Privacy Policy
How EmailGuard collects, uses, shares, protects, and retains personal information across the web app, API, and mobile app.
Overview
This Privacy Policy explains how Baker Assets LLC ("EmailGuard", "we", "us", or "our") handles personal information when you use EmailGuard, our websites, APIs, mobile applications, customer support, and related services.
This is example policy text for an enterprise SaaS deployment. Review and adapt it with counsel before using it in production.
Roles
Depending on the context, we may act as:
- A controller for account, billing, marketing, website, support, and business relationship information.
- A processor or service provider for customer content and end-user data that customers submit to the service under our Data Processing Addendum or a signed agreement.
Customers are responsible for providing required notices and obtaining required rights or consents for personal information they submit to the service.
Information we collect
We collect information needed to provide, secure, support, and improve the service, including:
- Account information such as name, email address, password credentials, verification status, MFA enrollment, profile settings, and authentication events.
- Team and workspace information such as team names, memberships, roles, invitations, billing status, security settings, and audit log events.
- Authentication information from enabled sign-in providers, including Google and GitHub OAuth identifiers and profile information when those options are used.
- Billing information processed through payment providers, such as customer identifiers, subscription status, plan metadata, invoices, payment status, and customer portal links. We do not store full payment card numbers.
- Customer content you submit, upload, generate, configure, or transmit through the service.
- Support, sales, procurement, and legal communications.
- Device, usage, and diagnostics data such as IP address, browser and device details, operating system, request paths, timestamps, log events, crash reports, performance telemetry, and approximate location derived from IP address.
- Cookie and local storage data described in our Cookie Policy.
How we use information
We use personal information to:
- Provide, operate, maintain, and secure the service.
- Create, authenticate, authorize, and protect accounts.
- Provide team collaboration, billing, notifications, audit logs, support, and mobile app features.
- Send transactional messages such as verification emails, password resets, invitations, invoices, product notices, and security notices.
- Process subscriptions, invoices, taxes, usage, and billing events.
- Monitor reliability, investigate errors, prevent abuse, enforce limits, and improve performance.
- Respond to support, procurement, security, legal, and privacy requests.
- Analyze usage trends and improve the service.
- Comply with legal obligations and enforce agreements.
Legal bases
Where applicable law requires a legal basis, we rely on one or more of the following: performance of a contract, legitimate interests, consent, compliance with legal obligations, protection of vital interests, or another basis permitted by law.
How we share information
We may share information with:
- Subprocessors and service providers that help us operate, secure, support, bill, and improve the service. See Subprocessors.
- Customer administrators and authorized team members according to workspace settings and roles.
- Professional advisors, auditors, insurers, and legal representatives.
- Authorities, courts, or third parties when required by law or necessary to protect rights, safety, security, or service integrity.
- Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets.
- Third parties when you direct us to share information or enable an integration.
We do not sell personal information as the term is commonly understood. If a deployment uses advertising or analytics features that legally qualify as a sale or sharing, update this policy and provide required choices before enabling them.
International transfers
We and our subprocessors may process information in the United States and other countries. Where required, we use appropriate safeguards such as standard contractual clauses, data processing terms, or other legally recognized transfer mechanisms.
Retention
We retain personal information for as long as needed to provide the service, meet legal obligations, resolve disputes, maintain security, enforce agreements, and support legitimate business needs.
Typical retention considerations include:
- Account and billing records may be retained while an account is active and for a reasonable period afterward.
- Audit logs, security logs, and backups may be retained for security, continuity, and compliance.
- Customer content may be deleted or exported according to customer settings, product functionality, and contractual terms.
- Support and legal communications may be retained for business records and dispute management.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These may include encryption in transit, access controls, logging, monitoring, MFA support, least-privilege practices, secure development practices, backups, and incident response procedures. See Security.
No system is perfectly secure. Customers are responsible for configuring accounts, roles, integrations, and devices appropriately.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict certain processing of personal information. You may also have the right to withdraw consent or appeal a denied request.
To make a privacy request, email [email protected]. We may need to verify your identity and may direct requests about customer-controlled data to the relevant customer.
Enterprise customer requests
If you are an enterprise customer, your agreement, order form, or DPA may provide additional controls for data deletion, export, audit, security review, subprocessors, and regulatory requests. If there is a conflict between this policy and a signed agreement, the signed agreement controls for that customer relationship.
Children's privacy
EmailGuard is not intended for children under 13 or the minimum age required by local law. We do not knowingly collect personal information from children.
Changes
We may update this policy from time to time. Material changes will be communicated as required by law or contract.
Contact
Privacy questions can be sent to [email protected].
Legal notices may be sent to:
Baker Assets LLC
123 Placeholder Avenue, Suite 100, Wilmington, DE 19801, United States
Looking for another policy?
Browse privacy, security, subprocessors, and other legal documents.