Privacy policy
Last updated 21 September 2026
mailcatchr is operated by Flahive Precision Engineering Pty. Ltd. (ABN pending), Australia ("we"). This page says what we collect when you visit mailcatchr.com or use the mailcatchr service, why, how long we keep it, who else processes it, and the choices you have. Questions go to support@mailcatchr.com.
What we collect and why
| Data | When | Why |
|---|---|---|
| Email address, password (stored as a hash), company name | You create an account | To sign you in and name your workspace. Your email also receives the verification code, password resets and service notices. |
| Test email your application sends to your mailbox subdomains, including attachments and headers | Mail arrives at a mailbox | This is the service: you read it back from the dashboard, the API, IMAP or POP3. It is deleted after your mailbox's retention window. |
| Requests captured by webhook interceptors | A system you test calls an interceptor URL | So you can inspect and replay them. Deleted after the interceptor's retention window. |
| Authenticator secrets you register | You add a TOTP authenticator | To produce codes for your tests. Encrypted at rest; never shown again after registration. |
| Billing details | You upgrade or top up | Handled by Stripe. We store the Stripe customer and subscription ids, your plan and invoice history, never card numbers. |
| Usage and audit records: request counts, storage used, sign-ins, admin actions, IP addresses in server logs | You use the service | To enforce plan limits, keep the service secure, investigate abuse and support you. |
| Where you came from (UTM parameters and ad click ids in the address you arrived on) | You land on mailcatchr.com and later sign up | To know which pages and campaigns lead to signups. Kept in a first-party cookie for 30 days and stored with your account if you sign up. |
| Analytics events (pages viewed, signup completed, plan purchased) | Only if you allow analytics in the banner | Sent to Google Analytics and Google Ads so we can measure our own advertising. Your email is hashed in your browser before it is sent, and only to match a conversion to an ad click. |
Cookies
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
mc_consent | mailcatchr.com | Remembers your analytics choice. | 180 days |
mc_attr | mailcatchr.com | Remembers the campaign you arrived from until you sign up. | 30 days |
| Session cookie | app.mailcatchr.com | Keeps you signed in to the dashboard. Essential. | Until you sign out or it expires |
_ga and related | Google Analytics | Distinguishes visitors for measurement. | Up to 2 years |
Analytics cookies are set only after you choose "Allow analytics". Choosing "No thanks" is remembered and nothing is measured. To change your mind, clear the mc_consent cookie for mailcatchr.com and the banner will ask again.
How long we keep things
- Test messages and attachments: your mailbox's retention window, 3 days on the Free plan and up to 30 days on Business, then deleted.
- Captured webhook requests: the interceptor's retention window, then deleted.
- Account, workspace and billing records: while your account exists. You can export your workspace data or delete the workspace and account from the dashboard at any time; deletion removes the data within 30 days, except invoices we must keep for tax law.
- Server logs and audit records: up to 90 days.
Who else processes data
We use these providers, each under their own data processing terms:
- Amazon Web Services, Sydney region (ap-southeast-2): hosting, storage and email delivery. All customer data is stored in Australia.
- Stripe: payments and subscriptions.
- Cloudflare Turnstile: a check that signups are made by people, not scripts.
- Google Analytics and Google Ads: only with your consent, as described above.
We do not sell data and we do not share it with anyone else, except when the law requires it.
Your rights
You can see, export, correct and delete your data from the dashboard. If you are in the European Economic Area or the United Kingdom, you also have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR, and you may complain to your supervisory authority. Under the Australian Privacy Act you may ask for access and correction and complain to the Office of the Australian Information Commissioner. Write to support@mailcatchr.com for any of these.
Security
Data is encrypted in transit and at rest. Passwords are hashed. Authenticator secrets and mailbox credentials are encrypted with keys that never leave our infrastructure. Access to production is limited to the operator and is audited.
Changes
When this policy changes we update the date above. Material changes are announced in the dashboard.