SaveMyService Hosting
Privacy Policy
Effective Date: TBD | Last Updated: 8/4 | Version 1.04
CONTENTS
- About This Policy
- Who We Are; Controller and Processor Roles
- Information We Collect
- How We Use Information and Our Legal Bases
- What We Do Not Do With Your Data
- Automated Processing: Spam, Malware, and Abuse Detection
- Cookies and Similar Technologies
- How We Share Information
- Subprocessors
- International Data Transfers
- How Long We Keep Data
- How We Protect Data
- Your Rights Under the GDPR and UK GDPR
- Your Rights Under California Law
- Your Rights Under Other U.S. State Privacy Laws
- Children’s Privacy
- Government and Law Enforcement Requests
- Data Breach Notification
- Changes to This Policy
- How to Contact Us and Complain
1. About This Policy
This Privacy Policy explains how Exactpoint Technologies, an Ohio LLC dba SaveMyService Hosting, (“SaveMyService Hosting,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with the SaveMyService Hosting Email service — our hosted mailbox service accessible by POP3, IMAP, and SMTP, together with any web interface, applications, APIs, and our website at www.savemyservice.com (collectively, the “Service”).
This Policy forms part of, and is incorporated by reference into, our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use. Where this Policy and the Terms of Use conflict on a data protection matter, this Policy controls; where an executed Data Processing Addendum applies, that addendum controls.
Email is unusual among online services in that the operator necessarily handles the contents of private correspondence in order to deliver it. We have written this Policy to be specific about what that involves, rather than relying on general language.
2. Who We Are; Controller and Processor Roles
SaveMyService Hosting is the entity responsible for the Service. Our contact details are in Section 20.
Where we act as a controller. We determine the purposes and means of processing for account registration data, billing records, authentication and connection logs, security and abuse-prevention data, support correspondence, and website analytics. This applies to individual consumer, prosumer, and commercial subscribers generally.
Where we act as a processor. Where a business or organizational subscriber uses the Service to handle personal data of its own employees, customers, or contacts within message content, that subscriber is the controller and we act as a processor on its documented instructions. Under U.S. state privacy law we act, in that same capacity, as a “service provider” (California) or “processor” (Virginia, Colorado, Connecticut, and comparable states).
3. Information We Collect
3.1 Information You Provide
- Account registration data: your name or chosen identifier, the mailbox address or addresses you create, a recovery email address, and a text capable recovery telephone number.
- Authentication credentials: your password, stored only as a salted cryptographic hash; multi-factor authentication secrets; and any application-specific passwords issued for POP3, IMAP, or SMTP access.
- Billing information: billing name, billing address, country, tax identifiers where applicable, plan selection, and transaction history. Full payment card numbers are collected and stored by our payment processor, not by us; we receive a token, the card brand, the last four digits, and the expiry date. Your personal payment data is not within our systems nor control.
- Support correspondence: the content of tickets, emails, and chat sessions you send to our support, billing, abuse, or security addresses, including any diagnostic information you choose to attach.
- Optional profile settings: display name, signature, time zone, language, filters, aliases, and forwarding rules.
3.2 Content You Store or Transmit
The Service stores and transmits the contents of your mailbox — message bodies, subject lines, attachments, headers, drafts, folder structure, flags, address book entries, and calendar or notes data where the Service offers those features. This information necessarily includes personal information about your correspondents, over which they, not you, may also have rights.
3.3 Information Generated by Using the Service
- Connection and protocol logs: source IP address, connection timestamp, protocol used (POP3, IMAP, SMTP, HTTPS), authentication outcome, client-supplied identifiers such as the IMAP ID string or user agent, TLS version and cipher, and bytes transferred.
- Mail transmission metadata: SMTP envelope sender and recipient addresses, message identifiers, message size, delivery status and bounce codes, spam and malware filter verdicts, and DKIM, SPF, and DMARC authentication results.
- Storage and quota data: mailbox size, message counts, and folder statistics.
- Security signals: failed authentication attempts, rate-limit events, abuse reports referencing your Account, and indicators used for fraud and account-takeover detection.
3.4 Website and Marketing Information
If you visit our website, we collect standard server log data and, subject to Section 7, information from cookies and similar technologies. If you subscribe to product announcements, we collect your email address and engagement data for that mailing.
3.5 Information From Third Parties
We receive limited information from our payment processor (transaction outcomes, chargeback notices, fraud scores), from abuse and threat-intelligence sources (blocklist status, spam reports, malware signatures), and from identity verification providers where fraud screening is required. We do not purchase nor sell personal information from data brokers.
3.6 Sensitive Information
We do not intentionally collect special category data. Message content may, however, contain such information because you or your correspondents put it there. We process that content only as necessary to deliver the Service, and never to infer characteristics about you.
4. How We Use Information and Our Legal Bases
| Purpose | Data used |
| Provisioning mailboxes, storing and delivering mail over POP3/IMAP/SMTP | Account data, content, transmission metadata |
| Authenticating you and maintaining sessions | Credentials, connection logs |
| Billing, invoicing, tax and accounting records | Billing data, transaction history |
| Spam, phishing, and malware filtering | Content, metadata, threat signals |
| Preventing abuse, fraud, and account takeover | Connection logs, security signals |
| Maintaining service integrity, capacity, and deliverability reputation | Metadata, quota data |
| Responding to support requests | Support correspondence, account data |
| Service and security notifications | Account data, recovery address |
| Optional product marketing emails | Email address, engagement data |
| Responding to valid legal process | Whatever the process compels |
| Establishing, exercising, or defending legal claims | As relevant to the claim |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is necessary and proportionate and does not override your rights.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. What We Do Not Do With Your Data
To be explicit, SaveMyService Hosting does not:
- scan or analyze the content of your messages to build advertising or interest profiles;
- sell your personal information, or share it for cross-context behavioral advertising;
- use your message content, attachments, or contacts to train machine learning or artificial intelligence models, whether our own or a third party’s;
- disclose message content to advertisers, data brokers, or marketing partners;
- read your mail for any purpose other than those in Section 6 and the limited access circumstances described in Section 8.5; or
- serve third-party advertising within the Service.
6. Automated Processing: Spam, Malware, and Abuse Detection
Delivering email requires automated inspection of message content and metadata. Inbound and outbound messages pass through filtering systems that evaluate headers, body text, attachments, embedded links, sender reputation, and authentication results in order to classify them as legitimate, spam, phishing, or malware. Attachments may be scanned by antivirus engines, and URLs may be checked against reputation services.
These systems operate automatically and no person reads your mail as part of this process. Classification outcomes are logged, and derived signals — such as a spam score, a malware signature hit, or an aggregated sender reputation — may be retained to improve filtering, but message content is not retained by the filtering systems beyond what is necessary to complete the evaluation and, where a message is quarantined, to allow you to review or release it.
Automated abuse controls may suspend outbound sending or restrict an Account under ; where such a restriction is applied automatically, you may request human review by contacting support@savemyservice.com.
7. Cookies and Similar Technologies
The POP3, IMAP, and SMTP interfaces do not use cookies. Our website and webmail interface use:
- Strictly necessary cookies for authentication, session management, load balancing, and cross-site request forgery protection. These cannot be disabled without breaking the Service.
- Preference cookies to remember settings such as language, theme, and layout.
- Analytics cookies, where enabled, to understand aggregate usage.
8. How We Share Information
We disclose personal information only in the following circumstances:
- Subprocessors and service providers that support the Service under written contract, as listed in
- Payment processors, to take payment and manage subscriptions;
- Recipients you send mail to, and the mail servers, intermediaries, and DNS operators along the delivery path — this is inherent to how email works, and once a message leaves our infrastructure its handling is governed by the recipient’s providers, not by this Policy;
- Professional advisers such as auditors, accountants, and lawyers, under duties of confidentiality;
- Government and law enforcement authorities, only as described in Section 17;
- In a corporate transaction, such as a merger, acquisition, financing, or sale of assets, subject to the notice and termination rights in Section 26 of the Terms of Use, and on condition that the acquirer is bound by commitments no less protective than this Policy; and
- With your direction or consent, including where you connect a third-party client, add-on, or integration.
We do not disclose personal information for any other purpose.
9. Subprocessors
We engage the following categories of subprocessor.
| Category | Purpose |
| [Cloud infrastructure / Hostway] | Hosting mail storage and compute |
| [Payment processor / Stripe via Zoho Payments] | Subscription billing and fraud screening |
| [Email deliverability / Hostway] | Outbound delivery and reputation monitoring |
| [Anti-spam / Spam Experts by N-able] | Content filtering and threat detection |
| [Support ticketing platform / Zoho Desk] | Handling support correspondence |
| [Backup / Hostway] | Encrypted operational backups |
Each subprocessor is bound by written terms imposing confidentiality and data protection obligations no less protective than those we owe you, and is permitted to process personal information only to deliver its contracted function.
10. How Long We Keep Data
Retention periods correspond to those in of the Terms of Use.
| Data | Retention |
| Mailbox content while your Account is active, not in Trash | Until you delete it |
| Deleted messages (Trash) | 30 days, or immediately on expunge |
| Purged message content in operational backups | Up to 24 hours (backup rotation) |
| Mailbox (Inbox Only) content after cancellation or termination | 30 days, then permanent deletion |
| Connection, authentication, and delivery logs
Mailbox access logs |
24 hours
7 days |
| Security and abuse investigation records/CRM and Billing Systems Only | Up to 12 months, or longer where an investigation is open |
| Support correspondence | 12 months after the ticket closes |
| Billing and tax records | 7 years, or as required by applicable law |
| Marketing consent and preference records | Until withdrawn, plus 3 years to evidence the withdrawal |
| Non-Paid Subscriptions/Inactive account data | Terminated after 3 months’ inactivity, per Terms of Use §9.5 |
We may retain data beyond these periods where necessary to comply with a legal obligation, respond to a valid legal hold, or establish, exercise, or defend legal claims. Retained data is restricted to that purpose.
Because of how POP3 works, messages your client downloads and deletes from our servers cannot be recovered by us after downloaded. See Section 4.2 of the Terms of Use.
11. How We Protect Data
We maintain a security program including encryption of data in transit using TLS with modern cipher suites, encryption of data at rest, role-based access control with least privilege, mandatory multi-factor authentication for personnel, logging and monitoring of administrative access, network segmentation, vulnerability management and patching, secure software development practices, background screening of personnel with production access, written confidentiality obligations, incident response procedures, and periodic testing and review.
Access to message content by our personnel is limited to the circumstances in Section 8.4 of the Terms of Use.
The Service does not provide end-to-end encryption. Message content is stored in a form we are technically able to access, which is what allows server-side search, filtering, and protocol access. If you require that we be unable to read your mail, apply client-side encryption such as OpenPGP or S/MIME before sending.
No security program eliminates risk entirely, and we cannot guarantee absolute security.
12. Your Rights Under U.S. State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sell personal data, or engage in profiling with legal or similarly significant effects, so those opt-outs have no practical application to the Service; you may nonetheless exercise them at support@savemyservice.com. Where a state provides an appeal right following denial of a request, we will describe the appeal process in our response, and you may thereafter contact your state attorney general.
13. Children’s Privacy
The Service is not directed to children under 16, and we do not knowingly collect their personal information. Accounts require subscribers to be at least 16, or the age of digital consent in their jurisdiction if higher, per Section 3.1 of the Terms of Use. If we learn that a child under has created an Account, we will terminate it and delete the associated data. Parents or guardians who believe a child has provided information to us should contact support@savemyservice.com.
14. Government and Law Enforcement Requests
We disclose personal information to government or law enforcement authorities only where compelled by legal process we reasonably determine to be lawful, valid, and properly served, or where an emergency involving danger of death or serious physical injury requires immediate disclosure.
We require a search warrant or demand legally equal to, based on probable cause before disclosing the content of communications to U.S. authorities. We review each request, and object to or seek to narrow requests that are overbroad, defective, or inconsistent with applicable law. Requests from foreign authorities are directed through mutual legal assistance channels or other lawful mechanisms rather than answered directly, unless applicable law requires otherwise.
Unless we are prohibited by law or court order, or a risk to life or safety exists, we notify the affected subscriber before disclosure and allow a reasonable opportunity to object.
15. Data Breach Notification
We maintain an incident response plan. In the event of a personal data breach, we will notify the competent supervisory authority without undue delay. We will also comply with applicable U.S. state breach notification statutes. Where we act as a processor, we will notify the controlling subscriber without undue delay and provide the information needed for their own notification obligations.
16. Changes to This Policy
We may update this Policy. For material changes — including any change to the categories of personal information we collect, the purposes of processing, our subprocessor categories, or your rights — we will give at least thirty (30) days’ notice by email to your registered and recovery/alternative email address and by posting the revised Policy with a new “Last Updated” date. Changes required by law or to address a security risk may take effect sooner.
17. How to Contact Us
Exactpoint Technologies LLC dba SaveMyService Hosting
General support: support@savemyservice.com
Billing: accounting@savemyservice.com
Abuse reports: abuse@savemyservice.com
Privacy and data protection: abuse@savemyservice.com
Security disclosures: abuse@savemyservice.com
Legal: legal@savemyservice.com
Mailing address:
40 Grace Dr.
P.O. Box 401
Powell, OH 43065
If you are not satisfied with our response, you may contact your state attorney general (United States), however would appreciate the chance to address your concern first.
© 2026 SaveMyService Hosting. All rights reserved. Version 1.1 — 8/4.
