Privacy Policy
How BigStats.email collects, uses and protects personal data.
Last updated August 4, 2026
1. Who we are
BigStats.email, 507 Ft. Pena, San Antonio, TX 78245 USA. Inquiries: hello@bigstats.email.
BigStats is a delivery reporting service. Customers connect their own mail transfer agent (MTA) and we process the delivery events it sends us on their behalf.
2. Data we process
- Account data: name, work email address, workspace membership and authentication records.
- Event data sent by a customer's MTA: recipient email addresses and domains, message and campaign identifiers, timestamps, sending IPs and bindings, SMTP reply codes, DSN statuses and diagnostic text, and open/click/unsubscribe/complaint events.
- Service data: ingest keys, API tokens, alert settings and recipient lists, and application logs needed to operate and secure the service.
3. How we use it
- To produce delivery, ISP and bounce reports and exports inside the customer's workspace.
- To authenticate users and keep workspaces separated.
- To send service and alert emails the customer has configured.
- To maintain, secure, debug and improve the service.
We do not sell personal data, and we do not use customer event data to build advertising or marketing profiles.
4. Legal roles
For event data ingested from a customer's MTA, the customer is the controller and BigStats.email is the processor, governed by the Data Processing Agreement. For account and billing data about our own customers, BigStats.email is the controller.
5. Sharing and subprocessors
We share data only with the infrastructure providers needed to run BigStats — application and database hosting, and our transactional email provider — and only as needed to deliver the service. A current list of subprocessors is available on request at hello@bigstats.email.
6. Security
- Data is encrypted in transit over TLS and encrypted at rest by our hosting provider.
- Workspace data access is enforced at the database with row-level security; members only see workspaces they belong to.
- Ingest keys and API tokens are workspace-scoped and can be rotated or revoked at any time.
- Administrative access is limited to personnel who need it to operate the service.
No system is perfectly secure, and we make no guarantee that a breach can never occur.
7. Retention
Event data is retained for the customer's configured retention window, or for the life of the account where no shorter window has been set. On account closure we delete or return workspace data on request as described in the DPA. Backups age out on our provider's normal cycle.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict processing of your personal data, and to object to it. If your data reached BigStats because one of our customers sent mail to you, please contact that sender — we will forward requests we receive and assist them. Otherwise, write to hello@bigstats.email and we will respond within the time required by applicable law.
9. International transfers
BigStats is operated from the United States and data may be processed there. Where required, transfers rely on Standard Contractual Clauses, which are incorporated by reference into our DPA.
10. Cookies
We use only the cookies and local storage needed to keep you signed in and to remember basic preferences. We do not run third-party advertising trackers.
11. Changes and contact
We will post any material change to this policy here and update the date above. Questions, requests or complaints: hello@bigstats.email, or write to us at 507 Ft. Pena, San Antonio, TX 78245 USA.
This document is maintained by BigStats.email and is provided for information; it is not legal advice.