OquMail
Loading account…

Legal

Privacy Policy

What personal data OquMail collects, why we collect it, how long we keep it, and the choices you have.

Last updated:

1. Who we are

OquMail provides business email hosting on our customers' own domains. This policy covers our website (oqumail.com), the webmail and admin app (app.oqumail.com), the transactional email API (api.oqumail.com) and our mail servers, including IMAP and SMTP access.

When a business signs up, it creates a workspace and can add mailboxes for its team. For the email stored in those mailboxes, the business that owns the workspace decides how it is used, and we process it on that business's behalf to run the service. For account, billing, security and website data, OquMail decides how the data is used.

Questions about this policy can be sent to hello@oqumail.com.

2. What we collect

We collect only what we need to run the service:

  • Account details. When you sign up: your name, sign-in email address, phone number, country, time zone, business name and business category, and your password. We never store your password itself, only a one-way hash of it. Members added by a workspace admin have a name, sign-in email and, optionally, a recovery email address.
  • Mailbox contents. The email you send and receive, including headers, message bodies and attachments, plus drafts, folders, your display name and your signature.
  • Domain and configuration data. Your domain names, DNS verification records and the DKIM signing keys we generate for your domains. If you choose to connect a DNS provider account for one-click setup, we store the access tokens it issues in encrypted form.
  • API keys. Keys for the transactional email API are stored as a hash and in encrypted form, never in plain text, along with when each key was last used.
  • Delivery records. For outgoing mail: recipient addresses, the receiving mail server, its response, and whether delivery succeeded, was deferred or failed. We also keep sending counts and bounce and complaint statistics for each mailbox and workspace.
  • Security and activity logs. IP addresses, browser or device information (user agent), sign-in times, failed sign-in attempts, actions taken in the admin area, and technical logs from our servers.
  • One-time codes. Sign-in and verification codes are stored only as a hash and expire after 10 minutes.
  • Support requests. Messages and attachments you send us through support tickets or by email.
  • Notification settings. If you turn on browser email alerts, the push subscription your browser gives us.
  • Website usage. How visitors use oqumail.com, collected through Microsoft Clarity (see Cookies and local storage).

3. How we use your data

  • To create and run your account, workspace, domains and mailboxes.
  • To receive, store and deliver your email, and to serve it through webmail, IMAP and SMTP.
  • To send email through the transactional API on your behalf.
  • To keep the service secure: verifying sign-ins, sending sign-in codes, slowing down or blocking repeated failed sign-ins, and detecting stolen credentials.
  • To protect recipients and our sending reputation from spam, phishing and other abuse.
  • To answer support requests and fix problems.
  • To send you service messages, such as sign-in codes, security notices and changes to your account.
  • To send account holders occasional news about OquMail. You can ask us to stop at any time by emailing hello@oqumail.com.
  • To understand how our website is used and improve it.

We do not sell your personal data, and we do not use the content of your email for advertising.

4. Automated processing

Some of our processing is automated:

  • Incoming mail checks. We check incoming mail against the sender's SPF, DKIM and DMARC records. Mail that fails a sender's enforcing DMARC policy is placed in your spam folder.
  • Outgoing mail checks. Outgoing messages are checked by automated rules for signs of spam, phishing and other abuse. Messages the rules flag may go through automated and AI-assisted processing by our service providers, and may be held for review by authorized OquMail staff. Flagged messages can be held or not sent.
  • Sending reputation. We track bounces and complaints. If a mailbox's reputation drops too far, its sending may be paused automatically, and we notify the mailbox owner.
  • Writing assistant. If you use the optional writing assistant in webmail, the text and instructions you give it are sent for automated and AI-assisted processing by our service providers to produce a suggestion.
  • Operations. We may use automated and AI-assisted tools to analyze our technical logs so we can find and fix faults.

If you think an automated decision about your mail or account is wrong, contact us at hello@oqumail.com and a person will review it.

Where data protection laws such as the GDPR apply, we rely on these legal bases:

  • Contract: to provide the service you or your organization signed up for, including storing and delivering email.
  • Legitimate interests: to keep the service secure, prevent spam and abuse, protect our sending reputation, fix problems, understand how our website is used, and tell account holders about OquMail. We balance these interests against your rights.
  • Legal obligation: where we must keep or disclose data by law.
  • Consent: for optional features you choose to turn on, such as browser notifications. You can withdraw consent at any time.

6. Cookies and local storage

  • Sign-in cookie. When you sign in, we set a cookie named oqumail_token that keeps you signed in for up to 7 days. It is shared across oqumail.com subdomains so our website can show that you are signed in.
  • Browser storage. The app stores your session and a few display preferences (such as the reading pane layout) in your browser. Our website keeps a short-lived copy of your session details for the current browser tab.
  • Analytics. Our website (oqumail.com) uses Microsoft Clarity, which sets cookies and records how visitors interact with pages, such as clicks, scrolling and mouse movement, to help us improve the site. Clarity is not loaded in the webmail app. You can block these cookies in your browser settings.

We do not use advertising cookies.

7. Who we share data with

We share personal data only as needed to run the service:

  • Hosting provider. Our servers and databases run on infrastructure rented from our hosting provider.
  • Automated and AI-assisted processing providers. For the outgoing-mail checks, writing assistant and log analysis described above.
  • Analytics provider. Microsoft Clarity, for our website only.
  • Services you connect. A DNS provider, if you connect one for automatic DNS setup, and your browser's push service, if you turn on notifications.
  • Recipients' mail servers. Sending email means passing the message to the recipient's mail server.
  • Your workspace. Your workspace owner and admins can manage your mailbox, including resetting its password and removing it.
  • Authorities. When the law requires it, or when needed to investigate abuse, protect people, or protect our rights.
  • A buyer or successor. If OquMail is involved in a merger, acquisition or sale of assets, under the terms of this policy.

8. International transfers

Our service providers may process data in countries other than yours, which may have different data protection laws. When we transfer personal data internationally, we take steps to make sure it stays protected, such as relying on contractual safeguards where the law requires them.

9. How long we keep data

  • Account and mailbox data is kept while your account is active. Email stays until you delete it. Deleting a message from Trash removes it and its attachments permanently.
  • Closed accounts: when an account is closed, sign-in and mail access stop right away. We keep the data for up to 30 days so a closure made by mistake, or by someone else, can be reversed. After that, the mail, attachments, support tickets and personal details are permanently erased.
  • One-time codes expire after 10 minutes and are deleted automatically.
  • Technical server logs are deleted automatically after about 30 days.
  • Security audit records and delivery records may be kept after an account is closed, to prevent abuse, investigate incidents and meet legal obligations. Audit records refer to a closed account by an internal ID rather than by name.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Export your email. You can download all of it at any time with any IMAP email app.
  • Correct inaccurate data. You can edit much of it yourself in the app.
  • Delete your account and data. Email us to close your account.
  • Object to or ask us to restrict processing based on legitimate interests.
  • Withdraw consent for anything that relies on it.
  • Complain to your local data protection authority.

To use these rights, email hello@oqumail.com. We may need to confirm your identity first, and we will respond within the time required by applicable law. If your mailbox belongs to an organization's workspace, some requests, such as deleting a work mailbox, may need to go through that organization.

11. How we protect data

  • Connections to our website, app and API are encrypted with TLS (HTTPS).
  • IMAP and SMTP connections from email apps are encrypted with TLS 1.2 or newer. When we deliver to other mail servers, we use encryption whenever the receiving server supports it.
  • Outgoing mail is signed with DKIM so recipients can check it really came from your domain.
  • Passwords are stored as bcrypt hashes. Sign-in codes and API keys are stored as hashes.
  • Workspace owners confirm sign-in with an emailed one-time code in addition to their password.
  • We limit request rates and temporarily block addresses that repeatedly fail to sign in to the app, IMAP or SMTP.
  • We keep audit records of important account and admin actions.

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify you and the authorities as the law requires.

12. Children

OquMail is a service for businesses and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service changes. We will change the "Last updated" date above, and for significant changes we will notify account holders by email or in the app before they take effect.

14. Contact us

For privacy questions or requests, email hello@oqumail.com. See also our Terms of Service.