Spooler Data Policy Last updated: 9 September 2026 This policy says what data Spooler holds, where it is stored, who else touches it, and how personal data is handled. It forms part of the Spooler Terms of Service (spooler.sh/legal/terms-of-service.txt); words defined there mean the same here. Section 8 is our processing terms for customers whose messages contain personal data. 1. Who is responsible The Service is provided by Sergey Kamardin, a sole trader established in the United Kingdom, trading as Spooler ("Spooler", "we", "us"). Trading address: 18 Margaret Street, Brighton BN2 1TS Contact: sergey@spooler.sh For the personal data of account holders (section 3) we are the controller. For personal data inside your messages (section 4) you are the controller and we are the processor. 2. Two kinds of data There are two kinds of data in the Service, and this policy treats them differently. Account data is what we hold about you as a customer: who you are, how you sign in, what plan you are on, and how you use the Service. We decide why and how it is processed. Customer Data is the messages you send through the Service and the data inside them. We do not look at it, do not know what it contains, and process it only to store and deliver it as you instruct through the API. 3. Account data 3.1 What we hold - The email address you sign in with, and your name and company name if you give them. - How you sign in: a magic link sent to your email, or a Google or GitHub account you connect. For a connected account we hold the identifier and email that provider returns, never its password. - Your plan, subscription status and billing history. Card details go straight to our payment provider (section 6); we never see or store a card number. - API keys, as hashes; the key itself is shown to you once. - Usage metadata: request counts, sizes and timings per account, spool and queue, used to enforce plan limits, bill, and operate the Service. - Server logs, which include the IP address that made a request, the time, the path, the outcome, and for failed authentication the prefix of the key used. Logs never include message content. - Emails we exchange with you about the Service. 3.2 Why, and on what basis We process account data to provide the Service under the contract with you (sign-in, billing, limits, support), to keep the Service secure (logs, rate limiting, abuse investigation) as our legitimate interest, and to meet legal duties (tax and accounting records). We do not use account data for advertising, do not sell it, and do not share it except as described in section 6. 3.3 How long - Account data: for the life of your account and a short grace period after it closes, then deleted, except where the law requires us to keep a record for longer (billing records, for the period tax law requires). - Server logs: for a short period for security and debugging, then deleted. - Backups of the account database: hourly backups are kept for a day, daily for a week, weekly for a month and monthly for six months, so a deleted record leaves the last backup within six months. 3.4 Cookies and tracking spooler.sh sets no cookies. It and docs.spooler.sh count visits with Plausible (section 6), which uses no cookies and stores no personal data: a visit is counted against a hash of the IP address and browser that changes every day, so no visitor is identified or followed across days, and what we see is aggregate page views, referrers and countries. console.spooler.sh is not counted. console.spooler.sh sets a session cookie to keep you signed in, and short-lived cookies that exist only while a sign-in or a return from the billing portal is in progress, to protect those steps from forgery. All of them are strictly necessary; none identifies you to anyone else. We use no advertising or tracking on any Spooler site. 4. Customer Data 4.1 What we do with it We store messages durably when you send them, deliver them to your consumers when they receive, and delete them when acknowledged, discarded, or when their retention expires. That is all. We do not read, index, analyse or share the content of your messages, and nobody outside the Service does either. We have no way to recover a message after deletion. 4.2 Where it is Customer Data is stored on dedicated servers in Falkenstein, Germany, operated for us by Hetzner Online GmbH. A message is written to as many of those servers as your plan's replica count says; the count is shown at sign-up and in the console. Customer Data is not copied off that estate: there is no off-site backup of messages, by design, because the Service holds them for a retention window and not as a system of record. Keep your own copy of anything you cannot afford to lose. 4.3 In transit Clients connect to the Service over TLS. Message data travels between you and our servers directly; it does not pass through a third-party proxy in normal operation. If the Service comes under attack we may route API traffic through Cloudflare's network for the duration (section 6); during that time Cloudflare terminates TLS and sees request contents in transit. 5. Where everything lives - Messages: Falkenstein, Germany (Hetzner dedicated servers). - Account database: Falkenstein, Germany (Hetzner cloud servers). - Backups of the account database: Helsinki, Finland (a Hetzner storage box), taken hourly. - Monitoring: Nuremberg, Germany (a Hetzner cloud server). Monitoring holds metrics and alerts, not Customer Data. - Email, payments and DNS: with the providers in section 6, in the locations they operate. The Service is operated from the United Kingdom. 6. Sub-processors and other recipients We use these providers to run the Service. Each processes only what its column says, under a contract that binds it to confidentiality and to processing on our instructions. Hetzner Online GmbH (Germany) Hosting for everything in section 5. Holds all Customer Data and account data at rest. Does not access it. Cloudflare, Inc. (United States; EU and UK operations) DNS for our domains; the network path for spooler.sh, console.spooler.sh and the account API, so it sees account-data requests in transit; and, only under attack, the API traffic described in 4.3. Stripe Payments Europe, Ltd. (Ireland), Stripe Payments UK Ltd (United Kingdom) and Stripe, LLC (United States) Payments and invoicing. Receives your email, name, company name and billing address, and holds your card details, which never reach us. AC PM LLC, part of ActiveCampaign, trading as Postmark (United States) Transactional email: magic links, billing and account notices. Receives your email address and the content of those emails. Google LLC and GitHub, Inc. Only if you choose to sign in with them. They act as independent providers of the sign-in, not on our instructions; their own policies apply to what they do with the fact that you signed in. Plausible Insights OÜ (Estonia) Visit counting on spooler.sh and docs.spooler.sh, hosted in the EU. It is not loaded on console.spooler.sh. Receives the page address, referrer, and the IP address and browser of a visit, which it hashes with a daily salt and does not store. No cookies, no customer data. UptimeRobot (external availability checks) Probes our public endpoints. Receives no customer data. We will give account holders at least 30 days' notice by email before adding or replacing a sub-processor that handles Customer Data. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the Service without penalty before the change takes effect. We disclose data to public authorities only when legally required, and where the law allows we tell you first. 7. International transfers Customer Data and the account database stay in Germany and Finland. Some providers in section 6 are established in the United States: Cloudflare, Stripe, LLC and Postmark. Each is certified under the EU-US Data Privacy Framework and its UK Extension, which is the basis for transfers to them; each also offers the UK International Data Transfer Addendum to the EU standard contractual clauses as a fallback should a certification lapse. 8. Processing terms These terms apply where Customer Data contains personal data protected by the UK GDPR, the EU GDPR or similar law. They satisfy Article 28 of those regulations and take effect with the Terms of Service. 8.1 Roles. You are the controller of personal data in your messages; we are your processor. 8.2 Subject matter, nature and purpose. Storage, replication, delivery and deletion of messages you send through the Service, for the purpose of operating a message queue on your behalf. Duration: for the life of your account and the deletion period in the Terms. 8.3 Types of data and data subjects. Whatever you choose to put in messages. You determine the categories of data and of data subjects; we have no visibility of them. You must not send special category data, payment card data or similarly regulated data without our written agreement. 8.4 Instructions. We process personal data only on your documented instructions, which are the operations you perform through the API and console, plus these terms. We will tell you if we believe an instruction breaks data protection law. 8.5 Confidentiality. Everyone with access to the systems that hold Customer Data is bound to confidentiality. Today that is the sole trader named in section 1. 8.6 Security. We protect Customer Data with measures appropriate to the risk, including: TLS for all connections; disks encrypted at rest on every server; API keys held as hashes; replication of messages to the number of servers your plan provides; hosts reachable for administration only from named addresses over SSH; a private network between our servers; firewalls on every host; and deletion at retention as a property of the system. The Terms describe the durability boundary. 8.7 Sub-processors. You authorise the sub-processors in section 6 and any added under its notice procedure. We remain responsible for their performance. 8.8 Assistance. We will help you, so far as the Service allows, to respond to data subject requests and to meet your security, breach notification and impact assessment duties. Because we cannot search message content, the practical way to act on a data subject request is to consume, ack or discard the messages concerned through the API. 8.9 Breaches. We will tell you without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information you need to meet your own duties. 8.10 Deletion. Customer Data is deleted when acknowledged, discarded, or at retention. When your account closes, any remaining Customer Data is deleted after the grace period in the Terms. Nothing is returned, because consuming your messages is the return. 8.11 Information and audit. We will make available the information needed to show compliance with these terms, and allow an audit by you or an auditor you appoint, on reasonable notice, at most once a year unless required by a supervisory authority or following a breach, at your cost, and under confidentiality. 8.12 Transfers. Section 7 applies. 9. Your rights If we hold personal data about you as an account holder, you can ask us to access, correct, delete or export it, to restrict or object to processing, and to stop marketing (we send none). Write to sergey@spooler.sh. You can complain to the Information Commissioner's Office (ico.org.uk) or, in the EU, to your local supervisory authority. 10. Changes We may change this policy. For material changes we will email account holders at least 30 days before they take effect, and sub-processor changes follow section 6. The current policy is always at spooler.sh/legal/data-policy.txt.