Account data
Google sign-in requests only OpenID Connect identity claims: your verified email address and basic profile. SendArq does not request Gmail, contacts, directory, offline, or signature-management access.
Sessions are server-side and revocable. The marketing site does not receive an application session cookie.
Signature and media data
We store the business identity, contact fields, layout choices, and images you deliberately add to a signature. Static PNG and JPEG uploads are validated and reconstructed before delivery. Published media uses immutable HTTPS URLs so existing emails do not silently change.
Privacy-first click analytics
SendArq records eligible HTTPS link clicks from published signatures by default and classifies likely human, automation, and unknown traffic for aggregate reporting. Email and telephone links remain direct.
Recipient email or name, message subject or body, attachments, mailbox content, thread identity, IP address, geography, device profile, referrer, or advertising identifier.
Retention
Accepted raw click events are retained for no more than 30 days. Daily aggregate rollups may be retained for up to 24 months. Account or workspace deletion enters a seven-calendar-day recovery period before final deletion work begins. Security and audit evidence is minimized for its operational purpose.
Your controls
Owners can export supported workspace data, revoke sessions, and request account or workspace deletion from the application. Deletion of object-bearing data completes only after the required active storage and cache reconciliation; disaster-recovery history is not a substitute for active service data. It cannot recall a signature, image, or copied HTML already stored in a recipient's mailbox, email-client cache, or downloaded file.
Privacy contact
For a privacy request, email privacy@sendarq.com. Do not include passwords, session cookies, OAuth tokens, recipient data, or confidential message content.
See Subprocessors for the limited providers used to operate the hosted service.