Privacy Policy – Sidemail.io

This Privacy Policy describes how Avantis Innovations LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information when you visit or use the Sidemail.io service (“Sidemail”), including its website, application, APIs, and related services and features (collectively, the “Services”); create or use a Sidemail account (“Account”); purchase a subscription; contact us; or otherwise interact with us.

This Privacy Policy applies where the Company determines the purposes and means of processing personal information as a controller or business. It does not govern Customer Personal Data that we process solely on behalf of a Sidemail customer. That processing is addressed in the section titled Customer-controlled data and our Data Processing Agreement.

Information we collect

Depending on how you interact with the Services, we may collect the following categories of personal information:

  1. Account and contact information, such as your name, business email address, company, job title, Account identifiers, profile information and communication preferences.
  2. Billing and transaction information, such as billing contact details, billing address, subscription tier, transaction history, tax information, payment status, card brand and limited payment-card information made available by our payment providers. Payment providers process full payment credentials under their own terms and privacy policies.
  3. Service and usage information, such as projects, domains, enabled integrations, subscription usage, feature interactions, settings, API activity, timestamps and information about how you use and configure the Services.
  4. Device, network and log information, such as IP address, browser type, operating system, device information, referring page, pages viewed, access times, application events, error information and security-related activity.
  5. Communications and support information, such as messages, support requests, feedback, survey responses and other information you provide when communicating with us.
  6. Marketing and analytics information, such as cookie identifiers, website interactions, campaign engagement and marketing preferences, subject to applicable consent and opt-out requirements.
  7. Integration information, such as Account identifiers, configuration information and data made available when you connect a third-party service to Sidemail.
  8. Other information you choose to provide through forms, Account fields, support requests or other interactions with the Services.

Please do not provide sensitive or regulated personal information through Account, billing or support fields unless we specifically request it and have agreed to process it.

Sources of information

We may collect personal information:

  1. directly from you, including when you register, subscribe, configure the Services, contact us or submit information through the Services;
  2. automatically from your browser, device and use of the Services;
  3. from your organization, Account owner or another authorized Account user;
  4. from third-party services that you connect or direct us to use;
  5. from payment, analytics, security and other service providers; and
  6. from publicly available business sources where permitted by law.

How we use personal information

We may use personal information to:

  1. create, authenticate, administer and secure Accounts;
  2. provide, maintain, support and improve the Services;
  3. process subscriptions, payments, invoices, taxes, renewals, cancellations and related transactions;
  4. communicate about Accounts, transactions, support, security, policy changes and Service updates;
  5. personalize and configure the Services;
  6. monitor performance, diagnose errors, manage capacity and develop new or improved features;
  7. analyze website and Service usage;
  8. protect Sidemail, the Company, our customers, recipients and others against spam, abuse, fraud, security threats, unlawful activity and violations of our policies;
  9. enforce the Terms of Service, Anti-spam Policy and other agreements and policies;
  10. comply with legal obligations and respond to lawful requests, disputes and claims;
  11. maintain business, tax, accounting, compliance and corporate records;
  12. send marketing communications where permitted by law and consistent with your preferences; and
  13. create and use aggregated or de-identified information for analytics, security, benchmarking, capacity planning and improvement of the Services, provided that we do not use such information to identify you.

We may use automated systems to support security, spam and abuse prevention, deliverability, fraud detection and operation of the Services. We do not intend to make decisions about Account users based solely on automated processing that produce legal or similarly significant effects unless we provide any notice and safeguards required by applicable law.

Where European, United Kingdom or similar data protection law requires a legal basis, we rely on one or more of the following:

  1. Contract: processing necessary to enter into or perform our contract with you or your organization, including providing the Services, Account administration, billing and support.
  2. Legitimate interests: processing necessary for our legitimate interests or those of another person, including securing and improving the Services, preventing abuse, administering our business, communicating with business users and conducting proportionate analytics and marketing, except where those interests are overridden by your rights.
  3. Legal obligation: processing necessary to comply with tax, accounting, sanctions, law-enforcement, regulatory and other legal obligations.
  4. Consent: processing based on your consent, including certain cookies, analytics or marketing activities where consent is required. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
  5. Legal claims and vital interests: processing necessary to establish, exercise or defend legal claims or, in limited circumstances, protect a person’s vital interests.

The legal basis may vary depending on the context and jurisdiction.

Customer-controlled data

Sidemail customers may submit, import, transmit, store or otherwise process contact records, recipient information, email content, attachments, message events, inbound email and other personal information through the Services (“Customer Personal Data”).

For Customer Personal Data:

  1. the customer generally determines why and how the data is processed and acts as controller or business;
  2. the Company generally acts as the customer’s processor, service provider or contractor;
  3. we process the data according to the customer’s instructions, the Data Processing Agreement and the applicable Services agreement; and
  4. the customer is responsible for its privacy notices, legal bases, recipient rights and compliance with applicable privacy, electronic-communications and marketing laws.

If you received an email from a Sidemail customer or have a question about personal information that a customer submitted to the Services, contact that customer first. We may direct your request to the customer or provide reasonable assistance as required by law and the Data Processing Agreement.

This Privacy Policy applies to our independent processing of Account, billing, support, security, abuse-prevention and Service-usage information, even where that information relates to a customer or its users.

Cookies and analytics

We and our service providers use cookies, local storage, pixels and similar technologies to operate, secure and understand use of the website and Services.

Necessary technologies

Necessary technologies support functions such as Account authentication, security, fraud and abuse prevention, load balancing, session management and storage of privacy preferences. These technologies are used because they are required to provide or secure the website and Services.

Analytics technologies

We use Google Analytics to understand how visitors use our website and to improve its content, performance and usability. Google Analytics may process information such as cookie or device identifiers, IP address, approximate location, browser and device information, referring pages, pages viewed, interactions and visit timestamps.

Where required by law, Google Analytics and other non-essential technologies will not be enabled until you provide consent. You may accept or reject non-essential technologies through the cookie banner or settings made available on the website, and you may change or withdraw your choice later through those settings.

Google processes information under its own terms and privacy practices. Google Analytics cookies and similar identifiers remain for the period configured in our Google Analytics and consent-management settings, unless deleted earlier through your browser or privacy settings.

We do not use cookies to collect full payment-card details or the contents of Customer emails.

Your choices

You can control cookies through:

  1. the cookie banner or privacy settings available on our website;
  2. your browser settings, which may allow you to block or delete cookies; and
  3. controls offered by Google and other applicable providers.

Blocking necessary technologies may prevent parts of the website or Services from functioning correctly.

Browser “Do Not Track” settings are not interpreted consistently across the industry. Where applicable law requires us to recognize a legally valid opt-out preference signal, we will process that signal as required.

Payments

Payments may be processed by Stripe and supported payment-wallet providers such as Google Pay. These providers collect and process payment information under their own terms and privacy policies. We receive transaction and limited payment information made available by the provider to administer subscriptions, accounting, fraud prevention, refunds and support.

We may disclose information reasonably necessary to payment providers, banks, tax providers and financial advisers to complete transactions and meet legal obligations.

Integrations and third-party services

The Services may allow you to connect third-party services, including payment, customer-management and application integrations. When you enable an integration, you direct us to exchange information with that third party as required for the integration.

Third-party services are governed by their own terms and privacy practices. We do not control and are not responsible for how a third party processes information once it receives that information independently from us.

How we disclose information

We may disclose personal information to:

  1. Service providers and contractors that support hosting, infrastructure, storage, payment processing, communications, analytics, customer support, security, fraud prevention and other business operations.
  2. Your organization and Account users, where necessary to administer an organizational Account, provide the Services or respond to an authorized request.
  3. Third-party services you enable, when you connect or direct us to interact with an integration.
  4. Professional advisers, such as lawyers, accountants, auditors, insurers and financial advisers.
  5. Authorities and other parties for legal or safety reasons, where we reasonably believe disclosure is necessary to comply with law or legal process, protect rights and safety, investigate fraud or abuse, enforce our agreements, or defend legal claims.
  6. Parties to a business transaction, including in connection with a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, subject to appropriate confidentiality protections where applicable.
  7. Other parties with your direction or consent.

We may also disclose aggregated or de-identified information that does not reasonably identify an individual.

We do not disclose Customer Personal Data for our own cross-context behavioral advertising or independent marketing purposes.

Sale, sharing and targeted advertising

We do not sell personal information for monetary consideration.

Certain privacy laws define “sale,” “sharing” or “targeted advertising” broadly enough to include some disclosures through analytics, advertising or similar website technologies. Where our use of such technologies is subject to those laws, we will provide the notices and choices required by applicable law, including through our cookie banner or privacy settings.

We do not knowingly sell or share personal information of individuals under 16 years of age.

International data transfers

The Company is located in the United States, and we and our service providers may process personal information in the United States and other countries. Those countries may have privacy laws different from the laws where you live.

Where required, we use legally recognized safeguards for international transfers, which may include adequacy decisions, standard contractual clauses, the United Kingdom international-transfer addendum, contractual protections and other mechanisms permitted by applicable law.

International transfers of Customer Personal Data are addressed in the Data Processing Agreement.

Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, administer Accounts, maintain security, prevent abuse, comply with legal and accounting obligations, resolve disputes and enforce agreements.

Retention depends on factors including:

  1. the nature and sensitivity of the information;
  2. how long an Account or business relationship remains active;
  3. the period needed to provide the applicable feature or respond to a request;
  4. legal, tax, accounting and regulatory requirements;
  5. security, fraud, abuse-prevention and suppression needs; and
  6. applicable limitation periods and anticipated disputes.

When information is no longer reasonably required, we may delete, anonymize or restrict it. Information may remain in backups until overwritten through ordinary backup cycles. We may retain limited records longer where necessary to prevent fraud, enforce opt-outs and suppression lists, comply with law or establish and defend legal claims.

Retention and deletion of Customer Personal Data are governed by the Data Processing Agreement and the customer’s instructions.

Security

We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration and disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your Account credentials and for promptly notifying us if you suspect unauthorized access to your Account.

Your privacy rights

Depending on where you live and applicable law, you may have rights to:

  1. know whether and how we process your personal information;
  2. request access to or a copy of your personal information;
  3. request correction of inaccurate personal information;
  4. request deletion of personal information;
  5. request restriction of or object to certain processing;
  6. receive certain personal information in a portable format;
  7. withdraw consent where processing is based on consent;
  8. opt out of sale, sharing, targeted advertising or certain profiling;
  9. appeal our refusal to act on a request, where applicable; and
  10. lodge a complaint with a competent privacy or data protection authority.

These rights are subject to legal conditions and exceptions. For example, we may retain information required for legal compliance, security, fraud prevention, billing, suppression or legal claims.

To exercise a right concerning information controlled directly by the Company, contact us at [email protected]. You may also update certain Account information through the Services. We may request information reasonably necessary to verify your identity, authority and jurisdiction. Authorized agents may submit requests where permitted by law, but we may require evidence of authorization and direct identity verification.

We will not discriminate against you for exercising an applicable privacy right. If applicable law provides a right to appeal, you may appeal by replying to our decision or contacting [email protected] and stating that you are submitting a privacy appeal.

For Customer Personal Data controlled by a Sidemail customer, submit your request directly to that customer.

Additional United States disclosures

For purposes of United States state privacy laws, the categories of personal information we may have collected during the preceding 12 months are described in Information we collect. They generally include:

  1. identifiers and contact information;
  2. customer records and transaction information;
  3. commercial and subscription information;
  4. internet, device and Service-usage activity;
  5. approximate location inferred from IP address;
  6. professional or employment-related information;
  7. communications and support content; and
  8. inferences drawn from usage information for security, analytics and Service improvement.

We collect and use these categories for the business and commercial purposes described in How we use personal information. We may disclose them to the categories of recipients described in How we disclose information.

We do not use or disclose sensitive personal information for the purpose of inferring characteristics about an individual. We do not offer financial incentives or price differences in exchange for personal information unless separately disclosed as required by law.

Nothing in this section admits that a particular state privacy law applies to the Company or to a specific interaction.

Marketing communications

You may opt out of our marketing emails by using the unsubscribe link in the message or contacting us. You may still receive transactional, security, billing, support and Account-related communications.

Sidemail customers are independently responsible for marketing messages they send through the Services. Requests concerning a customer’s message should generally be directed to that customer or handled using the unsubscribe mechanism in the message.

Children

The Services are intended for business and professional users and are not directed to children. You must be at least 18 years old to create or use an Account.

We do not knowingly collect personal information directly from children under 13 through our website or Account registration. If we learn that we collected such information contrary to this policy, we will take reasonable steps to delete it.

Customers may not use the Services to unlawfully collect or process children’s personal information.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Where required by law, we will provide additional notice of material changes.

Contact us

Avantis Innovations LLC is the controller or business responsible for the personal information covered by this Privacy Policy.

Questions, privacy requests and complaints may be sent to:

[email protected]

Avantis Innovations LLC
75 East 3rd Street
Sheridan, WY 82801
United States

You may also lodge a complaint with the privacy or data protection authority responsible for your location. We encourage you to contact us first so we can try to address the issue.

This Privacy Policy is effective as of July 25, 2026.