Privacy Policy

Effective Date: July 1, 2026 · Last Updated: July 2026

1. Introduction & Core Privacy Commitment

RenderOps("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we process it, and your rights under global privacy regulations, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Our 100% Client-Side Architecture Guarantee: All standard email engineering utilities (including our CSS Inliner, Spam Checker, Table Converter, Accessibility Auditor, Dark Mode Simulator, and Diff Viewer) run 100% locally inside your web browser. Your proprietary email templates, code, and subscriber copy are never uploaded to, stored on, or analyzed by our servers.

2. Information We Collect

We collect only the minimum necessary information required to deliver and secure our Service:

  • Account Information: When you register for an account or start a Pro trial, we collect your email address and authentication credentials.
  • Payment & Subscription Information: Subscription purchases are processed directly by our primary Merchant of Record (Dodo Payments). We do not collect, store, or process credit card numbers or full banking details on our servers.
  • Transient Server-Side Requests: For specific edge features (such as AI template generation, live countdown timer GIF generation, and DNS MX/DKIM domain verification), request parameters pass through our secure Edge servers transiently. This data is held in volatile memory only for the duration of the HTTP request and is not stored permanently.
  • Anonymized Telemetry & Analytics: We collect aggregate, non-identifying usage statistics (such as page visits and feature adoption counts) to optimize performance and catch system errors.

3. How We Use Your Information

We process your personal information strictly for the following purposes:

  • To authenticate user sessions and provision Pro subscription features.
  • To process transactions and issue digital VAT/sales tax invoices through our Merchant of Record.
  • To deliver critical transactional communications (such as password reset links or subscription receipts).
  • To protect against malicious activity, unauthorized API abuse, and security threats.
  • To comply with statutory legal and financial reporting obligations.

We do not sell, rent, or trade your personal data to third parties or advertising networks.

4. Sub-Processors & Infrastructure Partners

We rely on trusted third-party cloud infrastructure providers to host and secure our Service:

  • Supabase: Provides encrypted PostgreSQL database storage and secure user authentication services.
  • Dodo Payments: Acts as our primary Merchant of Record (MoR) for secure checkout, payment card processing, automated recurring billing, and global tax compliance.
  • Vercel: Provides serverless edge hosting infrastructure, SSL certificate encryption, and global CDN asset routing.
  • OpenAI / Groq: Executes transient serverless calls for AI template generation and email summarization models.

5. Cookies & Local Browser Storage

We use essential cookies and local browser storage to maintain security and user preferences:

  • sb-access-token (httpOnly): Essential authentication cookie used to verify active user sessions securely (expires in 7 days).
  • sb-refresh-token (httpOnly): Essential security cookie used to maintain encrypted user login status (expires in 30 days).
  • Local Storage (Browser): Stores local UI preferences (such as code editor themes, tool state, and draft templates) locally on your device.

We do not employ third-party tracking pixels, remarketing tags, or cross-site tracking cookies.

6. Data Security & Retention

We implement robust technical and organizational security measures, including transport layer security (TLS 1.3) in transit and AES-256 encryption at rest. Authentication cookies are configured with strict httpOnly and SameSite=Lax attributes to mitigate Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities.

We retain account data for as long as your account remains active. If you delete your account, your personal data is permanently deleted from our primary databases within 30 days.

7. Your Rights under GDPR & CCPA

Depending on your location, you have the following data protection rights:

  • Right of Access: You may request a copy of the personal information we hold about you.
  • Right to Rectification: You may request that we correct any incomplete or inaccurate data.
  • Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and personal data.
  • Right to Data Portability: You may request an export of your account data in a structured, machine-readable format.
  • Right to Opt-Out: You may opt out of non-essential product update emails at any time via the unsubscribe link.

To exercise any of these rights, please contact our Data Protection Officer at privacy@renderops.tech. We respond to all verified requests within 30 days.

8. Updates to This Policy

We may update this Privacy Policy periodically to reflect technological updates or legal requirements. Material changes will be announced via email or via a prominent notification banner on our website prior to taking effect.

9. Contact Information

For questions or concerns regarding this Privacy Policy or our data practices, please contact us at:

📧 Email: privacy@renderops.tech