Privacy Policy

Last updated: 22 August 2026

ICO Registration Number: ZC101614

1. Who we are

Mailbox Fleet is a trading name of Meridian Interface Ltd, a company registered in England and Wales (Company No. 16150489). Our registered address is Park House, Wilmington Street, Leeds, LS7 2BP.

We provide managed cold-email sending infrastructure for business customers: we provision and operate the sending domains, mailboxes and IP addresses our customers use for their outreach, with deliverability and compliance controls built in.

For data protection enquiries, contact us at: privacy@peachdata.co.uk

2. The two roles we act in

Under the UK GDPR we act in two distinct roles, and your rights run differently under each:

  • As a controller for the data we decide to collect ourselves: customer accounts, identity verification and business vetting, sanctions screening, billing, our platform-wide suppression (opt-out) lists, service and deliverability telemetry, and this website.
  • As a processor for the recipient and campaign data our customers bring to the platform. Each customer is the controller of their own recipient lists and message content; we process that data only on their documented instructions under a data processing agreement.

If you received a marketing email sent through our infrastructure, the sender named in that email is the controller of your data. You can always opt out using the unsubscribe link in the message — we enforce that opt-out at platform level (section 6) — and you can contact us at privacy@peachdata.co.uk if you need help identifying or reaching the sender.

3. Customer accounts

When you create an account we process your name, work email address and sign-in credentials. Authentication is handled by our sign-in provider (Clerk); we never see your password. We use this data to operate and secure your account under our agreement with your organisation — Article 6(1)(b) UK GDPR (contract) and 6(1)(f) (legitimate interests in account security). Account data is kept for the life of the agreement.

4. Identity verification and business checks

Because sending infrastructure can be abused, we verify every customer before provisioning anything. Verification has an identity step, a business step and a screening step (section 5).

4.1 The identity check (biometric)

The self-serve identity check runs on Stripe Identity, our verification provider, on pages Stripe hosts: you photograph a government-issued identity document and take a short selfie, and Stripe uses biometric technology to confirm the document is genuine and belongs to you. Because the selfie comparison identifies you uniquely, this is special category biometric data under the UK GDPR.

  • Lawful basis: your explicit consent (Articles 6(1)(a) and 9(2)(a)). Starting the check is the affirmative act of consent, requested with clear notice on the page where you start it.
  • A real alternative: the biometric route is optional. You can verify manually with our team instead — same outcome, same one-business-day timescale — by emailing hello@commissionmadesimple.co.uk. Declining the biometric check never disadvantages your application.
  • What we receive: the verification outcome and the verified details (name, date of birth, document type and validity). Our vetting team can review the verification report in Stripe's dashboard; we do not copy identity documents, selfies or biometric data into our own systems.
  • Deletion: once the vetting decision is made — approved or not — we instruct Stripe to redact the verification session, which permanently deletes the images and extracted personal information from Stripe. We keep only a session reference, the outcome and our own decision records.
  • Stripe's role: Stripe processes verification data as our processor, and for limited purposes of its own (such as fraud prevention and legal compliance) as an independent controller — see Stripe's privacy policy.

4.2 The business check

We confirm the business you represent against public registers — principally Companies House — checking the company exists, is active, and that the verified individual is genuinely connected to it. This uses publicly available register data under Article 6(1)(f) (legitimate interests in preventing fraud and abuse of sending infrastructure).

5. Sanctions screening

UK financial sanctions law applies to all UK businesses, so before activating an account we screen the business and its beneficial owners against the UK Government's consolidated list of sanctions targets, and re-screen periodically while the account is active. Lawful basis: Article 6(1)(c) (legal obligation). We keep a record of each screening — what was checked, against which list version, and the result.

6. Suppression lists — how we honour opt-outs

When a recipient opts out of a customer's emails — through the one-click unsubscribe link, a reply, or a complaint — we record the email address in a suppression list, and our sending systems refuse to send to that address from then on. Platform-wide opt-outs (such as one-click unsubscribes) are our own controller processing; we keep them because deleting them would defeat their entire purpose: the opt-out would be forgotten.

  • Lawful bases: Article 6(1)(c) (our obligations under the Privacy and Electronic Communications Regulations to honour opt-outs) and 6(1)(f) (legitimate interests in enforcing recipients' choices against every customer on the platform).
  • Retention: suppression entries are kept indefinitely, because they exist to prevent contact permanently.
  • Erasure requests: if you ask us to erase your data, we redact the readable form of your address and keep only a cryptographic hash — enough to keep blocking mail to you, without holding your address itself.

Unsubscribe links must work without proving who you are: following one never requires sign-in and is effective immediately.

7. Delivery and service telemetry

Operating sending infrastructure produces operational records: delivery attempts and their outcomes (accepted, bounced, deferred), complaint notifications from mailbox providers, and the health signals mailbox providers publish about our sending domains and IPs. These records contain recipient email addresses and message metadata, not message bodies read by us. We use them to run the service, protect deliverability and detect abuse — Article 6(1)(b) and (f) — and customers see their own slice of this data in their dashboard. Records are kept while relevant to operating the service and then deleted or aggregated.

8. Data we process on our customers' behalf

Recipient lists and campaign content belong to our customers. For that data we are a processor: we act only on the customer's documented instructions under our data processing agreement, we require customers to have a lawful basis for their outreach and to comply with UK GDPR and PECR, and our acceptable-use policy and sending policy are contractual conditions of using the platform.

Platform safeguards apply to every send regardless of customer: suppression enforcement (section 6), a working unsubscribe path in every message, authentication (SPF, DKIM, DMARC) on every sending domain, and volume and reputation controls.

9. How long we keep data

  • Account data: life of the agreement, then deleted within 90 days except where retention is required below.
  • Verification and vetting records (outcomes, screening records, signed agreements — never identity documents, which Stripe deletes on redaction): up to 5 years after the relationship ends, reflecting limitation periods and sanctions record-keeping expectations.
  • Billing and invoicing records: 6 years, as required by UK tax law.
  • Suppression entries: indefinitely (section 6), redacted to a hash on request.
  • Delivery telemetry: while operationally relevant, then deleted or aggregated.
  • Enquiries and support: up to 12 months after the matter closes.

10. Your rights

As a data subject you have the following rights under the UK GDPR. Where we are a processor (section 8), we will pass your request to the customer who controls your data and help them answer it.

  • Access: request a copy of the personal data we hold about you.
  • Rectification: have inaccurate data corrected.
  • Erasure: request deletion. For verification data this triggers redaction at Stripe (section 4.1). For suppression entries we redact to a hash rather than delete, so your opt-out keeps working (section 6).
  • Objection: you have an absolute right to object to direct marketing — use the unsubscribe link or email us, and the opt-out is applied platform-wide.
  • Restriction and portability in the circumstances the UK GDPR provides.
  • Withdraw consent: where processing rests on consent (the biometric identity check), you can withdraw it at any time before completing the check by simply not proceeding — the manual route remains available — and afterwards by asking us to redact the verification session.

To exercise any right, contact privacy@peachdata.co.uk. We respond within one month and never charge for reasonable requests.

11. Data security

Personal data is protected by technical and organisational measures proportionate to the risk: encryption in transit and at rest, row-level security so each customer can only ever read their own records, least-privilege credentials with no shared administrative keys in application code, append-only audit records for compliance-relevant events, and access restricted to authorised personnel. Identity documents and biometric data never enter our systems at all — they are collected, held and deleted by Stripe (section 4.1).

12. Cookies and site analytics

We keep our use of cookies and tracking deliberately small. The first time you visit, a banner asks whether to enable optional tools. Your choice is stored in your browser and you can change it at any time using the control below.

No choice is saved right now. Use the banner at the bottom of the page to accept or reject optional tools.

CategoryWhat it doesConsent
Strictly necessarySign in and session security (Clerk), portal UI preferences and storage of your cookie choice itself.Always on
First party site analyticsPage views and interaction events (clicks, scroll depth) recorded against a hash that rotates daily on our servers, so visits cannot be linked across days. Your IP address and browser user agent are processed transiently on our servers and never stored in our analytics data; we use them to derive coarse signals only: approximate location (city level, from our hosting provider's request headers), device type, browser family and browser language. When you arrive from an advert we record the advertising platform (for example Google Ads or LinkedIn Ads) but not the click identifier itself.Always on (cookieless, no device storage)
Performance + privacy-friendly analyticsVercel Analytics and Vercel Speed Insights. Vercel describes both as cookieless; they collect aggregate device-level metrics so we can improve site speed.Only with your consent
Anti-spam (demo form)Google reCAPTCHA loads on the demo form to stop automated submissions. Loaded only after you accept or when you submit the form.Loaded on demand

We do not use advertising cookies, behavioural retargeting or social media trackers anywhere on this site. Site analytics events are retained for up to 12 months and then deleted.

Business visitor identification

For visits from business networks we look up the organisation associated with the visiting IP address so we can understand which companies are researching us. The lookup, performed by our processor ipinfo.io, returns a company name and city only. The IP address is used transiently for the lookup, held briefly in server memory to avoid repeat lookups and never stored in our analytics data. Visits from consumer internet providers are filtered out and no individual is identified. A match may generate an internal notification to our team.

We do this under Article 6(1)(f) of the UK GDPR (legitimate interests). It is covered by our Legitimate Interest Assessment, available on request at privacy@peachdata.co.uk.

13. Data you give us directly

Separately from the service data described above, we process personal data that you choose to give us when you interact with Mailbox Fleet:

  • Enquiries and demo requests: your name, work email address, company name and anything you write in the message. We use this to respond to you and take steps towards a contract at your request. Enquiry records are kept for up to 12 months after our last contact with you.
  • Billing: billing contact and payment details are handled by our payment provider (Stripe). We keep invoicing records for 6 years as required by UK tax law.
  • Support and email correspondence: kept for up to 12 months after the matter is closed.

We contact you only about your enquiry or the service. We do not add you to marketing lists and we do not share this information with anyone except the service providers listed in section 14.

14. Our service providers and international transfers

We use a small number of service providers to run Mailbox Fleet. Each processes personal data under a data processing agreement and only as needed for its function:

  • Website hosting and content delivery (Vercel)
  • Databases (Supabase)
  • Sign in and account security (Clerk)
  • Identity verification (Stripe Identity — section 4.1)
  • Payments and invoicing (Stripe)
  • Sending infrastructure hosting (Hetzner, Germany/EU)
  • Network security and content delivery for unsubscribe pages (Cloudflare)
  • Transactional email (Resend)
  • Content management for our blog (Sanity)
  • Spam protection on the demo form (Google reCAPTCHA)
  • Business network lookup for visitor identification (ipinfo.io)

Some of these providers are based in the United States. Where personal data is transferred outside the UK, the transfer is protected by the UK Extension to the EU-US Data Privacy Framework or by the ICO's International Data Transfer Agreement or Addendum, as applicable to the provider. You can request further detail on the safeguard used for any provider at privacy@peachdata.co.uk.

15. Changes to this policy

We review this policy annually and following any significant change to our processing activities. The current version date is shown at the top of this page.

16. Complaints

If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk | 0303 123 1113

We would appreciate the opportunity to address your concerns directly before you contact the ICO. Please email privacy@peachdata.co.uk first.