Legal

Privacy policy

Data about you

When you create an account we store:

  • your name and email address;
  • a hash of your password, if you signed up with one — never the password itself;
  • your Google account identifier, if you signed in with Google;
  • your subscription status and payment history, so we know what your plan allows.

We use it to run your account, to send you the emails the product depends on — your audit is ready, contacts are waiting for your approval, what was archived, the monthly summary — and to answer you when you write. We don't send marketing email you didn't ask for, and we don't sell or rent any of it.

Your Mailchimp connection

We store the access token Mailchimp issues when you authorise the connection, along with your Mailchimp account name, email and data centre. The token is stored encrypted at rest by our database provider.

That token can read and write in your Mailchimp account, because Mailchimp's OAuth offers no narrower scope. What limits it is our code, not the permission — see the terms for exactly which operations write.

The people in your audiences

To produce a report we store, for each contact in the audiences you connect: email address, audience name, subscription status, signup date, last change date, member rating, average open and click rates, tags, VIP flag, engagement dates derived from your campaign reports, and — if you have an ecommerce store connected — order count, total spent and last order date.

These people are not acadion users and never agreed to anything with us. For their data you are the controller and we are your processor: we use it only to run the analysis and the archiving you asked for, on your instructions. We never contact them, never sell or share their data, and never use it to train anything.

If one of your contacts exercises a right with you — access, deletion, objection — delete or amend them in Mailchimp and the record follows on the next audit, or write to us and we'll action it directly. You are responsible for having a lawful basis to process their data and for telling them, in your own privacy notice, that a processor like us is involved.

Technical data

Our hosting and error-reporting keep the usual server logs — IP address, user agent, the request and when it happened — and records of errors, which can include the URL and the account involved. We use them to keep the service up and to debug what broke. We don't use tracking cookies or third-party analytics; the only cookies we set are the ones that keep you signed in and remember which connected account you are looking at.

Who else processes it

We use these subprocessors, each for one job. They act on our instructions and can't use your data for their own purposes.

  • Vercel — hosting, background job queue and server logs.
  • [database provider] — the Postgres database where everything above is stored.
  • Stripe — payments. Card details go straight to Stripe; we only see the subscription status and the last four digits.
  • Resend — the transactional emails the product sends.
  • Sentry — error reporting.
  • Intuit Mailchimp — the source of the data, and where the archiving happens.
  • Google — only if you choose to sign in with Google.

Some of these are based in the United States, so your data is transferred there under [transfer mechanism — SCCs or equivalent].

How long we keep it

Contact data stays while the connection is active, because it is what makes the archive log verifiable — the record of who was archived, when and under which rule is the thing that lets you undo it.

Disconnecting a Mailchimp account stops all processing for it. Deleting your acadion account removes your user record, your connections, every contact we stored and your audit history, permanently. Payment records are kept as long as tax law requires. Server logs and error reports age out on our providers' retention schedules.

To delete your account, write from the address you signed up with: hello@acadion.ai.

Your rights

Depending on where you live you can ask for a copy of your data, have it corrected or deleted, object to or restrict how we use it, and receive it in a portable form. Write to hello@acadion.aiand we'll respond within 30 days. If you think we've handled your data badly you can complain to your local data protection authority.

Security

Data is encrypted in transit and at rest, passwords are hashed, and access to production is limited to people who need it. No system is perfect — if a breach affects you, we'll tell you and the relevant authority within the deadlines the law sets.

Changes and contact

We may update this policy. For material changes we'll notify the address on your account before they take effect, and the date at the top always reflects the current version.

Questions: hello@acadion.ai, [postal address].