1. Who We Are
SendWaves (“SendWaves,” “we,” “us”) provides infrastructure for outbound email operations, including: (a) setup and hosting of email mailboxes, (b) monitoring of email deliverability and mailbox health, and (c) purchase and management of domains on behalf of customers. This policy explains what information we collect, how we use it, and the rights available to you.
2. Information We Collect
- Account Information: name, company, email, phone, login credentials, and other details you provide when creating a SendWaves account.
- Billing Information: billing address and payment details, processed by our payment processor Stripe. SendWaves does not store full payment card numbers.
- Mailbox & Domain Provisioning Data: domain names, DNS records (SPF/DKIM/DMARC), mailbox configuration, and registrant information submitted when you set up a mailbox or purchase a domain through SendWaves.
- Deliverability & Monitoring Data: technical signals about mailbox and domain health — bounce rates, spam-complaint rates, blacklist status, authentication pass/fail results, and sending volume/pacing. This data is metadata about delivery outcomes, not the content of messages.
- Usage Data: log data, IP address, device/browser information, and cookies collected when you use our dashboard or visit sendwaves.com.
3. What We Do Not Access
SendWaves does not read, scan, store, or otherwise access the content — subject line, body, or attachments — of email messages sent through mailboxes we help set up or host. Our monitoring is limited to delivery outcomes (e.g., whether a message bounced, was marked as spam, or passed authentication checks) needed to keep your mailboxes and domains healthy. We do not have visibility into, and do not monitor, the substance of your correspondence.
4. How We Use Information
We use the information above to: provision and maintain mailboxes and domains; monitor and report on deliverability health; process domain purchases and renewals; bill for services; provide customer support; detect and prevent fraud or abuse of our infrastructure; and comply with legal obligations.
5. Domain Purchases
When you purchase a domain through SendWaves, we or our domain registrar partner collect and submit registrant (WHOIS) information as required by ICANN and the relevant domain registry. Where available, we may offer WHOIS privacy protection. Domain-related personal data is handled per our registrar partner’s own obligations as well as this policy.
6. Third-Party Service Providers
We share limited data with vendors who help us operate our service, including: our payment processor Stripe, a domain registrar partner, and our cloud hosting providers. Our email-sending infrastructure is operated in-house by SendWaves, not by a third-party vendor. These vendors are contractually bound to use data only to provide services to us and are subject to data processing agreements where required by law. We do not sell personal information.
7. Data About Email Recipients
SendWaves’ customers use our infrastructure to send email to their own prospects or contacts. SendWaves does not independently collect, use, or sell data about these recipients beyond the limited technical delivery metadata described in Section 2 (e.g., bounce responses needed to maintain deliverability). Our customers are the data controllers for the content and targeting of their own outbound email and are responsible for their own compliance with applicable anti-spam and privacy laws, including CAN-SPAM, CASL, and GDPR, as relevant to their sending activity.
8. Data Retention
We retain account and billing information for as long as your account is active and as needed to meet legal, tax, and accounting obligations. Deliverability and monitoring metadata is retained for 90 days to support troubleshooting and historical reporting. Domain registration records are retained per registrar and ICANN requirements.
9. Data Security
We use industry-standard safeguards, including encryption in transit and at rest, access controls limiting employee access to the minimum necessary, and regular security review of our infrastructure. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Your Rights
Depending on your location, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. California residents have rights under the CCPA/CPRA, including the right to know what personal information we collect and to request deletion. EU/UK residents have rights under the GDPR, including the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at the address below.
11. International Data Transfers
If we transfer personal information across borders, we rely on appropriate safeguards such as Standard Contractual Clauses where required by applicable law.
12. Children’s Privacy
SendWaves is a business-to-business service not directed at individuals under 18, and we do not knowingly collect personal information from minors.
13. Cookies
sendwaves.com uses cookies and similar technologies for authentication, analytics, and site functionality. You can control cookies through your browser settings.
14. Changes to This Policy
We may update this policy from time to time. We will post the updated version with a new “Last Updated” date and, for material changes, provide additional notice.
15. Contact Us
Questions about this policy or your data: support@sendwaves.com
SendWaves LLC1920 E. Riverside Drive
Suite A120-116
Austin, TX 78741