Last updated: March 2026
We collect the following categories of personal data when you use ZapMailer Pro:
We use the data we collect to:
We do not use your data or your subscribers' data for advertising or sell it to third parties.
All ZapMailer Pro application data — including your account details and subscriber records — is stored on Hetzner Cloud servers located in Helsinki, Finland (EU).
Data is encrypted at rest. Connections to our servers are encrypted in transit using TLS. Hetzner is ISO 27001 certified and compliant with GDPR data processing requirements.
As a UK-based business, we comply with both UK GDPR (as retained by the UK Data Protection Act 2018) and EU GDPR for our EU-based customers. Storing data in Finland (EU) ensures compliant data transfer for EU customers.
ZapMailer Pro uses Resend (resend.com) as its email delivery infrastructure. Your Resend API key is stored encrypted using AES-256 encryption at rest in our database.
Your API key is used solely and exclusively to send emails on your instruction via Resend's delivery infrastructure. It is never shared with any third party or used without your explicit instruction to send emails.
You may revoke or rotate your Resend API key at any time via the Settings page. We recommend using a domain-scoped API key with the minimum required sending permissions.
ZapMailer Pro uses the following third-party services as part of its operation:
We only share data with these parties to the extent necessary for them to provide their services to us.
Under the UK GDPR and EU GDPR, you have the following rights regarding your personal data. To exercise any right, contact us at privacy@zapmailerpro.com.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been processed unlawfully.
ZapMailer Pro uses session cookies only — small files placed on your device solely to maintain your authenticated session and remember your preferences within the app.
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies that profile your behaviour across other websites. No cookie consent banner is displayed because we only use strictly necessary session cookies.
We retain your account data for as long as your account is active, and for a period of up to 90 days after account closure for backup and legal compliance purposes.
Upon written request to privacy@zapmailerpro.com, your account data will be permanently deleted within 30 days of your account closure.
Subscriber data you have imported or collected belongs to you. Upon account deletion it will be removed from our systems within the same 30-day window unless a legal hold applies.
For any privacy-related questions, requests to exercise your data rights, or concerns about this policy, please contact:
Data Controller: Bhupinder Sahota, ZapMailer Pro
Email: privacy@zapmailerpro.com
Jurisdiction: England and Wales, United Kingdom
We aim to respond to all privacy requests within 30 days.