Privacy Policy
Last updated September 2026
This Privacy Policy explains how SendBeam, operated by STATUSAPP LTD ("we", "us"), handles personal data. It covers data about our customers (the people who hold SendBeam accounts). Personal data that customers upload about their own contacts is processed on their behalf under our Data Processing Addendum — for those, the customer is the controller and you should contact them. That includes contact data we import on a customer's written instruction from another platform under the Move-in service.
Who we are
SendBeam is a trading name of STATUSAPP LTD, the controller of the personal data described in this notice.
- Registered name: STATUSAPP LTD
- Registered in Companies House, England and Wales, number 16897842
- Registered office: 86-90 Paul Street, London, EC2A 4NE, United Kingdom
- Email: hello@sendbeam.io
Data we collect about customers
- Account data: name, email, workspace name, password (hashed).
- Billing data: plan and payment identifiers (card details are held by our payment processor, not by us).
- Usage data: logins, sending activity, and diagnostic logs.
How we use it
- to provide, secure, and support the Service;
- to enforce sending limits and prevent abuse;
- to bill you and communicate about your account;
- to meet legal obligations.
Our lawful bases are performance of our contract with you, our legitimate interests in running and securing the Service, and compliance with law.
For people who receive email sent through SendBeam: when you open an email, the sender may use the time you opened it to choose the hour later emails reach you. This uses the last six months of opens and applies only to that sender.
Sub-processors
These are the service providers we use to run SendBeam. Each processes data only as needed to provide its service, under contract, and we remain responsible for them. We give customers at least 30 days' notice before adding or replacing one, as set out in the Data Processing Addendum.
| Provider | What it does for us | Where it processes |
|---|---|---|
| Cloudflare | Website and application hosting, CDN, DNS, bot protection on forms, and inbound routing for our own email addresses | Global edge network |
| Supabase | Database and authentication — where account data and customers' contact data are stored | United Kingdom (London) |
| Resend | Email delivery — the route customer email takes today | United States |
| Microsoft | Email delivery through Azure Communication Services, in trial on selected workspaces | United Kingdom |
| Amazon Web Services | Email delivery, and the bounce and complaint notifications that feed suppression. Configured and being brought into service; customer email does not go through it yet | United Kingdom (London) |
| Stripe | Subscription billing. Card details go to Stripe and are never held by us | United States and European Union |
| Google Analytics | Traffic measurement on the public marketing pages only — never inside the application, and only if you allow analytics cookies | United States |
Separately, when you use the Move-in importer we connect to whichever platform you are leaving — Mailchimp, MailerLite, Kit, Brevo, EmailOctopus or Buttondown — using credentials you supply, and only to read the data you ask us to import. Those platforms are your providers, not ours.
Cookies and analytics
Our public website (the marketing pages, pricing and documentation) uses Google Analytics to understand which pages help people. It sets analytics cookies only after you choose Allow analytics in the bar shown on your first visit; until then, and if you choose No thanks, no analytics cookies are set. IP addresses are anonymised. Your choice is stored in your browser; clear the site's storage to be asked again. The application itself uses only the cookies needed to keep you signed in.
Google user data, and Google's Limited Use requirements
If you connect a Google account to SendBeam, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We ask only for the permissions the connected feature needs, and you can withdraw them at any time.
What each permission is used for:
- Google Sheets (read-only) — used solely to import contacts from a spreadsheet you choose. When you start an import, we read the tabs of the single spreadsheet whose link you paste, then the rows of the tab you select. We store only the contacts you map into your workspace; the spreadsheet itself is not copied or retained. We never list, browse or search your Google Drive, and we never write to a spreadsheet.
- Your Google account email address — used only to label the connection, so you can tell which account is connected.
- Google Postmaster Tools (read-only) — used only to show sending reputation on your Deliverability page. We store daily aggregate statistics for the domains your workspace has verified in SendBeam, and for no others. These statistics contain no message content and no recipient addresses.
We do not transfer Google user data except as necessary to provide these features, to comply with the law, or as part of a merger or acquisition following notice to you. We do not use it for advertising of any kind, and we do not sell it. We do not use it to develop, improve or train generalised artificial-intelligence or machine-learning models. No SendBeam employee reads it, except where you have given explicit consent for a specific support request, where it is necessary for security purposes or to comply with the law, or where the data has been aggregated and anonymised for internal operations.
Access tokens are encrypted at rest. Disconnecting the integration in Settings → Connections deletes the connection and its tokens from our database, and you can additionally revoke SendBeam's access from your Google account permissions page.
Retention
Send records (which message went to which address, and its delivery status) are kept for the life of the workspace. Engagement events (opens, clicks, deliveries) are kept for 180 days and contact-form submissions for 90 days, after which they are purged automatically. We keep engagement events for six months by choice rather than indefinitely: knowing that a named person opened a particular email is information about them, not just about the campaign, and it stops being useful long before it stops being personal.
Deleting a workspace withdraws access straight away and schedules it for permanent deletion 14 days later. During those 14 days an owner or account admin can restore it, after which its contacts, campaigns and history are destroyed and cannot be recovered. You can ask us to skip the 14 days and delete it at once. Copies in backups expire within 30 days. A request from a person to erase their own data is never held this way — it is carried out straight away. Suppression records are kept so opt-outs continue to be honoured: a one-way hash of the address, and — for records made from 14 September 2026 — a masked form of it (its first character and domain, such as j***@example.com), the reason and the date, so that a customer can review the list. An address erased at a person's request keeps the hash alone. A longer period applies only where the law requires it.
Your rights
Subject to applicable law, you may request access, correction, deletion, portability, or restriction of your personal data, and may object to certain processing. Send your request through the contact form and we will reply by email. If you are not satisfied with our answer you can complain to the UK Information Commissioner's Office at ico.org.uk, which is our supervisory authority, or to the data protection authority where you live.
Where your data is held, transfers and security
Account data and the contact data customers upload are stored in the United Kingdom. Email is delivered by the providers listed above: the route most customer email takes today is in the United States, and one in the United Kingdom is in trial. Some of the providers listed above are US companies, and billing and analytics data reach the United States; where personal data leaves the UK we rely on UK adequacy regulations or, where none applies, the ICO's International Data Transfer Addendum to the standard contractual clauses.
Data is encrypted in transit, access is limited to those who need it, credentials you give us for imports and form protection are encrypted at rest, and suppression records store the address as a one-way hash (with a masked display form, never the address itself).
Contact
STATUSAPP LTD, SendBeam. Email hello@sendbeam.io or use the contact form; we reply by email. Our registered office is 86-90 Paul Street, London, EC2A 4NE, United Kingdom.