1.1 SMTPCart is a managed email delivery infrastructure service operated by BEINCART LLC, a limited liability company organised under the laws of the State of Wyoming, United States. 1.2 References to "we", "us" and "our" mean BEINCART LLC of 30 N Gould St Ste N Sheridan, WY, 82801. References to "you" mean the person whose personal information we hold — whether you are a customer, a visitor to our website, or a recipient of email sent through our infrastructure. 1.3 This Policy applies to smtpcart.com, to the SMTPCart platform, and to all related services. It does not apply to the websites or services of our customers, whose own privacy policies govern their handling of your data.
2.1 We have written this Policy to be read, not to be survived. Where a legal term is unavoidable we explain it in plain language the first time it appears.
2.2 If you received an email sent through SMTPCart infrastructure and want to know why, section 4 is the relevant part, and section 14 explains how to get an answer.
3.1 Data protection law distinguishes between the party that decides why personal data is used (the "controller") and the party that handles it on that party's instructions (the "processor"). SMTPCart is both, depending on whose data is involved.
| Our role | Whose data | Examples | Who decides how it is used |
| Controller | Our customers and website visitors | Account holder name, billing details, support correspondence, site analytics | We do |
| Processor | Our customers' email recipients | Recipient addresses, message content in transit, delivery and engagement events | Our customer does — they are the controller |
3.2 This distinction has a practical consequence. We decide how we use our own customers' data and answer directly for it. We do not decide who our customers email, what they send, or where they obtained an address — those are their decisions, and they answer for them as controller.
4.1 We transmit email on behalf of our customers. We do not select recipients, compile lists, or write content, and we have no relationship with you unless our customer tells us of one.
4.2 If you want to stop receiving a particular sender's mail, the fastest route is the unsubscribe link in the message, which our Acceptable Use Policy requires our customers to honour within two days. If you want to know what data a sender holds about you, or to have it erased, the request must go to that sender — they are the controller.
4.3 We will help. Write to us at [email protected] and we will forward your request to the customer concerned and, where we are able, tell you who they are. Our contractual arrangements with customers, including the data processing addendum available at privacy policy, require them to respond to such requests.
4.4 If a sender does not honour an unsubscribe request, or the unsubscribe mechanism does not work, that is a breach of our Acceptable Use Policy. Report it to us and we will act on it under our Anti-Abuse Policy.
5.1 The table below sets out what we collect about customers and website visitors, where it comes from, and the legal basis on which we hold it.
| Category | Examples | Source | Why we hold it | Legal basis (GDPR) |
| Account and identity | Name, business name, email, phone, job role, verification documents | You, at signup and verification | To provide the Services and to verify you are a legitimate sender | Contract; legitimate interests (abuse prevention) |
| Billing | Billing address, tax identifiers, transaction records, partial card data held by our payment processor | You and our payment processor | To take payment and meet tax obligations | Contract; legal obligation |
| Technical and usage | IP address, browser and device data, authentication logs, API usage, dashboard activity | Automatically, as you use the Services | Security, troubleshooting, capacity planning | Legitimate interests |
| Delivery telemetry | Volumes, bounce, complaint and rejection rates, authentication results, blocklist status | Generated by the Services | To manage deliverability and detect abuse | Contract; legitimate interests |
| Support | Tickets, correspondence, and any information you include in it | You | To answer you and improve support | Contract; legitimate interests |
| Website and marketing | Pages viewed, referrer, campaign identifiers, cookie and advertising identifiers | Cookies and similar technologies | To measure and promote our services | Consent (where required); legitimate interests |
5.2 We do not intentionally collect special category data (such as health, biometric, or data revealing political or religious belief) about our customers, and we ask that you do not include it in support correspondence.
5.3 Where we rely on legitimate interests, we have assessed that our interest in operating secure, non-abusive infrastructure does not override your rights. You may object to that processing as described in section 13.
6.1 Our website uses cookies and similar technologies in three categories.
| Category | What it does | Consent needed? | How to control it |
| Strictly necessary | Session management, authentication, load balancing, security | No — the site cannot function without them | Browser settings only; disabling breaks the site |
| Analytics / performance | Measures how visitors find and use the site so we can improve it | Yes in the EU, UK and similar jurisdictions | Our cookie banner, or the opt-out below |
| Advertising / retargeting | Builds an audience profile so our advertising can be shown to you on other sites | Yes in the EU and UK; opt-out right in California and similar US states | Our cookie banner, the Do Not Sell or Share link, or a Global Privacy Control signal |
6.2 Advertising and retargeting. We use advertising technologies that share identifiers with advertising partners so that our marketing can be shown to you elsewhere. Under California law and several other US state privacy laws, this activity is treated as a "sale" or "sharing" of personal information, even though no money changes hands for your data.
6.3 You can opt out of that sharing at any time through the "Do Not Sell or Share My Personal Information" link on our website, through our cookie banner, or by enabling a Global Privacy Control signal in your browser, which we honour automatically.
6.4 We do not knowingly sell or share the personal information of anyone under 16.
6.5 In the EU and UK, non-essential cookies are set only after you consent. You can change or withdraw your choices at any time.
7.1 We do not sell customer account data. We share personal information only in the following circumstances.
7.2 We describe service providers by category rather than by name so that this Policy does not become inaccurate each time a vendor changes.
7.3 Content involving the sexual exploitation of minors is reported to the National Center for Missing & Exploited Children and to law enforcement, without notice to the account holder.
7.4 Customers who require a current list of sub-processors for their own compliance purposes may request one at [email protected].
8.1 We are established in the United States. If you are located outside those regions, your personal information will be transferred to and processed in them.
8.2 Email delivery is inherently international. A message addressed to a recipient abroad is transmitted to mail systems in that country, and we cannot deliver it otherwise.
8.3 Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on appropriate safeguards — normally the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit. A copy of the relevant safeguards is available on request at [email protected].
9.1 We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires.
| What | How long we keep it | Why |
| Message content in transit | Only as long as needed for transmission, queueing and immediate troubleshooting | It is not our data to keep |
| Delivery logs and metadata | 3 months | Troubleshooting, billing accuracy, abuse detection |
| Account and billing records | lifetime. | Tax, accounting and legal defence obligations |
| Abuse investigation records | Per the Anti-Abuse Policy, or longer if required by law or an ongoing matter | Abuse prevention and legal obligation |
| Support correspondence | Duration of the relationship plus a reasonable period | Service continuity and dispute resolution |
| Marketing contact data | Until you withdraw consent or object | Consent-based marketing |
| Cookie and advertising data | Per the lifetime disclosed in our cookie banner | Analytics and advertising |
9.2 Where we are required to keep records for abuse, tax or legal reasons, we retain the minimum necessary and restrict access to it.
10.1 We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data we hold, including encryption in transit, authenticated relay, access controls and logging, and segregation of customer environments.
10.2 No system is completely secure. We do not claim that our safeguards are impenetrable, and we encourage customers to protect their own credentials, since a substantial share of incidents originate from compromised customer credentials rather than provider infrastructure.
10.3 Where a personal data breach is likely to result in a risk to individuals, we notify the relevant supervisory authority and affected parties as required by applicable law and without undue delay.
11.1 We use automated systems to detect abuse — for example, monitoring complaint rates, volume anomalies and authentication failures — and these systems may automatically throttle or suspend a sending account.
11.2 These decisions concern accounts and infrastructure rather than individuals' personal circumstances, and a human reviews any suspension before it becomes a termination. Customers may seek human review of any automated enforcement action under our Acceptable Use Policy.
The Services are business services and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, write to [email protected] and we will delete it.
You have the right to access your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to data portability; to object to processing based on legitimate interests or to direct marketing; to withdraw consent at any time; and to lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner's Office.
You have the right to know what personal information we collect and how we use it; to access and to delete it; to correct inaccuracies; to opt out of sale, sharing and targeted advertising; and not to be discriminated against for exercising these rights. Our advertising activity is treated as sharing, and the opt-out is described in section 6.3. We do not use sensitive personal information for purposes requiring a separate limitation right.
You have the right to access the personal information we hold about you, to challenge its accuracy, and to withdraw consent subject to legal and contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada.
If your data reached us because one of our customers sent you email, we hold it as processor and your rights are exercised against that customer. Section 4 explains how we help you reach them.
14.1 Write to [email protected]. Tell us what you are asking for and enough information to locate your records.
14.2 We verify requests before acting, because disclosing personal information to the wrong person is itself a breach. Verification is proportionate to the sensitivity of what is requested, and we will not ask for more than we need. An authorised agent may act for you with written authority.
14.3 We respond within 48 ~ 72 hours, and in any event within the period applicable law requires. If we need longer we will tell you why. Exercising your rights is free unless a request is manifestly unfounded or excessive.
14.4 If we cannot act on a request — for example because we hold the data as processor, or because a legal obligation requires us to retain it — we will tell you why and, where possible, tell you who can.
15.1 We send marketing email only to people who have asked for it, or to existing customers about services similar to those they already use. Every marketing message carries a working unsubscribe link, and we honour requests within two days.
15.2 We hold ourselves to the standard our Acceptable Use Policy imposes on customers. If our own marketing does not meet it, tell us at [email protected].
16.1 We may update this Policy to reflect changes in our practices, technology or the law.
16.2 Where a change materially affects how we use your personal information, we will give notice before it takes effect — by email to customers, or by a prominent notice on the website. Other changes take effect on publication.
16.3 This version is effective from 09/26/2026. We keep prior versions and will provide one on request.
17.1 Privacy enquiries and rights requests: [email protected].
17.2 Legal process and regulator correspondence: [email protected], or in writing to BEINCART LLC, 30 N Gould St Ste N Sheridan, WY, 82801.
17.3 EU and UK representatives: Individuals in the EEA or UK may contact us in writing to in writing to [email protected]
17.4 If you are not satisfied with our response, you may complain to your data protection authority. We would prefer you raise it with us first, and we will take it seriously.
