SonarSend Privacy Policy

Effective September 15, 2026

This Privacy Policy explains how Framework Learning, LLC, which operates SonarSend (“SonarSend,” “we,” “us”), collects, uses, and shares personal data. It applies to our website, our marketing, and your use of the SonarSend platform and services (the “Service”).

1. Two roles — please read first#

SonarSend handles personal data in two different capacities:

  1. As a controller. When we decide how and why to process personal data — for example, data about our customers and their users, visitors to our website, and prospective customers — we act as a controller (or “business” under U.S. state laws). This Privacy Policy describes that processing.
  2. As a processor. When our customers use the Service to manage and email their own contacts (their “Contacts”), and when we process information about a customer’s authorized users on that customer’s behalf, we process that data on our customers’ behalf and on their instructions, acting as a processor (or “service provider”). That processing is governed by our Data Processing Addendum (DPA) and our agreement with the customer — not by this Privacy Policy. If you are a Contact of a SonarSend customer and want to exercise your privacy rights, please contact that customer directly (see Section 11).

2. Who this Policy covers#

This Policy covers personal data of: (a) our customers and their authorized users (“account users”); (b) visitors to our website and recipients of our own marketing; and (c) prospective customers.

3. Personal data we collect#

  • Account and profile data: name, business name, email address, username, password (hashed), role, and preferences.
  • Billing data: billing contact, plan, and transaction records. Payment-card details are entered directly into, and processed by, our payment processor, Stripe; we do not receive or store full card numbers.
  • Sending Provider connection data: the credentials or keys you connect to send through your own Sending Provider. We store these encrypted (AES-256-GCM) and use them only to operate the Service on your behalf.
  • Integration data: if you connect Google Postmaster Tools, the authorization tokens Google issues to us and the aggregate domain-reputation data we retrieve with them.
  • Usage and device data: log data, IP address, device and browser information, feature usage, and diagnostic data (including error reports) generated when you use the Service.
  • Website data: information collected when you visit our website, such as your IP address, browser information, the pages you view, and the page that referred you (see Section 7).
  • Support and communications: the content of your communications with us (support requests, emails, surveys).

4. How we use personal data#

We use personal data to: (a) provide, operate, secure, and maintain the Service and your account; (b) process payments and manage billing; (c) prevent, detect, and investigate fraud, abuse, security incidents, and violations of our terms, and protect our shared infrastructure and our standing with sending providers; (d) provide support and respond to your requests; (e) analyze and improve the Service and develop new features; (f) send you service, security, and administrative communications, and (with your consent where required) marketing about SonarSend; and (g) comply with law and enforce our agreements.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service and account); legitimate interests (to secure, improve, and market our products, and to prevent abuse — balanced against your rights); consent (for certain marketing and cookies, where required); and legal obligation (to comply with law).

6. How we share personal data#

  • Service providers. We share personal data with the vendors below, which help us operate the Service. Each is bound by contract to protect it and to use it only to provide its services to us.

    ProviderWhat they do for usLocation
    Railway CorporationHosts our application, databases, background workers, logs, backups, and file storageUnited States (US West)
    Cloudflare, Inc.Website hosting, DNS, content delivery and network security, tracking-domain routing, encrypted backup storage, cookieless web analytics, and our AI-assistant (MCP) connectorGlobal network; R2 storage in Western North America (WNAM)
    Stripe, LLCBilling, subscriptions, and payment processingUnited States
    Functional Software, Inc. (Sentry)Error monitoring and diagnosticsUnited States
    AC PM, LLC (Postmark)Delivers our own account, security, and notification emails (e.g., sign-up, invitations, password resets, alerts)United States

    We will update this list when we add or replace a provider. Our own website analytics (Section 7) runs on SonarSend itself, hosted by the providers above; no additional vendor receives that data.

  • Your Sending Provider. When you send messages, we transmit content and the necessary data to your own Sending Provider (for example, Amazon SES, SendGrid, or Mailgun), as you direct. That provider is your vendor, not ours.

  • Integrations you connect. If you connect a third-party integration (such as Google Postmaster Tools, a webhook endpoint, or an AI assistant using our MCP connector), we exchange data with it as you direct.

  • Legal and safety. We may disclose personal data to comply with law, respond to lawful requests, enforce our terms, protect our shared infrastructure, or protect the rights, safety, and property of SonarSend, our customers, or others.

  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We do not sell your personal data, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws.

7. Cookies and similar technologies#

  • Our website does not use advertising cookies or ad-network trackers. We measure how it’s used with SonarSend’s own website tracking, described under Analytics below. Our hosting and security provider, Cloudflare, may set strictly necessary cookies to protect the site from abuse.
  • The Service uses a strictly necessary session cookie to keep you signed in. It is not used for advertising.
  • Analytics. We use analytics to understand how our website and the Service are used — which pages and features people use — so we know what to improve. We do not use it for advertising.
    • On our website, we use SonarSend’s own website tracking. Each time you view a page, your browser sends us the page address, the page title, the page that referred you, your screen size, your browser’s user agent, and your IP address. It sets first-party cookies on sonarsend.com. _emts recognizes your visits within a session and when you return. If you arrive by clicking a link in an email we sent you, or give us your email address on our website (for example, to book a demo), _emt and _emc connect your visits to your contact record with us, so we can follow up on the interest you’ve shown. These cookies last up to one year.
    • In the Service, we use Cloudflare Web Analytics, which does not use cookies or collect personal data for advertising; Cloudflare receives limited request and device information, such as IP address, user agent, referrer, and page information, to produce analytics and protect the service.
  • Web fonts. The Service and some of our emails load fonts from Google Fonts, so your browser or email client sends your IP address to Google when those fonts load.
  • Customer tracking. Our customers can use the Service to measure email engagement and website activity on their own domains using first-party cookies. We do that on the customer’s behalf as a processor; see the customer’s own privacy policy.

Strictly necessary cookies do not require consent. The analytics cookies on our website are not strictly necessary. You can block or delete them in your browser settings, and our website works without them.

8. International data transfers#

We and our service providers process and store personal data in the United States and other countries where those providers operate. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum / Swiss addendum, as applicable), or our providers’ certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where available. Contact us for more information.

9. Data retention#

We retain personal data for as long as needed to provide the Service and your account, and thereafter as required for legitimate business, legal, tax, and security purposes. When no longer needed, we delete or de-identify it. Deleted data can remain in our database backups until they expire automatically, which happens on a rolling basis, within 90 days. We do not access or use data held in backups except to recover from an incident. Retention of Contacts processed on your behalf is governed by the DPA and your instructions.

10. Security#

We maintain administrative, technical, and organizational measures designed to protect personal data. These include TLS encryption in transit; AES-256-GCM encryption of connected Sending Provider credentials and of our daily database backups; access-restricted backup storage; separation of each customer’s data within the application, checked by automated tests; access controls; and monitoring. No system is perfectly secure, and we cannot guarantee absolute security. A summary of our measures is in Annex 2 of the DPA.

11. Your rights#

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. U.S. state-law residents may have rights to access, delete, correct, and opt out of sale/sharing/targeted advertising. To exercise rights regarding data we control, contact us at privacy@sonarsend.com; we will respond as required by law and will not discriminate against you for exercising your rights.

If you are a Contact of a SonarSend customer (i.e., you received email sent through the Service), SonarSend processes your data on that customer’s behalf. Please direct your requests to the customer that contacted you; we will assist that customer as required by the DPA and applicable law.

12. Children#

The Service is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.

Our website and Service may link to or integrate third-party services, including your Sending Provider and integrations you connect (such as Google Postmaster Tools). Their processing is governed by their own privacy policies, not this one.

14. Changes to this Policy#

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice as required.

15. Contact us#

Questions or requests: privacy@sonarsend.com, or Framework Learning, LLC, 1775 W. State St. #173, Boise, ID 83702.