Privacy Policy
Last updated: [EFFECTIVE DATE]
BetterSend (“BetterSend,” “we,” “us”) provides an email campaign platform for small organizations. This policy explains what data we collect, how we use it, and — because BetterSend integrates with Google APIs — specifically how we handle any data accessed through your Google account.
1. What BetterSend Does
BetterSend lets organizations import or upload contact lists, build email templates, and send campaigns either from their own verified email domain, or, optionally, from their own connected Gmail account.
2. Information We Collect
- Account information: name, email address, and organization details you provide when you sign up.
- Contact data: the recipient lists you upload or import — names, email addresses, and any custom fields you add. This is your data; we process it on your behalf to run your campaigns.
- Campaign content: the templates, subject lines, and message bodies you create.
- Send and event logs: records of what was sent, to whom, and delivery-related events (sent, delivered, bounced, opened, clicked, complained, unsubscribed) so you can see campaign performance and so we can maintain suppression lists.
- Authentication data: session tokens and, if you connect Gmail, an OAuth refresh token (see Section 4).
- Cookies: used for login sessions and basic app functionality — not for advertising or cross-site tracking.
3. How We Use Information
We use the information above to operate the platform: rendering your templates, sending your campaigns, tracking delivery events, enforcing unsubscribe/suppression rules, and billing. We do not sell your data, your contacts' data, or your campaign content. We do not use your contact lists or campaign content for advertising, and we do not share your data with third parties except the service providers listed in Section 5, who process it only to help us run the platform.
4. Google User Data
If you choose to connect a Gmail account so campaigns can send “as you,” BetterSend requests exactly one Google permission: gmail.send (“send email on your behalf”). Specifically:
- We use this permission only to send the campaign messages you compose and explicitly send within BetterSend, through your own Gmail account.
- We do not read your inbox, sent mail, drafts, contacts, labels, filters, or account settings. We never request gmail.readonly, gmail.modify, gmail.compose, or any Gmail scope beyond send.
- No data obtained through this connection is used for advertising, and it is never used to train AI/ML models.
- No human at BetterSend reads the content of messages sent through your Gmail connection, except as strictly necessary for security, abuse investigation, or a support request you initiate.
- OAuth refresh tokens are envelope-encrypted at rest; the decryption key is stored separately from the database. Access tokens are short-lived and are never stored.
- You can disconnect your Gmail account at any time from BetterSend account settings, or directly at myaccount.google.com/permissions. Disconnecting immediately revokes our access.
BetterSend's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Subprocessors
We share data with the following service providers only to operate the platform:
| Provider | Purpose |
|---|---|
| Neon | Postgres database hosting (account data, contact data, send/event logs) |
| Resend | Email sending infrastructure for domain-based campaigns |
| Vercel / Cloudflare | Application hosting |
| Trigger.dev | Background job processing for campaign sends |
| OAuth authentication and, if you connect it, sending via your Gmail account | |
| Stripe | Billing and payment processing |
6. Data Retention
We retain account data, contact data, and send/event logs for as long as your account is active. If you delete your account, we delete your account data, contact data, and campaign content within [30 days], except where we're required to retain records for legal, tax, or fraud-prevention purposes, or aggregated/de-identified data that can no longer be tied to you.
7. Your Rights & Deletion Requests
You can request access to, correction of, or deletion of your account data and contact data at any time by emailing privacy@bettersend.ai. We'll respond and complete verified deletion requests within a reasonable timeframe, consistent with applicable law.
8. Your Responsibilities as a Sender
BetterSend is a tool for sending email to recipients you have a legitimate basis to contact. You're responsible for complying with applicable anti-spam law — including the U.S. CAN-SPAM Act and Canada's CASL — for your own campaigns: only emailing people who've consented, honoring unsubscribe requests promptly, and including accurate sender identification. BetterSend enforces a mandatory unsubscribe link and physical mailing address on every campaign, and automatically suppresses unsubscribed and bounced addresses from future sends — but the underlying legal responsibility for your list and your sends is yours.
9. Security
Encryption in transit (TLS) and at rest, with OAuth tokens specifically envelope-encrypted as described in Section 4. Access to production data is restricted to what's necessary to operate the platform.
10. Children's Privacy
BetterSend is not directed to children under 13, and we do not knowingly collect data from them.
11. Changes
We'll update this page if practices change and update the date above; material changes are communicated to account holders.
12. Contact
privacy@bettersend.ai. BetterSend, [PHYSICAL MAILING ADDRESS].