Privacy Policy

Effective 18 July 2026

1. Who we are

Sendscape is operated by Digital Scape ("we", "us"). This policy explains what personal data we collect and how we use it, in line with Malaysia's Personal Data Protection Act 2010 (PDPA). It applies alongside our Terms of Service.

2. Data we collect

  • Account data: your name, email address, and a hashed password (or your Google profile name and email if you sign in with Google).
  • Credentials: API keys and SMTP passwords, stored hashed. We cannot read them back after creation.
  • Send logs: for each email you send, the sender and recipient addresses, subject line, and delivery status (delivered, bounced, complained).
  • Suppression entries: recipient addresses that have bounced or complained, kept so we do not email them again.
  • Basic technical data: such as request timestamps needed to operate and secure the service.

We do not store the full body content of your emails after they are relayed.

3. How we use it

  • Operating the service: relaying your email, verifying your domains, enforcing sending quotas.
  • Protecting deliverability: processing bounces and complaints, maintaining suppression lists, monitoring for abuse.
  • Supporting you: responding to requests you send us.
  • Billing: processing payments if and when you subscribe to a paid plan.

We do not sell your data or use your recipients' addresses for anything except delivering your email and protecting deliverability.

4. Where your data goes

We use a small number of service providers to run Sendscape:

  • Amazon Web Services (Amazon SES, Singapore region): delivers your email. Email content and recipient addresses transit AWS infrastructure in Singapore.
  • Our hosting provider: runs the Sendscape application and database.
  • Google: only if you choose to sign in with Google.
  • CHIP (payment processing): only if and when you subscribe to a paid plan.

5. Your recipients' data

When you send email through Sendscape, you are the party responsible for having a lawful basis (such as consent) to email your recipients. We process recipient addresses on your behalf, solely to deliver your email and manage bounces, complaints, and suppressions.

6. Retention

We keep account data while your account exists. Send logs and suppression entries are kept for as long as they are needed for deliverability, abuse prevention, and legal compliance. You can request deletion of your account by contacting us; some records may be retained where we have a legitimate need, such as suppression entries that protect recipients from further email.

7. Security

Passwords, API keys, and SMTP credentials are stored hashed. Data in transit is protected with TLS. Access to production systems is restricted.

8. Your rights

Under the PDPA you may request access to or correction of your personal data, or withdraw consent to its processing (which may mean we can no longer provide the service). Send requests to support@sendscape.ai and we will respond within a reasonable time.

9. Changes and contact

We may update this policy from time to time; material changes will be notified by email or through the dashboard. Questions about privacy? Contact us at support@sendscape.ai.