Privacy Policy
Last updated: September 26, 2026
1. Introduction
Welcome to WhopMail ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email marketing platform and related services (collectively, the "Service").
WhopMail is an email marketing and communication platform that enables businesses to create, send, and manage email campaigns, SMS messages, and automated marketing workflows. By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
2.1 Account Information
When you create an account or use our Service, we collect:
- Whop user ID and company ID (from Whop platform integration)
- Email address associated with your account
- Profile information (name, company name, if provided)
- Authentication credentials and API keys
2.2 Contact and Audience Data
To provide email marketing services, we process:
- Email addresses of your contacts and audience members
- Contact names (first name, last name)
- Phone numbers (for SMS messaging features)
- Custom fields and tags associated with contacts
- Audience segmentation data
2.3 Email Engagement Data
We track email engagement metrics including:
- Email open rates and timestamps
- Click-through rates and clicked links
- Bounce rates and bounce types
- Unsubscribe requests and preferences
- Email delivery status
- Complaint rates (spam reports)
2.4 SMS Engagement Data
For SMS messaging features, we collect:
- SMS delivery status
- Reply messages and timestamps
- Opt-in and opt-out confirmations
2.5 Analytics and Usage Data
We collect analytics information through:
- Microsoft Clarity analytics (user behavior, session recordings)
- Meta Pixel tracking (conversion tracking, advertising analytics)
- Service usage statistics (campaigns sent, features used)
- Device and browser information
- IP addresses and location data (general geographic area)
2.6 Integration and Configuration Data
When you configure integrations, we store:
- API keys and authentication tokens (encrypted)
- Email platform configuration settings
- Custom domain settings and DNS configurations
- Email template designs and content
2.7 Form Submissions and User-Generated Content
We process data from:
- Embedded form submissions
- Email content created through our email builder
- Newsletter content and campaigns
- Automation workflow configurations
3. How We Use Your Information
3.1 Service Delivery
We use your information to:
- Deliver email campaigns to your specified recipients
- Send SMS messages through our SMS service providers
- Process and manage your contact lists and audiences
- Execute automated marketing workflows
- Provide CRM and contact management features
3.2 Analytics and Reporting
We use engagement data to:
- Generate email and SMS performance reports
- Provide analytics dashboards and insights
- Track campaign effectiveness and engagement rates
- Identify optimal send times and audience segments
3.3 Service Improvement
We analyze usage data to:
- Improve our platform features and functionality
- Enhance email deliverability and performance
- Develop new features based on user needs
- Fix bugs and resolve technical issues
3.4 Customer Support
We use your information to:
- Respond to your support requests and inquiries
- Provide technical assistance
- Send service-related notifications and updates
- Notify you of important changes to our Service
3.5 Legal Compliance
We process data to:
- Comply with applicable laws and regulations (CAN-SPAM, TCPA, GDPR, CCPA)
- Respond to legal requests and court orders
- Enforce our Terms of Service and Acceptable Use Policy
- Protect our rights and prevent fraud or abuse
4. Data Sharing and Third-Party Services
4.1 Service Providers
We share data with trusted third-party service providers who assist in operating our Service:
- Supabase: Database hosting and data storage
- Whop: User authentication and membership data integration
- ClickSend: SMS message delivery services
- Email Service Providers: Email delivery infrastructure (we do not disclose specific providers in compliance with security best practices)
- AI Providers: Google Gemini and Anthropic Claude for email design and content generation features
- OpenAI: when you connect WhopMail to ChatGPT, data you request is returned to OpenAI as described in section 4.2
4.2 AI Assistants Connected via MCP
You can connect WhopMail to third-party AI assistants, such as ChatGPT (OpenAI), Claude (Anthropic), Cursor, and Grok (xAI), using the Model Context Protocol (MCP). Connections are made only when you sign in and approve access on our authorization page, and they are limited to the permissions (scopes) you grant.
When you ask a connected assistant to perform a task, WhopMail returns the data needed for that request to the assistant provider under your authorization. Depending on what you ask, this can include:
- Contact and member information, such as names and email addresses (some listings are partially redacted)
- Campaign and automation content, such as subjects, email copy, and HTML
- Analytics, such as audience counts, open rates, click rates, and campaign statistics
- Account settings, such as sender name, reply-to address, and domain status
The assistant provider processes that data under its own privacy policy and terms (for example, OpenAI's privacy policy for ChatGPT). Assistants can also create drafts or, when you instruct them, send emails and change automations on your behalf. WhopMail logs these actions. You can revoke access at any time by disconnecting WhopMail in the assistant or deleting the associated MCP key in WhopMail settings.
4.3 Analytics Providers
We use analytics services that may collect information:
- Microsoft Clarity: Website analytics and user behavior tracking
- Meta Pixel: Conversion tracking and advertising analytics
These services may use cookies and similar technologies. See our Cookie Policy for more information.
4.4 Legal Requirements
We may disclose information when required by law, court order, or government regulation, or to:
- Comply with legal processes or government requests
- Enforce our Terms of Service or Acceptable Use Policy
- Protect the rights, property, or safety of WhopMail, our users, or others
- Prevent fraud or investigate potential violations
4.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
5. Email Marketing Practices and Compliance
5.1 CAN-SPAM Act Compliance
We are committed to compliance with the CAN-SPAM Act and require all users to:
- Include accurate sender information in all emails
- Provide clear and conspicuous unsubscribe mechanisms in every email
- Process unsubscribe requests within 10 business days
- Refrain from sending deceptive subject lines or misleading content
- Honor opt-out requests and maintain suppression lists
5.2 Unsubscribe Mechanisms
All emails sent through our platform include:
- Clear unsubscribe links in email footers
- Automatic processing of unsubscribe requests
- Email preference management options
- Suppression list management to prevent re-adding unsubscribed contacts
5.3 Opt-In and Consent Requirements
We require users to obtain proper consent before sending marketing emails:
- Explicit opt-in consent for marketing communications
- Clear disclosure of what subscribers are signing up for
- Double opt-in options for enhanced consent verification
- Maintenance of consent records and timestamps
5.4 List Hygiene and Best Practices
We provide tools and features to maintain healthy email lists:
- Automatic bounce handling and list cleaning
- Spam complaint monitoring and suppression
- Engagement-based segmentation recommendations
- Domain reputation monitoring and alerts
6. SMS Practices and TCPA Compliance
6.1 TCPA Compliance
We comply with the Telephone Consumer Protection Act (TCPA) and require:
- Prior express written consent before sending SMS messages
- Clear disclosure of message frequency and content
- Opt-out instructions in every SMS message
- Immediate processing of opt-out requests (STOP keyword support)
- Maintenance of opt-in consent records
6.2 SMS Opt-In and Opt-Out
Our SMS features include:
- Explicit opt-in mechanisms for SMS subscriptions
- Automatic opt-out processing via STOP keyword
- SMS preference management
- Compliance with CTIA guidelines for SMS marketing
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. For detailed information about our cookie practices, please see our Cookie Policy.
7.1 Types of Tracking
- Email Tracking Pixels: We use tracking pixels in emails to detect opens and engagement
- Analytics Cookies: Microsoft Clarity and Meta Pixel for website analytics
- Session Cookies: Authentication and session management
- Functional Cookies: User preferences and settings
8. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data in transit (TLS/SSL) and at rest (encrypted databases)
- Access Controls: Role-based access control and authentication requirements
- API Key Security: Encrypted storage of API keys and credentials
- Regular Security Audits: Ongoing security assessments and vulnerability testing
- Data Backup: Regular backups with secure storage
- Incident Response: Procedures for detecting and responding to security incidents
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
9. Data Retention
We retain your information for as long as necessary to provide our Service and comply with legal obligations:
- Account Data: Retained while your account is active and for a reasonable period after account closure
- Email Engagement Data: Retained for analytics and reporting purposes, typically for 2 years
- Contact Lists: Retained until you delete them or close your account
- Unsubscribe Records: Retained indefinitely to maintain suppression lists and comply with CAN-SPAM
- Legal Requirements: Some data may be retained longer if required by law or legal proceedings
10. Your Privacy Rights
10.1 General Rights
You have the right to:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal information (subject to legal requirements)
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing activities
- Restriction: Request restriction of processing in certain circumstances
10.2 GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including:
- Right to be informed about data processing
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Rights related to automated decision-making
To exercise these rights, please contact us using the information provided in the "Contact Us" section below.
10.3 CCPA Rights (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
California residents may request information about our data practices by contacting us as provided below.
10.4 Exercising Your Rights
To exercise any of these rights, please contact us at the email address provided in the "Contact Us" section. We will respond to your request within 30 days (or as required by applicable law) and may require verification of your identity.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by data protection authorities
- Adequacy decisions where applicable
- Other appropriate legal mechanisms to ensure adequate protection
By using our Service, you consent to the transfer of your information to countries outside your jurisdiction, including the United States, where our servers and service providers are located.
12. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will take steps to delete such information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated Privacy Policy on this page
- Updating the "Last updated" date at the top of this policy
- Sending you an email notification (for significant changes)
- Displaying a notice on our Service
Your continued use of our Service after any changes constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@whopmail.com
- Website: whopmail.com
For data protection inquiries or to exercise your privacy rights, please include "Privacy Request" in your subject line.