PRIVACY POLICY
Privacy Policy
This notice explains how Postlane handles personal data for the transactional email service at postlane.email.
Read the Terms of ServiceAcceptable useContact
1. Who we are
Postlane is operated by TMD SPACE CO., LTD. (“TMD SPACE”, “we”, “us”). Our registered office is 466/31 House Sathon Building, 6th Floor, Soi Suanplu, Thung Maha Mek, Sathon, Bangkok 10120, Thailand. Postlane is the transactional email service at https://www.postlane.email. This notice covers that service only. Other TMD SPACE products have their own notices.
Privacy, legal, billing, and abuse questions go to info@tmdspace.com or +66 (0)2 679 3585. You can also use the contact form. Do not send passwords, API keys, or full private message bodies unless we ask for a specific header or identifier to investigate a problem.
2. What this covers
This notice applies when you visit the site, create an account, pay for a plan, connect a sending domain, call the API, or write to us. It also describes personal data inside the emails you ask us to send, such as a recipient address or a name in a template.
Postlane sends mail your application requests. It is not a mailbox, webmail inbox, or marketing-broadcast product. We do not read your product’s database, and we do not sell personal data.
3. Controller and processor
We decide why and how we process account, billing, security, and support data. For that data we are the data controller under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA).
You decide the content, recipients, and purpose of the messages you send. For recipient data and message content that you submit to the API, you are the controller and we are the processor. We handle that data to provide the service, under the Terms of Service and your API requests. You must have a lawful basis to email each recipient.
4. Information we collect
Account
- Name, email address, and account status.
- A password hash and salt if you choose a password. We do not store the password itself.
- If you continue with Google, your name, email address, and Google account identifier. The scopes we request are openid, email, and profile. We do not receive your Google password.
- A session record: a hash of the session token, the kind of session, the user agent string, and the expiry time. The session cookie lasts 14 days.
Workspace
- Workspace name, address slug, recovery email, contact email, and timezone.
- Team memberships, roles, and invitations, including the invited email address.
- API key name, scope, a hash of the secret, and a short prefix and tail so you can recognise the key. The full secret is shown once and is not stored in readable form.
- Sending domains, verification status, and the DNS token we issue for that domain.
- Saved templates: name, subject, HTML, and text.
- Suppression entries: the recipient address, the reason, and whether it was added from the dashboard or from a delivery event.
- Webhook URLs you configure.
Messages you send
For each API request we store the workspace, idempotency key, status, from address, recipient addresses, subject, HTML body, text body, provider message id, a short error description when a send fails, the time, and how many recipients counted toward your quota. Delivery events such as queued, delivered, deferred, bounced, failed, or complained are stored with a short detail.
Cloudflare authorization
If you authorize Cloudflare so we can add the DNS records you approve, we store the tokens required for that connection on the workspace. A short-lived cookie carries the authorization attempt. The browser window may also write a local result so the dashboard can tell whether authorization finished. That result is the domain name and whether it succeeded, not message content.
Billing
Launch and Scale are billed by Stripe. We store the plan, subscription status, and Stripe customer and subscription identifiers. Stripe collects the payment method, billing country, and tax details. We do not store card numbers.
Support and operations
The contact form collects your name, email address, and message, and delivers that message to info@tmdspace.com. We also keep security logs needed to run the service, including request identifiers and error details. We do not run a third-party advertising or analytics product on this site, and we do not drop marketing cookies.
5. How we use it
- Create and secure your account, workspace, and sessions.
- Verify domains, send the messages you request, record delivery events, and enforce suppressions.
- Apply plan limits, bill subscriptions, and show usage.
- Detect abuse, bounces, spam complaints, and compromised keys, and pause sending when a workspace is harming delivery.
- Answer support and legal requests, and keep records we are required to keep.
- Operate, debug, and protect the service.
We do not use message content to train public models, and we do not sell or rent personal data.
6. Why we may process it
Depending on the activity, we rely on one or more of these grounds:
- Contract. Processing needed to provide the account, API, and paid plan you asked for.
- Legal duty. Tax, accounting, and lawful requests from authorities.
- Legitimate interests. Securing the service, preventing abuse, keeping delivery records, and improving reliability, where those interests are not overridden by your rights.
- Consent. Where a law requires consent, such as an optional sign-in with Google that you start yourself. You can withdraw consent by stopping that method. Withdrawal does not undo processing that already happened lawfully.
8. International transfers
TMD SPACE is established in Thailand. Cloudflare, Stripe, and Google process data in the countries where they operate, which can include the United States and other countries outside Thailand and outside the country where you or your recipients live. We use providers that offer contractual and technical safeguards appropriate to the service. Where the PDPA or another law requires a specific transfer mechanism, we use that mechanism.
9. How long we keep it
- Activity you can see. The dashboard and the email list API show sends from the plan window: 7 days on Sandbox, and 30 days on Launch and Scale. Older rows drop off that view.
- Stored message content. Subject, body, and recipient addresses are not deleted automatically when they leave the activity window. They remain while the workspace exists so we can operate sending, investigate abuse, and answer support questions.
- Account and workspace data. Kept while the account is open.
- Billing records. Kept for as long as Thai tax and accounting rules require, even after the subscription ends.
- Security and abuse records. Kept for as long as needed to investigate, block, or defend a claim.
- Contact messages. Kept until the enquiry is finished and any follow-up period we need has passed.
- Sessions and sign-in cookies. The session cookie expires after 14 days. Google and Cloudflare authorization cookies expire after about 10 minutes.
You can ask us to delete a workspace’s message content or close an account. We will delete or anonymize what we hold, except records we must keep for billing, abuse prevention, or a legal duty. There is no self-serve delete button yet, so send the request from the account email to info@tmdspace.com.
10. Security
Passwords and API secrets are stored as hashes. Session cookies are HTTP-only, restricted to this site, and marked secure on HTTPS. Workspaces are separated in the application. Access to production systems is limited to people operating the service.
No method of transmission or storage is perfectly secure. This page is not a security certification or a penetration-test report. If you believe an account or key is compromised, revoke the key in the dashboard and write to info@tmdspace.com.
11. Your rights
Under the PDPA, and under other privacy laws when they apply to you, you may ask to access, correct, delete, restrict, or object to processing of your personal data, ask for a portable copy where the law provides that right, and withdraw consent where processing is based on consent. You may also complain to the Personal Data Protection Committee of Thailand, or to the supervisory authority where you live.
Send requests to info@tmdspace.com from the email on the account, or with enough detail for us to verify that the request is yours. We may ask for confirmation before we act. If you are asking about a message someone else sent through Postlane, contact that sender first. They control the content and the reason it was sent.
If you are a recipient and do not want further mail from a customer, use the sender’s unsubscribe or reply path where the message has one. You may also write to info@tmdspace.com with the from address and the time of the message. We can suppress further sends from that workspace when the report is valid. We do not control mail that a customer sends through a different provider.
13. Children
Postlane is a business service. It is not directed at children under 16, and we do not knowingly create accounts for them. If you believe a child has given us personal data, write to info@tmdspace.com and we will delete the account when we confirm it.
14. Changes
We will post changes on this page and update the effective date. If a change materially reduces your rights, we will also give notice in the dashboard or by email to the account address before the change applies, where that is practical.
15. How to reach us
TMD SPACE CO., LTD.
466/31 House Sathon Building, 6th Floor, Soi Suanplu, Thung Maha Mek, Sathon, Bangkok 10120, Thailand
info@tmdspace.com
+66 (0)2 679 3585
Contact form