PricklyMails is committed to protecting your privacy. This policy explains what data we collect, how we use it, and the choices you have. We believe in transparency and data minimalism: we collect only what is strictly necessary to provide the service.
Data Controller
The data controller is Hugo Deltour, operating as PricklyMails. For any data-related inquiries, contact hugodeltour.pro@gmail.com.
Data We Collect
We collect the following categories of data:
- Email verification data: Email addresses submitted for verification are processed in memory, verified, and immediately discarded. No verified email address is ever stored. Only irreversible hashes of domain names are retained for aggregate statistics.
- Account data: When you create an account, we store your email address (for authentication) and a hashed version of your password (Argon2id). We never store passwords in plain text.
- Usage data: API call counts, token consumption, and error rates for billing and service monitoring. No email content is included in usage logs.
How We Use Your Data
- Provide, maintain, and improve the email verification service.
- Process billing, manage your account, and enforce usage limits.
- Send transactional emails (account confirmation, billing receipts).
- Prevent abuse, fraud, and unauthorized access to the service.
Legal Basis for Processing
We process your personal data only when we have a valid legal basis under GDPR Article 6. Depending on the purpose, the legal basis is one of the following:
- Service provision and account management: performance of a contract (art. 6.1.b) between you and us.
- Billing and accounting: performance of a contract and compliance with a legal obligation (art. 6.1.c), notably French accounting and tax law.
- Abuse prevention, fraud detection, and security monitoring: our legitimate interest (art. 6.1.f) in keeping the service safe and reliable, balanced against your rights and freedoms.
- Transactional emails (account confirmation, billing receipts, service notices): performance of a contract (art. 6.1.b).
Data Retention
Email verification data: zero retention. Emails pass through the verification pipeline and are immediately discarded. Only irreversible hashes of domain names are kept for aggregate statistics.
Account data: retained for as long as your account is active. Upon account deletion, all personal data is permanently removed within 30 days.
Billing and accounting records: retained for the legally required period, up to 10 years, to comply with French accounting and tax obligations, even after your account is deleted.
Technical and security logs: retained for a limited period (a few months) for security monitoring and troubleshooting, then automatically deleted.
Security
We implement industry-standard security measures to protect your data:
- Passwords hashed with Argon2id (OWASP recommended parameters).
- All data transmitted over TLS encryption.
- Infrastructure runs in isolated, non-root containers with resource limits.
- Sensitive configuration values managed with zeroing-on-drop secret storage:secrets are never logged or exposed in stack traces.
Third-Party Services
PricklyMails infrastructure is hosted entirely within the European Union. We use third-party services only for infrastructure hosting, DNS, and payment processing. We do not sell, share, or provide your data to any third party for marketing or advertising purposes. For the current list of subprocessors, contact us at hugodeltour.pro@gmail.com.
Sub-Processors
We rely on a small number of carefully selected sub-processors to operate the service. Each acts under a data processing agreement and only within the scope described below:
- Hetzner Online GmbH (Germany, European Union): infrastructure hosting. All application data is stored on Hetzner servers within the EU.
- Stripe: payment processing for subscriptions and token top-ups. Stripe processes billing and payment card data directly; we never see or store your card details.
- Resend: delivery of transactional emails (account confirmation, password reset, billing receipts).
- Umami (self-hosted, on our own infrastructure): privacy-friendly, cookieless website analytics. No data is shared with a third-party analytics provider.
International Data Transfers
PricklyMails infrastructure and primary data storage are located entirely within the European Union (Germany). Where a sub-processor may process data outside the European Economic Area (EEA), such transfers are covered by an applicable EU adequacy decision or by Standard Contractual Clauses (SCC) as approved by the European Commission, in accordance with Chapter V of the GDPR.
Cookies
PricklyMails uses only strictly functional cookies: authentication and session cookies for secure access, and preference cookies for storing your locale and theme settings. We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.
Automated Decision-Making
The verification pipeline automatically computes a deliverability score and status for each email address submitted. This automated processing does not, on its own, produce legal effects or similarly significantly affect you within the meaning of GDPR Article 22: it evaluates an email address, not a person, and does not result in an automated decision about you (such as denial of a service or benefit) without human involvement. If you believe an automated result has been used to make a significant decision affecting you, you may request human review by contacting us.
Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate personal data.
- Request deletion of your personal data (right to be forgotten).
- Receive your data in a portable, machine-readable format.
- Object to processing of your personal data.
- Request restriction of the processing of your personal data under certain circumstances.
- Withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal.
- Lodge a complaint with the French supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr, if you believe your rights have not been respected.
To exercise any of these rights, contact us at hugodeltour.pro@gmail.com. We will respond within 30 days.
Minimum Age
PricklyMails is not directed at children and is not intended for use by anyone under the age of 16, or the age of digital consent applicable in your country of residence if higher. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.
Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, as required by GDPR Article 34.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service after changes constitutes acceptance of the revised policy.
Contact
For any privacy-related questions or concerns, contact Hugo Deltour at hugodeltour.pro@gmail.com.