1. Overview
CODARI GLOBAL, LLC, a Wyoming limited liability company doing business as MillionSend ("MillionSend", "we"), operates a hosted email platform. This policy distinguishes two roles:
- For account data — the information customers give us to open and operate an account — we are the data controller.
- For Customer Content — the contacts, recipient addresses, and email content our customers submit in order to send email — we are a data processor acting on the customer's instructions. The customer is the controller.
2. Data we collect as controller
- Account data: name, email address, password hash, organization name, locale.
- Billing data: plan, invoices, and the last four digits and brand of your card. Full payment credentials are held by Stripe, not by us.
- Usage and log data: API request logs, IP addresses, user-agent, dashboard actions, and security events.
3. How we use account data
To provide and secure the service, bill for it, respond to support requests, meet legal obligations, and send service notices. Creating an account also subscribes you to occasional product updates from MillionSend (new features, announcements); every such email carries a working unsubscribe, and unsubscribing never affects account notices such as password resets or invitations. We do not sell personal data, do not use Customer Content to train machine-learning models, and do not permit our subprocessors to do so.
4. Customer Content, processed on behalf of customers
Customer Content includes recipient email addresses, contact attributes, segments, templates, message bodies, and delivery events (sent, delivered, bounced, opened, clicked, complained). We process it only to deliver email, render the customer's dashboard and metrics, operate suppression lists and unsubscribes, and provide support. Email bodies are encrypted at the application layer with AES-256-GCM before being stored. Section 5 sets out every case in which a person at MillionSend, or an automated check, can see it.
5. When MillionSend staff can see Customer Content
A person at MillionSend, or an automated check, can see Customer Content only through the three paths below. Support sessions appear at once in an audit trail your account can read for itself, under Settings; security reviews are added to it as set out below.
- Automated content screening. To keep phishing, malware, and spam off a platform whose sending reputation every customer shares, a sample of the mail you send is scored automatically after it has been accepted for delivery. What is sent for scoring is your team's name, verified domains, plan, and how long it has been sending; the From and Reply-To headers; the subject; the visible rendered text (up to 6,000 characters, leaving out elements hidden by their own inline style); up to 30 links, each shown as its anchor text and the domain it points to; the number of images; attachment file names and types; and a count of hidden characters. Before the text goes to TypeSafe, the subject, text, anchor text, and file names are redacted: links are cut to their domain and a short part of the path, key- and token-shaped strings are masked, as are numeric codes that follow words such as "code", "PIN", or "password", and email addresses are reduced to their domain. Names, phone numbers, postal addresses, and other personal details written in the text are not removed. What is sent never includes recipient addresses, attachment contents, or raw HTML. Scoring is carried out by TypeSafe (Section 6). We do not store the text sent for scoring; we keep only the result (a score, a verdict, and short labels for the reasons, the category, and the language) for 90 days. TypeSafe processes the text under its data processing addendum, may keep it for as long as necessary to provide its service, to monitor that service for fraud and abuse, to derive service telemetry, and to comply with law, and does not use it to train models.
- Support access, at your request. When you ask us for help, an authorised operator may open your dashboard in a read-only support view for up to 30 minutes. The content of sent emails, exports, and secrets are not visible in that view; the session appears in your account's audit trail at once; and the account owner is emailed when it starts and can end it at any time from Settings.
- Security review of specific messages. When our automated checks or a report from a mailbox provider indicate that an account may be sending phishing, malware, or spam, an authorised operator may read the subject and rendered text of the specific messages concerned, for a recorded security reason, for at most 30 minutes, with recipient addresses, attachments, and credentials withheld. Every such access is logged and disclosed to the account about seven days later, unless by then the account has been suspended for phishing.
We do not read Customer Content for any other purpose, and none of the paths above is used to build profiles, advertising, or training data.
6. Subprocessors
We use the following subprocessors to operate the service:
- Amazon Web Services (AWS) — Email delivery via SES, application hosting, storage. Location: Data storage and application hosting in the United States; email delivery via SES in the region chosen per sending domain.
- Stripe — Payment processing and billing. Location: United States.
- Cloudflare — DNS, content delivery, and network security. Location: Global edge network.
- TypeSafe — Automated screening of sent message content for phishing, malware, and spam. Location: United States.
We will provide notice of subprocessor changes to customers with an executed DPA before the change takes effect.
7. Retention
- Account data: for the life of the account and up to 90 days after deletion, except records we must keep for tax and accounting law.
- Customer Content: for the life of the account; deleted within 30 days of account deletion, and earlier when the customer deletes specific contacts or messages.
- Email bodies, attachments, API request logs and delivery-event payloads: 30 days by default. Email metadata (sender, recipients, subject, status) and webhook delivery records: 365 days. Billing event ledger: 90 days. Expired sign-in sessions are purged hourly.
- Suppression entries (bounces, complaints, unsubscribes): retained while the account exists, because deleting them would cause re-sending to people who opted out.
8. Security
Data is encrypted in transit (TLS) and at rest; email bodies carry an additional application-side AES-256-GCM layer. Access to production systems is restricted and logged. API keys are shown once and stored hashed. If we learn of a personal-data breach, we will notify affected customers without undue delay and within the timelines the GDPR and LGPD require.
9. International transfers and residency
Our application and its database run in a single primary region in the United States; your account data and stored email content (encrypted at rest) reside there. Message content sampled for the automated screening described in Section 5 is processed by TypeSafe in the United States. When you add a sending domain you choose an AWS region — that choice selects where Amazon SES delivers that domain's mail, and does not change where your data is stored. Where personal data subject to the GDPR or UK GDPR is transferred to a third country, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum. TypeSafe's data processing addendum includes the EU Standard Contractual Clauses (Modules 2 and 3) and the UK Addendum. For LGPD data, we rely on the contractual safeguards of Article 33; these do not cover the screening transfer to TypeSafe.
10. Your rights under the GDPR
If you are in the EEA or UK, you may request access, rectification, erasure, restriction, portability, and object to processing, and you may lodge a complaint with your supervisory authority. For account data, contact us directly. For personal data in Customer Content, contact the sender who controls it; we will refer requests we receive to the responsible customer and assist them as processor.
11. Your rights under the LGPD
If you are in Brazil, Lei Geral de Proteção de Dados grants you the corresponding rights: confirmation of processing, access, correction, anonymization or deletion, portability, and information about sharing. Requests are honored through the same channels as Section 10, and you may petition the ANPD.
12. Data Processing Addendum
A DPA covering our processing of Customer Content — including the subprocessor list above, the Standard Contractual Clauses, and LGPD processing terms — is available to all customers. Request it at [email protected].
13. If you received an email sent through MillionSend
The sender, not MillionSend, chose to email you and controls your data. Use the unsubscribe link in the message — marketing email sent through MillionSend supports one-click unsubscribe — or contact the sender directly. If you believe a sender is abusing the platform, report it to [email protected].
14. Cookies
The dashboard uses only cookies and local storage necessary to sign you in and remember preferences such as theme and language. We do not run third-party advertising or cross-site tracking cookies.
15. Children
The service is not directed to children under 16, and we do not knowingly collect their personal data.
16. Changes to this policy
We may update this policy; material changes will be announced by email or in the dashboard before they take effect. The current version always lives at this page.
17. Contact
CODARI GLOBAL, LLC, doing business as MillionSend. Notices: 7345 W Sand Lake Rd Ste 210, Office 4592, Orlando, FL 32819, USA · [email protected]. EU/UK and Brazil data-protection inquiries reach our privacy team at the same address.