Privacy Policy
Version 1.0, effective 22 September 2026
In short: We collect what we need to run your account and bill you. Recipient data that you send through the API is processed on your instructions as an operator under POPIA, encrypted at rest, and message bodies are redacted after 30 days. We use no advertising or tracking cookies, and we do not sell personal information.
1. Who is responsible
Sendbaze (Pty) Ltd (registration number 2026/758394/07), Tygerpoort, Monroe Close, Shere, Silver Lakes, Pretoria, Gauteng, 0084, South Africa, is the responsible party for the account information described in this policy and the operator for Customer Content. Our Information Officer is Leo Saini, registered with the Information Regulator, reachable at privacy@sendbaze.com.
This policy is written for POPIA. Where you or your recipients are in the European Union or United Kingdom, the GDPR terms controller and processor correspond to responsible party and operator, and the rights in section 8 apply equally.
2. Two kinds of personal information
Account information is information about you and your team: names, email addresses, company details, billing details, login activity, support conversations and requests you submit through the website, including early-access requests. Sendbaze is the responsible party for this information.
Customer Content is information you submit through the API or dashboard to send messages: recipient email addresses and phone numbers, message contents, contact records and consent records. You are the responsible party and Sendbaze is your operator. Our obligations as operator are set out in the Data Processing Agreement, which applies to every customer automatically.
3. What we collect about you and why
- Registration and profile details: name, email address, organisation name, role. To create and secure your account and to contact you about it. Basis: performance of a contract.
- Early-access request details: name, work email, company, website, what you plan to send and expected volume. To evaluate and set up your account and to reply. Basis: steps taken at your request before a contract.
- Billing details and payment references, processed by Paystack. To invoice you and to comply with tax law. We never see or store full card numbers. Basis: contract and legal obligation.
- Usage data: API requests, message counts, timestamps, IP addresses, user agents, request ids. To operate the Service, show you your logs, prevent abuse, rate-limit and investigate incidents. Basis: legitimate interest in running a secure service.
- Support and abuse correspondence. To help you and to act on reports. Basis: contract and legitimate interest.
- Domain and DNS records you add, and sender IDs you request. To verify that you may send from them. Basis: contract.
4. Cookies and tracking
The marketing site at www.sendbaze.com sets no cookies and uses no analytics, advertising or social-media trackers. Pages are served without third-party scripts.
The dashboard sets only the cookies needed to keep you signed in and to protect against cross-site request forgery. They are first-party, marked secure and HTTP-only where the browser allows, and expire when your session ends or after 30 days, whichever is sooner. There is nothing to opt out of because there is no tracking to opt out of. If that changes we will update this section and ask for consent where POPIA or ECTA requires it.
Emails sent through Sendbaze contain open and click tracking only if you, the customer, enable it for your organisation. Where enabled, the tracking pixel and rewritten links are served from a domain you control or from a Sendbaze tracking domain, and the resulting events are Customer Content that belongs to you.
5. How we process Customer Content
- Recipient addresses and numbers are encrypted at rest. Message bodies are redacted 30 days after sending; metadata such as status, timestamps and segment counts is retained for your logs and invoices.
- Customer Content is shared only with the providers needed to deliver it: Amazon Web Services (Simple Email Service, Africa (Cape Town) region) for email and our SMS aggregators for SMS.
- Each organisation's data is isolated at the data-access layer. Sendbaze staff access Customer Content only to provide support you request, to investigate abuse or a security incident, or as required by law, and such access is logged.
- Bounce, complaint and opt-out signals are stored in suppression lists, per organisation and, for hard bounces and spam complaints, platform-wide, so that no customer keeps sending to an address or number that has rejected mail. Suppression lists contain the address or number, the reason and the date, nothing else.
6. Who we share information with and where it lives
We update this list at least 14 days before adding a provider that processes Customer Content, by email to organisation owners, as the Data Processing Agreement describes.
Some providers process personal information outside South Africa. Where they do, we rely on section 72(1)(a) of POPIA: each provider is bound by a written contract, binding corporate rules or a law that provides a substantially similar level of protection to POPIA, including limits on onward transfer. Copies of the relevant contractual terms are available on request.
- Email delivery: Amazon Web Services, Simple Email Service, Africa (Cape Town), South Africa.
- SMS delivery: licensed SMS aggregators connected to the mobile networks in the countries we deliver to.
- Database and file storage: Supabase (Postgres), hosted on Amazon Web Services in Frankfurt, Germany.
- Queue: Upstash (Redis), European Union.
- Workers: Fly.io, Johannesburg, South Africa.
- Website and API hosting: Vercel, with serverless functions in the European Union and a global content delivery network for static pages.
- Payments: Paystack (South Africa and Nigeria). Authentication: Clerk (United States). Error monitoring and logs: Sentry and Axiom (European Union).
- Professional advisers under confidentiality, and public authorities where the law requires disclosure. We tell you about a request for your data unless the law forbids it.
7. Retention
- Account information: for the life of the account and up to 5 years afterwards for tax, accounting and legal records.
- Early-access requests that do not become accounts: 12 months, then deleted.
- Message bodies: 30 days. Message metadata and events: 13 months, or longer where your plan includes extended logs.
- Consent records: for as long as the related contact exists in your organisation, and 3 years after deletion to evidence compliance.
- Suppression lists: until the address or number is removed by the responsible customer or by us on the data subject's request.
- Backups: rolling 30 days. Security and access logs: 12 months.
- After termination: export for 30 days, deletion within a further 30 days, backups within a further 30 days.
8. Your rights
Under POPIA you may ask what personal information we hold about you, ask us to correct or delete it, object to processing, and withdraw consent where processing is based on consent. Email privacy@sendbaze.com or use the Information Regulator's Form 1 (objection) or Form 2 (correction or deletion). We acknowledge requests within 5 business days and respond within 30 days. There is no charge for a first request; a reasonable fee may apply to repeated requests as PAIA allows.
If you received a message sent by one of our customers, that customer is the responsible party. We will pass your request to them within 5 business days and, for opt-outs, add you to their suppression list immediately. You can also reply STOP to any marketing SMS.
Our PAIA manual, prepared under section 51 of the Promotion of Access to Information Act, 2 of 2000, is available on request from the same address.
You may complain to the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; complaints by email to POPIAComplaints@inforegulator.org.za; www.inforegulator.org.za.
9. Security
We apply the safeguards section 19 of POPIA requires: encryption in transit (TLS 1.2 or higher) and at rest, API keys stored only as hashes, least-privilege and role-based access, multi-factor authentication for staff and available to customers, audit logs of security events, dependency and secret scanning in the build pipeline, and daily backups with restore tests.
No system is perfectly secure. If a security compromise affects personal information we notify the Information Regulator and affected data subjects or, for Customer Content, the responsible customer, as soon as reasonably possible and as section 22 of POPIA requires, with what happened, what was affected and what we are doing about it.
10. Children
The Service is for businesses and adults. We do not knowingly collect account information from anyone under 18. Customers may not send special personal information or personal information of children through the Service unless the law permits it and we have agreed in writing.
11. Changes
We notify organisation owners by email of material changes at least 14 days before they take effect, and each version carries its version number and effective date at the top of the page. Previous versions are available on request.
12. Contact
Information Officer: Leo Saini, privacy@sendbaze.com. Postal and physical address: Sendbaze (Pty) Ltd, Tygerpoort, Monroe Close, Shere, Silver Lakes, Pretoria, Gauteng, 0084, South Africa.