Privacy Policy
Last updated: August 8, 2026
1. Who we are
ColdOps ("we", "us") provides monitoring, alerting and reporting software for cold email agencies ("the Service"). This policy explains what data we collect, why and how we handle it. Questions: support@coldops.io.
2. Data we collect
Account data: your email address, password (hashed by our authentication provider) and agency name.
Connected platform data: when you connect a sending platform (e.g. Instantly) we store the API key you provide (encrypted with AES-256-GCM) and use it to read campaign names, aggregate campaign statistics (sends, opens, replies, bounces, opportunities) and mailbox account status. We do not read the content of your emails and we do not store your leads' personal contact data.
Client records you create: client names, company names and the contact details you choose to store for sending weekly updates.
Tool submissions: when you use a free tool that asks for your email (e.g. the deliverability checker), we store the email address and the domain you entered so we can return the result and, with your agreement, send you related tips. You can unsubscribe at any time.
Usage data: first-party product events (e.g. sync completed, report generated) stored in our own database to improve the Service. We also use Vercel Analytics and Vercel Speed Insights, which record page views and page-performance measurements for our own internal use. Both are cookieless, neither builds a profile of you across sites and the data is never sold, shared or used for advertising. We use no advertising or cross-site tracking networks of any kind.
Visitor firmographics: We derive company-level firmographic data (e.g. company or network name and country) from visitor IP addresses for internal analytics. We do not store raw IP addresses and do not identify individuals through this process.
Billing data: payment is processed by Stripe. We never see or store full card numbers.
3. Legal basis for processing
For customers in the EEA/UK, we rely on: performance of a contract to provide the Service you sign up for; our legitimate interests in operating, securing and improving the Service (balanced against your rights); and your consent where the law requires it — for example, optional marketing email — which you can withdraw at any time.
4. How we use data
To provide the Service: syncing campaign metrics, detecting issues, sending the alerts and digests you configure and generating AI summaries. Campaign metrics are shared with our AI provider (Anthropic) solely to generate the summaries you request; they are not used to train models. We do not sell your data. We do not use your data for advertising.
5. Cookies
We use only strictly-necessary cookies — the session cookies our authentication provider (Supabase) sets to keep you logged in. We use no advertising or tracking cookies. The analytics described in section 2 are cookieless, so no cookie-consent banner is required. You can clear these cookies in your browser at any time, though doing so will sign you out.
6. Subprocessors
Supabase (database & authentication), Vercel (hosting, plus the cookieless page and performance analytics described in section 2), Stripe (payments), Resend (transactional email), Anthropic (AI summaries). Each processes data only as needed to provide their service to us.
Two narrower cases: when visitor firmographics are enabled, IPinfo receives the visitor IP address to return company-level data, which we store without the IP itself. Domain reputation and DNS checks send only the sending domain — never an email address or a person — to Spamhaus and to WHOIS/RDAP lookup providers. The full list, including what each one receives, is in our Data Processing Agreement.
Where we act as a processor for the campaign data you connect, we have a written Data Processing Agreement (GDPR Article 28). It sets out the full subprocessor list, the technical measures we apply, our breach-notification commitment and what we do on deletion — including, plainly, what we don't have. Email support@coldops.io and we'll send it within one business day.
7. International data transfers
Some of our subprocessors are located in the United States. Where personal data is transferred outside the EEA/UK, that transfer is covered by the European Commission's Standard Contractual Clauses (or an equivalent safeguard) provided by the subprocessor, together with the technical measures described below.
8. Security
All traffic is encrypted in transit (TLS). Platform API keys are encrypted at rest with AES-256-GCM and are never displayed after entry. Database access is isolated per agency with row-level security. Deleting a connection permanently destroys its stored key; deleting your account removes your data within 30 days.
9. Data retention & your rights
We retain synced metrics while your account is active. You may export or request deletion of your data at any time by emailing support@coldops.io. If you are in the EEA/UK, you have the rights provided by the GDPR (access, rectification, erasure, portability, objection); we act as processor for the campaign data you connect and as controller for your account data.
10. Changes
We will notify account holders by email of material changes to this policy at least 14 days before they take effect.