Privacy Policy

Last updated: July 24, 2026 (draft, not yet in effect)

Who we are

Cocomail (cocomail.cc) is a newsletter sending platform operated by Panara Studio LLC, 8 The Green, STE B, Dover, DE 19901, a United States company. Its administration is carried out from India, and authorized operational access to our systems (for support, security and operations) may occur from India. You can reach us at [email protected].

Cocomail customer accounts are not offered to individuals resident in, or businesses established in, the EEA or the United Kingdom (see the Terms of Service). The subscribers on a customer's list are a separate matter: customers decide who they email, and Cocomail does not determine or infer where those subscribers live.

We act in three distinct roles:

  • Controller of your account and billing data (the customer relationship).
  • Processor of the subscriber data you upload or collect, of delivery, and of the engagement tracking you direct: we process it only on your instructions, under our Data Processing Addendum where it applies. You, the customer, are the controller of your subscriber lists, campaigns and recipient targeting: you determine your recipients, your lawful basis, your notices and your tracking choices.
  • Independent controller of platform-wide suppression, security and abuse-prevention records (bounce and complaint histories we must keep to run a deliverable, lawful email platform).

Data we collect

  • Account data: name, email address, a hash of your password (we never store the password itself), and, if you sign in with Google, the basic profile Google shares with us (name, email address).
  • Billing data: handled by Stripe. Your card details never touch our servers; we store only Stripe customer and subscription identifiers, plan and billing status.
  • Sending configuration: your sending domains and their DNS records, sender identities, physical mailing address (required in email footers by anti-spam law), and any webhook URLs you configure.
  • Content: your newsletters, templates and transactional email we send on your behalf.
  • Subscriber data (processed for you): email address, first name, last name and tags for every contact you import, export or collect via subscribe forms, including the CSV files themselves.
  • Engagement data (processed for you):when open/click tracking is enabled for a newsletter (see “Audience and tracking controls” below), our tracking endpoints record opens, clicked URLs and the browser user agent of the click or open. Our application does not store subscriber IP addresses with these events; IP addresses do appear transiently in infrastructure logs (see the next point).
  • Infrastructure logs: our hosting provider and reverse proxy process the IP address of every request (including subscriber opens/clicks) as ordinary web-server traffic.
  • Delivery data: delivery, bounce and complaint events from Amazon SES, and the suppression records derived from them.
  • Support: anything you send to [email protected].
  • Analytics:only if you accept the cookie banner. If you reject it (or make no choice), no analytics script loads at all. You can change your choice any time via “Cookie settings” in the site footer or in the app under Settings → Profile.

Audience and tracking controls

Open/click tracking of newsletter engagement is controlled by the sender and never activates while the audience question below is unanswered:

  • Every account must answer, before its first send, whether its subscriber audience may include people in the EEA or the United Kingdom. Until it is answered, no campaign can be sent and tracking never activates.
  • If the answer is “no”, open and click tracking is enabled by defaulton plans that include it (Creator and Pro), unless the sender disables it for a newsletter. If the answer is “yes, or not sure”, tracking defaults to off, and the sender can enable it per newsletter only after confirming that they have provided any required notice and obtained any consent required by the laws applicable to their recipients. That confirmation is recorded with the newsletter.
  • Cocomail cannot reliably determine a subscriber's country from an email address and does not attempt to geolocate or classify subscribers: the declaration and the responsibility for recipient-facing notice and consent rest with the sender.

This is separate from the cookie-consent banner on our own website, which governs only our website analytics and is described under “Analytics” above and “Cookie settings” below.

Why we process it (legal bases where GDPR/UK GDPR applies)

Where EU or UK data protection law applies to a given processing activity, these are the bases we rely on for the processing where Cocomail acts as controller:

PurposeLegal basis (GDPR)
Your customer account: registration, sign-in, service administrationPerformance of a contract (Art. 6(1)(b))
Billing, invoicing, tax recordsContract + legal obligation (Art. 6(1)(b), (c))
Transactional email to you (password resets, alerts)Performance of a contract (Art. 6(1)(b))
Deliverability, suppression, abuse and spam prevention, platform securityLegitimate interest (Art. 6(1)(f))
Cookie analytics on our websiteConsent (Art. 6(1)(a)), via the cookie banner

Subscriber management, newsletter delivery and engagement tracking are deliberately not on this table: for that processing, the customer is the controller and determines the lawful basis for their subscribers. Cocomail processes subscriber data only on the customer's documented instructions, as a processor under the DPA where it applies.

Subprocessors and service providers

We use the following vendors to run Cocomail. Subscriber data your account processes through them is covered by the DPA.

VendorPurposeProcessing location
ConvexApplication backend and databaseUnited States (AWS us-east-1, N. Virginia)
Amazon Web Services (SES/SNS)Email delivery; bounce and complaint eventsUnited States (us-east-1)
StripePayments and subscription billingUnited States (Stripe, LLC; affiliates and sub-processors may process in other jurisdictions)
ResendCocomail's own transactional email (password resets, notifications)United States (N. Virginia)
GoogleOptional “Sign in with Google”Global Google infrastructure
DataFastWebsite analytics (only with cookie consent)United States and other locations outside the EU (per DataFast DPA)
HostingerApplication hosting (VPS) and request handlingUnited States (Boston, Massachusetts)

Retention and deletion

  • Import and export CSV files (including rejected-rows reports) are automatically deleted 30 days after the import/export finishes.
  • Suppression records (bounces, complaints, unsubscribes) are kept for as long as needed to honor opt-outs and protect deliverability: that permanence is the point of a suppression list.
  • When you delete your account, access is disabled immediately and deletion of your data from our active systems begins immediately. An automated purge then runs without intentional delay, in continuous batches until every tenant-scoped record is removed from the live database (the product does not queue a retention hold on account deletion). Billing records are retained by Stripe and by us where tax and accounting law requires. Residual copies may remain in Convex platform backups for up to 14 days (Convex publishes daily backups kept for 7 days and weekly backups for 14 days); we do not store the application database or customer lists on the Hostinger VPS, so Hostinger does not retain customer-data backups.
  • Security audit records of administrative account access (see Security below) are an exception to account-deletion purge: they are kept for 12 months from the access and then deleted automatically. They contain only internal identifiers, the action, and timestamps: no account content.

Your rights

If you are in the EU/EEA or UK (GDPR/UK GDPR), you can request access, rectification, erasure, restriction of processing, data portability, and object to processing based on legitimate interest. You may also lodge a complaint with your supervisory authority. Where processing is based on consent (cookie analytics), you can withdraw it at any time via “Cookie settings”.

If you are a California resident (CCPA/CPRA), you have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of its sale or sharing (we do not sell or share personal information), to limit the use of sensitive personal information (we do not use it beyond providing the service), and to not be discriminated against for exercising these rights.

To exercise any right, email [email protected] from the address associated with your account (or with enough information for us to verify you). We respond within the timelines the applicable law sets (one month under GDPR, 45 days under CCPA, extendable where the law allows).

If you are a subscriber on a customer's list, the newsletter sender is the controller of your data: direct requests to them (every email includes an unsubscribe link that works immediately). We assist our customers in fulfilling these requests under the DPA.

Where we process data

Our own infrastructure stores and processes data in the United States: the application backend and database (Convex, AWS us-east-1, N. Virginia), email delivery (AWS SES/SNS, us-east-1), our transactional-email provider (Resend, N. Virginia) and our application hosting (Hostinger VPS, Boston, Massachusetts).

That said, we do not claim that all processing occurs exclusively in the United States: Panara Studio LLCis administered from India, so customer account data and, where support, security or operations require it, subscriber data may be accessed from India by authorized personnel; and some vendors (such as payment and sign-in providers) may process or access data from other locations, as noted in the table above. Where a customer's subscriber lists include people whose data is protected by EU or UK law, the transfer safeguards described in our DPA (Standard Contractual Clauses and the UK Addendum, where legally applicable) are available for execution on request.

Security

All traffic is encrypted in transit (TLS). Passwords are stored only as hashes. Access to production systems is limited to those who operate the service. Card data is handled entirely by Stripe.

When an operator accesses an account in support of that account (for example to reproduce a problem you reported), that administrative access is logged: we record which operator accessed which account, and when the access started and ended. These logs exist for support, security, accountability and the investigation of unauthorized access (where GDPR/UK GDPR applies, our legitimate interest in operating the service securely). They contain only internal identifiers and timestamps, never the content viewed.

Children

Cocomail is a paid business tool for adults. You must be 18 or older to create an account; the service is not directed to children, and we close the account and delete the account data of any account holder we discover to be under 18. Subscribers on a customer's list are a separate matter: the newsletter sender is the controller of that data, so age-related requests about a subscriber should be directed to the sender. We assist them under the DPA.

Changes

We will announce material changes to this policy by email or in-app notice before they take effect, and the “Last updated” date above always reflects the current revision.

Contact

Panara Studio LLC · 8 The Green, STE B, Dover, DE 19901 · [email protected]