PRIVACY POLICY

Privacy Policy

This notice explains how Postlane handles personal data for the transactional email service at postlane.email.

Operator
TMD SPACE CO., LTD.
Service
Postlane · www.postlane.email
Effective
5 October 2026
Contact
info@tmdspace.com · +66 (0)2 679 3585

Read the Terms of ServiceAcceptable useContact

Who we areWhat this coversController and processorInformation we collectHow we use itWhy we may process itWho receives itInternational transfersHow long we keep itSecurityYour rightsCookiesChildrenChangesHow to reach us

1. Who we are

Postlane is operated by TMD SPACE CO., LTD. (“TMD SPACE”, “we”, “us”). Our registered office is 466/31 House Sathon Building, 6th Floor, Soi Suanplu, Thung Maha Mek, Sathon, Bangkok 10120, Thailand. Postlane is the transactional email service at https://www.postlane.email. This notice covers that service only. Other TMD SPACE products have their own notices.

Privacy, legal, billing, and abuse questions go to info@tmdspace.com or +66 (0)2 679 3585. You can also use the contact form. Do not send passwords, API keys, or full private message bodies unless we ask for a specific header or identifier to investigate a problem.

2. What this covers

This notice applies when you visit the site, create an account, pay for a plan, connect a sending domain, call the API, or write to us. It also describes personal data inside the emails you ask us to send, such as a recipient address or a name in a template.

Postlane sends mail your application requests. It is not a mailbox, webmail inbox, or marketing-broadcast product. We do not read your product’s database, and we do not sell personal data.

3. Controller and processor

We decide why and how we process account, billing, security, and support data. For that data we are the data controller under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA).

You decide the content, recipients, and purpose of the messages you send. For recipient data and message content that you submit to the API, you are the controller and we are the processor. We handle that data to provide the service, under the Terms of Service and your API requests. You must have a lawful basis to email each recipient.

4. Information we collect

Account

  • Name, email address, and account status.
  • A password hash and salt if you choose a password. We do not store the password itself.
  • If you continue with Google, your name, email address, and Google account identifier. The scopes we request are openid, email, and profile. We do not receive your Google password.
  • A session record: a hash of the session token, the kind of session, the user agent string, and the expiry time. The session cookie lasts 14 days.

Workspace

  • Workspace name, address slug, recovery email, contact email, and timezone.
  • Team memberships, roles, and invitations, including the invited email address.
  • API key name, scope, a hash of the secret, and a short prefix and tail so you can recognise the key. The full secret is shown once and is not stored in readable form.
  • Sending domains, verification status, and the DNS token we issue for that domain.
  • Saved templates: name, subject, HTML, and text.
  • Suppression entries: the recipient address, the reason, and whether it was added from the dashboard or from a delivery event.
  • Webhook URLs you configure.

Messages you send

For each API request we store the workspace, idempotency key, status, from address, recipient addresses, subject, HTML body, text body, provider message id, a short error description when a send fails, the time, and how many recipients counted toward your quota. Delivery events such as queued, delivered, deferred, bounced, failed, or complained are stored with a short detail.

Cloudflare authorization

If you authorize Cloudflare so we can add the DNS records you approve, we store the tokens required for that connection on the workspace. A short-lived cookie carries the authorization attempt. The browser window may also write a local result so the dashboard can tell whether authorization finished. That result is the domain name and whether it succeeded, not message content.

Billing

Launch and Scale are billed by Stripe. We store the plan, subscription status, and Stripe customer and subscription identifiers. Stripe collects the payment method, billing country, and tax details. We do not store card numbers.

Support and operations

The contact form collects your name, email address, and message, and delivers that message to info@tmdspace.com. We also keep security logs needed to run the service, including request identifiers and error details. We do not run a third-party advertising or analytics product on this site, and we do not drop marketing cookies.

5. How we use it

  • Create and secure your account, workspace, and sessions.
  • Verify domains, send the messages you request, record delivery events, and enforce suppressions.
  • Apply plan limits, bill subscriptions, and show usage.
  • Detect abuse, bounces, spam complaints, and compromised keys, and pause sending when a workspace is harming delivery.
  • Answer support and legal requests, and keep records we are required to keep.
  • Operate, debug, and protect the service.

We do not use message content to train public models, and we do not sell or rent personal data.

6. Why we may process it

Depending on the activity, we rely on one or more of these grounds:

  • Contract. Processing needed to provide the account, API, and paid plan you asked for.
  • Legal duty. Tax, accounting, and lawful requests from authorities.
  • Legitimate interests. Securing the service, preventing abuse, keeping delivery records, and improving reliability, where those interests are not overridden by your rights.
  • Consent. Where a law requires consent, such as an optional sign-in with Google that you start yourself. You can withdraw consent by stopping that method. Withdrawal does not undo processing that already happened lawfully.

7. Who receives it

We share personal data with the providers that run the service, and with recipients you address. We do not sell it.

ProviderRoleData involved
Cloudflare, Inc.Hosts the application, database, and email delivery. May also apply DNS records you authorize.Account and workspace data, message content, domains, delivery events, and the tokens needed for an authorized DNS change.
Stripe, Inc.Subscriptions, invoices, and the billing portal.Account email, workspace identifier, plan, and payment details Stripe collects directly.
Google LLCOptional sign-in.Name, email address, and Google account identifier, only if you choose Google.
Recipient mail serversDeliver the message you requested.The from address, recipient addresses, subject, and body of that message.

We may also disclose information if the law requires it, to protect customers and the service from fraud or abuse, or as part of a merger or sale of the business that operates Postlane. A buyer would have to honour this notice for the data it receives.

People you invite to a workspace can see workspace activity that their role allows, including domains, templates, and recent sends.

8. International transfers

TMD SPACE is established in Thailand. Cloudflare, Stripe, and Google process data in the countries where they operate, which can include the United States and other countries outside Thailand and outside the country where you or your recipients live. We use providers that offer contractual and technical safeguards appropriate to the service. Where the PDPA or another law requires a specific transfer mechanism, we use that mechanism.

9. How long we keep it

  • Activity you can see. The dashboard and the email list API show sends from the plan window: 7 days on Sandbox, and 30 days on Launch and Scale. Older rows drop off that view.
  • Stored message content. Subject, body, and recipient addresses are not deleted automatically when they leave the activity window. They remain while the workspace exists so we can operate sending, investigate abuse, and answer support questions.
  • Account and workspace data. Kept while the account is open.
  • Billing records. Kept for as long as Thai tax and accounting rules require, even after the subscription ends.
  • Security and abuse records. Kept for as long as needed to investigate, block, or defend a claim.
  • Contact messages. Kept until the enquiry is finished and any follow-up period we need has passed.
  • Sessions and sign-in cookies. The session cookie expires after 14 days. Google and Cloudflare authorization cookies expire after about 10 minutes.

You can ask us to delete a workspace’s message content or close an account. We will delete or anonymize what we hold, except records we must keep for billing, abuse prevention, or a legal duty. There is no self-serve delete button yet, so send the request from the account email to info@tmdspace.com.

10. Security

Passwords and API secrets are stored as hashes. Session cookies are HTTP-only, restricted to this site, and marked secure on HTTPS. Workspaces are separated in the application. Access to production systems is limited to people operating the service.

No method of transmission or storage is perfectly secure. This page is not a security certification or a penetration-test report. If you believe an account or key is compromised, revoke the key in the dashboard and write to info@tmdspace.com.

11. Your rights

Under the PDPA, and under other privacy laws when they apply to you, you may ask to access, correct, delete, restrict, or object to processing of your personal data, ask for a portable copy where the law provides that right, and withdraw consent where processing is based on consent. You may also complain to the Personal Data Protection Committee of Thailand, or to the supervisory authority where you live.

Send requests to info@tmdspace.com from the email on the account, or with enough detail for us to verify that the request is yours. We may ask for confirmation before we act. If you are asking about a message someone else sent through Postlane, contact that sender first. They control the content and the reason it was sent.

If you are a recipient and do not want further mail from a customer, use the sender’s unsubscribe or reply path where the message has one. You may also write to info@tmdspace.com with the from address and the time of the message. We can suppress further sends from that workspace when the report is valid. We do not control mail that a customer sends through a different provider.

12. Cookies

We use cookies that are required to sign you in and to finish a connection you start. We do not use advertising or analytics cookies.

CookiePurposeLifetime
postlane_sessionKeeps you signed in. HTTP-only.14 days
postlane_oauthCompletes Google sign-in.About 10 minutes
postlane_cf_oauthCompletes a Cloudflare DNS authorization you start.About 10 minutes

13. Children

Postlane is a business service. It is not directed at children under 16, and we do not knowingly create accounts for them. If you believe a child has given us personal data, write to info@tmdspace.com and we will delete the account when we confirm it.

14. Changes

We will post changes on this page and update the effective date. If a change materially reduces your rights, we will also give notice in the dashboard or by email to the account address before the change applies, where that is practical.

15. How to reach us

TMD SPACE CO., LTD.
466/31 House Sathon Building, 6th Floor, Soi Suanplu, Thung Maha Mek, Sathon, Bangkok 10120, Thailand
info@tmdspace.com
+66 (0)2 679 3585
Contact form