Privacy Policy
Last updated: 13 August 2026.
1. Who we are
Aerlet B.V. ("Aerlet", "we", "us") is the data controller for the personal data described in this policy. We are registered in Amsterdam, the Netherlands. You can reach us at [email protected].
2. What data we collect
We collect only what's needed to run your mailbox and bill you for it:
Account data — the email address you choose, a billing name and address, and your authentication credentials (stored hashed, never in plain text).
Payment data — handled entirely by Stripe. Aerlet never receives or stores your card number; we hold only a Stripe customer reference and the payment status it reports back to us.
Mailbox content — the email you send and receive through your Aerlet address. This is necessary to provide the service and is not scanned, profiled, or used for advertising.
Technical data — IP address, login timestamps, and basic client/device information, kept for security and abuse prevention.
3. Legal basis for processing
We process account, payment, and mailbox data under Article 6(1)(b) GDPR (performance of a contract — you can't have a mailbox without it). Technical/security logs are processed under Article 6(1)(f) (our legitimate interest in keeping the service secure and abuse-free). Where the law requires it — for example invoicing records — we process under Article 6(1)(c) (legal obligation).
4. Who we share data with
Stripe, for payment processing. Our mail infrastructure provider, to store and deliver your mailbox. We do not sell data, and we do not share it with advertisers, data brokers, or analytics networks — we don't run any.
We disclose data to law enforcement or courts only when legally compelled to, and only to the extent the request requires.
5. International transfers
Mailboxes are hosted within the European Economic Area. Where a processor (such as Stripe) transfers data outside the EEA, that transfer is covered by Standard Contractual Clauses or an equivalent adequacy mechanism recognized under GDPR.
6. Data retention
We keep account and mailbox data for as long as your account is active. If you close your account, we delete mailbox content within 30 days, except for records we're legally required to retain (e.g. invoices, typically 7 years under Dutch tax law).
7. Your rights
Under GDPR, you have the right to:
Access the personal data we hold about you · Correct inaccurate data · Request erasure ("right to be forgotten") · Restrict or object to processing · Receive your data in a portable format · Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with your national data protection authority — in the Netherlands, theAutoriteit Persoonsgegevens.
8. Security
Mail is encrypted in transit (TLS) and access to production systems is limited to what's needed to operate them. Passwords are stored hashed. We run no third-party trackers or analytics on this site or in the product, so there's nothing there to secure or leak.
9. Cookies
This website sets no tracking or analytics cookies. If we ever need a strictly functional cookie (for example, to keep you signed in), we'll update this section before we do.
10. Children
Aerlet is not directed at children under 16. We don't knowingly collect data from anyone under that age.
11. Changes to this policy
If we make material changes, we'll update the date at the top of this page and, for significant changes, notify you by email.