Legal
Privacy Policy
Last updated
This Privacy Policy explains how Work Reactor Inc., operating as Unitpost (“Unitpost,” “we,” “us,” or “our”), collects, uses, and protects personal information when you use our website, API, dashboard, and related services (the “Service”).
Unitpost is email and SMS infrastructure for developers. Two very different kinds of data flow through us, and we treat them differently: the account data you give us to run your account, and the recipient and message data you send through us to deliver email and text messages. For the latter we act only as your processor: we handle it on your instructions and never sell it.
01Scope: controller vs. processor
Data-protection laws distinguish between a controller (who decides why and how data is processed) and a processor (who processes data on a controller’s behalf). Unitpost plays both roles:
- We are the controller of the information about you as our customer — your account details, billing information, support conversations, and how you use the dashboard and website.
- We are a processor for the personal data contained in the emails you send: recipient addresses, names, message content, and the resulting delivery, open, and click events. You are the controller of that data; we process it solely to provide the Service to you and as described in our Terms of Service.
- We are likewise a processor for the personal data in the text messages you send: recipient phone numbers, the consent and opt-out records you keep with us, message content, inbound replies, and the resulting delivery events. You are the controller of that data and the sender of record with the carriers; we process it solely to deliver your messages, keep your consent and suppression records, and meet carrier and legal requirements.
If you received an email or text message delivered through Unitpost and want to know how your data is used or exercise your rights, please contact the sender (our customer), who controls that data. We will support our customers in responding to those requests. To stop text messages from a sender, reply STOP to the number they came from; you can also report unwanted messages to us under our SMS Messaging Policy.
02Information we collect
Information you provide
- Account information. Your email address, name, and workspace/organization details. Unitpost is passwordless — you sign in with a one-time passcode sent to your email, or through Google or GitHub — so we do not store passwords. Where you enable two-factor authentication, a verification code may also be delivered by SMS. If you optionally opt in during account setup, we may also send account-notification texts (security alerts and important updates about your own account) to that number. Phone verification is not consent to those texts — see our SMS Terms.
- Billing information. Plan selection and billing contact details. Card payments are handled by our payment processor, Stripe; Unitpost does not store full card numbers.
- Sending configuration. Sending domains, DNS/DKIM records, API keys (stored only as a hash), webhook endpoints, templates, and suppression entries. For SMS: the business, contact and use-case details, sample messages, opt-in description and HELP/STOP text you submit for carrier registration of a number or Sender ID, the documents you upload to support it, and an immutable snapshot of each submission as sent to the carrier registry.
- Support & communications. Messages you send us and any information you choose to include.
Information collected automatically
- Usage & log data. IP address, browser and device type, pages and features used, timestamps, and diagnostic data, used to operate, secure, and improve the Service.
- Sending activity. Records of API calls, message events (queued, sent, delivered, bounced, complained, opened, clicked), and rate-limit and abuse signals tied to your account.
- SMS recipient data (as your processor). For each text message you send: the recipient's phone number, the country derived from that number, the message text, the sending number or Sender ID, and the delivery receipts carriers return (sent, delivered, failed, with the carrier's reason). For each consent action you record or a recipient triggers: the action (opt-in, opt-out, re-opt-in, import), its source (web form, keyword, import, API, dashboard, and so on), the purpose (marketing or transactional), the time it occurred and the time we recorded it, and, where you supply them, a link to your evidence and the version of the disclosure shown. For replies a recipient sends to your number: the reply text (including STOP, HELP and START keywords) and the time received. We do not collect the recipient's IP address or device for SMS consent; if your opt-in form captures those, they stay in your systems unless you include them in the evidence you link.
03How we use information
- Provide, maintain, and secure the Service and your account.
- Deliver the emails and text messages you send and provide deliverability analytics, logs, and webhooks.
- Keep the SMS consent, opt-out and suppression records you and your recipients create, register your numbers and Sender IDs with carriers and registries, and answer STOP and HELP replies on your behalf.
- Process payments, manage subscriptions, and enforce plan limits.
- Detect, prevent, and investigate fraud, spam, and abuse, and enforce our Terms and Acceptable Use rules.
- Communicate with you about your account, security, and service-related notices.
- Send product or marketing messages where permitted — you can opt out at any time; account and transactional notices are not optional.
- Comply with legal obligations and enforce our agreements.
We may also create aggregated or de-identified data (for example, platform-level delivery statistics) that no longer identifies you or your recipients, and use it to operate, benchmark, and improve the Service. We commit to not re-identifying such data.
04Recipient & message data
When you send email through Unitpost, we process the recipient addresses and message content you supply purely to deliver that email and give you the associated logs and analytics. We act as your processor for this data and do not sell it or use it for our own marketing. We do not read the content of your messages except as needed to operate the Service, for example automated scanning to prevent spam, phishing, and abuse, or to troubleshoot a delivery issue.
The same applies to the text messages you send. The text of every SMS is checked automatically against carrier content rules before it is sent, and a sample of unique messages may be reviewed by an automated model for abuse; this screening is described in the SMS Messaging Policy. Consent and opt-out records are kept so that you, we, and the carriers can show that a recipient agreed to be messaged and when they asked to stop.
You are responsible for having a lawful basis (such as consent) to email or text your recipients and for honoring unsubscribe, STOP and suppression requests. Unitpost maintains suppression lists to help prevent sending to addresses that have bounced, complained, or unsubscribed, and to phone numbers that have opted out. An SMS opt-out stops every text message from that workspace to that number, including service messages, and does not change the recipient's email subscription.
07Subprocessors
We use the following subprocessors to provide the Service, under contracts that impose data-protection obligations no less protective than this policy. We may update this list as our infrastructure evolves and will keep this page current; if you need advance notice of subprocessor changes, contact us at legal@unitpost.com.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, email delivery (SES), SMS delivery and carrier registration (End User Messaging SMS: message content, destination numbers, consent and registration details are passed to carriers and registries through it), file/object storage (S3), rate-limit counters (DynamoDB), encryption key management (KMS), and content delivery (CloudFront) | United States (us-east-1) |
| Supabase | Primary application database and authentication | United States |
| Stripe | Payment processing and subscription billing | United States |
| Google Cloud (Vertex AI) | Hosts the AI models behind the optional in-product assistant; processes the content you submit to the assistant to generate responses | United States |
| Intercom | In-app and website support messaging | United States |
| Twilio | Delivery of one-time passcodes over SMS (where enabled) | United States |
| PostHog | Product analytics and session replay to understand and improve how the Service is used | United States |
| Google Analytics | Aggregate website analytics for our public marketing pages | United States |
08Data retention
We keep account information for as long as your account is active and as needed to provide the Service. Email message logs and event data are retained according to your plan’s retention window; after that they are deleted or aggregated. Email message content is retained only as long as needed to deliver it and support the Service.
For SMS we keep, for as long as your workspace exists: the log of each text message you send and receive (number, text, sending identity, status and carrier receipts); the append-only record of every consent and opt-out action; the suppression entry created by an opt-out, which survives deletion of the contact it belongs to and is honored for every later send from your workspace until a new opt-in is recorded; and the snapshot of each carrier registration submission. These are not pruned by your plan’s log retention window, because carriers and telemarketing laws expect a sender to be able to show, years later, that a recipient consented and when they opted out.
You can delete your account at any time from Settings, Profile, which removes your workspace data, including the SMS records above, after your numbers and registrations have been released with the carrier. If you need consent or opt-out records after deleting a workspace, export them first (the API returns the consent history for each contact). We may retain limited information as required for legal, tax, accounting, security, and anti-abuse purposes. Deleted data may also persist for a limited period in encrypted backups and system logs maintained for disaster recovery and security; such residual copies are purged on our standard backup rotation schedule and are not used for any other purpose.
09Security
We apply industry-standard safeguards, including encryption of data in transit and at rest, encryption of sensitive credentials (such as DKIM keys) with managed keys, hashing of API keys, signed webhooks, rate limiting, and access controls. No method of transmission or storage is completely secure, but we work continuously to protect your information.
If we become aware of a breach of security affecting personal data we process, we will notify affected customers without undue delay, consistent with applicable law, and provide information reasonably needed to meet their own notification obligations.
10International transfers
We operate primarily in the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States and other countries. Where required, we rely on appropriate safeguards such as the Standard Contractual Clauses for such transfers.
11Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights for data we control, contact us at legal@unitpost.com. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law. For recipient data we process on a customer’s behalf, please contact that customer.
12GDPR (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases: performance of a contract (to provide the Service), our legitimate interests (to secure and improve the Service and prevent abuse), consent (where required, e.g. certain marketing), and compliance with legal obligations. You have the right to lodge a complaint with your local supervisory authority. When we process recipient data, we do so as your processor under our Terms, which incorporate our data-processing commitments.
13California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to not be discriminated against for exercising your rights. In the last 12 months we have collected the categories of personal information described in “Information we collect” above (identifiers, commercial information, internet activity, and professional information), for the purposes described in “How we use information,” and disclosed them only to the service providers listed under “Subprocessors.” We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. To make a request (directly or through an authorized agent), contact us at legal@unitpost.com.
14Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it. Customers who send text messages through Unitpost must not market to anyone under 13, or under the age of digital consent where the recipient lives if that is higher, as set out in the SMS Messaging Policy.
15Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.
16Contact us
Questions about this policy or our data practices? Reach us at legal@unitpost.com.
Work Reactor Inc.2055 Limestone Road STE 200-C
Wilmington, DE 19808
United States