Privacy & Data Protection
Privacy Policy
How we handle your account data and campaign analytics
Last Updated: July 20, 2026
Account & Payment Information
When you create a Good Mail Co. account and subscribe, we collect the information needed to provide the Service to you as a business customer:
- •Account details: Your name, email address, and the business information you provide (business name, phone, address, website, logo, and branding).
- •Authentication: Sign-in is handled by our authentication provider, Clerk. We do not store your password.
- •Payment data: Payments are processed by Stripe. We do not store full card numbers — Stripe handles card data directly. We retain records of your subscriptions and charges for billing and support.
- •Campaign data: The markets, lead volumes, designs, and offers you configure for your mail campaigns.
We use this information to operate your account, process payments, run and mail your campaigns, provide support, and comply with our legal obligations. We share it only with the service providers that make the platform work (such as our authentication, payment, and print/mail partners), and never sell it.
Data We Collect From QR Scans
When a QR code from a Good Mail Co. mailpiece is scanned, we collect limited data to give contractors campaign analytics:
- •Mailed address (per-household campaigns): Each mailpiece can carry a QR code unique to the home it was mailed to. When such a code is scanned, the scan is associated with that home's mailing address so the contractor can see which of the households they mailed responded. This address is disclosed only to the contractor who mailed that home, scoped to their own campaign — it is never shown publicly on the scan page or shared with other contractors.
- •IP-based geolocation: Approximate city/state region of the scan (not GPS coordinates); the raw IP address is hashed before storage.
- •Device type: Mobile vs desktop classification
- •Timestamp: Date and time of scan
- •Session fingerprint: A SHA256 hash used to distinguish unique vs repeat scans.
What We DO NOT Collect
We are committed to data minimization. From a QR scan, we explicitly do not collect:
- ✗The scanner's name, email address, or phone number
- ✗Precise GPS coordinates or continuous location
- ✗Browsing history or persistent tracking cookies
- ✗Raw IP addresses (we hash IPs using SHA256 before storage)
Note: for per-household campaigns, a scan is linked to the mailing address that mailpiece was sent to (see above). That address comes from the campaign's mailing list, not from the scanning device.
How We Use This Data
The data we collect from scans serves three purposes:
Analytics
Provide contractors with campaign analytics (scan counts, geographic trends, device breakdown, and — for per-household campaigns — which mailed homes responded)
Visitor Detection
Distinguish unique vs repeat scans using a hashed session fingerprint (helps measure campaign reach)
Service Quality
Improve our platform performance and user experience
Data Retention
We practice responsible data retention with automatic archival:
- 1Active storage: Scan data is retained for 12 months
- 2Automatic archival: After 12 months, scans are automatically archived and aggregated (monthly automated process)
- 3Data deletion: Individual scan records are deleted from active storage after archival
Your Rights
You have control over your data:
Opt-Out of Tracking
Upload your own PDF design without our QR code to completely disable tracking. You maintain full control over whether tracking is enabled on your mailers.
Data Deletion Requests
Contact [email protected] to request deletion of your scan data at any time.
GDPR & CCPA Compliance
We follow data minimization principles and respect your privacy rights under GDPR (European Union) and CCPA (California) regulations:
We recognize that some of the information we handle is personal information. In particular, for per-household campaigns, a mailing address linked to a QR scan is personal (and, under CCPA/CPRA, household) information, and we treat it accordingly — not as anonymous data. If you are a homeowner whose address may be associated with a scan, you may exercise the access and deletion rights below just as a contractor customer can; contact us and we will honor applicable requests.
- ✓Data Minimization: We collect only essential data needed for analytics
- ✓Privacy by Design: IP addresses are hashed (SHA256) before storage
- ✓Right to Access: Request a copy of your data via DSAR (Data Subject Access Request)
- ✓Right to Deletion: Request deletion of your data at any time
- ✓Transparency: Clear disclosure of data collection practices (this policy)
For data subject access requests (DSAR) or privacy inquiries, contact [email protected].
Questions About Privacy?
We're here to help. Contact our privacy team for any questions or concerns.
[email protected]