Last updated: August 2026
Privacy Policy
This policy describes how eusend collects and uses data when you use our service.
1. Who we are
Eusend is a transactional email service operated by Bjørnerås Labs (org.nr. 938 162 336), a Norwegian sole proprietorship and the data controller for the personal data described in this policy. Your email sending data is stored and delivered exclusively inside the European Union; the supporting services we use around it are listed in section 5. You can reach us at [email protected].
2. Data we collect
Account data — when you sign up we collect your name, email address, and a hashed password.
Email sending data — when you use the API to send email, we process the recipient addresses, message content, and delivery metadata (timestamps, bounce codes, open and click events) on your behalf. This data belongs to you and is processed only to deliver the service.
Open and click tracking — where you leave tracking enabled, an open records the requesting user agent and a click records the destination link. Neither records the recipient’s IP address, and we derive no location from it. You control whether this happens at all: tracking can be switched off per send, or for your whole organization in your settings. Because you decide whether to email these recipients and whether to measure them, you are the controller for that choice — see our Data Processing Addendum.
Content you save — if you store contact lists (audiences), reusable templates, or broadcasts in your account, we keep that content so you can reuse it. It belongs to you and stays until you delete it or close your account.
Billing data — Polar is the seller of record for every purchase and handles payment itself. We store only a Polar customer and subscription ID; we never see or store your card number.
Usage data — we log API requests for rate limiting, debugging, and abuse prevention. These operational logs are retained for up to 90 days.
Website analytics — we count visits to our public website using Umami, which we host ourselves on our own servers in Germany. It sets no cookies and stores nothing on your device, and the data never leaves our infrastructure or reaches a third party. Each request’s IP address and user agent are combined into a one-way hash so we can tell repeat page views apart within a day; the salt rotates daily and the IP address itself is never stored. We record the page visited, the referring site, the country, and rough device type. We do this on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in knowing which pages are useful. The dashboard, admin, and API are not covered — analytics runs on our public pages only.
3. How we use your data
- To operate and improve the email delivery service
- To authenticate your account and secure your API keys
- To process billing and send receipts
- To detect and prevent abuse, spam, and fraudulent use
- To respond to support requests
We do not sell your data or use it for advertising.
4. Data storage and residency
All customer data is stored within the European Union, on a mix of infrastructure we operate ourselves and managed EU providers:
- Germany (API servers and email delivery — Hetzner, Nuremberg and Falkenstein)
- Germany (managed database — UpCloud, Frankfurt)
- Finland (managed object storage for email attachments and template images — UpCloud)
- Germany (application error and performance diagnostics — Sentry EU region), as described in the next section
Your email sending data — recipient addresses, message content, and delivery events — is stored and delivered exclusively from these EU servers. A small number of external services support the platform around it; they are listed in the next section.
5. Sub-processors and third-party services
We keep the list of third parties short. The canonical, always-current list — with each one’s role, location, and transfer safeguard — lives on our Sub-processors page. Here is what each one does:
Hetzner (Germany) — hosts our application servers, queue, email delivery, and encrypted backups on EU machines we manage.
UpCloud (UpCloud Ltd, Finland) — hosts our managed application database (Frankfurt, Germany) and our managed object storage (Finland), both with encryption at rest. The database holds your recipient lists, message content, and account data; the object storage holds the files your emails carry — attachments and the images used in your templates.
Polar (Polar Software, Inc., USA) — the seller of record for all eusend purchases. Unlike the other services on this page, Polar is not our sub-processor: it sells the subscription to you in its own name and is an independent data controller for your billing data. It holds your name, email address, billing address, any tax identifier you provide, and your payment method. We receive only a customer ID, a subscription ID, and the plan you are on — never your card number. Polar is a US company, so your billing data is processed outside the EU/EEA — note that this applies to billing data only. The emails you send, your recipient lists, and your account content never reach Polar and remain on EU infrastructure as described above. Your billing data is governed by Polar's privacy policy, and you can exercise your data rights over it directly with Polar.
Cloudflare (USA) — provides DNS and sits as a security layer in front of our website and dashboard, so requests to those pages (including your IP address and request metadata) pass through Cloudflare's network in transit. Cloudflare also receives mail sent to our own operational addresses (such as abuse reports and bounce feedback) and runs the bot check on our signup form. Cloudflare does not store your email sending data, contacts, or database contents. Cloudflare is certified under the EU–U.S. Data Privacy Framework.
Vercel (USA) — serves the website and dashboard front-end. Requests to those pages are processed by Vercel; your email sending data is not stored there. Vercel is certified under the EU–U.S. Data Privacy Framework.
Better Stack (Czech Republic, EU) — monitors the uptime of our public endpoints. It only checks that our services respond and has no access to customer data.
Sentry (Functional Software, Inc., USA) — captures application error reports and performance traces so we can detect and fix faults. Diagnostic data (such as your IP address, the page or API request that failed, and technical error details) may be included in these reports. Sentry does not store your email sending data, contacts, or database contents. We use Sentry's EU data region, so this diagnostic data is stored in Germany.
6. Data retention
Sent-email logs and delivery events (opens, clicks, bounces) are retained for 30 days on Free, Lite, and Starter — 90 days on Pro and Scale — and then deleted automatically.
That window covers the rendered message body as well as the delivery record; both are deleted on the same schedule. Attachments are deleted sooner: they are held for 30 days on every plan and then removed from the storage they are held in, so on Pro and Scale they go before the log entry does. Past that point the entry still records the filename, size, and type of what was sent, but not the file. Nothing is archived.
Content you save in your account — audiences and contacts, templates, and broadcasts — is kept until you delete it. Account data is retained while your account is active and deleted within 30 days of account closure — unless we are legally required to retain it — at which point your sending identity is torn down as well.
7. Your rights
You can at any time:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion of your account and associated data
- Export your data in a machine-readable format
To exercise any of these rights, email [email protected].
8. Cookies and analytics
We use a single session cookie to keep you logged into the dashboard. We do not use tracking or advertising cookies.
Our website analytics sets no cookies and no other identifier on your device, which is why you see no cookie banner here — see section 2.
9. Changes to this policy
We may update this policy from time to time. We will notify registered users of significant changes by email. The date at the top of this page indicates when it was last updated.
10. Contact
Questions or concerns? Email us at [email protected].