SaveMyService Hosting

Privacy Policy

Effective Date: TBD | Last Updated: 8/4 | Version 1.04

CONTENTS

  1. About This Policy
  2. Who We Are; Controller and Processor Roles
  3. Information We Collect
  4. How We Use Information and Our Legal Bases
  5. What We Do Not Do With Your Data
  6. Automated Processing: Spam, Malware, and Abuse Detection
  7. Cookies and Similar Technologies
  8. How We Share Information
  9. Subprocessors
  10. International Data Transfers
  11. How Long We Keep Data
  12. How We Protect Data
  13. Your Rights Under the GDPR and UK GDPR
  14. Your Rights Under California Law
  15. Your Rights Under Other U.S. State Privacy Laws
  16. Children’s Privacy
  17. Government and Law Enforcement Requests
  18. Data Breach Notification
  19. Changes to This Policy
  20. How to Contact Us and Complain

 

 

1. About This Policy

This Privacy Policy explains how Exactpoint Technologies, an Ohio LLC dba SaveMyService Hosting, (“SaveMyService Hosting,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with the SaveMyService Hosting Email service — our hosted mailbox service accessible by POP3, IMAP, and SMTP, together with any web interface, applications, APIs, and our website at www.savemyservice.com (collectively, the “Service”).

This Policy forms part of, and is incorporated by reference into, our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use. Where this Policy and the Terms of Use conflict on a data protection matter, this Policy controls; where an executed Data Processing Addendum applies, that addendum controls.

Email is unusual among online services in that the operator necessarily handles the contents of private correspondence in order to deliver it. We have written this Policy to be specific about what that involves, rather than relying on general language.

2. Who We Are; Controller and Processor Roles

SaveMyService Hosting is the entity responsible for the Service. Our contact details are in Section 20.

Where we act as a controller. We determine the purposes and means of processing for account registration data, billing records, authentication and connection logs, security and abuse-prevention data, support correspondence, and website analytics. This applies to individual consumer, prosumer, and commercial subscribers generally.

Where we act as a processor. Where a business or organizational subscriber uses the Service to handle personal data of its own employees, customers, or contacts within message content, that subscriber is the controller and we act as a processor on its documented instructions. Under U.S. state privacy law we act, in that same capacity, as a “service provider” (California) or “processor” (Virginia, Colorado, Connecticut, and comparable states).

3. Information We Collect

3.1 Information You Provide

  • Account registration data: your name or chosen identifier, the mailbox address or addresses you create, a recovery email address, and a text capable recovery telephone number.
  • Authentication credentials: your password, stored only as a salted cryptographic hash; multi-factor authentication secrets; and any application-specific passwords issued for POP3, IMAP, or SMTP access.
  • Billing information: billing name, billing address, country, tax identifiers where applicable, plan selection, and transaction history. Full payment card numbers are collected and stored by our payment processor, not by us; we receive a token, the card brand, the last four digits, and the expiry date. Your personal payment data is not within our systems nor control.
  • Support correspondence: the content of tickets, emails, and chat sessions you send to our support, billing, abuse, or security addresses, including any diagnostic information you choose to attach.
  • Optional profile settings: display name, signature, time zone, language, filters, aliases, and forwarding rules.

3.2 Content You Store or Transmit

The Service stores and transmits the contents of your mailbox — message bodies, subject lines, attachments, headers, drafts, folder structure, flags, address book entries, and calendar or notes data where the Service offers those features. This information necessarily includes personal information about your correspondents, over which they, not you, may also have rights.

3.3 Information Generated by Using the Service

  • Connection and protocol logs: source IP address, connection timestamp, protocol used (POP3, IMAP, SMTP, HTTPS), authentication outcome, client-supplied identifiers such as the IMAP ID string or user agent, TLS version and cipher, and bytes transferred.
  • Mail transmission metadata: SMTP envelope sender and recipient addresses, message identifiers, message size, delivery status and bounce codes, spam and malware filter verdicts, and DKIM, SPF, and DMARC authentication results.
  • Storage and quota data: mailbox size, message counts, and folder statistics.
  • Security signals: failed authentication attempts, rate-limit events, abuse reports referencing your Account, and indicators used for fraud and account-takeover detection.

3.4 Website and Marketing Information

If you visit our website, we collect standard server log data and, subject to Section 7, information from cookies and similar technologies. If you subscribe to product announcements, we collect your email address and engagement data for that mailing.

3.5 Information From Third Parties

We receive limited information from our payment processor (transaction outcomes, chargeback notices, fraud scores), from abuse and threat-intelligence sources (blocklist status, spam reports, malware signatures), and from identity verification providers where fraud screening is required. We do not purchase nor sell personal information from data brokers.

3.6 Sensitive Information

We do not intentionally collect special category data.  Message content may, however, contain such information because you or your correspondents put it there. We process that content only as necessary to deliver the Service, and never to infer characteristics about you.

4. How We Use Information and Our Legal Bases

 

Purpose Data used
Provisioning mailboxes, storing and delivering mail over POP3/IMAP/SMTP Account data, content, transmission metadata
Authenticating you and maintaining sessions Credentials, connection logs
Billing, invoicing, tax and accounting records Billing data, transaction history
Spam, phishing, and malware filtering Content, metadata, threat signals
Preventing abuse, fraud, and account takeover Connection logs, security signals
Maintaining service integrity, capacity, and deliverability reputation Metadata, quota data
Responding to support requests Support correspondence, account data
Service and security notifications Account data, recovery address
Optional product marketing emails Email address, engagement data
Responding to valid legal process Whatever the process compels
Establishing, exercising, or defending legal claims As relevant to the claim

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is necessary and proportionate and does not override your rights.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

5. What We Do Not Do With Your Data

To be explicit, SaveMyService Hosting does not:

  • scan or analyze the content of your messages to build advertising or interest profiles;
  • sell your personal information, or share it for cross-context behavioral advertising;
  • use your message content, attachments, or contacts to train machine learning or artificial intelligence models, whether our own or a third party’s;
  • disclose message content to advertisers, data brokers, or marketing partners;
  • read your mail for any purpose other than those in Section 6 and the limited access circumstances described in Section 8.5; or
  • serve third-party advertising within the Service.

6. Automated Processing: Spam, Malware, and Abuse Detection

Delivering email requires automated inspection of message content and metadata. Inbound and outbound messages pass through filtering systems that evaluate headers, body text, attachments, embedded links, sender reputation, and authentication results in order to classify them as legitimate, spam, phishing, or malware. Attachments may be scanned by antivirus engines, and URLs may be checked against reputation services.

These systems operate automatically and no person reads your mail as part of this process. Classification outcomes are logged, and derived signals — such as a spam score, a malware signature hit, or an aggregated sender reputation — may be retained to improve filtering, but message content is not retained by the filtering systems beyond what is necessary to complete the evaluation and, where a message is quarantined, to allow you to review or release it.

Automated abuse controls may suspend outbound sending or restrict an Account under ; where such a restriction is applied automatically, you may request human review by contacting support@savemyservice.com.

7. Cookies and Similar Technologies

The POP3, IMAP, and SMTP interfaces do not use cookies. Our website and webmail interface use:

  • Strictly necessary cookies for authentication, session management, load balancing, and cross-site request forgery protection. These cannot be disabled without breaking the Service.
  • Preference cookies to remember settings such as language, theme, and layout.
  • Analytics cookies, where enabled, to understand aggregate usage.

8. How We Share Information

We disclose personal information only in the following circumstances:

  • Subprocessors and service providers that support the Service under written contract, as listed in
  • Payment processors, to take payment and manage subscriptions;
  • Recipients you send mail to, and the mail servers, intermediaries, and DNS operators along the delivery path — this is inherent to how email works, and once a message leaves our infrastructure its handling is governed by the recipient’s providers, not by this Policy;
  • Professional advisers such as auditors, accountants, and lawyers, under duties of confidentiality;
  • Government and law enforcement authorities, only as described in Section 17;
  • In a corporate transaction, such as a merger, acquisition, financing, or sale of assets, subject to the notice and termination rights in Section 26 of the Terms of Use, and on condition that the acquirer is bound by commitments no less protective than this Policy; and
  • With your direction or consent, including where you connect a third-party client, add-on, or integration.

We do not disclose personal information for any other purpose.

9. Subprocessors

We engage the following categories of subprocessor.

Category Purpose
[Cloud infrastructure / Hostway] Hosting mail storage and compute
[Payment processor / Stripe via Zoho Payments] Subscription billing and fraud screening
[Email deliverability / Hostway] Outbound delivery and reputation monitoring
[Anti-spam / Spam Experts by N-able] Content filtering and threat detection
[Support ticketing platform / Zoho Desk] Handling support correspondence
[Backup / Hostway] Encrypted operational backups

Each subprocessor is bound by written terms imposing confidentiality and data protection obligations no less protective than those we owe you, and is permitted to process personal information only to deliver its contracted function.

10. How Long We Keep Data

Retention periods correspond to those in of the Terms of Use.

Data Retention
Mailbox content while your Account is active, not in Trash Until you delete it
Deleted messages (Trash) 30 days, or immediately on expunge
Purged message content in operational backups Up to 24 hours (backup rotation)
Mailbox (Inbox Only) content after cancellation or termination 30 days, then permanent deletion
Connection, authentication, and delivery logs

Mailbox access logs

24 hours

7 days

Security and abuse investigation records/CRM and Billing Systems Only Up to 12 months, or longer where an investigation is open
Support correspondence 12 months after the ticket closes
Billing and tax records 7 years, or as required by applicable law
Marketing consent and preference records Until withdrawn, plus 3 years to evidence the withdrawal
Non-Paid Subscriptions/Inactive account data Terminated after 3 months’ inactivity, per Terms of Use §9.5

We may retain data beyond these periods where necessary to comply with a legal obligation, respond to a valid legal hold, or establish, exercise, or defend legal claims. Retained data is restricted to that purpose.

Because of how POP3 works, messages your client downloads and deletes from our servers cannot be recovered by us after downloaded. See Section 4.2 of the Terms of Use.

11. How We Protect Data

We maintain a security program including encryption of data in transit using TLS with modern cipher suites, encryption of data at rest, role-based access control with least privilege, mandatory multi-factor authentication for personnel, logging and monitoring of administrative access, network segmentation, vulnerability management and patching, secure software development practices, background screening of personnel with production access, written confidentiality obligations, incident response procedures, and periodic testing and review.

Access to message content by our personnel is limited to the circumstances in Section 8.4 of the Terms of Use.

The Service does not provide end-to-end encryption. Message content is stored in a form we are technically able to access, which is what allows server-side search, filtering, and protocol access. If you require that we be unable to read your mail, apply client-side encryption such as OpenPGP or S/MIME before sending.

No security program eliminates risk entirely, and we cannot guarantee absolute security.

12. Your Rights Under U.S. State Privacy Laws

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sell personal data, or engage in profiling with legal or similarly significant effects, so those opt-outs have no practical application to the Service; you may nonetheless exercise them at support@savemyservice.com. Where a state provides an appeal right following denial of a request, we will describe the appeal process in our response, and you may thereafter contact your state attorney general.

13. Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect their personal information. Accounts require subscribers to be at least 16, or the age of digital consent in their jurisdiction if higher, per Section 3.1 of the Terms of Use. If we learn that a child under has created an Account, we will terminate it and delete the associated data. Parents or guardians who believe a child has provided information to us should contact support@savemyservice.com.

14. Government and Law Enforcement Requests

We disclose personal information to government or law enforcement authorities only where compelled by legal process we reasonably determine to be lawful, valid, and properly served, or where an emergency involving danger of death or serious physical injury requires immediate disclosure.

We require a search warrant or demand legally equal to, based on probable cause before disclosing the content of communications to U.S. authorities. We review each request, and object to or seek to narrow requests that are overbroad, defective, or inconsistent with applicable law. Requests from foreign authorities are directed through mutual legal assistance channels or other lawful mechanisms rather than answered directly, unless applicable law requires otherwise.

Unless we are prohibited by law or court order, or a risk to life or safety exists, we notify the affected subscriber before disclosure and allow a reasonable opportunity to object.

15. Data Breach Notification

We maintain an incident response plan. In the event of a personal data breach, we will notify the competent supervisory authority without undue delay. We will also comply with applicable U.S. state breach notification statutes. Where we act as a processor, we will notify the controlling subscriber without undue delay and provide the information needed for their own notification obligations.

16. Changes to This Policy

We may update this Policy. For material changes — including any change to the categories of personal information we collect, the purposes of processing, our subprocessor categories, or your rights — we will give at least thirty (30) days’ notice by email to your registered and recovery/alternative email address and by posting the revised Policy with a new “Last Updated” date. Changes required by law or to address a security risk may take effect sooner.

17. How to Contact Us

Exactpoint Technologies LLC dba SaveMyService Hosting

General support: support@savemyservice.com

Billing:  accounting@savemyservice.com

Abuse reports:  abuse@savemyservice.com

Privacy and data protection: abuse@savemyservice.com

Security disclosures: abuse@savemyservice.com

Legal: legal@savemyservice.com

 

Mailing address:

40 Grace Dr.

P.O. Box 401

Powell, OH 43065

If you are not satisfied with our response, you may contact your state attorney general (United States), however would appreciate the chance to address your concern first.

© 2026 SaveMyService Hosting. All rights reserved. Version 1.1 — 8/4.