Privacy Policy
Last updated: August 17, 2026. This policy explains what we collect, why we collect it and the control you have over it.
Last updated: August 17, 2026
Contents
- 1. Scope and roles
- 2. Data we collect
- 3. How we use data
- 4. Sending credentials & encryption
- 5. Sub-processors and international transfers
- 6. Cookies and tracking
- 7. Data retention
- 8. Security
- 9. Billing data
- 10. GDPR rights (EU/UK)
- 11. CCPA/CPRA rights (California)
- 12. Children's privacy
- 13. Breach notification
- 14. Changes to this policy
- 15. Contact
1. Scope and roles
This policy describes how MunchReach, Inc. ("MunchReach", "we", "us") collects, uses and protects personal data when you use our website, application and API (together, the "Service").
When you use MunchReach to contact your own prospects, you act as the data controller for that prospect data and MunchReach acts as a data processor operating on your documented instructions. When we collect data about you as our customer or user (account, billing, support data), MunchReach is the controller.
2. Data we collect
Account data: name, email address, password hash, and authentication provider identifiers (e.g. Google OAuth subject ID).
Workspace data: workspace names, membership, roles, invitations and audit logs of administrative actions.
Campaign data: lead records you import, email content and templates, sending schedules, opens, clicks, replies and bounce/delivery events.
Connected mailbox data: OAuth tokens or SMTP/IMAP credentials, message headers and bodies needed to send and sync replies.
Technical data: IP address, browser type, device identifiers and usage logs collected for security, analytics and abuse prevention.
Support data: the content of tickets, emails or chat messages you send us, including any attachments.
3. How we use data
To operate the Service: authenticating you, sending email on your behalf, syncing replies, deduplicating leads and producing analytics.
To secure the Service: detecting abuse, fraud, credential stuffing and unauthorised access, and enforcing our Acceptable Use Policy.
To support you: responding to requests, diagnosing issues you report and providing onboarding.
To improve the Service: aggregated, de-identified usage statistics that cannot be tied back to an individual.
We do not sell personal data, and we do not use your lead or campaign content to train shared or third-party models.
4. Sending credentials & encryption
Provider credentials (SMTP passwords, API keys and OAuth refresh tokens) are encrypted with AES-256-GCM before storage, using keys held in a managed key-management service separate from the application database.
Decryption happens only inside server-side sending workers at the moment a send, sync, or connection test is performed, and is never exposed to the browser or logged in plaintext.
Access to decrypt operations is scoped per-workspace and recorded in internal audit logs.
5. Sub-processors and international transfers
We rely on a limited set of infrastructure, email-delivery, analytics and customer-support sub-processors to run the Service. A current list, including the purpose and location of each, is available on request at privacy@munchreach.app.
Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses or an equivalent adequacy mechanism with each relevant sub-processor.
We require every sub-processor to contractually maintain a level of data protection consistent with this policy and applicable law.
7. Data retention
Workspace data is retained while the workspace is active and for 30 days after deletion to allow recovery from accidental deletion.
Backups are rotated on a 30-day cycle and are purged of deleted workspace data at the end of that cycle.
Suppression records (opt-outs and bounces) are retained indefinitely, even after account closure, so that opt-outs are permanently honoured across the platform.
Billing records are retained for the period required by applicable tax and accounting law, typically 7 years.
8. Security
Access to workspace data is enforced at the database level with row-level security tied to workspace membership.
All traffic is encrypted in transit with TLS 1.2 or higher, and data is encrypted at rest using provider-managed disk encryption plus field-level encryption for credentials.
We perform regular access reviews, dependency scanning and third-party penetration testing at least annually.
Employee access to production systems requires multi-factor authentication and is logged and reviewed.
9. Billing data
Payment card details are collected and processed directly by our PCI-DSS-compliant payment processor; MunchReach does not store full card numbers on its own systems.
We retain invoice metadata (amounts, dates, plan) for accounting and dispute-resolution purposes.
10. GDPR rights (EU/UK)
If you are located in the EEA or UK, you have the right to access, rectify, export, restrict, object to, or erase your personal data, and the right to lodge a complaint with your local supervisory authority.
Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Prospects contacted through a MunchReach customer's campaigns may direct rights requests to us at privacy@munchreach.app; we will forward the request to the responsible workspace controller and, on request, suppress the address across the platform.
11. CCPA/CPRA rights (California)
California residents have the right to know what personal information is collected, request deletion, correct inaccurate information, and opt out of the sale or sharing of personal information.
MunchReach does not sell or share personal information as those terms are defined under the CCPA/CPRA.
You may submit a verifiable request to privacy@munchreach.app; we will respond within 45 days as required by law.
12. Children's privacy
The Service is intended for business use by adults. We do not knowingly collect personal data from anyone under 16, and we will delete any such data if discovered.
13. Breach notification
In the event of a confirmed data breach affecting your personal data, we will notify affected workspace owners without undue delay and, where required by law, within 72 hours of becoming aware of the breach.
14. Changes to this policy
We will notify workspace owners by email at least 14 days before any material change to this policy takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
15. Contact
Questions about this policy or requests to exercise your rights can be sent to privacy@munchreach.app. We aim to respond to all verified requests within 30 days.
Questions about your data?
Our privacy team is happy to walk through anything in this policy.
