1. Overview
BusinessMail by WebsitePuzzle is a business email platform. Depending on your setup, we may host your mailboxes on our infrastructure or connect to mail you already host elsewhere (Bring Your Own Mail / BYOM). In all cases, we process data needed to authenticate you, deliver the webmail experience, and operate the service securely.
We do not sell personal data. We do not use third-party advertising or behavioral analytics trackers in the web application. Operational telemetry may be collected by us for reliability and security when enabled in our deployment.
2. Who we are
The operator of BusinessMail is WebsitePuzzle ("WebsitePuzzle", "we"). For privacy-related questions or requests, contact us at postmaster@websitepuzzle.com.
If your organization uses BusinessMailunder a custom domain, your organization may also act as an independent controller of mailbox and message data for its users. Where that applies, your organization's policies may govern in addition to this policy.
3. Data we collect
Account and profile information
- Name, email address, username, and recovery email
- Password (stored only as a one-way hash; we never store plaintext passwords)
- Organization / workspace details such as business name, region, and team size when provided at signup
- Theme and appearance preferences
- Optional two-factor authentication (TOTP) configuration
Mailbox and mail metadata
- Mailbox addresses, display names, and mailbox-level settings
- Message headers, subjects, snippets, timestamps, labels/categories, and delivery status
- Attachment metadata (filenames, sizes, content types)
- Spam scores, virus scan results, and abuse-report records when applicable
Email content
When you use platform-hosted mail, we store the full content of messages and attachments needed to provide inbox, search, compose, and sync features. When you use BYOM, message content may be retrieved from and stored on our systems temporarily or persistently to power the web experience, depending on your configuration and sync behavior.
Technical and security data
- Session identifiers, IP addresses, and browser user-agent strings at sign-in and during active sessions
- Authentication event history (successful and failed sign-in attempts, lockouts, password resets)
- CSRF tokens and similar security tokens
- Server and application logs, rate-limit counters, and diagnostic information
Inquiries and waitlist
If public registration is closed, we may collect name, email, company, domain, plan interest, and a free-text message when you submit an access request.
4. How we use data
We use personal data to:
- Provide, maintain, and improve BusinessMail
- Authenticate users, enforce access controls, and protect accounts (including lockout and 2FA)
- Send, receive, store, index, and display email on your behalf
- Run spam filtering, virus scanning, blocklists, and abuse prevention
- Support domain verification, DKIM/SPF/DMARC configuration, and deliverability tooling
- Respond to support requests, legal process, and security incidents
- Send service-related notices such as password resets and important workspace updates
- Enforce our Terms & Conditions and protect the rights and safety of users and third parties
We process data based on contractual necessity (to provide the service you request), legitimate interests (security, fraud prevention, product improvement), and, where required, your consent.
5. Email content & search
To provide fast inbox search, message content and metadata may be indexed in our search subsystem (Meilisearch). Index contents are stored on infrastructure we control and are not shared with advertisers.
Smart inbox features (such as category tabs and training) may analyze subjects and message snippets to classify mail. Training signals you provide are stored to improve categorization for your mailbox.
6. Bring Your Own Mail (BYOM)
If you connect external IMAP and SMTP servers, we store the connection settings needed to sync and send mail. SMTP and IMAP credentials are encrypted at rest using keys controlled by us. We do not display your external credentials in the user interface after they are saved.
You are responsible for ensuring you have the right to connect third-party mail systems and that doing so complies with your provider's terms. We are not responsible for policies or outages of external mail hosts.
9. Security
We implement administrative, technical, and organizational measures designed to protect data, including encrypted transport (HTTPS/TLS), password hashing, encrypted storage for sensitive credentials, tenant isolation via database row-level security, rate limiting, CSRF protection, and optional two-factor authentication.
No method of transmission or storage is completely secure. You are responsible for choosing strong passwords, safeguarding 2FA devices, and controlling access within your organization.
10. Retention & deletion
We retain account and mail data for as long as your account or mailbox is active and as needed to provide the service. When a mailbox is deleted, we may retain data for up to approximately 6 months in a recoverable state before scheduled permanent purge, unless applicable law requires a different period or you submit an approved early erasure request where available.
Security logs, billing records, and legal hold data may be kept longer where necessary for compliance, dispute resolution, or enforcement. Backups may persist for a limited time after deletion before being overwritten.
11. Your choices & rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal data we hold about you
- Object to or restrict certain processing
- Export data where technically feasible
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
Workspace owners and administrators may manage member access, mailboxes, and deletion requests through org admin tools. To exercise rights directly with us, email postmaster@websitepuzzle.com. We may need to verify your identity before responding.
12. International transfers
We may process and store data in countries other than where you live. Where required, we use appropriate safeguards for cross-border transfers. By using the service, you acknowledge that data may be transferred to jurisdictions that may have different data-protection laws than your own.
13. Children
BusinessMail is intended for business and professional use. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the service after changes become effective constitutes acceptance of the revised policy, except where applicable law requires additional notice or consent.
15. Contact us
Questions about this Privacy Policy or our data practices: postmaster@websitepuzzle.com.
Effective date: July 28, 2026.