Legal

Privacy Policy

How Templ8.email collects, uses, and protects your personal data.

Last updated: February 21, 2026

Privacy at a Glance

We do not sell your data
GDPR & CCPA compliant
Cookie-free analytics (Umami)
You can delete your data anytime

1. Controller & Contact

Templ8.email (“Templ8”, “we”, “us”, “our”) is the data controller responsible for the processing of your personal data as described in this Privacy Policy.

Contact: privacy@templ8.email

General support: support@templ8.email

Location: The Netherlands

2. What Data We Collect

a) Information you provide directly

  • Account data: name, email address, profile picture, authentication identifiers
  • Billing data: transaction IDs, payment method metadata (we do not store full card numbers)
  • Support communications: messages, requests, and feedback you send to us
  • Content: email templates and designs you create using our Editor

b) Information collected automatically

  • Usage data: pages visited, features used, actions taken, timestamps
  • Device data: browser type and version, operating system, screen resolution
  • Network data: IP address, approximate geographic location (country/region level)
  • Referral data: how you arrived at our Service (referring URL, campaign parameters)

c) Information from third parties

  • Authentication providers: if you sign in via Google or other OAuth providers, we receive your name, email, and profile picture as authorized by you
  • Payment processors: transaction confirmation and limited billing metadata

3. How We Use Your Data

We process personal data for the following purposes:

  • Providing the Service — account management, template creation, storage, and export functionality
  • Billing and payments — processing subscriptions, invoicing, and refunds
  • Security and fraud prevention — monitoring for suspicious activity, enforcing our Terms of Use
  • Service improvement — analyzing usage patterns to improve features, performance, and user experience
  • Customer support — responding to your inquiries and resolving issues
  • Communications — sending service-related notifications (e.g., password resets, billing alerts) and, with your consent, marketing emails about new features and offers
  • Legal compliance — meeting our obligations under applicable law, such as tax reporting and responding to lawful requests

5. Cookies & Tracking Technologies

We use the following types of cookies and similar technologies:

TypePurposeConsent required
EssentialAuthentication, security, core functionalityNo (strictly necessary)
AnalyticsUsage statistics, performance monitoring (Umami — cookie-free, privacy-friendly)No (no personal data stored)
FunctionalPreferences, language, UI settingsNo (strictly necessary)
MarketingAdvertising measurement, remarketing (if enabled)Yes

Our primary analytics tool (Umami) is privacy-friendly and does not use cookies or collect personally identifiable information. Where we use cookie-based third-party analytics or marketing tools, we will request your consent before setting those cookies.

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Service.

6. Data Sharing & Processors

We do not sell your personal data. We share data only as described below:

  • Service providers / processors: We use trusted third-party providers for hosting (Google Cloud), authentication (Firebase), payment processing (Stripe), analytics (Umami, self-hosted), error tracking (Sentry), and customer support. These processors act only on our instructions under data processing agreements.
  • Legal requirements: We may disclose personal data if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity, subject to the same privacy commitments.
  • With your consent: We may share data for purposes not listed here if we obtain your explicit consent.

7. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where some of our service providers are located.

Where such transfers occur, we ensure an adequate level of protection through appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Data Processing Agreements with all processors

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

  • Account data: retained for the duration of your Account and deleted or anonymized within 30 days of Account closure, unless longer retention is required by law
  • Billing data: retained as required by applicable tax and accounting laws (typically 7 years in the Netherlands)
  • Usage and analytics data: retained in aggregated/anonymized form for service improvement; identifiable logs are deleted after 90 days
  • Support communications: retained for the duration of your Account plus 12 months

When data is no longer needed, we securely delete it or render it anonymous so that it can no longer be associated with you.

9. Your Rights (GDPR)

Under the GDPR, if you are located in the European Economic Area, you have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate or incomplete data.

Erasure

Request deletion of your data ("right to be forgotten").

Restriction

Request that we limit processing of your data.

Portability

Receive your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests or direct marketing.

Withdraw consent

Withdraw consent at any time where processing is based on consent.

Complaint

Lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at privacy@templ8.email. We will respond within 30 days. We may need to verify your identity before fulfilling your request.

You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

10. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know: You may request that we disclose what personal information we have collected, used, disclosed, and sold about you in the preceding 12 months.
  • Right to delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
  • Right to opt-out of sale: We do not sell personal information. If this practice changes, we will provide a “Do Not Sell My Personal Information” link.
  • Non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise these rights, contact us at privacy@templ8.email. We will verify your identity and respond within 45 days.

11. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at privacy@templ8.email, and we will take steps to delete such information promptly.

12. Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS)
  • Encryption of sensitive data at rest
  • Access controls and authentication for internal systems
  • Regular security assessments and monitoring
  • Employee and contractor confidentiality obligations

While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised version on this page with an updated “Last updated” date.

For material changes, we will provide additional notice (e.g., via email or an in-app notification). Your continued use of the Service after any changes constitutes acceptance of the updated Policy.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices:

Your privacy matters to us. If you have any questions, don't hesitate to reach out.