Privacy policy
This explains what Mooring does with personal data. We have tried to write it in plain English rather than the usual fog. If anything is unclear, ask us at [email protected].
Who is responsible
[LEGAL ENTITY NAME], [TRADING ADDRESS, UK], is the data controller for your account data and is registered with the Information Commissioner’s Office under [ICO REGISTRATION NUMBER].
There is an important split. For your account — your name, your email address, your domains — we are the controller and this policy governs it. For the contents of your mailbox, including messages other people send you, we act as a processor on your behalf: we store and transmit that mail so you can read it, and we do not use it for our own purposes.
What we collect and why
- Account details — your name, email address and password. Passwords are stored only as a bcrypt hash, so we never hold or see the password itself. Needed to perform our contract with you.
- Domains and mailboxes — the domain names you add and the mailbox addresses you create. Needed to perform the contract.
- DNS check results — the MX, SPF, DKIM and DMARC records published for your domain, and when we last looked. These are public records; we store the result so the setup page can show it.
- Mail content — messages, attachments, calendar entries and contacts in your mailbox, held so we can deliver the service. We do not read your mail, and we do not scan it for advertising. Staff access happens only where you ask for help with a fault, or where we are investigating abuse or are required by law, and it is logged.
- Waitlist entries — if you ask to be told when signups open, your email address, until we contact you or you ask us to remove it.
- Invite notes — if an administrator writes a note against an invite so they remember who it was for.
- Server logs — IP address, browser user agent, the page or mail transaction, and a timestamp. Kept for 30 days to keep the service secure, debug faults, and deal with abuse. Our legitimate interest in running a service that isn’t overrun.
We do not run analytics, advertising or tracking of any kind. There is no Google Analytics, no pixels, no fingerprinting, and we do not sell or rent personal data to anybody, ever.
Cookies
One cookie, used to keep you signed in. The detail is on the cookies page.
Who else sees it
- DigitalOcean (London) — hosts the servers the service runs on. Data is held in the United Kingdom.
- Cloudflare — when the setup page checks your DNS, we look the records up through Cloudflare’s public DNS resolver at cloudflare-dns.com. That query contains the domain name being checked.
- Mail recipients and their providers — self-evidently, mail you send goes to the people you send it to, and passes through their provider.
- Law enforcement or regulators — where we are legally required to disclose, or to establish or defend legal claims.
Typefaces are served from our own servers rather than a font CDN, so loading a page does not tell a third party that you visited.
Where it is held
On servers in the United Kingdom. We do not transfer personal data outside the UK, other than the unavoidable case of mail you choose to send to someone abroad.
How long we keep it
- Account data and mail: until you close your account.
- After closure: deleted from live systems within 30 days, and from backups within a further 30 days as the backups age out.
- Server logs: 30 days.
- Waitlist entries: until you join, ask to be removed, or we decide not to launch.
- Records we must keep by law, such as for tax, are kept for as long as the law requires.
Your rights
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you;
- correct it if it is wrong;
- delete it, where we have no overriding reason to keep it;
- restrict or object to how we use it;
- hand it to you, or to another provider, in a portable format — mailboxes can be exported over IMAP by your mail client.
Email [email protected] and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.
How we protect it
- Traffic to the site and to mail servers is encrypted in transit.
- Passwords are hashed with bcrypt, never stored in a readable form.
- Session cookies are HTTP-only, so page scripts cannot read them, and are marked secure in production.
- Administrative access is limited to those who need it.
No service is perfectly secure. If we suffer a breach that is likely to risk your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay.
Children
The service is not intended for under-16s and we do not knowingly hold their data.
Changes
If we change this policy materially we will email the address on your account. The date at the foot of the page shows when it was last revised.