Privacy policy

Last updated: 20 August 2026

WarmEnvelopes is operated by DataOps, s.r.o., registered in the Czech Republic, which is the data controller for the personal data described here.

1. What we store

  • Account data: your name, email address, and profile picture from Google sign-in, plus a session cookie.
  • Configuration data: the domains you add, the Resend API keys you paste, your ramp settings, and the recipient inbox addresses you list.
  • Sending logs: for every warm-up email, the sender address, recipient, template used, timestamp, delivery status, and any error message.
  • Billing data: your plan and Stripe customer and subscription identifiers. Card details are handled by Stripe and never touch our servers.

2. What we don't do

  • No advertising trackers, and no analytics cookies unless you accept them.
  • We do not sell or share your data for advertising.
  • We do not read mail in your inboxes — the service only sends, via your Resend account.

3. Cookies

We set one strictly necessary cookie: an HttpOnly session cookie after you sign in (expires after 7 days). Google Analytics cookies are set only if you accept them in the consent banner — if you decline, nothing is ever requested from Google. Your choice is kept in your browser's local storage so we only ask once.

4. Processors

Your data is processed by these providers on our behalf:

  • Vercel (hosting, USA/EU) — serves the application.
  • Neon (database, EU region) — stores the data listed above.
  • Stripe (payments) — processes subscriptions and payment details.
  • Google (authentication) — provides sign-in.
  • Google Analytics (site analytics) — only if you accept analytics cookies.

Warm-up emails are sent through Resend under your Resend account and Resend's own terms — for that sending, you are Resend's customer, not us.

5. Retention

Account and configuration data is kept while your account exists. Deleting a domain deletes its recipients and sending history. If you want your whole account and its data deleted, contact us and we will do it.

6. Your rights

Under the GDPR you can request access to, correction of, or deletion of your personal data, restriction or objection to its processing, and a portable copy. You can also complain to a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (ÚOOÚ).

7. Contact

DataOps, s.r.o. — reachable via wearedataops.cz.