Legal
Privacy Policy
Last updated: August 11, 2026
1. Information we collect
Account data. Name, work email, organization, and login records. We use one-time email codes instead of passwords.
Billing data. Payments are processed by Stripe. Relay stores your plan, invoices, and charge history, but never your full card number.
Customer Content. Mailing lists (recipient names, postal addresses, optional IDs and custom fields), artwork, and campaign settings you upload.
Engagement data. When a recipient scans a tracked QR code we record the scan time and technical details such as IP address and browser user agent, then redirect to the destination our customer configured. When a tracked phone number is called we record call metadata (caller number, time, duration) and, only if the customer has enabled it, a recording of the call.
Website data. Standard server logs and the information you submit through our forms, including the free artwork grader, which processes the artwork you upload and any contact details you provide.
2. How we use information
To provide the Service: printing and mailing campaigns, generating and resolving QR codes, forwarding calls, verifying addresses against USPS data, and building the reporting our customers see. To operate the business: billing, support, fraud and abuse prevention, and improving the product. To communicate: transactional email such as login codes, receipts, and billing notices, and marketing you can opt out of.
We do not sell personal information.
3. Recipient data
If you received a mail piece from a Relay customer, that sender chose and owns their mailing list; Relay processed it to print and deliver the piece and to report engagement back to the sender. Scanning the QR code records the scan for that sender’s report. To exercise rights over that data (access, correction, deletion, or opting out of future mailings), contact the sender named on the mail piece; you can also reach us through our contact page and we will forward your request or act on it as processor.
4. Sharing and service providers
We share data only with providers who process it for us under contract: cloud hosting and database (Supabase, Vercel), print and mail production (Lob and postal carriers), telephony (Twilio), payments (Stripe), address verification (Smarty), mapping and geocoding (Google), AI analysis of artwork you submit (OpenAI), transactional email (SendGrid), and bot protection (Cloudflare). We may also disclose information to comply with law, enforce our terms, or in a merger or acquisition with notice.
5. Retention
Account and campaign data is retained while your account is active and for a reasonable period afterward for export, then deleted. Engagement events are retained to power historical reporting. Call recordings, where enabled, are retained until the customer deletes them or the account closes. Billing records are kept as required by tax and accounting law.
6. Security
Data is encrypted in transit and at rest, access is scoped per organization with row-level security, secrets are stored in an encrypted vault, and client-visible reports support redaction of names and street numbers. No system is perfectly secure; we will notify affected parties of a breach as required by law.
7. Your rights and choices
You can access and update account information in the app, export your campaign data, and delete your account by contacting us. Depending on where you live, you may have statutory rights to access, correct, delete, or restrict processing of your personal information; we honor verified requests through the contact page. We do not discriminate for exercising privacy rights.
8. Children
The Service is for businesses and is not directed to children under 16; we do not knowingly collect their data.
9. Changes
We will post updates here and note the date above; material changes will be announced through the Service or by email.
Questions about these documents? Reach us through the contact page.