MailCraft Campaign Studio ("the Application") is a proprietary email campaign tool. The Application is owned and operated by Rujuta Sawant. For any privacy-related enquiries, contact the Application owner directly.
MailCraft is designed with a minimal data footprint. The table below describes what is processed and where it is stored:
| Data | Where Stored | Purpose | Retention |
|---|---|---|---|
| Login credentials (email & password) | Vercel environment variables (server-side) | Authenticate the authorised user | Until changed by admin |
| Session token | Browser localStorage | Keep user logged in | Until logout or browser clear |
| Campaign settings (headline, design, footer text) | Browser localStorage | Persist user preferences between sessions | Until browser clear |
| Contact list (send list) | Browser memory only (not persisted) | Drive the campaign send | Lost on page close |
| Suppression / opt-out list | Browser localStorage | Prevent sending to unsubscribed recipients | Until manually cleared |
| Terms acceptance record | Vercel function logs + browser localStorage | Compliance audit trail (B2 requirement) | Vercel logs: 3 days (free tier). localStorage: until cleared. |
| Recipient email addresses (campaign sends) | Transmitted to Resend API only | Deliver email campaigns | Per Resend's privacy policy |
Key point: MailCraft does not store recipient contact data on its own servers. Contact lists are held in your browser only and passed directly to Resend for delivery.
When you upload a contact list and send campaigns through MailCraft, you are the data controller and the Provider acts as your data processor under the Data Processing Agreement, processing recipient personal data only on your instructions and solely to deliver your campaigns.
As data controller, you are responsible for:
MailCraft uses the following third-party service as a data processor:
MailCraft does not use tracking cookies. It uses browser localStorage to store your session, campaign settings, and opt-out list. This data remains in your browser and is not transmitted to any server (except where explicitly described in Section 2 above). You can clear this data at any time via your browser's storage settings.
Access to the Application is protected by password authentication. API keys used to send campaigns are stored in your browser's localStorage and are transmitted only to the Application's own Vercel serverless function, which forwards them to Resend over HTTPS. You are responsible for keeping your login credentials and API key confidential.
Under UK GDPR, you have the right to access, correct, or delete personal data held about you by the Application. As described in Section 2, very little personal data is held server-side. To exercise any of these rights, contact the Application owner.
MailCraft requires a Resend API key to send campaigns. This key is provided by the account holder and is stored only in their browser's localStorage. It is never stored on MailCraft's servers.
The account holder is solely responsible for:
Important: The Application owner accepts no liability for any misuse, unauthorised use, or exposure of the account holder's Resend API key. Any breach of Resend's Terms of Service resulting from the account holder's key is the sole responsibility of the account holder.
This Privacy Policy may be updated at any time. The current version and effective date are shown at the top of this page. Continued use of the Application after any update constitutes acceptance of the revised policy.