MailHandover watches the mailbox you are moving away from and shows you who still writes to it. That means we handle information from your mailbox, and we take that seriously. This policy explains what we collect, why, who else sees it, and what you can do about it.
MailHandover is run by Lyne Technologies (“we”, “us”). We are the controller of the personal data described here. If you have a question about this policy or your data, email privacy@mailhandover.com.
The short version
- We only look at mail that arrives in your old mailbox after you connect it. We do not import your existing mail.
- For each new email we keep who sent it, the subject line and when it arrived. We never read or store message bodies or attachments.
- We ask Google and Microsoft for read-only, metadata-level access. We cannot send, delete, move or change your mail.
- We do not sell your data, use it for advertising, or use it to train AI models.
- Delete your account and we delete your connected mailboxes, their tokens and everything we collected from them.
What we collect
Your MailHandover account
When you sign up we collect your name, email address and password (stored only as a one-way hash). If you turn on two-factor authentication or passkeys, we store what is needed to verify them. We also keep basic technical records, such as the time of your last sign-in and your session, to keep your account secure.
Your old mailbox connection
When you connect a Gmail or Outlook mailbox, we store its address, which provider it is with, the provider’s account identifier and the OAuth access and refresh tokens the provider gives us. Tokens are encrypted at rest and are used only to check the mailbox for new mail. We never see or store your mailbox password.
Information about new mail
For each email that arrives in the connected mailbox after you connect it, we store:
- the sender’s email address and display name;
- the subject line;
- the date and time it arrived; and
- the provider’s message and conversation identifiers, and a link to open the message in Gmail or Outlook.
From the sender we work out a place: the person or organisation that wrote to you. We record each place’s address, domain and name, when we first and last saw it, and whether you have marked it Done or Ignored.
We do not store message bodies, attachments, recipients other than you, or any mail that was already in the mailbox before you connected it. We do not write email content, subject lines or tokens to our application logs.
Billing
If you pay for MailHandover, payments are handled by Stripe. We receive a customer reference, the status of your subscription and limited card details such as the brand and last four digits. Your full card number is sent directly to Stripe and never reaches our servers.
Cookies
We use only the cookies needed to run the site: a session cookie that keeps you signed in and a security cookie that protects forms against cross-site request forgery. We do not use advertising or third-party tracking cookies.
How we use it
- To run the service: watch your old mailbox, build your digest of places, apply your Done and Ignore choices, and reflag a Done place when it writes again.
- To email you about your account, for example to verify your address, reset your password or tell you a place has been reflagged.
- To take payment, if you are on a paid plan.
- To keep MailHandover secure, fix problems and prevent abuse.
- To meet our legal obligations.
Under UK and EU data protection law, we rely on the performance of our contract with you for running the service and billing, our legitimate interest in keeping the service secure and working, and legal obligation where the law requires us to keep or disclose information.
Senders who write to your old mailbox are not our users, but their name, address and subject lines pass through MailHandover. We process that information only to show you who has written to you, on the basis of our and your legitimate interest in helping you manage your own mailbox, and we keep it only as long as your account and mailbox connection exist.
Google and Microsoft data
For Gmail we request the gmail.metadata scope, which lets us read message headers and labels but not message bodies or attachments. For Outlook we request Mail.ReadBasic, which gives the same kind of limited access. We also request your basic profile and email address so we know which mailbox you connected.
MailHandover’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use data from your mailbox only to provide and improve the features you can see in MailHandover; we do not transfer it to others except as needed to run the service, to comply with the law, or as part of a merger or acquisition with notice to you; we do not use it for advertising; and no person at MailHandover reads it unless you ask us to for support, it is needed for security or to comply with the law, or it has been aggregated and anonymised. We apply the same rules to data we receive from Microsoft.
You can revoke our access at any time from your Google account permissions or your Microsoft account app access page. Once access is revoked we can no longer watch that mailbox.
Who we share it with
We share personal data only with service providers who help us run MailHandover, under contracts that limit their use of it to providing their service to us:
- Hosting and infrastructure providers that run our servers and databases.
- Email delivery providers that send account and reflag emails to you.
- Stripe, for payments.
- Google and Microsoft, when we call their APIs on your behalf to check your mailbox.
We may disclose information if the law requires it, to protect the rights and safety of our users or others, or to a buyer if MailHandover is sold or merged, in which case this policy will continue to apply to your data. We do not sell personal data.
Where it is stored
Our providers may process data outside the UK and European Economic Area. Where they do, we rely on adequacy decisions or standard contractual clauses to make sure your data gets equivalent protection.
How long we keep it
We keep your account, mailbox connections, places and message information for as long as your account is open. When you delete your account in Settings, we delete your account, your connected mailboxes and their tokens, your places and the message information we collected, straight away. Copies in our backups are overwritten within 30 days. Stripe and our accounting records may keep billing information for longer where tax or accounting law requires it.
Security
We encrypt data in transit, encrypt OAuth tokens at rest, hash passwords, offer two-factor authentication and passkeys, and restrict access to production systems. No system is perfectly secure, but if we become aware of a breach that affects your data we will tell you and the relevant regulator as the law requires.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw any consent you have given. You can update your details and delete your account yourself in Settings. For anything else, email hello@mailhandover.com and we will reply within one month.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk or your local data protection authority. We would appreciate the chance to sort it out first.
Children
MailHandover is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
If we make a material change, such as collecting a new kind of mailbox data, we will email you before it takes effect and update the date at the top of this page.