Draft template - replace before launch. This document is a structural starting point, not legal advice. Confirm the sub-processor list below matches your real vendors, fill in every bracketed value, and have a qualified attorney review it for your business and jurisdiction.

Privacy Policy

Last updated: [EFFECTIVE DATE]

1. Overview

[COMPANY LEGAL NAME] ("CommuniQueue", "we", "us") operates a templated messaging platform. This policy explains what personal information we collect, how we use it, and the choices you have. It covers data we handle as a controller (your account information) and data we process as a processor on your behalf (message content and recipient data you send through the service).

2. Information We Collect

  • Account data: name, email, organization, and authentication identifiers.
  • Billing data: subscription and payment metadata (card data is handled by our payment processor, not stored by us).
  • Usage data: logs, API usage, and delivery events (delivered, bounced, complained). Engagement events (opens, clicks) are processed by our email delivery provider (Twilio SendGrid) and stored by CommuniQueue; CommuniQueue no longer operates its own tracking pixel or redirect links.
  • Customer message data: template content and recipient details you submit, processed to deliver your messages.
  • Support data: support-case subjects and messages, workspace and account identifiers, case status, entitlement snapshots, and support-agent actions.

3. How We Use Information

We use information to provide and secure the service, process payments, deliver your messages, provide support, prevent abuse, comply with legal obligations, and improve the platform. We do not sell personal information.

4. Legal Bases (GDPR/UK GDPR)

Where applicable, we rely on the following legal bases: performance of a contract, legitimate interests (securing and improving the service), consent (where required), and compliance with legal obligations. For recipient data you send, you are the controller and are responsible for your lawful basis.

5. Sub-processors

We use trusted service providers to operate the platform. Confirm and keep this list current for your deployment:

  • Stripe - payment processing.
  • Auth0 - authentication and identity.
  • SendGrid and any customer-configured email providers (Postmark, Mailgun, Amazon SES, etc.) - email delivery.
  • Amazon Web Services - application hosting.
  • DigitalOcean - managed database hosting.
  • [ADD/REMOVE any other vendors you actually use - e.g. analytics, error monitoring.]

6. Data Retention

We retain account data for as long as your account is active and as needed to meet legal obligations. Delivery event and message data are retained according to the retention window configured for your workspace, after which they are purged or aggregated. Support cases and their messages are retained according to the approved support retention policy, subject to legal, security, fraud, dispute, and preservation obligations. Verified privacy requests or account deletion may require removal where no continuing legal basis applies. Complete this before launch: [SUPPORT RETENTION PERIOD AND OTHER RETENTION PERIODS].

7. Security

We use administrative, technical, and organizational safeguards to protect personal information, including encryption of sensitive credentials at rest and access controls. No system is perfectly secure; we cannot guarantee absolute security.

8. International Transfers

We and our sub-processors may process data in countries other than yours. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at [PRIVACY CONTACT EMAIL]. For recipient data you sent through the service, direct requests to the customer that sent the message.

10. Cookies

The application uses strictly necessary cookies for authentication and session management. Describe any additional cookies or analytics you use: [COOKIE DETAILS].

11. Children

The service is not directed to children and is not intended for use by anyone under the age required by applicable law.

12. Changes & Contact

We may update this policy and will post the updated version with a new effective date. Questions or requests? Contact us at [PRIVACY CONTACT EMAIL]. Customers requiring a Data Processing Addendum (DPA) may request one at the same address.