Effective 14 September 2026
Privacy Policy
This policy explains what information Email Campaign collects, how it is used, and the choices you have. Email Campaign is operated by Elena Digital at campaign.technologyelenasolution.in.
1. Who this policy covers
- Operators — people Elena Digital has given an account to sign in and run campaigns.
- Mailbox owners — people whose Gmail, Outlook or SMTP mailbox has been connected to send campaigns.
- Recipients — people whose email address is in a campaign’s recipient list.
2. Information we collect
Operator accounts
- Name, email address and password. Passwords are stored only as a salted scrypt hash, never in readable form.
- Sign-in sessions, including the IP address and browser user agent they were created from.
- An audit log of significant actions — such as creating or deleting a campaign, or connecting or removing a mailbox — with the time, IP address and user agent.
Connected mailboxes
- The mailbox’s email address, display name, and the provider’s account identifier.
- For Gmail and Outlook: the OAuth access and refresh tokens the provider issues, and the permissions granted.
- For SMTP: the server host, port, username and password.
- Sending counts, daily limits and health status used to pace campaigns.
OAuth tokens and SMTP passwords are encrypted with AES-256-GCM before they are stored, and are never written to logs.
Campaigns and recipients
- Campaign content, and any images or attachments uploaded for it.
- Each recipient’s email address, name, and any other columns included in the uploaded list, used to personalise messages.
- Delivery records for each message: status, attempts, the provider’s message identifier, and the reason for any failure.
- A suppression list of addresses that unsubscribed, bounced, or were excluded by an operator, with the reason and date.
3. Google user data
When a Gmail mailbox is connected, Email Campaign requests these Google permissions, and uses each only as described:
openidandemail— to identify which Google account was connected, so campaign messages are sent from the correct address.gmail.send— to send the campaign messages operators compose and schedule, from that mailbox. This permission cannot read, search, modify or delete mail.gmail.readonly— requested only if bounce detection is enabled.Email Campaign then searches the mailbox for messages frommailer-daemonorpostmaster— the automatic delivery-failure notices mail servers send back — and reads only those. From each notice it keeps the failed recipient’s address, the status code and the server’s one-line diagnostic. It does not store the notice itself, and it does not open, store or process any other message in the mailbox.
Email Campaign does not sell Google user data, use it for advertising, use it to train artificial-intelligence or machine-learning models, or transfer it to anyone except as needed to send the mail it was authorised to send or where the law requires. No person reads the contents of a connected mailbox.
Email Campaign’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Microsoft account data
When an Outlook or Microsoft 365 mailbox is connected, Email Campaign requests openid, email, profile and offline_access to identify the account and stay connected, and Mail.Send to send campaign messages.
If bounce detection is enabled it also requests Mail.Read. Microsoft’s API offers no way to search for delivery-failure notices directly, so Email Campaign lists the sender and subject of recently received messages to recognise those notices, and reads only the ones it recognises. It keeps the same three facts described above and nothing else from the mailbox.
5. How we use information
- To send campaigns operators create, through the mailboxes they have connected.
- To pace sending within each mailbox’s limits and protect its reputation.
- To honour unsubscribe requests and stop mailing addresses that bounce.
- To show operators delivery results, failures and campaign reports.
- To keep the service secure — authenticating operators and recording significant actions.
We do not use any of it for advertising, and we do not sell it.
6. Who information is shared with
- Mail providers. Messages are handed to Google, Microsoft or the configured SMTP server for delivery, which necessarily includes the recipient’s address and the message.
- Hosting. The service and its database run on Amazon Web Services in the Mumbai (ap-south-1) region.
- Fonts. Pages load typefaces from Google Fonts, so your browser sends its IP address to Google when it fetches them.
- Where required by law, or to protect the rights and safety of recipients, users or the service.
7. How long we keep it
- Campaigns, with their recipients, delivery records and uploaded files, are kept until an operator deletes the campaign, which removes all of them.
- Mailbox tokens are deleted when an operator removes the mailbox.
- The suppression list is kept so that people who opted out are never mailed again. Deleting an address from it would allow it to be mailed again.
- Sessions expire after 12 hours. Password-reset links are deleted once they expire.
- Audit records are kept to maintain a security history of the service.
8. Cookies and local storage
Email Campaign sets one cookie, bes_session, when an operator signs in. It is HTTP-only, is needed to keep you signed in, and expires after 12 hours. Your light or dark theme choice is saved in your browser’s local storage.
There are no analytics, advertising or tracking cookies, and campaign messages contain no tracking pixels.
9. Your choices and rights
- Revoke mailbox access at any time from your Google Account permissions or Microsoft account consents. Sending from that mailbox stops as soon as the provider withdraws the access.
- Stop receiving campaigns using the unsubscribe link in any message.
- Access, correct or delete your information by writing to dk.elenadigital@gmail.com. Depending on where you live, you may have further rights under India’s Digital Personal Data Protection Act, 2023, the EU or UK GDPR, or other laws, and we will respond to requests as those laws require.
10. Children
Email Campaign is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.
11. Changes to this policy
We will update this page when our handling of information changes, and revise the date at the top. Material changes to how Google user data is used will be made only with fresh consent.
12. Contact
Elena Digital
Sector 82, Noida, Uttar Pradesh 201304, India
dk.elenadigital@gmail.com
+91 97181 86185 · +1 408 351 2976
See also the Terms of Service.