We verify your lists. We never sell them.
The plain-English story of what we collect, why, how long we keep it, and the controls you hold. Same transparency we put in every verdict.
01The short version
We built EmailListChecker on the same principle we sell: transparency. So here is the whole privacy story in five lines, before the detail.
- We verify your lists — we never sell them.The email addresses you upload are processed to check deliverability and then they're yours. Full stop.
- Verification data is deleted on a clock you control. Uploaded lists auto-purge after your retention window (default 30 days), or instantly when you delete a job.
- We collect the minimum. Account details to run your account, list data to verify it, usage data to keep the service fast and secure.
- We don't train ad networks on you. No selling to data brokers, no enriching third-party profiles with your contacts.
- You can export or erase everything, anytime. From your dashboard or by emailing [email protected].
02Who we are
EmailListChecker (“we,” “us,” the “Service”) is an email-verification platform operated by EmailListChecker, Inc. This policy explains what we do with personal information when you visit our website, create an account, and use the Service to verify, clean, find, or analyze email addresses.
When you upload contacts to verify, you act as the data controller and we act as your data processor — we only handle that data on your documented instructions. When you simply use our website or manage your own account, we are the controller for that limited account data. Our role as a processor is covered in detail in our GDPR & Data Processing document.
03Data we collect
We collect three categories of data, and nothing beyond them:
1. Account data
- Name, work email, password hash, company name, and billing details handled by our payment processor.
- Plan, credit balance, and API keys associated with your workspace.
2. List & verification data
- The email addresses (and any columns) you upload, paste, or send via API to be verified, found, or analyzed.
- The verdicts we generate — such as VALID CATCH-ALL INVALID — and their confidence scores.
3. Usage & technical data
- Log data: IP address, browser, pages viewed, and API request metadata, used for security, debugging, and rate-limiting.
- Cookies strictly for session, security, and (with consent) product analytics. We do not run third-party advertising trackers.
We don't buy supplementary data about your contacts, build shadow profiles, or sell anything to data brokers. Your list is an input to a verdict, not a product we resell.
04How we use it
Every use of your data maps to a clear, lawful purpose. We use it to:
- Deliver the Service — run syntax, MX, SMTP, catch-all, disposable, role and spam-trap checks and return verdicts.
- Operate your account — authenticate you, meter credits, issue invoices, and provide support.
- Keep it secure and reliable — detect abuse, prevent fraud, and maintain our 99.9% uptime SLA.
- Improve the product — using aggregated, de-identified usage trends. We never train models on the raw contents of your lists.
- Communicate— send essential service notices, and marketing only where you've opted in (unsubscribe anytime).
05Retention & deletion
List data is the most sensitive thing you give us, so we hold it for the shortest time that still lets you work.
- Uploaded lists & results auto-delete after your configurable retention window (30 days by default). Delete a job and its data is purged immediately.
- Account & billing recordsare kept for the life of your account plus the period we're legally required to retain financial records.
- Logs are retained on a rolling 90-day window for security, then rotated out.
Set a shorter retention window — even “delete on completion” — in your workspace settings. Enterprise plans can pin custom retention and zero-retention API modes.
06Who we share with
We share data only with vetted service providers (sub-processors) who help us run the platform — cloud hosting, payment processing, transactional email, and product analytics — each bound by a data processing agreement and contractual confidentiality. A current list lives in our GDPR document.
We disclose data when legally compelled, to protect rights and safety, or as part of a merger or acquisition (you'll be notified). We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.
07How we protect it
Security isn't a checkbox for an email tool — it's the product. We maintain a SOC 2 Type II program and align to GDPR, with safeguards including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Least-privilege access, SSO, and audited admin actions for our team.
- Network isolation, continuous monitoring, and regular third-party penetration testing.
- A documented incident-response plan with breach notification within statutory timeframes.
08Your rights & choices
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar), you have rights to access, correct, delete, port, and restrict the processing of your personal data, and to object to certain uses. You can:
- Export or delete your account data and lists directly from your dashboard.
- Manage cookie preferences and opt out of analytics at any time.
- Email [email protected] to exercise any right — we verify and respond within 30 days, free of charge.
We'll never discriminate against you for exercising a privacy right. If you're unhappy with our response, you may complain to your local supervisory authority.
09International transfers
We operate globally and may process data in the United States and the EU. Where data moves across borders, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and we hold a Google Security assessment for our integrations. Details and our data-residency options are in the GDPR document.
10Changes & contact
We may update this policy as the product and the law evolve. Material changes are announced in-app and by email before they take effect; the “last updated” date always reflects the current version. Continued use after an update means you accept it.
Questions? Reach our privacy team at [email protected]. For data-protection-specific matters, our DPO is reachable at the same address.
EmailListChecker, Inc. · Privacy team: [email protected] · Data Protection Officer reachable at the same address.