Privacy Policy
Last updated: August 17, 2026. This policy explains what we collect, why we collect it and the control you have over it.
Last updated: August 17, 2026
Contents
- 1. Scope and roles
- 2. Data we collect
- 3. How we use data
- 4. Connected mailbox credentials & encryption
- 5. Sub-processors and international transfers
- 6. Cookies and tracking
- 7. Data retention
- 8. Security
- 9. Billing data
- 10. GDPR rights (EU/UK)
- 11. CCPA/CPRA rights (California)
- 12. Children's privacy
- 13. Breach notification
- 14. Changes to this policy
- 15. Contact
1. Scope and roles
This policy describes how MunchReach, Inc. ("MunchReach", "we", "us") collects, uses and protects personal data when you use our website, email outreach platform and API (together, the "Service").
When you use MunchReach to manage Leads and Contacts or send Campaigns, Sequences, follow-ups and replies, you act as the data controller for that customer-provided data and MunchReach acts as a data processor operating on your documented instructions. When we process account, billing, security and support data for our own business purposes, MunchReach acts as a controller.
2. Data we collect
Account data: name, email address, password hash and sign-in identifiers.
Workspace data: workspace names, membership, roles, invitations and audit logs of administrative actions.
Lead and contact data: email addresses, names, company information, job details, custom fields, lists, suppression status and other records customers upload or create.
Campaign data: Campaigns, Sequences, templates, personalized content, schedules, Recipients and related settings.
Connected Mailbox data: Email Account connection details, authorization tokens or credentials, Mailbox Authentication results, sender settings and identifiers needed to send Email Messages and sync replies.
Email communication data: message content, headers, Sending Activity, delivery and bounce events, complaints, unsubscribes, replies, conversations and Unified Inbox records.
Analytics and activity data: sends, delivery evidence, opens, clicks, replies, positive replies, bounces, unsubscribes, campaign performance and account activity.
Billing data: plan, subscription, invoice, payment status and transaction metadata. Full payment card details are handled by our payment processor rather than stored by MunchReach.
Integration data: connected integration settings, authorization data and records exchanged when you enable an integration.
Technical data: IP address, browser type, device identifiers and usage logs collected for security, analytics and abuse prevention.
Support communications: the content of tickets, emails, ratings or other messages you send us, including any attachments.
3. How we use data
To provide the platform: authenticating users, managing workspaces, connecting Email Accounts, sending Email Messages on your behalf, running Campaigns and Sequences, syncing replies and conversations, deduplicating Leads and Contacts, applying suppression rules and producing Analytics.
To secure the Service: detecting abuse, fraud, credential stuffing and unauthorised access, and enforcing our Acceptable Use Policy.
To support you: responding to requests, diagnosing issues you report and providing onboarding.
To improve the Service: aggregated, de-identified usage statistics that cannot be tied back to an individual.
We do not sell personal data, and we do not use your lead or campaign content to train shared or third-party models.
4. Connected mailbox credentials & encryption
Credentials and authorization tokens used to connect Email Accounts and Mailboxes are encrypted with AES-256-GCM before storage, using keys held in a managed key-management service separate from the application database.
Decryption happens only inside server-side sending workers at the moment a send, sync, or connection test is performed, and is never exposed to the browser or logged in plaintext.
Access to decrypt operations is scoped per-workspace and recorded in internal audit logs.
5. Sub-processors and international transfers
We rely on a limited set of infrastructure, email-delivery, analytics and customer-support sub-processors to run the Service. A current list, including the purpose and location of each, is available on request at privacy@munchreach.app.
Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses or an equivalent adequacy mechanism with each relevant sub-processor.
We require every sub-processor to contractually maintain a level of data protection consistent with this policy and applicable law.
7. Data retention
Workspace and customer-provided data is retained while needed to provide the Service and is deleted or anonymised after account closure in accordance with our retention schedule, except where continued retention is required or permitted by law.
Deletion timing may vary by data type and by operational, security, fraud-prevention, dispute-resolution, tax or legal requirements.
Suppression records (opt-outs and bounces) are retained indefinitely, even after account closure, so that opt-outs are permanently honoured across the platform.
Billing records are retained for the period required by applicable tax and accounting law, typically 7 years.
8. Security
Access to workspace data is enforced at the database level with row-level security tied to workspace membership.
All traffic is encrypted in transit with TLS 1.2 or higher, and data is encrypted at rest using provider-managed disk encryption plus field-level encryption for credentials.
We use access controls, monitoring and security review processes designed to protect customer and personal data.
Employee access to production systems requires multi-factor authentication and is logged and reviewed.
9. Billing data
Payment card details are collected and processed directly by our PCI-DSS-compliant payment processor; MunchReach does not store full card numbers on its own systems.
We retain invoice metadata (amounts, dates, plan) for accounting and dispute-resolution purposes.
10. GDPR rights (EU/UK)
If you are located in the EEA or UK, you have the right to access, rectify, export, restrict, object to, or erase your personal data, and the right to lodge a complaint with your local supervisory authority.
Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Prospects contacted through a MunchReach customer's campaigns may direct rights requests to us at privacy@munchreach.app; we will forward the request to the responsible workspace controller and, on request, suppress the address across the platform.
11. CCPA/CPRA rights (California)
California residents have the right to know what personal information is collected, request deletion, correct inaccurate information, and opt out of the sale or sharing of personal information.
MunchReach does not sell or share personal information as those terms are defined under the CCPA/CPRA.
You may submit a verifiable request to privacy@munchreach.app; we will respond within 45 days as required by law.
12. Children's privacy
The Service is intended for business use by adults. We do not knowingly collect personal data from anyone under 16, and we will delete any such data if discovered.
13. Breach notification
In the event of a confirmed data breach affecting your personal data, we will notify affected workspace owners without undue delay and, where required by law, within 72 hours of becoming aware of the breach.
14. Changes to this policy
We will notify workspace owners by email at least 14 days before any material change to this policy takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
15. Contact
Questions about this policy or requests to exercise your rights can be sent to privacy@munchreach.app. We aim to respond to all verified requests within 30 days.
Questions about your data?
Our privacy team is happy to walk through anything in this policy.
