PostBrix is a cloud-based email design and automation workspace that helps users create, store, preview, export, and manage responsive email templates and related digital assets. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the PostBrix website, application, support channels, and paid services.
- ✓Account information: name, email address, organization name, user identifiers, authentication information, and account preferences.
- ✓Workspace content: email templates, MJML/HTML, images, uploaded assets, brand settings, variables, preview links, test-send recipients, and project metadata that you create or upload.
- ✓Billing information: plan details, invoices, transaction status, billing name, billing email, GST or tax details where provided, and limited payment metadata received from our payment processors.
- ✓Usage and device information: IP address, browser, operating system, log events, feature usage, export counts, AI generation counts, error reports, and security audit logs.
- ✓Support information: messages, attachments, and contact details you share when requesting help, reporting bugs, or asking billing questions.
Under the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act (DPDP), we process your data under the following lawful bases: Contractual Necessity (to provide our service), Legitimate Interests (to secure and improve the platform), Consent (for optional marketing/cookies), and Legal Obligation (for tax and financial compliance).
- ✓To create and manage user accounts, workspaces, templates, exports, assets, and collaboration features.
- ✓To process subscriptions, renewals, cancellations, refunds, invoices, taxes, and payment disputes in a secure manner.
- ✓To enforce plan limits, prevent fraud, investigate misuse, secure the service, and maintain immutable audit trails for compliance.
- ✓To provide customer support, send service notices, respond to requests, and improve product reliability.
- ✓To analyze aggregated usage trends and improve the performance, usability, and security of PostBrix.
PostBrix utilizes secure, PCI-compliant payment gateways. For users in India, Razorpay handles transactions. For international users, Paddle acts as the Merchant of Record. Sensitive payment details (card numbers, CVV, passwords) are collected and processed directly by these providers, not by PostBrix. We receive limited transaction information such as payment IDs, order IDs, status, method, amount, and timestamp to activate plans and manage your subscription.
We share your data with trusted third-party service providers (subprocessors) to operate our platform securely and efficiently. We maintain written agreements with all subprocessors to ensure they meet our strict security, GDPR, and DPDP compliance standards.
- ✓A full, up-to-date list of our infrastructure, authentication, payment, and AI subprocessors is available on our Subprocessors page.
- ✓With law enforcement or government authorities only where disclosure is strictly required by applicable law, accompanied by a valid legal request.
- ✓Account and workspace data is retained while your account is active or as needed to provide the service securely.
- ✓Deleted projects and assets may remain in encrypted, immutable backups for disaster recovery for up to 60 days before automatic permanent removal.
- ✓Invoices, tax records, transaction logs, and refund records are retained for up to 7 years to comply with statutory accounting, tax, fraud prevention, and dispute-resolution requirements.
- ✓Security logs and abuse reports are retained for up to 12 months to protect PostBrix against coordinated threats.
We use HTTPS, access controls, least-privilege permissions, encrypted service connections where supported, monitoring, and operational safeguards to protect data. No internet service can guarantee absolute security, so users should use strong account credentials and promptly report suspected unauthorized access.
PostBrix operates globally. Data may be transferred to, and processed in, countries other than the country in which you are resident, primarily the United States or the European Union. When we transfer personal data subject to GDPR or the DPDP Act to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) and robust security measures to ensure your data remains protected.
Depending on your location (e.g., the EEA, UK, or India), you have specific rights regarding your personal data as a Data Subject or Data Principal:
- ✓Right to Access & Portability: You may request a copy of your personal data in a structured, machine-readable format.
- ✓Right to Rectification: You may correct inaccurate or incomplete data directly in your account settings.
- ✓Right to Erasure (Right to be Forgotten): You may request the deletion of your account and personal data (subject to legal retention exceptions).
- ✓Right to Withdraw Consent / Nominate: You may withdraw consent for optional processing or nominate a representative in the event of incapacity (under DPDP).
- ✓Right to Object / Restrict: You may object to certain processing activities, including marketing communications.
For enterprise customers and organizations subject to GDPR or the DPDP Act that require a formal Data Processing Addendum (DPA) to govern the relationship between you (the Controller) and PostBrix (the Processor), please email privacy@postbrix.com to execute our standard DPA.
PostBrix is a business-to-business (B2B) service and is not directed at or intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information immediately.
For privacy questions, data requests, or to contact our Grievance Officer (as required under the India DPDP Act), contact us at privacy@postbrix.com, or write to Madhya Pradesh, India.
Need legal clarification or have questions?
Our legal and privacy team is available to assist you with compliance inquiries, Data Processing Addendums (DPA), or billing details.