mxping

Privacy Policy

Last updated: June 13, 2026

This Privacy Policy explains how mxping ("we", "us") collects, uses, discloses, and safeguards personal data when you use our website, dashboard, and email validation API (the "Service"). We act as a data controller for account and billing data, and as a data processor for the email addresses you submit for verification.

1. Data we collect

Account data

When you sign up we collect your name, email address, and authentication identifiers. Authentication is handled by our identity provider, Clerk; we do not store your password.

Verification data (your customers' email addresses)

When you call the Service, you submit email addresses for verification. These addresses are personal data of your end users. We process each address to perform syntax, domain and MX checks and to return a result. We may cache verification results for a limited period to improve performance and reduce duplicate network lookups. We do not use submitted email addresses to send marketing, and we do not sell them.

Usage and billing data

We collect aggregated usage metrics (verification counts, timestamps, quota consumption) to operate quotas and analytics. Payments are processed by Stripe; we store a customer/subscription reference but not full card numbers.

Technical data

We collect IP addresses, request metadata, and device/browser information for security, rate limiting, and abuse prevention.

2. How we use data

  • to provide, operate, and secure the Service;
  • to perform the email verifications you request;
  • to enforce quotas and rate limits and prevent abuse;
  • to process payments and manage your subscription;
  • to communicate service notices and respond to support requests; and
  • to comply with legal obligations.

3. Legal bases (GDPR)

Where the GDPR applies, we rely on: contract (to provide the Service you signed up for), legitimate interests (security, abuse prevention, and improving the Service), and legal obligation (tax and accounting records). For email addresses you submit, you are the controller and are responsible for establishing a lawful basis to process them.

4. Data sharing and sub-processors

We share data with vendors who process it on our behalf under contract, including:

  • Clerk — authentication and user management;
  • Stripe — payment processing and billing;
  • Railway — application hosting and databases;
  • Vercel — website and dashboard hosting;
  • Cloudflare — DNS, object storage for bulk files and backups, and bot protection for our public demo;
  • Sentry — error monitoring (no email addresses or request bodies are sent); and
  • Resend — transactional email (welcome, quota and billing notices).

We do not sell personal data. We may disclose data if required by law or to protect our rights and the safety of users.

5. Data retention

Account and billing records are retained for the life of your account and as required by law thereafter. Verification results are kept in your account history for up to 13 months and then deleted automatically; a short-lived cache (up to 24 hours) speeds up repeated lookups. Deleting your account revokes your API keys and removes your verification history immediately; billing records are retained as required by law.

6. International transfers

Your data may be processed in countries other than your own. Where data is transferred out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. EEA/UK residents may lodge a complaint with a supervisory authority. California residents have rights under the CCPA/CPRA, including the right to know and the right to delete; we do not sell or share personal data as those terms are defined under California law. To exercise any right, contact us at privacy@mxping.dev. Note that for email addresses you submitted as a controller, end-user requests should be directed to you; we will assist you as your processor.

8. Security

We use encryption in transit, scoped API keys, access controls, and monitoring to protect data. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

10. Cookies

We use cookies and similar technologies as described in our Cookie Policy.

11. Changes

We may update this policy from time to time. Material changes will be announced through the Service or by email.

12. Contact

For privacy questions or to exercise your rights, contact privacy@mxping.dev.