Privacy & Data Protection

    Privacy Policy

    How we handle your account data and campaign analytics

    Last Updated: July 20, 2026

    Account & Payment Information

    When you create a Good Mail Co. account and subscribe, we collect the information needed to provide the Service to you as a business customer:

    • Account details: Your name, email address, and the business information you provide (business name, phone, address, website, logo, and branding).
    • Authentication: Sign-in is handled by our authentication provider, Clerk. We do not store your password.
    • Payment data: Payments are processed by Stripe. We do not store full card numbers — Stripe handles card data directly. We retain records of your subscriptions and charges for billing and support.
    • Campaign data: The markets, lead volumes, designs, and offers you configure for your mail campaigns.

    We use this information to operate your account, process payments, run and mail your campaigns, provide support, and comply with our legal obligations. We share it only with the service providers that make the platform work (such as our authentication, payment, and print/mail partners), and never sell it.

    Data We Collect From QR Scans

    When a QR code from a Good Mail Co. mailpiece is scanned, we collect limited data to give contractors campaign analytics:

    • Mailed address (per-household campaigns): Each mailpiece can carry a QR code unique to the home it was mailed to. When such a code is scanned, the scan is associated with that home's mailing address so the contractor can see which of the households they mailed responded. This address is disclosed only to the contractor who mailed that home, scoped to their own campaign — it is never shown publicly on the scan page or shared with other contractors.
    • IP-based geolocation: Approximate city/state region of the scan (not GPS coordinates); the raw IP address is hashed before storage.
    • Device type: Mobile vs desktop classification
    • Timestamp: Date and time of scan
    • Session fingerprint: A SHA256 hash used to distinguish unique vs repeat scans.

    What We DO NOT Collect

    We are committed to data minimization. From a QR scan, we explicitly do not collect:

    • The scanner's name, email address, or phone number
    • Precise GPS coordinates or continuous location
    • Browsing history or persistent tracking cookies
    • Raw IP addresses (we hash IPs using SHA256 before storage)

    Note: for per-household campaigns, a scan is linked to the mailing address that mailpiece was sent to (see above). That address comes from the campaign's mailing list, not from the scanning device.

    How We Use This Data

    The data we collect from scans serves three purposes:

    📊

    Analytics

    Provide contractors with campaign analytics (scan counts, geographic trends, device breakdown, and — for per-household campaigns — which mailed homes responded)

    🔍

    Visitor Detection

    Distinguish unique vs repeat scans using a hashed session fingerprint (helps measure campaign reach)

    ⚙️

    Service Quality

    Improve our platform performance and user experience

    Data Retention

    We practice responsible data retention with automatic archival:

    • 1Active storage: Scan data is retained for 12 months
    • 2Automatic archival: After 12 months, scans are automatically archived and aggregated (monthly automated process)
    • 3Data deletion: Individual scan records are deleted from active storage after archival

    Your Rights

    You have control over your data:

    Opt-Out of Tracking

    Upload your own PDF design without our QR code to completely disable tracking. You maintain full control over whether tracking is enabled on your mailers.

    Data Deletion Requests

    Contact [email protected] to request deletion of your scan data at any time.

    GDPR & CCPA Compliance

    We follow data minimization principles and respect your privacy rights under GDPR (European Union) and CCPA (California) regulations:

    We recognize that some of the information we handle is personal information. In particular, for per-household campaigns, a mailing address linked to a QR scan is personal (and, under CCPA/CPRA, household) information, and we treat it accordingly — not as anonymous data. If you are a homeowner whose address may be associated with a scan, you may exercise the access and deletion rights below just as a contractor customer can; contact us and we will honor applicable requests.

    • Data Minimization: We collect only essential data needed for analytics
    • Privacy by Design: IP addresses are hashed (SHA256) before storage
    • Right to Access: Request a copy of your data via DSAR (Data Subject Access Request)
    • Right to Deletion: Request deletion of your data at any time
    • Transparency: Clear disclosure of data collection practices (this policy)

    For data subject access requests (DSAR) or privacy inquiries, contact [email protected].

    Questions About Privacy?

    We're here to help. Contact our privacy team for any questions or concerns.

    [email protected]