Privacy Policy

What we collect, why we need it, who helps us process it, and the choices you have.

Effective or last updated 22 August 2026

Sendlander is a trading name of Pettman Consulting Limited, 12A Upoko Road, Hataitai, Wellington, New Zealand (NZBN 9429048985062; company number 8158392). We are the privacy agency responsible for personal information described in this policy unless a customer controls data that we process only on its instructions.

Information we collect

  • Account and identity: name, email, password hash, email-verification state, Google sign-in identity, organisation, roles, sessions, policy acceptances, and security records.
  • Product data: sender addresses and domains, seed recipients, tracking tokens, message headers, snippets or content needed for analysis, placement results, diagnostic evidence, tasks, monitors, connection state, and reports.
  • Connected-service data: OAuth identifiers, authorisations, mailbox or sending metadata, and encrypted credentials or tokens needed to provide the connection you request.
  • Billing: plan, credits, transactions, invoices, and Stripe customer, checkout, payment-method, and subscription identifiers. We do not store raw card details or complete card numbers.
  • Support and communications: messages, contact details, report references, and our response history.
  • Technical and usage: IP address, browser and device information, cookies, audit and security logs, feature events, errors, and performance data.

You must have the right to submit sender addresses, domains, email content, headers, recipient data, and any other personal information you provide to Sendlander or its MailSlurp/MS2/inbox-placement infrastructure.

We collect information from you, your organisation’s administrators, connected services you authorise, mailbox and infrastructure providers involved in a test, public technical records such as DNS, our providers, and use of the service. If we collect personal information indirectly, we provide notices required by applicable New Zealand privacy law unless an exception applies.

Why we use it

We use information to provide and personalise the service; authenticate users; perform tests, diagnostics, monitoring, and requested sending; manage organisations and tasks; process billing; provide support; send operational notifications; prevent abuse and fraud; investigate incidents; maintain and improve Sendlander; enforce contracts; establish or defend claims; and comply with law.

We may create aggregated or de-identified information that does not reasonably identify a person and use it for service reliability, research, benchmarking, and product improvement.

Google user data

If you connect Google, we request only the scopes needed for the feature you select. Google user data is used to provide or improve that user-facing feature, such as authenticating you or sending through a mailbox you authorise. We do not sell Google user data, use it for advertising, or allow humans to read it except with your affirmative permission for support or security, where necessary for abuse investigation, or where required by law.

Sendlander’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access through your Google account and disconnect a sender in Sendlander.

Disclosure and subprocessors

We disclose information only as reasonably needed to your authorised organisation members; providers that host, secure, analyse, bill for, communicate for, or operate Sendlander; connected services you select; professional advisers; a buyer or successor in a genuine corporate transaction; or regulators, courts, and law enforcement where lawfully required. Our current providers are listed on the Subprocessor page.

Some providers process information outside New Zealand. We take reasonable steps required by New Zealand Information Privacy Principle 12 and applicable law, which may include contractual safeguards, assessing comparable protections, or obtaining permission. Connected services you independently choose may process data under their own policies.

Retention and account closure

We retain information only for as long as reasonably needed for the purposes above. Product and connection data is generally held while the account or feature remains active. Account closure removes active credentials and product data within our live systems, subject to safety checks, while billing records, policy acceptance evidence, fraud-prevention records, and information needed for legal claims may be retained for the applicable legal period. New Zealand financial records are commonly retained for seven years.

Support and security records may be retained for a reasonable audit and dispute period. Deletion from encrypted backups occurs through normal backup expiry. We may retain de-identified information that cannot reasonably be linked back to you.

Security and breaches

We use reasonable technical and organisational safeguards appropriate to the service, including access controls, protected sessions, credential protection, logging, and provider security controls. No internet service is risk-free. You must protect your account and connected systems and tell us promptly about suspected compromise.

We assess privacy incidents and notify the New Zealand Privacy Commissioner and affected people where required. See our Security page for reporting instructions.

Cookies and analytics

Necessary cookies and browser storage support login, security, and preferences. Analytics is optional and loads only after consent through our cookie control. Consented analytics may record account creation, test starts, billing actions, report utility actions, and application errors so we can understand whether the service works and improve it.

We do not intentionally send email content, seed addresses, tracking tokens, report identifiers, sender addresses, or exact API URLs to analytics providers. You can reopen Cookie settings from the footer.

Your rights and choices

Subject to applicable exceptions, you may ask for access to or correction of your personal information. Signed-in users can export account data and request account closure from Account settings. You may disconnect providers, adjust notifications, change analytics consent, or unsubscribe from non-essential communications. We may verify identity before acting.

If your information is controlled by a Sendlander customer, first contact that customer. We will support its lawful request. You may also complain to the New Zealand Office of the Privacy Commissioner.

Children and changes

Sendlander is a business service and is not directed to children under 18. We may update this policy prospectively and will post the effective date. Material changes may also be notified in the service or by email.

Privacy contact

Privacy Officer, Pettman Consulting Limited
12A Upoko Road, Hataitai, Wellington, New Zealand
privacy@sendlander.com