Privacy Policy

What we collect, why, who we share it with, and the rights you have.

Last Updated: 2026-09-10

QUEENSMTP.COM is operated by RNS STAR LLC, 99 Wall Street #112, New York, NY 10005, United States ("we", "us", "our"). This policy explains how we handle information when you visit our website, open an account, or send mail through our services.

1. The two roles we play

We are an email infrastructure provider, so we handle two very different kinds of personal data, under two different legal roles. The distinction runs through this whole policy:

  • Your data — we are the controller. Your name, email address, company, billing details, login credentials, support messages and how you use the dashboard and API. We decide how this is handled, and this policy governs it.
  • Your recipients' data — we are the processor. The addresses you send to, the contents of those messages, and the delivery events they generate. You are the controller of that data. We process it only to deliver your mail, protect the platform, and meet our legal obligations, and only on your instructions. Your own privacy notice, not this one, governs your relationship with your recipients.

2. Information we collect

2.1 Information you give us

  • Name, company name, email address and, where you provide it, phone number.
  • Billing details. Card data is entered on our payment processor's hosted checkout — we never receive or store your full card number. We receive the card brand, last four digits, country and the outcome of the charge.
  • Account credentials. Passwords are stored only as salted hashes and cannot be recovered by anyone, including us.
  • Sending domains and the DNS records you configure for SPF, DKIM, DMARC and tracking.
  • The content of enquiries you send to support.

2.2 Information we collect automatically

  • Server and application logs: IP address, timestamp, request path, response status and user agent.
  • API and SMTP usage: authentication events, request volume, endpoints used and rate-limit activity.
  • Website analytics: pages visited, referring URL, approximate location, device and browser.

We keep these for security, abuse prevention, billing accuracy and troubleshooting.

2.3 Data you send us about your recipients

To deliver mail we necessarily process sender and recipient addresses, subject lines and headers, message bodies and attachments in transit, and the resulting delivery, bounce, complaint, open and click events.

We do not read, analyse or mine your message content for advertising, profiling or model training. Content is processed to deliver the message, to give you delivery analytics, and to run the automated abuse screening described in our Terms of Service — nothing else. Message bodies are not retained after delivery; see section 6.

3. Why we use it, and our legal basis

PurposeLegal basis (UK/EU GDPR)
Providing the Services and operating your accountPerformance of a contract
Taking payment, invoicing, renewals and refundsPerformance of a contract
Support and responding to enquiriesPerformance of a contract; legitimate interests
Abuse, spam and fraud prevention; rate limiting; blocking card testingLegitimate interests in protecting the platform, our sending reputation and other customers
Service, security and billing noticesPerformance of a contract; legal obligation
Product and marketing email to prospectsConsent, withdrawable at any time
Tax, accounting and regulatory recordsLegal obligation
Establishing or defending legal claimsLegitimate interests

Service messages about your account, billing, security and material changes are not marketing, and cannot be opted out of while you hold an account.

We do not sell personal information, and we do not share it with advertisers.

4. Who we share it with

We share personal data only with the following, and only as needed:

  • Stripe — payment processing. Stripe receives your billing and card details directly and handles them as a controller under its own policy.
  • Our own infrastructure — servers we operate in datacentres in the United States and Asia, and the network, transit and mail-delivery providers those servers depend on.
  • Receiving mail servers — delivering your mail necessarily discloses it to the recipient's mail provider. That is the service.
  • Professional advisers and authorities — where we are legally required to disclose, or need to establish, exercise or defend a legal claim.
  • An acquirer — if the business is merged, acquired or sold, subject to this policy continuing to apply. We will notify you.

Sub-processors are bound to confidentiality and to security obligations no weaker than ours. We update this list before adding a new category of processor.

5. International transfers

We operate infrastructure in the United States and in Asia, so your data and your recipients' data may be processed in either. Where data leaves the UK or EEA we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, and apply the protections in this policy wherever the data is held.

6. How long we keep it

  • Message content: not retained after successful delivery. Undeliverable mail is discarded within 72 hours of the final attempt.
  • Delivery logs and analytics: 30 days.
  • Suppression records (unsubscribes, hard bounces, complaints): kept for the life of the account — deleting one would cause us to mail someone who asked us not to.
  • Account data: for the life of the account, then 90 days after closure so it can be exported or restored.
  • Billing records: 7 years, as tax and accounting law requires.
  • Server logs: up to 12 months.
  • Support correspondence: up to 2 years.
  • Aggregated statistics that identify nobody: indefinitely.

7. Security

We operate our own infrastructure, so security is our responsibility rather than a vendor's. Our measures include:

  • TLS on every connection to our websites, API and dashboard, with HTTP redirected to HTTPS.
  • Opportunistic TLS on outbound mail wherever the receiving server offers it.
  • Passwords stored as salted hashes, never in plain text and never recoverable.
  • Administrative access restricted to the people who operate the platform, over key-based SSH from restricted networks, with credentials held in server-side configuration and never in source control.
  • Firewalled infrastructure with monitored service health, automatic certificate renewal, replicated databases and regular backups.
  • Rate limiting and a decline ledger on signup and checkout, to stop automated abuse and card testing.

No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, email support@queensmtp.com; we will respond within one business day and will not pursue anyone who reports a genuine issue in good faith without accessing others' data.

8. Cookies

We use a session cookie to keep you signed in, preference cookies to remember dashboard settings, and privacy-respecting analytics to understand site usage. We do not use advertising cookies or third-party ad trackers on this site. You can block or delete cookies in your browser, though the dashboard will not stay signed in without the essential ones.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where we rely on it.

If you are in the EEA, the UK or Switzerland these are your rights under the GDPR and UK GDPR, and you may also lodge a complaint with your local supervisory authority.

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to access and delete it, to correct it, and to opt out of sale or sharing — we do neither — and to limit the use of sensitive personal information, which we do not collect. We will not discriminate against you for exercising any of these rights.

To exercise any right, email support@queensmtp.com from the address on your account. We respond within 30 days and do not charge. We may ask you to verify your identity first.

If you are a recipient of mail sent through our platform and want your data accessed or deleted, the sender is the controller and holds it — contact them, or write to us and we will pass the request on and, where you ask, add you to suppression so that sender cannot mail you again.

10. Children

The Services are for business use by adults and are not directed at children. We do not knowingly collect personal information from anyone under 18, and will delete it promptly if we learn we have.

11. Data processing addendum

If you need a data processing addendum covering our role as your processor, including the Standard Contractual Clauses, request one from support@queensmtp.com.

12. Changes to this policy

We may update this policy. Material changes are posted here with a revised "Last Updated" date and, where significant, emailed to the address on your account.

13. Contact

RNS STAR LLC, 99 Wall Street #112, New York, NY 10005, United States.