Skip to content
Claim your free business email

Privacy Policy

Last updated

Who we are

In this policy, “Rasket”, “we” and “us” mean the company that operates Rasket.

Rasket is an API and dashboard for sending and receiving email. This policy covers the website, the dashboard, the API, and the email our customers send through us. It explains what we collect, why, how long we keep it, and who helps us run the service.

Our role

For your Rasket account, your use of the website and the dashboard, and billing, we decide how personal data is used.

For the email a customer sends or receives through Rasket, and for the contacts, recipients and content that go with it, the customer decides and we process that data on their behalf to provide the service. If you received email from a Rasket customer, see If you received email sent through Rasket.

What we collect

Your account

Your email address and, if you give one, your name. We store your password only as an Argon2id hash. If you sign in with a third-party account we receive your account identifier, your verified email address and your name from that provider; if your team uses single sign-on, we receive the same from your organisation’s identity provider. If you turn on two-factor authentication, its secret is stored encrypted.

Sign-in and security records

Each session records the IP address, the browser’s user agent and when it was last used. Each sign-in attempt, successful or not, is recorded with its time, IP address, country, browser and whether a second factor was used. We use these records to protect your account and to spot accounts that belong together. Changes made in a team — keys created, domains added, settings changed — are written to an audit log with who made them, when, and from which IP address.

When you create an account with a password we record where the sign-up came from: the IP address, the country our hosting provider reports for it, the browser’s user agent, the result of our automated check for scripted sign-ups, and whether we sent the confirmation email. We also keep a one-way hash of your email address, which lets us recognise the same inbox again but is still personal data. We use this to stop automated sign-ups and to avoid emailing people who never asked for an account.

Billing

Payments are handled by our payment processor. We never see or store your card number: we keep your customer identifier with the processor, whether a payment method is on file, and its brand and last four digits, together with your plan, usage and invoices. We also keep a one-way hash of the card fingerprint the processor gives us, so we can tell when two accounts pay with the same card.

API requests

For each API request we log the method, path, response status, IP address, user agent and timing, with the request body after credentials are removed and attachment content is replaced by its name, size and hash.

Email, contacts and content

To deliver and report on a customer’s email we store the sender, recipients, subject, HTML and text bodies, attachments and the delivery events that follow (such as delivered, bounced or complained). Where a customer receives email through Rasket, we store the messages and attachments sent to them. Customers can also store contacts, contact properties, topic subscriptions, templates, campaigns and automations.

If you use Rasket Inbox, we store the mail your mailboxes receive and send — including attachments — until you delete it or close the mailbox. A closed mailbox is kept for 30 days so it can still be exported, and is then deleted. You can export a mailbox at any time. An admin administers the list of addresses; no admin can read another person’s own mailbox.

AI assist

AI assist is off until a team admin turns it on. When it is used, the text needed for the task is sent to a third-party AI provider: the brief and template for a subject line or draft, or, to diagnose a message, its subject, sending domain, statuses, event timeline and each recipient’s domain — never a recipient’s address. We keep a record of each request (its kind, model, token counts, timing and status, and the stored result of a diagnosis), not the prompt text.

Support

When you write to us from the dashboard’s help panel, your message and any files you attach are emailed to our support team.

When you use the contact form on our website, we keep the name, email address and company you give us and your message as a support conversation, so that a person can reply to you by email. We use them only to answer you, and we delete them if you ask.

The website

We use a third-party web analytics provider on our website (the public pages, the documentation and the sign-in pages, never the dashboard or the Inbox) to learn how people find the site and which pages and steps they use. It records the pages you visit, the site or campaign that sent you, your browser and device type, an approximate location derived from your IP address, and steps such as choosing a plan or starting a checkout. We do not send it your name or email address, and we strip sign-in and invitation links of their tokens before anything is sent. The provider keeps this data for 14 months.

If you are in the European Economic Area, the United Kingdom or Switzerland, or we cannot tell where you are, website analytics is not loaded and sets no cookie until you choose Accept in the cookie banner; if you decline, it is never loaded. Elsewhere it loads when you visit, unless your browser sends a Global Privacy Control signal. You can change your choice at any time with “Cookie settings” at the bottom of the website. The provider’s advertising features are always off: the data is not used for ads, remarketing or ad personalisation.

When a browser that allowed analytics creates an account, signs in, or becomes the account that pays for a plan, sends its first email or verifies its first domain, our servers tell the analytics provider that the step happened. They send the random identifier from that browser’s analytics cookie, which we keep with your account for this, a one-way hash of your account identifier, and the step’s own details: the sign-in method, or for a payment the invoice number, amount, currency and plan. A browser that declined sends nothing of this, and signing in from it removes the identifier we kept.

We also use a third-party tag manager on our marketing pages and documentation, never on the sign-in pages, the dashboard or the Inbox, to load measurement tags without changing the website. It is loaded under the same choice as website analytics: in the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell where you are, only after you choose Accept, and if you decline it is not loaded again. Its advertising features stay off.

The website runs no advertising or other third-party tracking scripts. Our hosting provider keeps request logs, such as the IP address and the page requested, to operate and secure the service.

If you received email sent through Rasket

The customer who sent it decides who receives their email and what it says; we deliver it for them. To deliver it we process your email address, the message itself and what happened to it — whether it was delivered, bounced, or reported as spam.

  • Open and click tracking is off unless the sender turns it on for their domain. When it is on, opening the email or clicking a link in it records the time, your IP address and your user agent (and, for a click, the link), and passes them to the sender.
  • If you unsubscribe or change your preferences on our hosted page, we record what you chose, when, your IP address and your user agent, alongside a hash of your email address. That record is how the sender shows they respected your choice.
  • An address that bounces permanently or reports a message as spam is added to the sender’s suppression list, and Rasket does not send to it for that sender while it stays there.

To access, correct or delete what a sender holds about you, contact the sender. To report email sent through Rasket that you did not ask for, write to info@rasket.com.

Mailboxes

Your team’s admins decide who can read what. A shared channel is visible to the members they choose; a personal mailbox is visible only to the member it belongs to. An admin cannot read a personal mailbox that is not theirs. When a personal mailbox is closed, an admin can download an archive of it so the team keeps the correspondence, and that download is recorded.

Rasket staff do not read your mail. We open a message only when you report it to us, when our checks stop it, or when we have to in order to keep the service running — and each time is recorded against the person who did it, with their reason.

We give mail to a public authority only when the law requires it, and we tell the team unless we are not allowed to.

Reports you send to abuse@rasket.com, or file with Report on a message, are kept with the message they concern for 12 months.

Connected apps and AI assistants

You can connect an app to your Rasket team: an AI assistant such as Claude or ChatGPT through our MCP server, or any other app that signs in to Rasket with OAuth. Nothing is shared with an app until an admin of the team approves it on Rasket’s consent screen, which names the app, the team it will act for and every permission it asks for.

  • An approved app receives an access token for that one team, carrying only the permissions the admin approved. It never receives your password or an API key.
  • What it can see or do depends on those permissions — for example, reading the email your team has sent and how it was delivered, reading your contacts, or sending email from your verified domains. Each permission is described in the OAuth documentation.
  • No permission lets an app create or revoke API keys, change your plan, billing or team members, delete sent mail, or manage which apps are connected.
  • What an app reads from Rasket goes to that app and to whoever runs it — for an AI assistant, the company that provides it. From then on, that company’s own terms and privacy policy decide what happens to it.
  • Requests an app makes are logged like any other API request, and kept for the same 30 days.

To disconnect an app, go to Settings → Team → Authorized apps in the dashboard, which lists every app that can act for the team, and choose Revoke. Every token the app holds stops working at once. An access token lasts an hour and a refresh token 30 days, so an app the team stops using loses access on its own. A revoked or expired token is deleted 30 days later, and the record of the approval — which app, which permissions, when — 90 days after it is revoked.

If your team connects a team chat app for alerts, Rasket keeps the workspace’s name and id, an encrypted access token, the channel each alert goes to, and which people there are which members of your team. It posts the alerts your team chooses to the channels you pick: names and numbers, never the content of an email. The chat app is a destination you choose, not a provider that works for us, and its own terms and privacy policy cover what is posted there. Alerts are deleted from Rasket a week after they are posted, and everything else when your team disconnects the app.

If your team connects a website builder, Rasket keeps an encrypted access token, the name of the person who approved it, and each connected site’s name, domains and form names. It receives the submissions of the forms your team turns on and, if your team turns store orders on, new orders, and keeps what your team’s settings say to keep: contacts, their consent records and store events. It adds its script to your sites. The token is deleted when your team disconnects the website builder or removes the app there.

We do not sell personal data, and we do not give a connected app anything its permissions do not cover.

How we use it

  • To provide the service: accept, send, receive and report on email.
  • To keep accounts secure and prevent abuse: checking messages for phishing and malware patterns, and watching bounce and complaint rates so that a sender who harms other senders’ delivery is restricted.
  • To bill for paid plans and usage.
  • To answer support requests and send the email the service needs, such as address verification and password resets.
  • To meet legal, tax and accounting obligations.

How long we keep it

Retention is set per plan and enforced by a nightly deletion job. Email data is deleted, not just hidden, when its window ends.

DataKept for
Email metadata, bodies, attachments and events; API request logs; webhook deliveries30 days on every self-serve plan; Enterprise teams can agree a different window
Mail your mailboxes receive and sendUntil you delete it or the mailbox is full; a closed mailbox is kept 30 days for export, then deleted
Contact import files7 days after the import completes
AI assist records, automation run history, raw delivery notifications from our email delivery provider, platform metrics90 days
Unsubscribe and consent records3 years after the consent expires
Messages sent through the website’s contact formUntil you ask us to delete them
Audit logs, the usage ledger and billing records7 years
Your account, team, domains, contacts, templates and suppression listUntil you delete them, or the team is deleted
An account whose email address was never confirmed and that was never used, with its empty teamMay be deleted 7 days after sign-up
Sign-in sessions30 days at most, and 7 days without use
Sign-up records90 days, even if the account is deleted sooner
Sign-in records and the card fingerprint hash1 year

Deleted data can remain in database backups for up to 90 days. Backups are used only to recover from a disaster, never to answer a customer request. We may keep a team’s data beyond these periods while it is subject to a legal dispute, a lawful request or an abuse investigation.

Third parties that help us run the service

We use trusted third-party providers to run Rasket. They process personal data for us only to provide the service, and only the data their part of it needs. Our Data Processing Addendum covers the data we process for customers.

Kind of providerWhat they receiveWhy
Hosting and file storageEverything the website, dashboard and API handle, including attachments, raw messages and exportsTo run the service and store its files
Database hostingThe data the service storesTo keep the service’s database
Background jobsEach job’s message and result until it has runTo queue and schedule the work that sends, receives and reports on email
Email deliveryMessages, their senders and recipients, and delivery events; received messages briefly until processedTo send and receive email, including over SMTP
PaymentsBilling details, payment method and invoicesTo take payments and run the billing portal
Sign-inYour account identifier, email address and nameOnly if you choose to sign in with another account
DNSYour domain names and their DNS recordsTo verify domains, and to apply records if you connect a DNS provider
AI featuresThe text needed for the task, never a recipient’s addressTo answer AI assist requests when a team has turned it on, and help-assistant questions
Website analyticsPages visited on our website, how you arrived, device and browser type, approximate location, an analytics identifier, and the account steps listed above, never your name or email addressTo learn how people find and use the website, only with your consent where the law asks for it

Each provider is bound by a contract, including data processing terms, that limits what it may do with the data, requires it to keep the data confidential and secure, and forbids it to use the data for its own purposes. We do not sell personal data. We do not name our providers here. The current list is available on request: Request more information, or write to info@rasket.com.

Our application and database run in the United States, so personal data from other countries is transferred there, and some providers process it in other countries too. Where the law that applies to you requires it, we protect those transfers with the Standard Contractual Clauses approved by the European Commission, or the equivalent mechanism that law recognises.

Security

  • Connections to Rasket, and from Rasket to its database and storage, use TLS.
  • The database is encrypted at rest, and every team’s rows are separated by row-level security in the database as well as by the application.
  • Passwords are hashed with Argon2id; API keys are shown once and stored only as hashes.
  • Webhook signing secrets, DKIM private keys, two-factor secrets and single sign-on client secrets are encrypted with AES-256-GCM, each under its own data key.
  • Every member can turn on two-factor authentication, and teams can require OpenID Connect single sign-on on the Scale plan (as an add-on) and Enterprise.
  • Our logs leave out credentials, cookies and email bodies.

Your choices and rights

  • You can reset your password from the sign-in page and turn two-factor authentication on or off in the dashboard.
  • A team decides whether AI assist is on, and whether open and click tracking is on for each of its domains. Both are off by default.
  • Customers can delete a contact through the dashboard or the API; its personal data is removed and only the hashed consent record remains.
  • A project’s admin can download a copy of the project’s data, or delete the project, from Settings → Data in the dashboard. The export is a file of the project’s data that can be downloaded for 7 days. Deleting a project stops its sending immediately and erases its data 30 days later, and any admin can cancel it until then. These are how you use your rights of access, portability and erasure for a project’s data.
  • Deleting your own account is available on request: write to info@rasket.com from the account’s email address.

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how it is used, and to complain to a data protection authority. Write to us to use any of them.

Cookies

Rasket sets no advertising cookies. The cookies below that are needed to sign you in are set only when you sign in. The analytics cookies are set only as described above: after you accept them, or, outside the European Economic Area, the United Kingdom and Switzerland, unless you decline. We remember your choice in one more cookie.

CookiePurposeLasts
rsk_sessionKeeps you signed in30 days, or 7 days without use
rsk_themeRemembers whether you chose the light or the dark appearance1 year
rsk_mfaCarries you from your password to your two-factor code5 minutes
rsk_oauthProtects a sign-in with a third-party account10 minutes
rsk_ssoProtects a single sign-on sign-in10 minutes
Website analytics cookiesSet by our website analytics provider: tell one browser from another with a random identifier, and keep track of the current visitUp to 2 years
rasket_consentRemembers whether you accepted or declined analytics cookies1 year

The website also remembers a few display choices in your browser’s local storage, such as the code language you picked in the documentation.

To learn more about the cookies our providers set, Request more information.

Changes to this policy

When this policy changes we update the date at the top of this page. The Terms of Service describe what you agree to when you use Rasket, and the Acceptable Use Policy says what you may send.

Contact

Questions about this policy or your data: info@rasket.com. For help with your account: support@rasket.com. To report abuse from a Rasket mailbox or a message sent through Rasket: abuse@rasket.com.