Privacy Policy
How Templ8.email collects, uses, and protects your personal data.
Last updated: February 21, 2026
Privacy at a Glance
1. Controller & Contact
Templ8.email (“Templ8”, “we”, “us”, “our”) is the data controller responsible for the processing of your personal data as described in this Privacy Policy.
2. What Data We Collect
a) Information you provide directly
- Account data: name, email address, profile picture, authentication identifiers
- Billing data: transaction IDs, payment method metadata (we do not store full card numbers)
- Support communications: messages, requests, and feedback you send to us
- Content: email templates and designs you create using our Editor
b) Information collected automatically
- Usage data: pages visited, features used, actions taken, timestamps
- Device data: browser type and version, operating system, screen resolution
- Network data: IP address, approximate geographic location (country/region level)
- Referral data: how you arrived at our Service (referring URL, campaign parameters)
c) Information from third parties
- Authentication providers: if you sign in via Google or other OAuth providers, we receive your name, email, and profile picture as authorized by you
- Payment processors: transaction confirmation and limited billing metadata
3. How We Use Your Data
We process personal data for the following purposes:
- Providing the Service — account management, template creation, storage, and export functionality
- Billing and payments — processing subscriptions, invoicing, and refunds
- Security and fraud prevention — monitoring for suspicious activity, enforcing our Terms of Use
- Service improvement — analyzing usage patterns to improve features, performance, and user experience
- Customer support — responding to your inquiries and resolving issues
- Communications — sending service-related notifications (e.g., password resets, billing alerts) and, with your consent, marketing emails about new features and offers
- Legal compliance — meeting our obligations under applicable law, such as tax reporting and responding to lawful requests
4. Legal Bases (GDPR)
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases for processing your personal data:
Performance of a contract (Art. 6(1)(b))
Processing necessary to provide you with the Service, manage your Account, and fulfill our contractual obligations.
Legitimate interests (Art. 6(1)(f))
Processing for security, fraud prevention, service improvement, and analytics, where our interests do not override your rights.
Legal obligation (Art. 6(1)(c))
Processing required to comply with tax, accounting, and other legal requirements.
Consent (Art. 6(1)(a))
Marketing communications and non-essential cookies. You may withdraw consent at any time via unsubscribe links or by contacting us.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where some of our service providers are located.
Where such transfers occur, we ensure an adequate level of protection through appropriate safeguards, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements with all processors
8. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy:
- Account data: retained for the duration of your Account and deleted or anonymized within 30 days of Account closure, unless longer retention is required by law
- Billing data: retained as required by applicable tax and accounting laws (typically 7 years in the Netherlands)
- Usage and analytics data: retained in aggregated/anonymized form for service improvement; identifiable logs are deleted after 90 days
- Support communications: retained for the duration of your Account plus 12 months
When data is no longer needed, we securely delete it or render it anonymous so that it can no longer be associated with you.
9. Your Rights (GDPR)
Under the GDPR, if you are located in the European Economic Area, you have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate or incomplete data.
Erasure
Request deletion of your data ("right to be forgotten").
Restriction
Request that we limit processing of your data.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests or direct marketing.
Withdraw consent
Withdraw consent at any time where processing is based on consent.
Complaint
Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@templ8.email. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
10. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to know: You may request that we disclose what personal information we have collected, used, disclosed, and sold about you in the preceding 12 months.
- Right to delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to opt-out of sale: We do not sell personal information. If this practice changes, we will provide a “Do Not Sell My Personal Information” link.
- Non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise these rights, contact us at privacy@templ8.email. We will verify your identity and respond within 45 days.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at privacy@templ8.email, and we will take steps to delete such information promptly.
12. Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest
- Access controls and authentication for internal systems
- Regular security assessments and monitoring
- Employee and contractor confidentiality obligations
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised version on this page with an updated “Last updated” date.
For material changes, we will provide additional notice (e.g., via email or an in-app notification). Your continued use of the Service after any changes constitutes acceptance of the updated Policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices:
- Privacy inquiries: privacy@templ8.email
- General support: support@templ8.email
- Location: The Netherlands
Your privacy matters to us. If you have any questions, don't hesitate to reach out.