Skip to content
DearReach
ProductDeliverabilityPricingBlogHelp
Sign in Start free
ProductDeliverabilityPricingBlogHelp Sign in Start free
Draft, pending legal review. This document is a working template grounded in how DearReach handles data. It is not legal advice; a qualified lawyer should review it and the bracketed placeholders be completed before it is relied upon.
PrivacyTermsSub-processors

Sub-processors & Data Retention

Last updated: [DATE]

Sub-processors

We use the following providers to operate DearReach. Each processes only the data needed for its function.

ProviderPurposeData involved
Amazon Web Services (SES)Email transmission and delivery-event webhooksRecipient email address, message content, delivery/bounce/complaint events
Amazon Web Services / [hosting provider]Application hosting, database, and file/media storageAll customer and subscriber data at rest
StripeSubscription billing and paymentsCustomer billing identity and payment details (card data handled by Stripe directly)
Sentry (if enabled)Error monitoring and diagnosticsTechnical error metadata; configured to minimise personal data

[Confirm the exact legal entities, regions, and any additional providers you use in production, for example transactional or auth email, DNS, or a CDN.] We will give advance notice of new sub-processors so customers can object.

Data retention periods

DataRetention
Customer account & workspace dataFor the life of the account. On deletion, scheduled for permanent erasure after a 30-day recovery window.
Subscriber personal data (email, name, custom fields)Until the customer deletes it, or the account is erased. Erasing a subscriber removes personal data immediately.
Suppression hashes (unsubscribes / complaints)Retained up to 3 years as one-way hashes, to prevent unlawful re-contact. Cannot be reversed to an email address.
Delivery, bounce, complaint, open & click eventsKept for reporting and deliverability for the life of the campaign/account; erased with the account.
Billing & tax recordsRetained as long as tax and accounting law requires (typically [6–7] years).
Security & audit logsRetained for a limited period for security and abuse investigation.

Account deletion in detail

When you delete your DearReach account, it is deactivated and scheduled for permanent deletion 30 days later. During that window you can log back in and reactivate. After 30 days a background process irreversibly erases your workspaces, subscribers, campaigns, and media. The only data that survives is the one-way suppression hashes described above, which exist solely so people who opted out are never re-emailed. You may also request immediate erasure without the 30-day window.

© 2026 DearReach. This document is a draft template and does not constitute legal advice.

DearReach

Write personally. Reach reliably.

Deliverability-first email for people whose audience is their business.

Product

How it works Deliverability Pricing Blog Help Center

Get started

Sign in Create an account

Legal

Privacy Terms Sub-processors
© 2026 DearReach. All rights reserved. Built for the inbox.