shared mailboxes (team inboxes), we process the information necessary to provide shared access to a common mailbox, including:
- The messages, folders, and content stored in the shared mailbox (which are Customer Content);
- Membership and access configuration (which mailbox users are members of the shared mailbox and the actions they are permitted to take);
- Operational and audit metadata associated with shared access, used to provide the feature and to support security and abuse prevention.
- Note: Members of a shared mailbox may be able to view and act on messages within that shared mailbox. You are responsible for managing membership and for ensuring that shared access is appropriate for the data held in the shared mailbox.
Account Members, White Label, and Delegated Access:
If you invite account members or configure White Label or delegated-access features, we process the information needed to provide and secure that access, including names, contact information, roles, permissions, domain restrictions, invitation and access status, activity records, brand assets, branded domains, and customer-selected support information.
Read Receipts:
If a sender requests or receives a standard email read receipt, we may process the relevant mailbox, message, recipient, request, response, timestamp, and receipt identifiers as service metadata associated with that mailbox. The recipient or recipient's provider controls whether a receipt is returned.
Connected Accounts (External Mailboxes):
TrekMail lets you connect external mailboxes you control — such as Gmail, Yahoo, iCloud, Outlook.com / Microsoft 365, or any other IMAP mailbox — so you can read, reply to, and send from them inside TrekMail (including the combined “All inboxes” view). To provide this feature we process:
- Connection credentials. For most providers you supply an application-specific password, which we store using protective controls and use only to sign in to that mailbox on your behalf. For Microsoft (Outlook.com / Microsoft 365) accounts we use Microsoft’s secure sign-in (OAuth): we receive access and refresh tokens — not your Microsoft password — which we protect and refresh as needed. You can revoke this access at any time from your Microsoft account.
- Mailbox content, in transit. When you view or search a connected account, TrekMail connects to that provider’s servers and processes the messages, folders, and attachments needed to display them to you. This content is Customer Content; it is read live and only briefly cached to keep the interface responsive — we do not create a permanent copy of your connected mailbox inside the Services.
- Sending. When you send or reply from a connected address, the message is delivered through that provider’s own outgoing (SMTP) servers using your credentials, so it comes from your real address; a copy is placed in that account’s Sent folder where the provider supports it.
- Connection metadata. Server settings, connection status, and diagnostic information used to keep the account working and to prevent abuse. The Services are designed not to return raw credentials or tokens in ordinary responses or write them to ordinary application logs.
- Third-party providers. Connecting an account causes data to flow between TrekMail and that provider (for example, Google, Microsoft, Apple, or your mail host) under their own terms and privacy policies. You must own or be authorized to access any mailbox you connect.
- Disconnecting. Removing a connected account revokes TrekMail's active use of the stored credentials or tokens and schedules their removal from active systems, subject to limited security records and backup cycles. It does not delete mail at the original provider.
Email Verification Data:
If you use the Email Verifier feature, we process:
- Email addresses you submit for verification (ordinarily stored in active result storage for up to 15 days and then scheduled for deletion, subject to limited operational, security, and backup records);
- Verification results including status, trust score, and DNS metadata;
- Credit balance and transaction records.
- External Queries: To perform verification, TrekMail may query external data sources on a per-address basis, including DNS resolvers (MX, SPF, DMARC records), domain WHOIS/RDAP registrars (for domain age), DNS-based blocklists (such as Spamhaus and SURBL), Gravatar/Automattic (for web presence scoring), and may initiate SMTP connections to the recipient mail server to confirm mailbox existence. These queries transmit only the email address or domain being verified and are conducted solely to produce a verification result for you.
- Note: We do not read, store, or process the content of any emails at these addresses. We only verify whether the address exists and can receive email.
Webmail Avatar Display:
When you read mail in TrekMail Webmail, we can show the public Gravatar photo linked to a sender's email address (and to your own mailbox address). To do this:
- Our server — not your browser — requests the image from Gravatar (operated by Automattic) using a one-way SHA-256 hash of the email address. The plain email address itself is never sent to Gravatar.
- If a photo exists, we cache it on our own servers so it loads from our domain; your browser does not connect to Gravatar directly. If no photo exists, we simply show the sender's initials.
- This happens automatically as messages are displayed. You can turn it off at any time in Webmail under Settings → "Show sender photos"; when it is off, no sender's email is looked up on Gravatar. (Your own profile photo, which you set under "Profile photo," is handled separately.)
Bring Your Own SMTP (BYO SMTP) and Per-Domain SMTP Configuration:
If you use "Bring Your Own SMTP" or similar features — including configuring outbound SMTP at the account level and/or on a per-domain basis — you may provide:
- SMTP host, port, encryption mode;
- SMTP username and password or API key/secret (collectively, "SMTP Credentials").
- Note: We treat SMTP Credentials as Sensitive Configuration Data and limit access as described in Section 7.
Migration / Import Credentials:
If you use migration features (e.g., IMAP migration), you may provide:
- Source server settings (host/port/security);
- Source account credentials (passwords or app passwords) (collectively, "Migration Credentials").
- Note: We use Migration Credentials solely to perform the requested migration/import.
API Tokens and Configuration:
If you use the TrekMail API or connect AI agents via the MCP server, you may create:
- Operations token names (
tm_live_prefix), scopes (permissions), domain constraints, and expiration dates; - Message token names (
tm_msg_prefix) for programmatic email reading and sending, associated with specific mailboxes; - MCP server configuration (connection method, environment settings).
- Note: Both token types are hashed (SHA-256) at rest. The plaintext token is shown once at creation and cannot be recovered. We store the hash, a visible prefix, and associated metadata (scopes, constraints) to authenticate and authorize API requests.
Email Content Access via API:
If you use message tokens to read or send email via the API or MCP server, TrekMail processes email content (message bodies, headers, attachments) on your behalf in accordance with your instructions. This access is logged in API audit events (see Section 3B below). TrekMail does not use email content accessed via message tokens for any purpose other than fulfilling your API request.
Affiliate Program Data:
If you participate in the TrekMail Affiliate Program, we collect and process:
- Application information (name, promotional channels, audience description);
- Tax documentation (such as IRS Forms W-9, W-8BEN, or W-8BEN-E), which is encrypted at rest using AES-256-CBC;
- Payout details (payment method, recipient information as required by the selected payout rail);
- Click and conversion tracking data (Affiliate Link clicks, attributed signups, commission events);
- Activity logs (actions taken within the affiliate dashboard for compliance and fraud prevention purposes).
- Note: Affiliate attribution is tracked via a cryptographically signed first-party cookie set when a visitor clicks an Affiliate Link. See our Cookie Policy for details.
B. Information Collected Automatically
Device and Usage Information:
- IP address, device identifiers, browser type, OS;
- Timestamps, pages viewed, and feature usage;
- General location derived from IP (e.g., city/country).
Security and Abuse-Prevention Signals:
- Login activity and authentication events, including IP address, approximate location derived from IP (city, country, region), device type, browser, and operating system;
- Indicators of suspected fraud, abuse, or policy violations;
- Rate-limiting events and throttling signals.
API Audit Logs:
When you use the TrekMail API or MCP server, we automatically record:
- The API action performed (e.g., token created, mailbox deleted, forwarding updated);
- The API token used (name and prefix only, not the secret);
- The resource affected (type and identifier);
- IP address of the request and a unique request ID;
- Timestamp of the action.
- Note: API audit logs are visible in your dashboard under AI Agents & API → Audit Log.
Email Delivery and Performance Metadata (Service Telemetry):
To operate and protect email functionality, we may process metadata such as:
- Message envelope and routing metadata (e.g., sender/recipient domains, Message-IDs);
- Delivery events (delivered, deferred, bounced, rejected), complaint signals, and diagnostics.
Drive Operational Metadata:
To operate and protect Drive and public link functionality, we may process metadata such as:
- Upload and download timestamps, storage usage, file status, quota events, and public link activity;
- IP address, user agent, rate-limit events, and security signals associated with uploads, downloads, and public links;
- Administrative and audit events needed to support security, customer support, billing, and abuse prevention.
DMARC and TLS-RPT Reports:
To monitor and improve email authentication and transport security for your domains, TrekMail automatically ingests and processes:
- DMARC aggregate reports sent by external mail servers, which contain IP addresses, authentication results (SPF/DKIM pass/fail), and message disposition data;
- TLS-RPT (TLS Reporting) data sent by external mail servers, which contains information about TLS negotiation successes and failures for your domains.
- Note: These reports are generated and sent by third-party mail servers in accordance with publicly published DNS records (DMARC and TLS-RPT policies) configured for your domains. TrekMail processes this data solely to provide deliverability analytics and security monitoring within your dashboard.
Analytics and Conversion Tracking:
To measure the effectiveness of our marketing efforts and improve the Service, we may collect:
- Google Analytics 4 client identifiers and server-side event data (such as purchase and registration events transmitted via the GA4 Measurement Protocol);
- Meta (Facebook) Pixel identifiers, including
_fbpand_fbccookie values, and server-side conversion events transmitted via the Meta Conversions API (such as purchase, registration, and checkout events). Advanced matching may include hashed email, first name, last name, and an external identifier. - Campaign, click, device, and conversion information processed through other advertising-measurement services we use, which may include Microsoft Advertising, Quora, and OpenAI advertising tools. Depending on the service and event, this may include campaign or click identifiers, page or event information, browser and device information, IP address, country, transaction metadata, and limited identifiers used to match or deduplicate conversion events.
- Attribution parameters such as UTM values and advertising click identifiers associated with a visit, registration, trial, checkout, or purchase.
- Note: Use of these analytics services remains subject to applicable law. See our Cookie Policy for details about the technologies, browser controls, and available request methods.
C. Information from Third Parties
- Payment Providers: Confirmation of payment, chargeback notices.
- Fraud Providers: Signals used to reduce abuse (e.g., IP reputation).
- Social Login: If you use social login (Google, Facebook, X/Twitter, or Microsoft), we receive your email address (where provided by the provider), display name, and a unique provider identifier. You may link multiple social accounts to a single TrekMail account and manage these connections from your account settings.
- Marketplace Purchases: If you purchase a TrekMail plan through an authorized third-party marketplace (such as ClickBank or JVZoo), we receive your email address, name, transaction identifier, and purchase details from the marketplace operator in order to provision your account and manage your subscription.
4. How We Use Information & Legal Bases
We use the information described above for the following purposes. If you are located in the EEA or UK, we process data based on the following legal grounds:
-
Service Provision: To route, store, and deliver emails; provide shared mailboxes, calendar, contacts, Drive, and file storage features; manage domains; migrate data; and authenticate users.
- Legal Basis: Performance of Contract.
-
Billing: To process subscriptions and handle taxes.
- Legal Basis: Performance of Contract and Legal Obligation.
-
Security & Abuse Prevention: To detect, prevent, investigate, and respond to fraud, abuse, spam, malware, phishing, and security incidents. This includes automated decision-making (see Section 9).
- Legal Basis: Legitimate Interests (protecting our platform and other users).
-
Improvements: To troubleshoot, debug, and improve performance and reliability.
- Legal Basis: Legitimate Interests.
-
Communications: To send transactional messages (service notices, billing notices, security alerts) and respond to support tickets.
- Legal Basis: Performance of Contract.
-
Legal Compliance: To comply with applicable laws, lawful requests, and regulatory obligations.
- Legal Basis: Legal Obligation.
Marketing: We do not use the content of your emails for marketing or advertising purposes. We may use your account contact info to send product updates, which you may opt-out of.
5. How We Share Information
We do not sell Customer Content or disclose it to third parties for their independent marketing. We disclose limited information only for the purposes described below, including to operate, secure, support, and improve the Service, process payments, provide features requested by the customer, measure advertising performance, or comply with law.
A. Service Providers (Subprocessors)
We use third-party providers in different legal roles. Service Providers or Subprocessors process personal data on our behalf to provide services to TrekMail. Certain payment, authentication, marketplace, analytics, or advertising providers may separately process limited information under their own terms and privacy practices. We do not authorize any provider to use Customer Content for its independent marketing.
Key subprocessors we currently use include:
-
Stripe, Inc. (Payments / Subscription Billing). Used to process card payments, manage subscriptions, and support related fraud prevention and payment operations. Stripe acts as an independent service provider and may process payment-related data according to its own terms and privacy practices.
Privacy: https://stripe.com/privacy -
Backblaze, Inc. (Object Storage). Used to store certain file objects, Drive data, attachment objects, and related storage materials needed to provide the Services. Backblaze may process Customer Content and related metadata only as needed to provide storage services to TrekMail and subject to applicable contractual safeguards.
Privacy: https://www.backblaze.com/company/privacy -
NOWPayments (Crypto Payments, where enabled). Used to facilitate cryptocurrency payments when you choose crypto checkout (typically for yearly plans). NOWPayments processes payment-related data according to its own terms and privacy practices.
Privacy: https://nowpayments.io/privacy-policy -
Google LLC (Security, Authentication, and Analytics). We use Google services in connection with account security, site/app functionality, and analytics, such as:
- Google reCAPTCHA v2/v3 to prevent automated abuse on forms and authentication flows;
- Google OAuth / "Continue with Google" to enable optional social login;
- Google Analytics 4 (GA4) to understand how visitors use our website and to improve the Service, including client-side tracking and server-side event transmission via the GA4 Measurement Protocol (e.g., purchase and registration events). GA4 is subject to cookie/consent settings where required by applicable law.
-
Meta Platforms, Inc. (Facebook OAuth). We use Facebook Login / "Continue with Facebook" to enable optional social login. When you authenticate via Facebook, we receive your email address (if you grant permission), display name, and a unique Facebook identifier.
Privacy: https://www.facebook.com/privacy/policy/ -
X Corp. (X/Twitter OAuth). We use X (formerly Twitter) Login / "Continue with X" to enable optional social login. When you authenticate via X, we may receive your email address (depending on your X privacy settings), display name, and a unique X identifier.
Privacy: https://x.com/en/privacy -
Microsoft Corporation (Microsoft/Entra ID OAuth). We use Microsoft Login / "Continue with Microsoft" to enable optional social login via Microsoft Entra ID (formerly Azure Active Directory). When you authenticate via Microsoft, we receive your email address, display name, and a unique Microsoft identifier. Scopes requested include
openid,profile,email, andUser.Read.
Privacy: https://privacy.microsoft.com/en-us/privacystatement -
Meta Platforms, Inc. (Facebook Pixel and Conversions API). In addition to Facebook Login (described above), we use the Meta Pixel (client-side) and Meta Conversions API (server-side) to measure advertising effectiveness and attribute conversions. These technologies may collect or receive: hashed identifiers (email, name), browser and device data,
_fbpand_fbccookie values, and conversion event data (such as registration, trial start, checkout initiation, and purchase events). Meta processes this data as an independent controller in accordance with its own privacy policy. The Meta Pixel and Conversions API are subject to cookie consent where required by applicable law.
Privacy: https://www.facebook.com/privacy/policy/ - Other Advertising Measurement Providers. Where enabled, we may use Microsoft Advertising, Quora, and OpenAI advertising-measurement technologies to attribute visits, registrations, trials, checkouts, or purchases to an advertising campaign. These providers may receive limited campaign, click, event, device, network, country, transaction, and matching information as described in Section 3. We do not provide them with the contents of emails, contacts, calendars, or Drive files for advertising purposes.
-
Cloudflare, Inc. (DNS Management). If you use the Cloudflare DNS integration feature, TrekMail communicates with Cloudflare on your behalf to auto-provision DNS records (MX, SPF, DKIM, DMARC, MTA-STS) for your domains, either via the Domain Connect protocol or via Cloudflare's API. Cloudflare processes this data in accordance with its own privacy policy.
Privacy: https://www.cloudflare.com/privacypolicy/ -
jsDelivr (CDN — Performance Assets). Certain UI libraries (for example, Chart.js used in dashboard analytics charts) are loaded from the jsDelivr public CDN (
cdn.jsdelivr.net). jsDelivr is a non-tracking, open-source CDN. These requests do not contain any personal data beyond standard browser request metadata (IP address, User-Agent). jsDelivr is operated by Prospect One and processes request logs in accordance with its own privacy policy.
Privacy: https://www.jsdelivr.com/privacy-policy-jsdelivr-net -
ClickBank (Keynetics, Inc.) (Marketplace Purchases). If you purchase a TrekMail plan through the ClickBank marketplace, ClickBank processes your payment and transmits purchase details (email, name, transaction ID, product, and payment status) to TrekMail via Instant Notification Service (INS) webhooks and order verification API. ClickBank acts as an independent merchant of record for such transactions.
Privacy: https://www.clickbank.com/privacy-policy/ -
JVZoo.com, Inc. (Marketplace Purchases). If you purchase a TrekMail plan through the JVZoo marketplace, JVZoo processes your payment and transmits purchase details (email, name, transaction ID, product, and payment status) to TrekMail via Instant Payment Notification (IPN) webhooks. JVZoo acts as an independent payment facilitator for such transactions.
Privacy: https://www.jvzoo.com/privacy -
Admitad GmbH (Affiliate Network — Conversion Attribution). We participate in the Admitad affiliate network to track conversions originating from Admitad publisher traffic. When a visitor arrives via an Admitad publisher link, TrekMail may store the supplied
_admitad_uidattribution value in a first-party cookie on our domain. If that visitor subsequently purchases a plan, we may transmit a server-side conversion postback to Admitad containing the transaction identifier, commission-relevant order data, and the attribution value — but not the purchaser's full name or email address. Admitad processes this data as a performance marketing platform in accordance with its own privacy policy.
Privacy: https://www.admitad.com/en/privacy-policy/ -
Automattic Inc. (Gravatar — Avatar Display). If sender photos are enabled in Webmail, our servers request public avatar images from Gravatar using a one-way SHA-256 hash of the relevant email address (a sender's address, or your own mailbox address). The plain email address is not sent to Gravatar, the request is made server-side (your browser does not contact Gravatar), and any returned image is cached on TrekMail's own infrastructure. You can disable this in Webmail under Settings → "Show sender photos." Automattic processes these requests as an independent service provider in accordance with its own privacy policy.
Privacy: https://automattic.com/privacy/
In addition, we may use infrastructure and hosting providers (for example, hosting, storage, networking, and backups) and monitoring/logging tools to operate and secure the Service. Where a vendor acts as TrekMail's processor, it is authorized to access personal data only as needed to perform the contracted services and is subject to applicable contractual restrictions. Providers acting independently process information under their own terms and notices.
No sale of Customer Content. We do not sell Customer Content or provide it to advertising providers. We do not sell personal data for money. Limited disclosures for analytics, attribution, and advertising measurement are described above and may be treated differently under the privacy laws of different jurisdictions.
Updates. We may update this Subprocessors section from time to time as we add, remove, or replace vendors. If changes are material, we may provide additional notice through the Service where appropriate.
B. Payment Providers
Payments are processed by third-party payment providers (e.g., Stripe). We receive limited information such as payment confirmation and transaction metadata.
C. Customer-Directed Disclosures
You may direct us to share information through integrations, by configuring routing to third-party services (e.g., external SMTP providers, forwarding destinations), by sharing folders within your account, or by creating public Drive links. Public links are bearer links; anyone who obtains the link may access the linked file until the link expires, reaches its download limit, is revoked, is deleted, or is disabled.
D. Legal, Safety, and Enforcement
We may disclose information if we believe it is necessary to:
- Comply with law, regulation, legal process, or lawful government requests;
- Protect the rights, property, and safety of TrekMail, our users, and others;
- Detect, prevent, or address fraud, abuse, and security issues.
E. Business Transfers
If TrekGuider Inc. is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality protections.
6. International Data Transfers
TrekMail's primary email infrastructure and primary Customer Content storage are hosted in France. Certain supporting services, payment processing, analytics, advertising measurement, authentication, security, support, and other service providers may process limited information in the United States or other jurisdictions where they operate.
Where applicable law requires a transfer mechanism, the relevant provider terms and transfer arrangements may use safeguards such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another recognized mechanism.
- EEA/UK Users: Data processed outside the EEA/UK is handled under the transfer mechanism applicable to the provider and transfer, where one is required. Contact us through the Support Center for reasonably available information about safeguards relevant to your use of the Services.
- All Users: We apply contractual, technical, and organizational safeguards designed to protect personal data regardless of where it is processed.
7. Security
We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, and alteration.
Sensitive Configuration Data:
SMTP Credentials and Migration Credentials are treated as "Sensitive Configuration Data." Access to this data is restricted to authorized systems and personnel on a strict need-to-know basis (e.g., specifically for debugging active migration failures).
Vulnerability Disclosure:
For coordinated vulnerability disclosure, please see our Security & Vulnerability Disclosure Policy. Qualifying researchers may be recognized in our Security Hall of Fame at TrekMail's discretion.
Disclaimer: No security program is perfect, and we cannot guarantee absolute security. You are responsible for securing your login credentials and enabling 2FA.
8. Data Retention
We retain information for as long as reasonably necessary to provide the Services, comply with legal obligations, and prevent abuse.
- Account/Billing: Account data is retained while needed to provide the Services. Certain billing, transaction, tax, fraud-prevention, dispute, and legal records may be retained after account closure, commonly for approximately 7 years or longer where required.
- Migration Credentials: Retained only as long as needed to complete the migration/import and then deleted or minimized.
- Security and Authentication Logs: Login activity, authentication events, and related security signals are retained for 30–90 days for abuse detection and security monitoring.
- API Tokens and Audit Logs: Revoked and expired API tokens are retained for reference. API audit events are retained for 90 days and then automatically purged. Idempotency keys are retained for 24 hours.
- Email Content: Upon account deletion (which is scheduled with a 7-day grace period to allow cancellation), email content is deleted from the mail server. Backup copies may be retained for a limited period for disaster recovery purposes and are subject to the same access controls.
- Shared Mailbox Content: Content stored in a shared mailbox is retained on the same basis as other mailbox content and is deleted when the shared mailbox is deleted or as part of account closure, subject to the same grace period and backup practices described for Email Content above.
- Calendar and Contacts Data: Calendar entries and contact/address book data are retained while your account is active and the data remains stored in the Services, unless deleted by you, removed for abuse or legal reasons, or deleted as part of account closure.
- Backups: We maintain rolling operational backups for disaster recovery. Backup copies are retained only for a limited period and are subsequently overwritten or deleted in the ordinary course; data deleted from the live Services may persist in backups until those backups age out.
- Drive Files: Drive files are retained while your account is active and the files remain stored in the Services, unless they are deleted by you, removed under quota enforcement, removed for abuse or legal reasons, or deleted as part of account closure. If a Drive Storage Add-on ends for cancellation or failed payment and the account remains over its remaining storage cap after the applicable seven (7) day read-only grace period, Drive files may be permanently and irreversibly deleted to reduce usage.
- Drive Trash: Files moved to Drive Trash may remain recoverable for a limited period and continue to count toward storage usage until permanently removed. Files permanently deleted from Trash, automatically removed at the end of the Trash retention period, or removed through quota cleanup are not recoverable through the Services.
- Public Links: Active public links remain available until they expire, reach their download limit, are revoked, the underlying file is deleted, or access is disabled for security, abuse, legal, or operational reasons. Records of revoked links may be retained for a limited period for audit, abuse prevention, troubleshooting, and enforcement.
- Pending Uploads and Operational Records: Incomplete uploads, temporary upload state, download records, and quota events may be retained or removed according to operational schedules needed to provide, secure, and troubleshoot the Services.
- Email Verification Data: Email addresses submitted for verification and their results are ordinarily retained in active result storage for up to 15 days and then scheduled for deletion, subject to limited operational, security, and backup records. Verification credit balances and transaction records are retained while needed to provide the Service and for applicable accounting, dispute, security, and legal purposes.
- Affiliate Program Data: Click tracking data and activity logs are periodically purged in accordance with our internal retention schedules. Commission records and tax documentation are retained for the life of the affiliate relationship plus a period required for tax/audit compliance (typically 7 years). A financial snapshot is captured prior to account deletion to preserve audit integrity.
- Support Ticket Attachments: Screenshots and images attached to support tickets are automatically deleted 30 days after the ticket is closed.
- DMARC and TLS-RPT Reports: Aggregate report data is retained and rolled up into daily statistics for deliverability monitoring. Raw reports are processed and may be deleted after aggregation.
9. Automated Decision-Making and Profiling
We use automated systems, including machine learning models and rules-based logic, to help protect the Services and users. These systems may perform the following types of automated processing:
- Spam and Malware Detection: Inbound and outbound email is scanned by automated classifiers (including Bayesian machine learning) to detect spam, phishing, malware, and other abusive content. Messages exceeding configured thresholds may be automatically rejected, quarantined, or flagged.
- Abuse and Fraud Prevention: Automated systems monitor for suspicious patterns such as rapid sending, "snowshoe" spamming across domains, and abnormal API usage. These systems may automatically enforce rate limits, pause outbound sending, or restrict account functionality.
- Email Verification Scoring: The Email Verifier assigns a trust score (0–100) to each submitted email address based on automated analysis of multiple signals (syntax, DNS, SMTP response, blocklist status, and heuristic indicators). This scoring is fully automated and does not involve human review of individual addresses.
- Account Suspension: Accounts that trigger automated abuse-detection thresholds may be temporarily restricted pending review. Domains and mailboxes belonging to accounts suspended for abuse for more than 7 days may be automatically removed from the mail system.
These measures are designed to support the security and integrity of the platform. If you believe an automated restriction was applied in error, you may request review by submitting a support ticket. The availability, form, and timing of any review are subject to applicable law, identity and security checks, and the circumstances of the request.
10. Your Rights (US States & GDPR)
A. US State Privacy Rights
Subject to applicable law, residents of U.S. states with comprehensive privacy legislation may have one or more of the following rights:
- Right to Know/Access: Confirm whether we process personal information and request access to information covered by applicable law.
- Right to Delete: Request deletion of personal information.
- Right to Correct: Correct inaccuracies.
- Right to Portability: Request a portable copy where required by applicable law.
- Marketing and Profiling Choices: Opt out of a qualifying sale, sharing, targeted advertising, or profiling activity where the relevant law applies to TrekMail and the activity.
- Sensitive Information: Limit or withdraw consent to certain uses of sensitive personal information where applicable law grants that right.
- Appeal: Appeal a denial where applicable law provides that right.
- Non-Discrimination: We will not discriminate against you for exercising these rights.
B. EEA/UK Rights
If you are in the EEA/UK, you may also have the right to:
- Access and Copy: Request access to personal data covered by applicable law.
- Correction and Deletion: Request correction of inaccurate data or deletion where the applicable requirements are met.
- Portability: Request a portable copy where required.
- Withdraw Consent: Withdraw consent where processing is based on consent.
- Object/Restrict: Object to or request restriction of qualifying processing.
- Lodge a Complaint: With a supervisory authority (EEA) or the ICO (UK).
How to Exercise Rights:
Current customers should submit requests through the TrekMail Support Dashboard ticket system. Requests may also be submitted by postal mail using the address in Section 14. We may request information reasonably necessary to verify identity, authority, account ownership, and the scope of the request. We do not accept privacy requests by phone to protect account security.
11. Relationship to Terms and Legal Rights
The Terms of Service, including their dispute-resolution provisions, govern use of the Service to the extent applicable and enforceable. Nothing in this Privacy Policy limits a non-waivable privacy right, a right to contact or complain to a competent regulator, or any remedy that applicable law does not permit the parties to waive.
12. Children's Privacy
The Services are directed to businesses and adults and are not intended for account ownership by anyone under 18 or the applicable age of majority. We do not knowingly collect personal information directly from a child under 13 in a manner subject to the Children's Online Privacy Protection Act. If we learn that we collected such information without legally valid authorization, we will take reasonable steps to delete or disable it as required by law. Customer Content may contain information about minors supplied by a customer; in that context, the customer is responsible for having the authority and permissions required to process that information through the Services.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The revised Policy becomes effective when posted unless a later effective date is stated. If a change materially alters how we use previously collected personal information, we will provide any additional notice or obtain any consent required by applicable law.
14. Contact Information
We do not maintain a public phone line for legal compliance. All inquiries must be in writing.
Primary Contact Method:
Submit a ticket via the TrekMail Dashboard under "Privacy & Legal."
Mailing Address:
TrekGuider Inc.
Attn: Legal / Privacy Officer
1207 Delaware Ave, #2058
Wilmington, DE 19806
United States
Spam & Abuse Prevention
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.