Updated14 Aug, 2026

Privacy Policy

This policy explains what personal data SentFast processes, why we process it, who we share it with and what rights you have. It covers the sentfa.st website, the SentFast dashboard and the SentFast API.

The commercial terms of the service are covered separately in our Terms of Service.

Who we are

SentFast is an API-first platform for creating, managing and sending transactional emails. SentFast operates the sentfa.st website and the related dashboard and API.

For any question about this policy or to exercise your rights, write to hi@sentfa.st.

Two different roles

SentFast processes two very different sets of data, and our role is not the same in each one:

  • As controller, for the data of the people who open a SentFast account: account details, billing, support and usage of the platform.
  • As processor, for the data our customers send through the platform — in particular recipient addresses and the variables of each email. In that case the customer is the controller, decides what is sent and to whom, and SentFast only processes that data to deliver the emails the customer requests.

Data we process

Account data. Sign-in is handled through Google. When you sign in we receive your name, email address, profile picture and the identifier of your Google account. We never receive your Google password.

Billing data. Plan, subscription or credit-pack status, payment records and the Stripe identifiers linked to your account. Card details are handled entirely by Stripe: they are never sent to, nor stored on, SentFast servers.

Workspace content. The projects, email templates and their versions, subjects, dynamic variables and the sending configuration you create in the platform. This content may contain personal data if you choose to include it.

API keys. Stored hashed. The full key is shown only once, at creation, and cannot be recovered afterwards.

Sending logs. For every email sent through the API we record the recipient address, any addresses in copy, the delivery status and its timestamps, the provider message identifier, the error reason if the send fails, the variables used to render the message, metadata about attachments, and technical metadata of the request such as IP address and user agent. Message bodies are rendered at send time from your templates.

AI-assisted generation. Where the platform offers AI-assisted content features, the inputs you submit and the generated output are stored against your account and processed by our AI provider.

Website analytics. When analytics is enabled, Google Analytics collects aggregated usage data about visits to sentfa.st.

Support. The content of the messages you send us through the contact form or by email.

Why we process it, and on what legal basis

  • To provide the service — accounts, workspaces, templates, API access and email delivery. Basis: performance of the contract.
  • To bill and keep accounts — subscriptions, one-off purchases and invoices. Basis: performance of the contract and compliance with our legal accounting obligations.
  • To keep the service secure — authentication, API key validation, usage limits, abuse and fraud prevention, diagnostics. Basis: our legitimate interest in operating a safe and reliable service.
  • To understand how the site is used — web analytics. Basis: your consent, where consent is required.
  • To answer you — support requests. Basis: performance of the contract or our legitimate interest in responding.

Data of your recipients

When you send an email through SentFast you decide the recipients and the content. You are responsible for having a lawful basis to contact them and for the accuracy of that data.

SentFast processes recipient data only to deliver your emails, to keep the delivery logs and analytics you see in your dashboard, and to detect abuse. We do not sell recipient data, we do not use it for our own marketing and we do not use it to train AI models.

Please do not put special categories of data — health, financial detail beyond what the message requires, credentials, or similar — into template variables or attachments.

Who we share data with

We rely on a small set of providers to run the service. Each of them processes data only for the purpose described below:

  • Google — sign-in with Google (authentication) and, when enabled, Google Analytics for website usage.
  • Stripe — payment processing, subscriptions, invoices and the billing portal.
  • OpenAI — processing of prompts and generated content in AI-assisted features, where those features are used.
  • Email delivery provider — the SMTP service used to hand your messages over to the recipient's mail server.
  • Hosting infrastructure — the application and the PostgreSQL database run on VPS infrastructure operated by SentFast.

We may also disclose data when required by law, or to establish or defend legal claims. We do not sell personal data.

International transfers

Some of the providers above may process data outside the European Economic Area. Where that happens, transfers rely on the mechanisms allowed by the GDPR — an adequacy decision or the European Commission's Standard Contractual Clauses, together with the additional safeguards each provider documents.

How long we keep it

  • Account, workspace content and sending logs — for as long as your account exists. Deleting a project deletes its templates, API keys and sending logs; deleting your account deletes all of them.
  • Billing records — for the period required by tax and accounting law, even after the account is closed.
  • Support messages — while needed to handle the request and for a reasonable period afterwards.
  • Web analytics — according to the retention set in Google Analytics.

Security

The service is served over HTTPS. API keys are stored hashed and are scoped to a single project, so a key can only send using the templates of the project that owns it. Access to production data is limited to what is needed to operate the service.

No system is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the competent authority as required by law.

Your rights

You can ask us to give you access to your personal data, correct it, erase it, restrict or object to its processing, or receive it in a portable format. Where processing is based on consent, you can withdraw that consent at any time.

Write to hi@sentfa.st and we will respond within one month. You also have the right to lodge a complaint with your data protection authority — in Spain, the Agencia Española de Protección de Datos.

If your request concerns an email you received from a SentFast customer, please contact that customer: they decide what is sent and are the controller of that data. We will forward the request when we can identify them.

Cookies

We use a session cookie to keep you signed in, and a preference cookie to remember your light or dark theme. These are necessary for the site to work.

When website analytics is enabled, Google Analytics sets its own cookies to measure aggregated usage. You can block them in your browser without losing access to the service.

Children

SentFast is a tool for businesses and developers and is not intended for people under 16. We do not knowingly collect their data.

Changes to this policy

We may update this policy as the product evolves. The date at the top always reflects the current version, and we will let account holders know about material changes.

Contact

Questions about privacy: hi@sentfa.st. For anything else, use the contact page.