Skip to content

Legal

Privacy policy

We collect only what we need to run your email, we never sell it, and we never read your mail for advertising.

Last updated 16 September 2026

1. Scope and roles

This policy explains how Shwastik Mail (“we”) handles personal data when you visit our website, create an account, or use Shwastik Mail. It is written to meet the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules.

For account, billing and website data, we decide how the data is used (we are the data fiduciary). For the content of mailboxes (messages, contacts and calendars), the organization that owns the mailbox decides how it is used, and we process it on their behalf. If you use a mailbox provided by your employer, contact them first about your data.

2. Data we collect

  • Account data: your name, email address, password (stored only as a one-way Argon2id hash) and, if you enable it, your two-factor authentication secret.
  • Organization data: organization name, domains, mailbox names and addresses, aliases, groups, members and their roles, and mailbox profile pictures.
  • Mailbox content: messages, attachments, contacts, calendars and filters stored in mailboxes.
  • Billing data: plan, subscription status, invoices and payment references. Card, UPI and bank details are collected by Razorpay; we do not receive or store them.
  • Technical data: IP addresses, browser type, sign-in times, the audit log of console actions, and mail server logs (sender, recipient, time and delivery status of messages).
  • Communications: the emails you send to our support and other teams.

3. How we use it

  • to create and secure your account and provide the Service;
  • to deliver, filter, store and send mail, and to check your domain’s DNS records;
  • to process payments, issue invoices and meet tax obligations;
  • to send service emails such as verification, password resets, invitations and billing notices;
  • to detect and prevent spam, abuse, fraud and security incidents;
  • to answer support requests; and
  • to comply with law and respond to lawful requests from authorities.

We process data because it is necessary to provide the Service you signed up for, to meet legal obligations, or with your consent, which you may withdraw at any time. We do not send marketing email without your consent.

4. Your email content

We do not read, mine or analyse your mail for advertising, and we do not sell it. Automated systems scan messages only to filter spam and protect the Service. Our staff access mailbox content only when you ask us to for support, or when required by law.

5. Sharing

We do not sell personal data. We share it only with:

  • Service providers who help us run the Service under contract: our data-centre and hosting provider, and Razorpay for payments;
  • Recipients of your mail, when you send messages, as with any email service;
  • Authorities, when required by Indian law or a valid legal order; and
  • A successor, if our business is merged or sold, subject to this policy.

6. Cookies

The console uses only strictly necessary cookies: sm_access and sm_refresh keep you signed in, and sm_csrf protects forms against cross-site attacks. Webmail stores your session in your browser when you tick “Remember me”. We do not use advertising or third-party tracking cookies.

7. Retention

  • Account and organization data are kept while the account or organization exists.
  • Mailbox content is kept until you or your organization deletes it. Deleted data is removed from our live systems immediately and from backups within 14 days.
  • Billing records are kept for as long as Indian tax and accounting laws require.
  • Security and audit logs are kept for as long as needed to protect the Service and investigate abuse.

8. Security

We protect data with encrypted connections, hashed passwords, optional two-factor authentication, strict separation between organizations, restricted administrative access and daily backups. Read more on our security page. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.

9. Your rights

Subject to the law, you can:

  • access the personal data we hold about you and learn how it is used;
  • correct or update inaccurate data (most of it directly in the console);
  • ask us to erase data that is no longer needed;
  • withdraw consent where processing is based on consent;
  • nominate another person to exercise your rights in case of death or incapacity; and
  • raise a grievance with us, and then with the Data Protection Board of India.

To use these rights, email privacy@shwastik.com from the address on your account. We respond within 30 days.

10. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.

11. Changes

We will post any changes on this page and update the date above. For significant changes we will also email organization owners.

12. Grievance officer

You can reach our grievance officer at privacy@shwastik.com. We acknowledge complaints within 24 hours and resolve them within 15 days.