Last Updated: August 4, 2026
Sending.ac is operated by Scale With Value Limited (“Sending.ac,” “we,” “us,” or “our”), a company incorporated in Hong Kong. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our email infrastructure platform, including domain provisioning, Azure mailbox setup, DNS configuration, backup infrastructure, third-party integrations, and related services (the “Service”).
This Privacy Policy applies to visitors to our website and users of our Service (“you,” “user,” “Customer”). It is designed to address the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable data protection laws.
1. Information We Collect
1.1 Information You Provide Directly
Account Information: name, email address, business name, phone number, billing address, and authentication information.
Payment Information: processed by a third-party payment processor; we do not store full payment card numbers on our own servers.
Domain & DNS Information: domain names you register or connect, DNS records, registrar credentials or authorization codes required for provisioning.
Mailbox & Integration Information: mailbox identifiers, sender names, configuration settings, authentication credentials or tokens, and integration details needed to provision, maintain, and connect mailboxes to third-party sending platforms.
Mailbox Communications: emails sent or received through provisioned mailboxes may be processed by the underlying mailbox provider and connected third-party sending platform. Sending.ac is mailbox infrastructure and does not itself provide a campaign-sequencing service.
Support Communications: information you provide when contacting us, including messages, attachments, and information needed to investigate and resolve your request.
1.2 Information Collected Automatically
Usage Data: log data, IP address, browser type, device identifiers, pages viewed, features used, and timestamps.
Infrastructure & Deliverability Data: provisioning status, mailbox and domain health, DNS and authentication status, usage and administrative logs, blocklist or reputation signals, abuse reports, and provider suspension or error information needed to operate and protect the Service.
Cookies and Similar Technologies: as described in Section 9.
1.3 Information from Third Parties
Information from integrated third-party platforms you authorize, including domain registrars and supported sending or warm-up platforms, to the extent necessary to provide the Service.
Fraud-prevention and identity-verification signals from payment processors.
2. How We Use Information
We use the information described above to:
Provide, operate, and maintain the Service, including domain provisioning, DNS configuration, Azure mailbox setup, backup infrastructure, and integrations with third-party sending and warm-up platforms;
Process payments and manage billing, including failed-payment follow-up;
Communicate with you about your account, service updates, security alerts, and support requests;
Monitor for Acceptable Use Policy violations, fraud, abuse, or security threats, including activity that could result in blocklisting, restriction, or suspension of customer or provider infrastructure;
Improve, develop, and troubleshoot the Service, including through aggregated or de-identified analytics;
Comply with legal obligations, enforce our Terms of Service, and protect our rights and the rights of other users;
Send marketing communications about our own products, where you have opted in or as otherwise permitted by law (with an opt-out available at any time).
We do not use Customer Data processed on your behalf for our own marketing purposes, and we do not sell such data.
3. Legal Bases for Processing (GDPR)
Where GDPR applies, we rely on the following legal bases:
Contractual necessity — to provide the Service under our Terms of Service;
Legitimate interests — for fraud prevention, service security, deliverability monitoring, and product improvement, balanced against your rights;
Consent — for optional marketing communications and non-essential cookies, which you may withdraw at any time;
Legal obligation — where processing is required to comply with applicable law.
Role as Processor. Where we process personal data on your documented instructions to provide the Service, we act as a data processor on your behalf, and you act as the data controller responsible for the lawfulness of that data and its use. Where required by applicable law, the parties may enter into a Data Processing Addendum (DPA).
4. Data Sharing & Third Parties
We do not sell your personal information. We may share information with:
Service Providers/Sub-processors: hosting providers, payment processors, domain registrars, email delivery infrastructure partners, customer support tools, and analytics providers, bound by contractual confidentiality and data protection obligations.
Integrated Third-Party Tools: sending and warm-up platforms you explicitly connect to your account, such as Instantly or Smartlead, which will receive data only as necessary to perform the integration you configure.
Legal & Compliance: where required to comply with law, legal process, or government request, or to protect the rights, property, or safety of Sending.ac, our users, or others.
Business Transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
5. International Data Transfers
As a Hong Kong-based company serving customers globally, we may transfer, store, and process information in jurisdictions other than your own, including the United States and the European Economic Area. Where required by applicable law, we use appropriate safeguards for international transfers, which may include contractual protections such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum.
6. Data Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
Account data is retained for the duration of your active account and for a reasonable period thereafter for legal, accounting, and fraud-prevention purposes.
Domain and DNS data associated with a domain is retained as needed to provide the Service and administer domain renewal, transfer, expiration, or termination under Section 6 of our Terms.
Mailbox and integration data is retained for the duration of the applicable service and deleted or deactivated after account closure, subject to legal obligations, provider requirements, and standard backup-cycle deletion timelines.
7. Data Security
We implement reasonable technical and organizational measures designed to protect information. Depending on the system and information involved, these measures may include encryption in transit, protection of sensitive credentials, access controls, logging, monitoring, and security reviews. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
8. Your Privacy Rights
8.1 GDPR/UK GDPR Rights (EEA/UK Residents)
Subject to applicable law, you have the right to:
Access the personal data we hold about you;
Request correction of inaccurate data;
Request erasure (“right to be forgotten”);
Restrict or object to certain processing;
Request data portability;
Withdraw consent at any time (without affecting prior lawful processing);
Lodge a complaint with your local data protection authority.
8.2 CCPA/CPRA Rights (California Residents)
Subject to applicable law, you have the right to:
Know what personal information we collect, use, disclose, and sell (we do not sell personal information);
Request deletion of your personal information;
Correct inaccurate personal information;
Opt out of any sale or “sharing” covered by applicable law, if such activity occurs;
Non-discrimination for exercising your privacy rights.
8.3 Hong Kong Privacy Rights
Subject to the PDPO, you may request access to personal data we hold about you and request correction of inaccurate personal data. We may take reasonable steps to verify your identity and may charge a fee where permitted by law.
8.4 How to Exercise Your Rights
Submit requests by contacting us through the message bubble in the bottom-right corner of our website. We will verify your identity before fulfilling requests and respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA, subject to permitted extensions).
9. Cookies & Tracking Technologies
We and our service providers may use cookies, local storage, scripts, and similar technologies to operate the Service, remember preferences, analyze usage, and improve performance. Our website currently uses analytics services that may include PostHog, Framer analytics, and Simple Analytics. Depending on their configuration, these services may collect technical, interaction, and session information.
Categories include:
Strictly Necessary Cookies — required for login, security, and core functionality.
Analytics and Session Technologies — help us understand usage patterns, diagnose problems, and improve the website and Service.
Marketing Technologies — may be used with consent where required for advertising, attribution, or retargeting.
Where a consent-management tool is presented, you can use it to manage non-essential technologies. You may also control cookies through your browser settings. Disabling certain technologies may affect functionality of the Service.
10. Children’s Privacy
The Service is intended for business use by individuals 18 years of age or older. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated policy with a revised “Last Updated” date and, for material changes, provide additional notice (e.g., via email or in-app notification).
12. Contact Information
For privacy-related questions, requests, or complaints:
Scale With Value Limited (operating as Sending.ac)
Hong Kong
Contact us through the message bubble in the bottom-right corner of our website.
Website: https://sending.ac
EEA/UK users may also contact their local supervisory authority if they believe their data protection rights have not been adequately addressed.