1. Overview
This Privacy Policy explains how Paravane Labs, Inc. ("Paravane," "we," "us," or "our"), a company owned by DOYDL Technologies, LLC, collects, uses, discloses, and retains personal information in connection with our websites, dashboard, APIs, documentation, support, billing, and related services, including the smtpRS API (collectively, the "Services").
This Privacy Policy applies to personal information we process as a business/controller for our own purposes, such as account registration, billing, website operation, support, security, marketing, analytics, and service administration. When a customer submits personal data to the Services for Paravane to process on the customer's behalf, we generally process that data as a processor/service provider under the customer's instructions and our Data Processing Addendum.
Capitalized terms not defined in this Privacy Policy have the meanings given in the Terms of Service or Data Processing Addendum.
2. Personal information we collect
The personal information we collect depends on how you interact with Paravane and which Services you use.
| Category | Examples | Sources |
|---|---|---|
| Account and profile information | Name, business email address, company name, role/title, username, password hash, email verification status, password reset metadata, authentication events, session identifiers, workspace membership, preferences, and account settings. | Directly from you, your employer, workspace administrators, signup/evaluation forms, account invites, or authentication flows. |
| Billing and subscription information | Billing contact, billing address, invoice details, subscription plan, usage tier, tax information, Stripe customer/subscription identifiers, checkout session status, payment status, transaction metadata, and limited payment identifiers. Full payment card details are processed by Stripe or another payment processor and are not intended to be stored by Paravane. | Directly from you, your administrator, Stripe/payment processor, tax/billing providers, dashboard billing flows, or webhook updates from payment processors. |
| API inputs and customer-submitted identifiers | Email addresses, domain names, IP addresses, user-agent strings, request payloads, metadata, configuration settings, labels, feedback, test data, and other identifiers or fields submitted to the APIs or dashboard. | From customers, customer systems, users, and integrations that submit data to the Services. |
| API outputs and risk signals | Scores, labels, reason codes, confidence indicators, validation outcomes, domain intelligence, abuse indicators, model outputs, timestamps, and related response metadata. | Generated by the Services from customer inputs, service logic, internal models, data sources, and third-party or public signals where applicable. |
| Usage, device, and log information | IP address, browser type, device identifiers, operating system, pages visited, referring URLs, request and response metadata, endpoint usage, status codes, errors, latency, timestamps, API key identifiers or prefixes, session activity, dashboard activity, model profile, usage credits, and rate-limit events. | Automatically through the Services, server logs, dashboard flows, cookies, local storage, SDKs, security tools, and API usage instrumentation. |
| Support and communications | Support tickets, emails, chat messages, call notes, attachments, feedback, survey responses, vulnerability reports, and other communications with us. | Directly from you, your representatives, or support/communication tools. |
| Marketing and event information | Newsletter preferences, webinar registrations, demo requests, campaign source, business contact information, and interaction with marketing communications. | Directly from you, referral sources, business partners, public websites, or marketing tools where permitted. |
| Security and fraud-prevention information | Login attempts, authentication events, suspicious activity indicators, abuse reports, blocked requests, rate-limit events, and security investigation information. | Automatically from the Services, security tools, Cloudflare or similar providers, customers, or third parties. |
| Public, third-party, and enrichment data | Domain registration or DNS metadata, public website metadata, threat-intelligence signals, commercial data, data-source attributions, or publicly available business/domain information where used to provide or improve the Services. | From public or commercial data sources, customer systems and integrations, service-generated logs and outputs, payment processors, security tools, support communications, and business sources used for sales, support, service operation, or abuse-prevention context. |
3. Customer API Data
Customer API Data is data that a customer submits to, or receives from, the Services through API calls, dashboard uploads, integrations, or related workflows. Customer API Data may include personal information when it identifies or can reasonably be linked to a person, such as an email address, IP address, online identifier, or other submitted identifier.
We process Customer API Data to provide the Services, generate scores and outputs, authenticate requests, prevent abuse, debug errors, maintain security, monitor performance, enforce Usage Limits, provide support, comply with law, and fulfill the customer's documented instructions.
Unless a customer separately authorizes it, Paravane does not sell Customer API Data, share Customer API Data for cross-context behavioral advertising, or use Customer API Data to train general-purpose artificial intelligence models. Paravane may use aggregated, de-identified, or statistical information derived from Service usage to operate, secure, improve, and benchmark the Services, provided that it does not identify a customer, customer end user, or individual.
4. Information we do not want you to submit
The Services are not designed for all types of regulated or highly sensitive data. Unless Paravane has expressly agreed in a separate written agreement, you must not submit the following to the Services:
- Protected health information subject to HIPAA or similar health privacy laws.
- Full payment card numbers, CVV codes, magnetic stripe data, or other PCI-regulated cardholder data.
- Government identification numbers, passport numbers, driver's license numbers, taxpayer identification numbers, or social security numbers.
- Financial account numbers, bank credentials, or payroll information.
- Precise geolocation, biometric identifiers, genetic data, or sensitive authentication secrets.
- Data about children under 13 or other age thresholds requiring parental consent.
- Special categories of personal data under GDPR, including racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or sex life/sexual orientation data.
- Any data you are not legally authorized to provide to Paravane.
5. How we use personal information
| Purpose | Examples |
|---|---|
| Provide and administer Services | Create accounts, authenticate users, provide dashboard and API access, process requests, generate outputs, manage workspaces, and deliver support. |
| Operate and improve the Services | Debug, test, analyze usage, improve performance, develop new features, evaluate model quality, and maintain documentation. |
| Security and abuse prevention | Detect, prevent, investigate, and respond to spam, fraud, malware, unauthorized access, credential abuse, denial-of-service attacks, policy violations, and other harmful activity. |
| Billing and account management | Process payments, subscriptions, invoices, taxes, renewals, cancellations, plan changes, and usage-based charges. |
| Communications | Send operational notices, security alerts, account messages, support responses, product updates, legal notices, and marketing messages where permitted. |
| Compliance and enforcement | Comply with law, enforce our Terms and AUP, protect rights and safety, respond to legal requests, resolve disputes, and maintain records. |
| Analytics and de-identified data | Measure service adoption, reliability, performance, and abuse trends; create aggregated or de-identified metrics that do not identify individuals. |
6. Legal bases for EEA/UK processing
Where GDPR, UK GDPR, or similar laws apply, our legal bases may include:
- Contract: to provide the Services, manage accounts, process subscriptions, and respond to support requests.
- Legitimate interests: to secure and improve the Services, prevent abuse, communicate with business contacts, analyze service usage, and enforce legal terms, where those interests are not overridden by rights and interests of individuals.
- Legal obligations: to comply with tax, accounting, legal, regulatory, sanctions, and law-enforcement obligations.
- Consent: for certain cookies, marketing communications, or optional features where consent is required and obtained.
- Customer instructions: where we process Customer API Data as a processor/service provider on behalf of a customer.
7. How we disclose personal information
We may disclose personal information as described below:
| Recipient | Purpose |
|---|---|
| Service providers and subprocessors | Hosting, infrastructure, CDN/security, payment processing, subscription billing, email delivery, analytics if enabled, error monitoring if enabled, support, communications, tax, and professional services providers that process information for us. |
| Customers and workspace administrators | Account usage, users, API keys, logs, invoices, and settings may be visible to the customer organization or its administrators. |
| Customer-selected integrations | If you connect the Services to third-party systems, we may disclose information as directed by you or your administrator. |
| Legal and safety purposes | Courts, regulators, law enforcement, government authorities, or third parties where we believe disclosure is required by law or necessary to protect rights, safety, security, or prevent abuse. |
| Corporate transactions | In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or due diligence, subject to appropriate confidentiality safeguards. |
| Professional advisors | Lawyers, accountants, auditors, insurers, banks, and consultants who need the information to provide professional services. |
| With consent or instructions | Other disclosures with your consent, at your direction, or as described at the time of collection. |
We do not sell Customer API Data. We do not share personal information for cross-context behavioral advertising unless we provide a legally required notice and opt-out mechanism.
8. Data retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain security. The table below describes our standard retention approach.
| Data type | Retention period |
|---|---|
| Account profile data | While the account is active plus up to 3 years after closure, unless deletion is requested and no legal basis requires retention. Authentication/session records may be retained for shorter operational periods unless needed for security, fraud prevention, legal claims, or compliance. |
| Billing, invoices, and tax records | 7 years, or another legally required accounting, tax, audit, or compliance period. Stripe customer/subscription identifiers and payment metadata may be retained as needed to administer subscriptions, resolve disputes, and maintain required records. |
| Payment card data | Processed by Stripe/payment processor; Paravane does not intend to store full card numbers. Limited payment tokens/metadata may be retained as needed for billing records. |
| API request logs | 90 days by default for ordinary API request metadata and usage events, unless a shorter or longer period is required for security, abuse prevention, debugging, legal claims, compliance, billing, plan enforcement, or customer agreement. |
| API payloads or full request/response bodies | Not stored by default where feasible. If temporary storage is enabled for debugging, support, security investigation, or a customer-requested feature, Paravane minimizes, redacts, or deletes full payloads as soon as reasonably practicable. |
| Security logs and abuse investigation records | 1 year by default for security and abuse investigation records, or longer if needed for an active investigation, fraud prevention, legal claims, compliance, or enforcement of the Terms. |
| Support tickets and communications | 3 years after resolution or account closure, unless a shorter period applies, deletion is requested, or retention is needed for legal, security, or compliance reasons. |
| Marketing contacts | Until you unsubscribe or request deletion; suppression records may be retained to honor opt-outs. |
| Backups | 30 to 90 days, after which backups are overwritten or deleted in the ordinary course. |
| De-identified or aggregated data | May be retained without time limit if it does not identify individuals and is maintained in de-identified or aggregated form. |
9. Cookies and similar technologies
We may use cookies, local storage, pixels, SDKs, and similar technologies to operate the website and dashboard, authenticate sessions, remember preferences, protect against abuse, measure performance, understand usage, and, where enabled, conduct marketing analytics. See the Cookie Notice for more information and cookie controls.
You can configure your browser to block or delete cookies. Blocking necessary cookies may prevent the Services from functioning correctly. Where required, we will obtain consent for optional cookies and honor applicable opt-out signals as required by law.
10. Privacy rights and choices
Depending on where you live and how we process your personal information, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or opt-out of certain processing. You may also have the right to appeal a decision regarding your request.
To exercise privacy rights, contact privacy@paravane.io. We may need to verify your identity and authority before completing a request. If your request concerns Customer API Data that we process on behalf of a customer, we may refer your request to that customer or act on the customer's instructions.
| Right/choice | Description |
|---|---|
| Access/know | Request information about categories or specific pieces of personal information we process about you, subject to legal exceptions. |
| Correction | Request correction of inaccurate personal information. |
| Deletion | Request deletion of personal information, subject to legal exceptions and retention obligations. |
| Portability | Request a copy of certain personal information in a portable format where required. |
| Opt-out of sale/share or targeted advertising | We do not sell Customer API Data or share personal information for cross-context behavioral advertising unless separately disclosed. If this changes, we will provide required opt-outs. |
| Limit sensitive personal information | We do not use sensitive personal information to infer characteristics unless separately disclosed and permitted by law. |
| Marketing opt-out | You can unsubscribe from marketing emails using the link in the email. You will still receive operational and legal notices. |
| Appeal | Where applicable, you may appeal our decision by replying to our response or contacting the privacy email with “Privacy Appeal” in the subject line. |
11. U.S. state privacy notice
Some U.S. state privacy laws require additional disclosures. Applicability often depends on thresholds, revenue, data volumes, and processing purposes. Even where a law does not apply, we aim to provide clear information about our practices.
| Category | Examples | Purposes | Disclosures |
|---|---|---|---|
| Identifiers | Name, email, account ID, workspace/tenant ID, Stripe customer/subscription IDs, IP address, API key ID or prefix, online identifiers. | Account creation, Service provision, security, billing, support, communications. | Service providers, subprocessors, customer administrators, legal/safety recipients. |
| Commercial information | Subscription plan, invoices, checkout session status, payment status, purchase history, usage tier, billing contact information. | Billing, taxes, account management, customer support. | Payment processors, tax providers, professional advisors. |
| Internet or network activity | Website/app activity, logs, requests, device/browser information, API usage. | Security, analytics, debugging, performance, abuse prevention. | Hosting, CDN/security, analytics, error monitoring, support providers. |
| Professional or employment-related information | Company, role, business contact details. | Account management, demos, sales, support, communications. | CRM, email, support, analytics providers. |
| Geolocation information | Approximate location inferred from IP address. | Security, fraud prevention, localization, analytics. | Security, analytics, infrastructure providers. |
| Inferences or risk indicators | Scores, labels, confidence indicators, reason codes tied to submitted identifiers. | Provide smtpRS outputs, fraud/abuse/security workflows, product improvement where permitted. | Customer that submitted the request, infrastructure/subprocessors as needed to provide Services. |
| Sensitive personal information | Authentication credentials, password hashes, account login information, session tokens, verification/reset tokens; other sensitive data should not be submitted. | Account security and authentication only; not used to infer characteristics. | Authentication, security, hosting providers. |
We do not knowingly sell personal information of individuals under 16. The Services are not directed to children.
12. International transfers
Paravane may process and store personal information in the United States, the European Economic Area, and other locations where Paravane or its service providers operate. Where required, we use appropriate safeguards for cross-border transfers, which may include Standard Contractual Clauses, the UK Addendum, Swiss addendum terms, data processing agreements, transfer impact assessments, or other lawful mechanisms.
Paravane does not claim participation in the EU-U.S. Data Privacy Framework unless and until it has completed and maintains self-certification.
13. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect personal information. These may include encryption in transit, access controls, least-privilege permissions, logging, monitoring, backups, credential controls, vulnerability management, and vendor review. The specific controls may vary over time and by data type.
No method of transmission or storage is completely secure. You are responsible for protecting your account, API keys, devices, systems, and integrations and for promptly notifying us of suspected unauthorized access.
14. Children's privacy
The Services are not directed to children, and we do not knowingly collect personal information from children under 13 or under any higher age threshold that applies in a particular jurisdiction. If you believe a child has provided personal information to us, contact us so we can review and delete it where appropriate.
15. Third-party links and services
Our websites and Services may link to third-party websites, documentation, repositories, integrations, or services. We are not responsible for the privacy practices of third parties. Review their privacy notices before providing information to them.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by a new last-updated date. Where required by law or appropriate for material changes, we will provide additional notice.
17. Contact us
For privacy questions or privacy rights requests, contact privacy@paravane.io. For legal notices, contact legal@paravane.io. For security-related privacy concerns, contact security@paravane.io. For general information requests, contact contact@paravane.io. Mailing address: 11166 Fairfax Blvd Suite 500 #1378, Fairfax, VA 22030, United States; Phone: (703) 972-1286.