Privacy Policy
Last updated 26 September 2026
This Privacy Policy explains how Sequenzo (“Sequenzo”, “we”, “us”) collects, uses, stores, shares and deletes personal data when you use Sequenzo, the dashboard, API or Chrome extension. It covers both customers who hold a Sequenzo account and recipients of email sent by a customer through Sequenzo.
Controller contact. The controller for account, billing, support, security and website data is Sequenzo. Our privacy contact is [email protected].
1Roles and responsibilities
For your account, billing, support and security data, Sequenzo is the controller. For contact records, message content and recipient data that you upload or create in your workspace, you are generally the controller and Sequenzo is your processor. We process that data on your documented instructions to provide the features you request. Our Data Processing Agreement explains the processor terms.
If a recipient contacts Sequenzo directly, we may forward the request to the customer who sent the message and, where required by law, act on the request ourselves. Customers remain responsible for having a lawful basis and providing any notice required for their outreach.
2What we collect and where it comes from
Account and workspace data. Name, email address, hashed password, account settings, workspace and team membership, roles, plan and entitlements, two-factor data, support conversations, audit events, invoices and payment-related metadata. Payment gateways process card details; Sequenzo does not store full card numbers.
Mailbox and message data. The address of a connected mailbox, connection metadata, SMTP/IMAP app-password information or OAuth tokens where that connection method is enabled, and metadata needed to send and monitor messages: recipients, sender, subject, thread identifiers, timestamps, delivery outcome, bounce and reply status. Message bodies you write in Sequenzo, including templates, sequence steps and signatures, are stored so the service can send them. A connected mailbox may also provide the messages or headers needed to detect replies, depending on its connection method and your settings.
Contact and recipient data. Customers may upload names, email addresses, companies, job titles, phone numbers, custom fields, notes and other contact data. We also create engagement records such as sent, delivered, opened, clicked, replied, bounced, unsubscribed and suppressed.
Technical and usage data. IP address, browser and device information, request identifiers, timestamps, error information, security events and application logs. If a customer enables tracking, an open pixel records an event and approximate client information, and a tracked link records a click. Customers can switch tracking off for supported flows.
Data sources. We receive data directly from you, from your workspace members, from connected mailboxes and integrations, from the Chrome extension and browser, from payment and transactional-email providers, from support messages and inbound webhooks, and from recipients who click, open, reply, unsubscribe or report a message.
We do not intentionally request special-category or sensitive personal data. Customers must not upload it unless they have a lawful basis and the necessary safeguards.
3Why we use data and legal bases
- Provide the service — create and secure accounts, operate workspaces, store sequences and contacts, send requested messages, detect replies and provide reports; normally performance of our contract with you.
- Secure and prevent abuse — rate limiting, fraud and spam detection, sending controls, suppression, audit logs and incident response; our legitimate interests and legal duties.
- Bill and account for the service — contract, accounting and tax obligations.
- Provide support — answer requests, investigate problems and protect the service; contract and legitimate interests.
- Improve reliability — diagnose errors, measure performance and maintain security; legitimate interests, with minimisation and access controls.
- Send service communications — verification, security, billing and operational notices; contract and legal obligations. Marketing communications use consent where required and include an unsubscribe mechanism.
We do not sell personal data or share it with advertisers. We do not use customer content or recipient data to train general AI or machine-learning models. Where you request an AI feature, the text needed to produce that response is sent to the configured model provider under the applicable provider terms and controls.
4Who we share data with
We share only the data needed for the relevant task with service providers acting under contract, including:
- cloud hosting, database, backup and infrastructure providers;
- your connected mail provider or SMTP/IMAP host, to send or process the messages you request;
- transactional email providers for verification, password-reset and system notices;
- payment gateways for billing and subscription administration;
- error monitoring, security and operational-log providers, with data minimised where practical;
- CRM, calendar, webhook or AI providers only when you enable the relevant feature; and
- professional advisers, regulators, courts or law enforcement when disclosure is required by law.
We do not disclose recipient data to advertisers or data brokers. A current subprocessor list and processing details are available from [email protected].
5Google services, Gmail and the Chrome extension
The Chrome extension is optional. It runs on the supported webmail hosts listed in its Chrome Web Store description and manifest, plus Sequenzo’s own origin for sign-in and connection flows. It helps you attach a follow-up sequence to a message you are composing and may process the recipients, subject and body of that compose message when you choose to use a Sequenzo feature.
Current Gmail connection status. Gmail mailbox OAuth is currently disabled by the Sequenzo platform administrator. The currently supported Gmail mailbox setup is an app-password or SMTP/IMAP configuration, where available. Those credentials are handled by the server and encrypted at rest. This platform setting does not prevent Google account sign-in from being reviewed or enabled separately.
Google OAuth capability. The submitted extension contains a Google browser-authentication flow. It requests the identity scopes openid, email and profile, together with the Gmail send scope https://www.googleapis.com/auth/gmail.send. The current shipped mode does not request gmail.readonly or Gmail modify access. Google data obtained through that flow is used only to authenticate the selected account and send the messages that the user explicitly asks Sequenzo to send. It is not sold, transferred to advertisers or data brokers, used for advertising, or used to train general AI models.
Sequenzo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Humans do not read Google user data except with your explicit permission for support, where required by law, or where strictly necessary for security and abuse investigation.
What the extension does not do. The extension does not download, index or scan your entire inbox, read unrelated messages, collect passwords, track general browsing, or silently scrape arbitrary websites. It does not send mail content to unrelated third parties for advertising. Mailbox app passwords and server-side mailbox OAuth credentials are not stored in the extension. Authentication/session tokens used to maintain the Sequenzo extension session are stored locally in Chrome as described below.
Extension storage and permissions. The extension uses chrome.storage.local for extension session data, including authentication/session tokens, cached sequence state and local preferences. This storage is on your device; uninstalling the extension removes its local storage but does not delete server-side account or mailbox data. Its permissions are used as follows:
- storage stores sessions, cached sequences and settings locally.
- identity supports Google or Microsoft browser authentication when you use it.
- alarms refreshes cached extension data and scheduled local checks.
- tabs and scripting identify supported compose pages and render Sequenzo controls.
- Listed host access allows operation on supported webmail products.
- Optional broader host access is requested only if you grant it for custom or private webmail; it is not used to run silently across the entire web.
Extension requests for Sequenzo features go to https://app.getsequenzo.com/api. You can revoke mailbox access with your mail provider or disconnect the mailbox in Sequenzo.
6AI and automated processing
AI features may draft text, personalize a message, classify a reply or provide a suggested action when you request them. AI output is a suggestion and you remain responsible for reviewing it, the recipients you select and the message you send. AI does not make final decisions about your legal rights, billing, account ownership or whether a message must be sent.
Abuse controls and sending safeguards may automatically pause or limit an account based on operational signals such as bounce, complaint, authentication or payment events. You may contact[email protected] if you need information about a decision affecting your account or wish to challenge it.
7How long we keep data
- Account and workspace data: while the account is open, then deleted or anonymised within 30 days of closure, subject to legal exceptions.
- Contacts, sequences, templates and engagement history: until you delete them or the workspace is closed, followed by the applicable deletion process.
- Deleted follow-ups: normally recoverable for 7 days before permanent purge.
- Deletion requests: a 14-day grace period allows the account holder to cancel an accidental request; sending is paused during that period.
- Suppression records for unsubscribes, complaints and hard bounces: retained indefinitely or for as long as needed to prevent re-contact.
- Invoices and tax records: for the period required by applicable tax and accounting law.
- Application, security and operational logs: according to the configured retention policy and normally no longer than 90 days unless needed for an incident or legal claim.
- Database backups: retained on a rolling schedule, currently 14 days for the standard backup script, subject to configured deployment settings.
8Security
Traffic is protected with TLS. Passwords are hashed. Mailbox credentials, gateway keys and other secrets are encrypted at rest using separate encryption domains where applicable. Access is restricted by role and tenant, production access is audited, administrative accounts use stronger authentication controls, and backups are verified through restore procedures. No system is perfectly secure; if a legally reportable incident affects your data, we will notify the relevant parties within the applicable legal deadlines.
9Your rights and deletion requests
Depending on your location, you may have rights to access, correct, delete, restrict or port your personal data, object to processing based on legitimate interests, and withdraw consent. Customers can export workspace data and request account erasure from Account → Privacy & data. We may verify a request before acting on it.
Write to [email protected]. We aim to respond within 30 days, or within the shorter period required by applicable law. You may also complain to your local data protection authority. Deletion may not remove suppression records, invoices, security records or data that we must retain by law.
10If you received an email sent through Sequenzo
The sender is our customer, not Sequenzo. Use the unsubscribe link in the message or your mail client’s own unsubscribe control. This stops queued follow-ups and adds your address to the sender’s suppression list. If the link does not work or you want help, email [email protected] with the message and relevant headers. We will act on the request and, where appropriate, pass it to the sender.
11Cookies, tracking and local storage
Sequenzo uses an essential secure HttpOnly session cookie for authentication and may store small amounts of interface state in your browser. We do not use advertising or cross-site advertising cookies. Email open pixels and tracked links are separate message-level technologies controlled by the customer and described above; they are not advertising cookies on this website.
12Children and sensitive data
Sequenzo is intended for businesses and professional users and is not directed to children under the minimum age required in their jurisdiction. We do not knowingly collect children’s data. Customers must not upload special-category, sensitive or children’s data unless they have a lawful basis and appropriate safeguards.
13International transfers
Our infrastructure and service providers may process data outside your country. Where required, we rely on an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Addendum or another legally recognised safeguard, together with security measures such as encryption, access controls and data minimisation.
14Changes and contact
We may update this policy to reflect product, legal or operational changes. Material changes are announced in-app or by email where appropriate, and the date at the top of this page shows the current version. Contact for this policy, data rights, Google user-data questions or deletion requests: [email protected].