SOSendOperatorSign in
Back to SendOperator

Privacy

Privacy, without the fog.

This policy explains what SendOperator handles when a team plans outbound campaigns, connects a mailbox, sends messages, and manages replies.

Effective and last updated August 26, 2026

1. Who operates SendOperator

Accelara AI Solutions Limited, a private company registered in the Dubai International Financial Centre and trading as Accelara AI Solutions, operates the SendOperator private-beta outbound workflow service (“SendOperator,” “we,” “us,” or “our”). SendOperator helps teams prepare audiences and email copy, require human launch approval, send through connected mailboxes, and organize replies.

For account, billing, security, and service-operation data, we act as the data controller. For campaign and recipient data a customer provides and directs us to process, that customer generally determines the purpose of the processing and we act on its instructions, subject to the agreement and applicable law.

Privacy questions and requests can be sent to alexwohl@accelara.ai, or mailed to:

Accelara AI Solutions LimitedIH-00-01-03-OF-05, Level 3Innovation HubDubai International Financial CentreDubai, United Arab Emirates

2. Information we handle

  • Account and workspace data: names, email addresses, authentication records, team membership, preferences, roles, and the workspace mailing address.
  • Campaign and contact data: lead names and addresses, company details, lists, suppression and unsubscribe records, campaign settings, schedules, templates, and approved email content.
  • Mailbox and message data: connected mailbox identity, encrypted OAuth credentials, provider identifiers, message headers, subjects, bodies, reply content, threading data, delivery events, and attachment indicators.
  • Managed sending data: company domain, target audience and expected volume; suggested and approved secondary domains; registrar resource, service-term and expiry details; DNS records; and provisioning or suspension status.
  • Purchase and billing data: approved quote contents, prices, payment status, payment and invoice identifiers, billing contact details, refunds, and the records needed to reconcile a domain order. Full payment card numbers are handled by the payment processor, not SendOperator.
  • Files and knowledge: documents, URLs, text, and files a workspace intentionally uploads or selects for campaign planning.
  • Operational data: audit events, security and diagnostic records, IP address and user agent where recorded, feature usage, page traffic, and performance measurements.

3. Google user data

When you connect Gmail, Google authorizes SendOperator to identify the connected account, send messages on its behalf, and read mailbox data. SendOperator uses that read access to find replies related to SendOperator campaigns, preserve conversation context, stop follow-ups after a reply, classify the reply, and prepare a response for human review.

The Gmail permission is technically broad. SendOperator does not use it to build advertising profiles, sell mailbox data, or inspect unrelated mail for a purpose disconnected from the user-facing reply workflow.

Relevant reply text and campaign context may be sent to OpenAI through its API solely to provide classification and drafting features. We limit human access to Google user data to support with permission, security or abuse investigation, legal obligations, or other cases allowed by Google policy.

Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

4. How we use information

  • Provide, secure, maintain, and troubleshoot the service.
  • Plan campaigns, generate drafts, enforce approvals and sending caps, deliver approved messages, and synchronize related replies.
  • Check domain availability; register, configure, monitor, suspend, expire, or explicitly renew platform-managed domains; and reconcile the exact fixed-term setup a workspace approved.
  • Process payments, prevent duplicate purchases, record fixed-term purchases, and provide billing and renewal notices.
  • Apply suppression, bounce, unsubscribe, and stop-on-reply rules.
  • Respond to support requests and communicate material service or policy changes.
  • Measure reliability and aggregate usage so we can improve the product without using mailbox content for advertising.

5. When information is shared

We do not sell personal information or Google user data.

We disclose information only as needed:

  • To workspace members according to their role and the workspace’s instructions.
  • To infrastructure and processing providers—including Supabase, Vercel, Resend, Google, and OpenAI—that help us host, authenticate, secure, send, receive, or process the service.
  • To Stripe for payment processing and to Cloudflare for domain registration and DNS. SendOperator’s account-level registrant contact, rather than customer registrant data, is used for managed domains. We send only the order and technical details needed to fulfill, secure, monitor, support, expire, or explicitly renew that setup.
  • When you direct an integration, export, or other transfer.
  • When reasonably necessary to comply with law, protect people, investigate abuse, or preserve the integrity of the service.
  • In connection with a merger, financing, acquisition, or sale, with appropriate confidentiality protections and notice where required.

6. Retention and deletion

We retain workspace, campaign, contact, and message data while the workspace is active and for as long as reasonably needed to provide the service, maintain suppression and audit records, resolve disputes, and meet security or legal obligations.

Connected-mailbox credentials are retained while the mailbox remains connected in SendOperator. Revoking Google access makes the credential unusable and prevents new access, but it does not automatically erase the mailbox record, campaign data, or reply records already stored in SendOperator. You can ask us to remove them.

Domain registration, platform control, payment, tax, invoice, expiry, and renewal records may be retained after cancellation when needed to preserve an audit trail, prevent duplicate charges, resolve a dispute, or meet accounting, registrar, security, or legal obligations. Provider credentials are removed or made unusable when the related service is disconnected, subject to the provider’s ordinary deletion and backup cycle.

A workspace owner may request account, workspace, or Google-derived data deletion by emailing us. We verify requests before acting. Data may remain temporarily in backups or be retained where required for fraud prevention, security, suppression compliance, or law, and is then removed through the ordinary backup lifecycle.

7. Security

We use access controls, tenant isolation, encryption in transit, and encryption of connected-mailbox credentials at rest. We restrict privileged database access and keep an operational audit trail. No system is perfectly secure, so please report suspected security issues promptly and never send passwords or access tokens by email.

8. Your choices and rights

The DIFC Data Protection Law No. 5 of 2020 applies to our processing. Depending on the circumstances and applicable exemptions, you may have rights to access, correct, erase, restrict, or obtain a copy of personal data, and to object to certain processing. We verify requests and respond as required by applicable law.

  • Disconnect or revoke Google access from your Google Account’s third-party connections page.
  • Ask to end managed-domain access. Managed domains do not auto-renew and are not transferable to the customer.
  • Ask us to access, correct, export, restrict, or delete your personal information, subject to identity verification and applicable law.
  • Unsubscribe from campaign email using the link in the message. The resulting suppression record is kept so the request remains honored.
  • Control essential session and theme storage through your browser; blocking essential storage may prevent sign-in from working.

9. International use

SendOperator and its providers may process information in countries other than where you live. Those locations may have different privacy laws. Where required, we use appropriate safeguards for cross-border processing.

10. Questions and complaints

Please contact us first so we can investigate a privacy concern. If the concern is not resolved, you may have the right to complain to the DIFC Commissioner of Data Protection.

11. Changes and contact

We may update this policy as SendOperator or applicable requirements change. The date above shows the latest revision. If a change materially affects how we use previously collected information, we will provide notice appropriate to the change.

Contact Accelara AI Solutions Limited at alexwohl@accelara.ai, or at the postal address in section 1.