Privacy policy

Effective date: October 3, 2025

Your privacy is important to us. This Privacy Policy explains how Your Last Letter collects, uses, and protects your personal data. We comply with the General Data Protection Regulation (GDPR) and other applicable laws. By using our services, you agree to this policy.

1. Who we are

Your Last Letter is based at Grovestins 51, 9051 GX Stiens, The Netherlands, and is registered under KVK number 77041755 and VAT number NL003151916B91. You can reach us at support@yourlastletter.com.

2. Scope

This Privacy Policy applies to both our marketing website (yourlastletter.com) and our application (app.yourlastletter.com). On the marketing website we only collect limited analytical data and essential cookies. Within the application we process account information, contacts, messages, attachments and technical data.

3. What data we collect

On the marketing website we collect analytical data through Plausible, IP addresses and essential cookies.

In the application we collect account details such as name, email address and encrypted password. We also collect contact details including name, email address and optionally a phone number. The messages you prepare and the attachments you upload are stored with us, as well as technical data such as IP addresses, device logs and activity logs.

Payment data is processed entirely by Stripe. We do not store or process payment details ourselves.

4. Encryption and storage

The contents of your messages are encrypted when stored in our databases. Attachments and contact details are not encrypted. All data is hosted in the Netherlands or, if our infrastructure changes, another country within the European Union.

5. How we use your data

We use your data to provide and improve our services. This includes delivering your messages to your chosen contacts, managing your subscription and account, sending check-in reminders and important notifications, generating logs for security and reliability, and tracking message delivery and open status via Postmark. We do not access or review the content of your messages.

6. Processors and third parties

We work with trusted third parties. Paddle processes all payments and invoices. Postmark, together with our own mail server, handles email delivery and open tracking. Plausible is used for analytics and is self-hosted, meaning data is not shared externally. Hosting providers are located within the EU. We never sell or share your data with advertisers.

7. Data retention

We keep your data for as long as your account is active. If you close your account, all data including messages and contacts will be deleted within 30 days.

8. User rights

You have the right to access your data, correct or update it, request deletion, export your data (data portability), and object to processing where applicable. You can exercise these rights through your account dashboard or by contacting us at support@yourlastletter.com. If you live in the EU, you also have the right to file a complaint with your national Data Protection Authority, in the Netherlands this is the Autoriteit Persoonsgegevens.

9. International use

Our service is available worldwide. Data is stored within the EU. If data is transferred outside the EU, for example by Paddle or Postmark, this will always be protected by Standard Contractual Clauses or equivalent safeguards.

10. Cookies and tracking

We use essential cookies for the functioning of the service. On the marketing website we use Plausible for anonymous analytics. Within the application we use Postmark’s tracking function to monitor whether emails are opened. We do not use Google Analytics or third-party marketing trackers.

11. Changes to this policy

We may update this Privacy Policy from time to time. If the changes are significant, we will notify you via email or through your dashboard. Continued use of our service after changes means you accept the updated version.