Privacy Policy
This policy covers the MarkRelay website, customer account, checkout, documentation, contact forms, and support portal. It distinguishes that website data from mailbox data in a customer-operated MarkRelay deployment.
1. The self-hosted data boundary
MarkRelay Self-Hosted runs in the customer's Cloudflare account. Its D1 database and R2 bucket hold that deployment's application data, including mailbox indexes, message content, attachments, recipients, and configuration. We do not receive that data merely because you purchased a license.
This does not mean email avoids third parties. Cloudflare processes inbound and outbound email and hosts the deployment, and recipient providers process delivered messages. The customer operating the deployment is responsible for its privacy notices, lawful basis, access controls, retention, deletion, and data-subject requests. If you intentionally include deployment data in a support request, we process that copy as support data.
2. Information the MarkRelay website collects
- Account information: name, email address, profile image if provided, authentication status, and account identifiers.
- Order information: product, amount, order status, Stripe customer and checkout references, invoices or receipt links, and related timestamps. We do not store full payment-card numbers.
- Communications: contact forms, support tickets, email correspondence, company and job title if supplied, and files or technical details you choose to send.
- Technical and usage data: IP address, browser and device information, requested pages, referrer, timestamps, cookie identifiers, approximate location, analytics events, and error or security logs.
3. How we use website information
- create and secure customer accounts;
- process orders, prevent duplicate purchases, and deliver licenses;
- provide deployment guidance, updates, and customer support;
- send authentication codes and service-related communications;
- operate, measure, troubleshoot, and improve the website and docs;
- prevent fraud, abuse, unauthorized access, and legal violations;
- comply with accounting, tax, sanctions, and other legal obligations.
Depending on applicable law, processing is based on performing a contract, legitimate interests in operating and securing the service, consent where required, or compliance with law.
4. Service providers
We use providers that process limited data for these purposes:
- Cloudflare hosts the website Worker, database, storage, network, and related logs.
- Stripe processes checkout, payment, receipts, and fraud signals under Stripe's privacy terms.
- Resend delivers website authentication and support email.
- Google Analytics measures website usage when the analytics integration is enabled, using cookies or similar identifiers as permitted by browser settings and applicable law.
We may also disclose information to professional advisers, authorities when legally required, or a successor in a merger, acquisition, financing, or sale. We do not sell customer mailbox data, and we do not sell website personal information for money.
5. Cookies and local storage
The website uses essential cookies for authentication, security, and session continuity. It may use preference storage for interface settings and analytics cookies to understand visits. You can control non-essential cookies through browser settings or applicable consent controls, but blocking essential cookies may prevent sign-in and checkout.
6. Retention
We retain account and order records while an account or license is active and as needed for support, security, accounting, tax, dispute, and legal obligations. Contact and ticket records are retained as long as reasonably necessary to resolve the request and maintain service history. Technical logs and analytics are retained according to operational and provider settings. We delete or de-identify data when it is no longer reasonably needed, subject to legal and backup retention.
7. Security
We use reasonable administrative and technical measures intended to protect website data, including access controls and managed service security features. No network, storage system, or email channel is completely secure. Do not send production secrets, API keys, mailbox exports, or unnecessary personal data in support messages.
8. International processing
We and our providers may process information in countries other than your own. Where required, we use available contractual or legal safeguards for international transfers. A self-hosted deployment's Cloudflare location and data controls are selected and managed by its operator, subject to Cloudflare's services.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or export personal information, withdraw consent, or complain to a regulator. To make a request about data held by this website, email us from the address associated with your account. We may need to verify identity and retain information where law permits or requires it.
For data in a customer's self-hosted deployment, contact that deployment's operator. MarkRelay cannot access or delete data that is held only in a Cloudflare account we do not control.
10. Children
The website and software are intended for business and professional users, not children. We do not knowingly collect personal information from children under 13. If you believe a child submitted information, contact us so we can review and delete it where appropriate.
11. Changes
We may update this policy as the product, providers, or laws change. The current version and effective date will be posted here. Material changes may also be communicated through the website or account email.
12. Contact
Privacy questions and requests can be sent to support@markrelay.com.
Last updated: July 21, 2026