Privacy Policy

Our privacy policy and how we use your data

Effective: September 1, 2026

Tangible Post LLC (“Tangible Post,” “we,” “us”) operates a platform that turns customer data into real, handwritten direct mail. This policy explains what personal information we handle, why, who we share it with, and the choices you have.

Tangible Post is offered to businesses in the United States. Our services are not directed to individuals outside the U.S.

1. Scope — and the two very different roles we play

This is the most important section in this policy, because Tangible Post handles two kinds of personal information that the law treats very differently.

When we are the business making the decisions (a “controller”), this policy governs. That covers information about our own customers — the businesses and people who sign up for Tangible Post — and visitors to our website.

When we are simply carrying out a customer’s instructions (a “processor” or “service provider”), this policy does not govern how that data is used. That covers the mailing lists our customers upload or sync to us: the names and addresses of their customers. We hold that data on their behalf, use it only to produce and mail what they ask us to produce and mail, and never for our own purposes. The business that gave us that data decides what happens to it, and their own privacy policy applies.

Which data falls into which role

InformationOur role
Your account, login, and contact detailsController — this policy applies
Your business profile and return addressController
Billing and payment recordsController
Website and in-app activity, cookies, device dataController
Support, sales, and marketing communications with youController
Recipient lists you upload or sync — names, mailing addresses, and any custom fieldsProcessor / service provider — we act on your instructions only
Message content and artwork you supply for a mail pieceProcessor / service provider
Order and campaign results tied to individual recipientsProcessor / service provider

If you are a Tangible Post customer, you are responsible for having the right to give us the recipient data you upload, and for telling those people how you use their information. Section 9 of our Terms of Service covers this in detail.

2. If you received mail from a business using Tangible Post

You may be reading this because a handwritten card arrived and you looked us up. Here’s the plain version:

We didn’t choose to mail you. A business you have some relationship with used our platform to send it. They provided your name and address; we printed, wrote, stamped, and mailed the piece on their behalf. We do not own that list, we do not sell it, and we do not use your address to market anything of our own to you.

To stop receiving mail, the fastest route is to contact the business whose name is on the card — they control the list and can remove you directly.

You can also contact us at terms@tangiblepost.co. If you tell us the business that mailed you (their name is on the piece), we will forward your request to them, ask them to honor it, and help them do so. Where the law gives you rights directly against us for data we hold, we will honor those too — see Section 10.

3. Information we collect

From you, our customer

  • Account information — name, email address, password, and, for team accounts, the role you hold.
  • Business profile — company name, website, and your business mailing address, which doubles as the default return address printed on your mail.
  • Additional return addresses you save.
  • Billing information — your billing email and a customer reference from our payment processor. We never see or store full payment card numbers; card details are entered directly with Stripe.
  • Communications — messages you send us through the contact form, support requests, and survey or feedback responses.

Automatically, when you use our site or app

  • Log and device data — IP address, browser type and version, operating system, referring pages, and timestamps.
  • Usage data — pages viewed and actions taken in the product.
  • Security records — sign-in attempts (including IP address and browser user-agent, retained for 90 days), and records of any support-authorized account access by our staff.
  • Cookies and similar technologies — see our Cookie Policy.

Recipient data, on our customers’ behalf

When a customer builds an audience — by uploading a CSV or syncing a segment from their own Klaviyo account — we receive and store, for each recipient: first and last name, company, street address (lines 1 and 2), city, state, and ZIP code, plus any custom fields they choose to include (for example, a last order date or a pet’s name to personalize the note).

When an order is paid, we take a frozen snapshot of exactly who that order mails. That snapshot is what production reads — never the live list — so a later edit to the audience can’t change what has already been printed. Snapshots are stored in a restricted area that customers cannot query directly.

Where a customer connects their own Klaviyo account, we may also receive conversion events (such as a purchase) so we can report back which orders their mail drove. We automatically strip anything that looks like a credential from imported custom fields.

We do not knowingly collect, and customers must not send us, Social Security numbers, payment card numbers, driver’s license or passport numbers, or information regulated by HIPAA, GLBA, FERPA, or COPPA.

4. How we use information

As a controller, we use information about our customers to:

  • provide, operate, secure, and improve the platform;
  • create and administer accounts, and authenticate users;
  • process payments, manage credits, and issue invoices and refunds;
  • send transactional messages — order confirmations, shipping notices, billing and account notices, and security alerts (these are not marketing and you cannot opt out of them while you hold an account);
  • send marketing communications, where you have opted in — you can unsubscribe at any time;
  • provide customer support;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • comply with legal obligations and enforce our Terms.

As a processor, we use recipient data only to produce and deliver the mail our customer ordered, to report results back to that customer, and to meet legal requirements. We do not use it to build our own marketing lists, we do not sell it, and we do not use it to train models.

5. How we share information

We do not sell personal information. We share it only as described here.

Service providers

We rely on a small number of established third-party providers to run the platform — for hosting and data storage, payment processing, transactional email, background processing, error monitoring, and our own website analytics and marketing. Each is bound by contract to use the information only to provide services to us, and not for its own purposes.

Two limits are worth stating plainly:

  • Payment card details never reach us. Card numbers are entered directly with our payment processor.
  • Recipient data goes only where it must. The providers that store or process it do so on our behalf under contract, and the only other party that receives it is the postal carrier that delivers the mail.

We maintain a current list of the providers that handle personal information on our behalf. If you would like it, write to terms@tangiblepost.co and we will send it to you.

If you are a customer and you connect your own Klaviyo account, we exchange data with your Klaviyo account at your direction — reading the lists and codes you point us at, and writing back campaign results. That is your account and your data, under your agreement with Klaviyo.

Postal carriers. To deliver mail, recipient names and addresses are physically printed on envelopes and handed to the United States Postal Service or another carrier. This is unavoidable — it is how mail works.

Other disclosures

  • Legal — when required by law, subpoena, or valid legal process, or to protect our rights, safety, or property, or that of others.
  • Business transfers — in a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply.
  • With your direction — anywhere you ask us to share.

6. Error monitoring

We use a third-party error-monitoring service to find and fix problems. When something goes wrong, it receives a report of the error itself — the error message, the page it happened on, the browser and device, and a short trail of the actions leading up to it — along with performance timings so we can find slow pages.

We do not record your screen or your session. Some monitoring tools offer a session-replay feature that captures video-like recordings of what a user sees and types. We have deliberately not enabled it, because the signed-in application displays customer mailing lists, and we would rather that content never leave our systems at all.

Before an error report is transmitted, we strip email addresses out of it and remove one-time tokens and credentials from any web addresses it contains.

7. Our commitment on order data

We want to be unambiguous about the thing that matters most to our customers:

We do not share recipient names, mailing addresses, message content, artwork, or payment information with any third party for that third party’s own marketing purposes. We do not sell it. We do not rent it. We do not add it to any list of our own.

The only parties that receive recipient data are the service providers described above, who process it on our behalf under contract, and the postal carrier that delivers the mail.

8. Cookies and tracking

We use cookies and similar technologies for authentication, preferences, referral attribution, and analytics. Our full disclosure, including the categories we use, the two analytics providers we rely on, and how to control them, is in our Cookie Policy.

We do not currently respond to browser “Do Not Track” signals, as there is no common standard for them. We do honor Global Privacy Control (GPC) signals as an opt-out of sale or sharing where applicable law requires it.

9. How long we keep information

As a general rule, we keep information for the life of your account. When you close your account, the data associated with it is deleted.

Four things sit outside that general rule, and they are the ones worth knowing:

  • You can delete sooner. Deleting a contact or an audience removes it from our active systems at any time, without closing your account. You can also export any audience yourself before you do.
  • Paid orders are an exception. Records already used to produce a paid order remain in that order’s frozen snapshot, because we must be able to show what we actually printed and mailed.
  • Some records are kept because the law requires it. Billing and transaction records are retained as tax and accounting records, generally for seven years.
  • Security logs are short-lived by design. Sign-in and security events are kept for 90 days.

We never store payment card details at all. Where we retain anything after an account closes, we keep only what the law requires, or keep it in de-identified form that cannot be linked back to any individual.

10. Your privacy rights

If you are a Tangible Post customer

You can access and correct most of your information directly in your account settings. You may also request access, correction, deletion, or a copy of your data by writing to terms@tangiblepost.co. You can export any audience as a CSV from within the product at any time.

If you are a California resident

Under the CCPA/CPRA you have the right to:

  • Know what personal information we collect, use, disclose, and the sources and purposes;
  • Access a copy of it, in a portable form;
  • Correct inaccurate information;
  • Delete it, subject to legal exceptions;
  • Opt out of sale or sharing for cross-context behavioral advertising;
  • Limit use of sensitive personal information;
  • Not be discriminated against for exercising these rights.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

In the twelve months before the effective date of this policy, we collected the categories described in Section 3 — identifiers, commercial information, internet and network activity, and, for customers, limited financial information — for the business purposes described in Section 4, and disclosed them to the service providers listed in Section 5.

Under California’s “Shine the Light” law you may request information about disclosures to third parties for their direct marketing purposes; as stated, we make none.

If you live in another state with a privacy law

Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others with comparable laws in force have similar rights — to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Some of these states also give you the right to appeal a denied request; if we deny yours, our response will explain how to appeal.

How to make a request

Email terms@tangiblepost.co with the subject line “Privacy Request.” Tell us what you want and enough information for us to find your records. We will verify your identity before acting — usually by confirming control of the email on the account. We respond within 45 days, and will tell you if we need a permitted extension. An authorized agent may submit a request on your behalf with written permission we can verify.

If your data is held on a customer’s behalf

If we hold your information because one of our customers uploaded it — that is, you received mail rather than signed up — see Section 2. We will forward your request to the business responsible and support them in honoring it.

11. Data security

We maintain administrative, technical, and physical safeguards designed to protect personal information. These include encryption of data in transit, encrypted storage of any integration credentials you connect, access controls that scope data to the account that owns it, private storage for uploaded artwork, role-based permissions with optional multi-factor authentication, logging of any support access to an account, and protections against automated attacks on sign-in.

We review these controls as the product changes, and we test them as part of our regular development process.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.

12. Children’s privacy

Tangible Post is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. Customers must not upload recipient data about individuals they know to be under 16. If we learn we have collected such information, we will delete it promptly.

13. Third-party links

Our site and product link to third-party services. This policy does not cover them, and we are not responsible for their practices. Review their policies before providing information.

14. Changes to this policy

We review this policy at least annually. If we make material changes, we will update the effective date above and notify you — by email to your account address, or by a prominent notice on the site — before the changes take effect. Continued use after that means you accept the updated policy.

15. Contact us

Privacy questions and requests: terms@tangiblepost.co
General support: handson@tangiblepost.co


This policy works together with our Terms of Service, Cookie Policy, and The Tangible Promise.