Skip to content

MailerLite Classic closed signups and free accounts. TinyCourier picks up where they left off. See the migration guide

Legal

Privacy Policy

This policy explains what personal data TinyCourier collects, why, who we share it with, and the rights you have over it. We have tried to write it in plain language. Where we use a defined term like “controller” or “processor”, it has the meaning given in the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).

Effective:
27 June 2026
Last updated:
27 June 2026

1. Who we are

TinyCourier is a simple email newsletter service. The service is operated by Regula Rothen, a sole proprietor based in Switzerland (“TinyCourier”, “we”, “us”, “our”).

For the personal data described in this policy, the data controller is:

  • Regula Rothen, trading as TinyCourier
  • Bern, Switzerland — full registered address available on request
  • Email: help@tinycourier.com

We are established in Switzerland and primarily subject to the Swiss FADP. Because we offer the service to customers and recipients in the European Economic Area (EEA), the EU GDPR also applies to that processing. Where the GDPR requires it, you can reach us at the contact address above; we have not appointed an EU representative under Article 27 GDPR at this time.

2. Our two roles

Depending on the data, we act in one of two capacities:

  • As a controller — for data about you, our customer: your account details, billing information, and how you use the product. We decide why and how this data is processed, and this policy governs it.
  • As a processor — for the subscriber data you upload and the content of the campaigns you send. You are the controller of that data; we only process it on your documented instructions to provide the service. This relationship is governed by our Data Processing Agreement (DPA), which forms part of our terms.

Section 4 below describes the subscriber data we handle as a processor. The rest of this policy concerns data we control.

3. Data we collect about you

Information you give us

  • Account & identity: your name, email address, password (stored hashed), company or sender name, and country.
  • Sign-in with Google: if you choose to sign in with Google, we receive your name, email address, and Google account identifier through Google's OAuth service. We do not receive your Google password.
  • Billing: your billing name and address, VAT/tax details where applicable, and your subscription plan. Card and payment details are entered directly with our payment processor (Stripe) and are not stored on our servers; we receive only a token, the last four digits, card brand, and expiry.
  • Support & communications: the content of emails and messages you send us, including any information you choose to include.

Information we collect automatically

  • Usage & log data: IP address, browser and device type, pages and features used, timestamps, and actions taken in the app.
  • Audit and security logs: records of significant account actions (logins, configuration changes, sends) that we keep to secure the service and meet our legal obligations.
  • Essential cookies: a session cookie that keeps you signed in and a small number of cookies required for security and core functionality (see Section 7).

4. Subscriber data you entrust to us

To run your newsletters, you upload and manage information about your own subscribers — for example their email addresses, names, custom fields, sign-up source, and engagement data such as opens and clicks. We process this data only as a processor on your behalf, to deliver the service you have asked for.

We do not sell this data, use it for our own marketing, or share it with anyone except the sub-processors listed in Section 8 who help us run the service. You remain responsible, as the controller, for having a lawful basis to collect and email your subscribers and for honoring their rights. Our handling of subscriber data is governed by the DPA.

5. How and why we use data

We use the data described in Section 3 to:

  • provide, operate, and maintain the TinyCourier service;
  • create and secure your account and authenticate you when you sign in;
  • send your campaigns and our own transactional emails (receipts, security notices, service updates);
  • take payment and manage your subscription;
  • provide customer support and respond to your requests;
  • monitor, debug, and improve reliability, performance, and security, and prevent abuse and fraud;
  • comply with our legal obligations (for example tax and accounting law).

We do not use your personal data or your subscriber data to train artificial-intelligence models.

7. Cookies

We keep cookies to a minimum. TinyCourier uses only essential cookies that are strictly necessary to sign you in, keep your session secure, and remember basic preferences such as your theme. We do not use advertising cookies, and we do not run third-party analytics or tracking on the application or this website. Because these cookies are essential to a service you have requested, we do not show a cookie consent banner; you can still block cookies in your browser, but parts of the service may then stop working.

8. Sub-processors

We use a small number of carefully chosen third parties to run the service. They process data only on our instructions and under contracts that require them to protect it. Our current sub-processors are:

Provider Purpose Location
Hetzner Online GmbH Application hosting, databases, backups Finland
Oracle Corporation Campaigns and double opt-in email delivery Zurich, Switzerland
Stripe, Inc. / Stripe Payments Europe Subscription billing and payment processing Ireland & United States
Functional Software, Inc. Application error and crash monitoring European Union
Hiver, Inc. Customer support tooling United States
Google LLC Sign-in with Google (OAuth) authentication United States
Plus Five Five, Inc. Transactional email for TinyCourier system notifications Ireland

We will update this list before adding or replacing a sub-processor that handles personal data. If you have an active subscription and object to a new sub-processor on reasonable data-protection grounds, contact us at help@tinycourier.com.

9. International transfers

We keep the data that powers the service inside Switzerland and the EU wherever we can. Your account data and your subscribers' data are hosted with Hetzner in Finland (EU), and your email is sent through Amazon SES in the Zurich, Switzerland region.

Some of our sub-processors are based in or transfer data to the United States (Stripe for payments, and Hiver and Google for support and sign-in). When personal data is transferred to a country that Switzerland or the EU has not recognized as providing adequate protection, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses together with the Swiss FDPIC addendum, and, where applicable, the provider's certification under the EU–US and Swiss–US Data Privacy Framework. Copies of the relevant safeguards are available on request.

10. How long we keep data

  • Account and subscriber data: kept for as long as your account is active. When you ask us to delete your data, or after you close your account, we delete it from our active systems within 30 days and from routine backups as those backups expire.
  • Invoices and accounting records: kept for 10 years as required by Swiss accounting law (Art. 958f of the Swiss Code of Obligations).
  • Audit and security logs: kept for up to 2 years for security, fraud-prevention, and legal-defense purposes, then deleted or anonymized.
  • Support correspondence: kept for as long as needed to handle your request and a reasonable period afterward.

We may keep limited information longer where the law requires it or to establish, exercise, or defend legal claims.

11. Security

We take appropriate technical and organizational measures to protect personal data, including encryption in transit, hashing of passwords, access controls on a need-to-know basis, regular backups, and monitoring. No system is perfectly secure, but we work to protect your data and will notify you and the competent authority of a personal-data breach where the law requires it.

12. Your rights

Under the FADP and, where it applies, the GDPR, you have rights over your personal data. Subject to the conditions in the law, you can:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate or incomplete data corrected;
  • have your data deleted (“right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing already carried out.

To exercise any of these, email help@tinycourier.com. We will respond within the time the law allows (generally 30 days). Many account details can also be updated directly in your account settings.

If you have a subscriber whose request you need us to action, we will help you as your processor — but please direct the request to the customer who controls that list.

You also have the right to complain to a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EEA you may complain to the data protection authority of your country.

13. Children

TinyCourier is a business tool and is not directed to children. The service is not intended for anyone under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the “Last updated” date above and, where appropriate, notify you by email or in the app. Your continued use of the service after a change takes effect means you accept the updated policy.

15. How to contact us

For any question about this policy or your personal data, contact us at help@tinycourier.com or by post at the address in Section 1. We read every message.