Privacy Policy

Last updated 21 July 2026

Ledger is a transactional email service operated by AIM Internet (“Ledger”, “we”, “us”). This policy explains what personal data we process when you use the Ledger website and portal, and when we relay email on your behalf. We are the data controller for your account data, and a data processor for the email you send through us.

Who this covers

There are two groups of people whose data we handle: customers — the people and businesses who hold a Ledger account — and recipients — the people your website sends transactional email to. We process recipient data only to deliver your mail and give you a record of what happened to it.

What we collect

  • Account data: your email address, the sending domains you add, and DNS/authentication records for those domains.
  • Billing data: your plan and subscription status. Card details are handled entirely by our payment processor, Stripe — we never see or store your full card number.
  • Message data: the emails you relay through us, including sender and recipient addresses, subject, headers, size and content. Message bodies are held only transiently to complete delivery; we retain metadata (who, when, and the delivery outcome) so you have an auditable log.
  • Delivery events: the outcome reported by the receiving mail servers — delivered, bounced, complained, deferred — and, where applicable, opens (see below).
  • Technical data: a session cookie to keep you signed in to the portal, and standard server logs (IP address, timestamps) for security and abuse prevention.

Open tracking

Ledger records when a delivered message is opened, so you can see engagement in your delivery log. This works by our email infrastructure inserting a small, invisible image (a 1×1 “pixel”) into the HTML of the messages you send; when a recipient’s mail client loads that image, an open is recorded against the message. We store the time of the first open and a count of opens — we do not build recipient profiles, and we do not use this data for advertising.

Open tracking is a property of the messages you send. If you or your recipients would rather not have opens recorded, note that many mail clients block remote images by default, which prevents an open from being registered. You are responsible for making any disclosures your own privacy obligations require to the people you email.

How we use data

  • To provide the service — authenticate your domains, relay your email, and record delivery outcomes.
  • To manage your account, plan and billing.
  • To protect the platform’s deliverability and prevent abuse (spam, fraud, compromised credentials).
  • To respond to support requests and send you essential service notices.

Our lawful bases (UK GDPR) are performance of a contract with you, our legitimate interests in running a secure and reliable service, and, where required, legal obligation. We do not sell personal data, and we do not send marketing email to your recipients.

Who we share it with

We use a small number of subprocessors to run the service:

  • Amazon Web Services (Amazon SES) — email delivery infrastructure, delivery-event and open-tracking reporting, and hosting.
  • Stripe — subscription billing and card processing.

Each processes data only on our instructions and under its own security and privacy commitments. We may also disclose data where the law requires it. We do not otherwise share your data or your recipients’ data with third parties.

International transfers

We host and send from infrastructure in the UK/EU where possible. Some subprocessors (such as Stripe) may process data outside the UK; where they do, that transfer is covered by appropriate safeguards such as the UK International Data Transfer Agreement or equivalent.

Retention

We keep account data for as long as your account is active. Message bodies are not retained after delivery; delivery metadata and logs are kept for a limited period to give you an audit trail and to support abuse investigations, after which they are deleted or anonymised. When you close your account we delete your data within a reasonable period, except where we must retain it to meet a legal obligation.

Your rights

Subject to UK GDPR, you may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing. To exercise these rights, or if you are a recipient with a query about mail sent to you, contact us at hello@ledgersmtp.com. You also have the right to complain to the UK Information Commissioner’s Office (ICO).

Changes

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify account holders.

Contact

Questions about this policy or your data: hello@ledgersmtp.com. Ledger is a service of AIM Internet.