LEGAL

Privacy Policy

Last updated: 23 July 2026

MailKaka is a product owned and operated by POLARA VENTURE STUDIO (OPC) PRIVATE LIMITED (“MailKaka”, “we”, “us”), a One Person Company incorporated under the Companies Act, 2013 (CIN: U62013KL2026OPC104127), with its registered office in Kerala, India. This policy explains what data we collect, why, and the rights available to you under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable Indian law.

READ THIS FIRST

We play two different roles under this policy.

MailKaka is used in two distinct ways, and the DPDP Act treats them differently. It matters which one applies to any given piece of data:

1. Data Fiduciary — for your account with us.

If you sign up for MailKaka, we are the Data Fiduciary for your account data: your name, work email, organization details, billing information, API keys, domain and webhook configuration, and usage logs of the product itself. This policy governs that relationship directly, and the rights described below (access, correction, erasure, grievance redressal, and so on) apply to this data.

2. Data Processor — for email you send or receive through the platform.

Our business customers use MailKaka to send transactional email to their own end users, and to run team inboxes that receive mail from the public. For that email content and the recipient/sender addresses inside it, MailKaka acts only as a Data Processor on behalf of the customer, who remains the Data Fiduciary for their own recipients. We process that data strictly to provide the service (deliver the email, store it in the mailbox, run spam/abuse checks, show it in the customer's dashboard) and under the customer's instructions, not for our own purposes.

If you received an email from, or sent an email to, a business that uses MailKaka your relationship for that message is with that business, not with us. MailKaka customers are solely responsible for having a lawful basis (consent, contract, legitimate use, or otherwise) to email their own recipients, for honoring unsubscribe and data-subject requests from their own users, and for complying with the DPDP Act and any other law that applies to their use of the product. Requests about the content of a specific email should go to the business that sent or hosts it; we will assist that business as its processor where required by law.

ACCOUNT DATA

What we collect as Data Fiduciary.

  • Identity and contact details — name, work email address, and organization name provided at signup or via OAuth login.
  • Billing data — plan, subscription status, and payment metadata processed through Razorpay. We do not receive or store full card, UPI, or bank account numbers; Razorpay handles those directly as our payment processor.
  • API keys — we store only a one-way bcrypt hash of each key. The plaintext key is shown once at creation and is not retrievable afterward, even by us.
  • Webhook signing secrets — stored encrypted at rest (AES-256-GCM) and only decrypted at the moment a webhook delivery is signed.
  • Domain and DNS configuration — the domains you verify for sending, along with the SPF, DKIM, and DMARC DNS records generated to authenticate them.
  • Product usage data — sending volume, mailbox and team-member counts, storage consumption, and AI-credit usage, tracked against your plan's entitlements.
  • Support communications — anything you send us at support@mailkaka.in or sales@mailkaka.in.

CUSTOMER-CONTROLLED DATA

Email traffic we process on a customer's behalf.

When you use MailKaka to send transactional email or run a hosted business mailbox, the platform necessarily handles the email content itself. We process this strictly to operate the service:

  • Outbound (send API): sender/recipient addresses, subject, body (HTML/text), and attachments submitted to the send endpoint are transmitted to AWS SES for delivery and logged (status, timestamps, tags) for delivery reporting and webhook events.
  • Inbound (hosted mailboxes): mail addressed to a customer's verified domain is received via AWS SES/SNS, parsed, threaded, and stored in that customer's team inbox, visible only to members of that organization.
  • Attachments: stored in object storage (AWS S3, Mumbai region). Executable and active-content file types (e.g. .exe, .js,.html, .svg) are blocked or quarantined automatically regardless of the declared content type, as an anti-malware safeguard.
  • Suppression lists: addresses that bounce, complain, or unsubscribe are recorded per organization so we do not send to them again — this is required to maintain sender reputation and comply with anti-spam norms, and customers can view or manually manage their own suppression list.
  • Abuse and reputation monitoring: we automatically evaluate an organization's recent bounce and complaint rates to protect the shared sending infrastructure. This produces an internal risk signal and, if thresholds are exceeded, an account suspension flag — it does not involve reading message content beyond delivery status.
  • Optional AI features: on eligible plans, a customer may ask MailKaka's mailbox assistant to summarize a thread or answer a question about it. Only when a customer actively uses this feature, the relevant thread content is sent to our AI sub-processor (Anthropic) to generate the response — see “Sub-processors” below.

We do not read, sell, or use this customer-controlled email content for advertising, model training, or any purpose outside operating the service and complying with law.

PURPOSE

How we use the data described above.

  • To provide, maintain, and secure the MailKaka service.
  • To authenticate requests, enforce plan entitlements, and meter usage.
  • To process payments and manage subscriptions via Razorpay.
  • To detect and prevent abuse, fraud, and deliverability harm to the shared sending pool.
  • To respond to support requests and legal or Grievance Officer complaints.
  • To comply with applicable law, regulation, or a valid legal process.

THIRD PARTIES

Sub-processors and who else sees data.

We do not sell personal data. We share data only with the following categories of sub-processors, each bound by contract to process it solely to provide their service to us:

Sub-processorPurpose
Amazon Web Services (SES, S3, SNS — ap-south-1 Mumbai)Sending, receiving, and storing email and attachments
RazorpaySubscription billing and payment processing
DigitalOceanManaged DNS record configuration for domain verification
Anthropic (Claude API)Optional mailbox AI summaries and Q&A, only when a customer invokes that feature

We may also disclose data where required to comply with law, enforce our Terms of Service, or protect the rights, property, or safety of MailKaka, our customers, or others.

RETENTION

How long we keep data.

  • Mailbox messages and attachments are retained per the customer's plan — from 30 days on the Free plan up to 365 days on the Scale plan — and are automatically aged out of search and thread views once that window passes.
  • Suppression list entries (bounced, complained, or unsubscribed addresses) are retained indefinitely by default, since removing them would risk re-sending to a recipient who opted out or bounced — an organization can manually remove an entry from its own suppression list at any time.
  • Account and billing records are retained for the life of the account and for the period required afterward under Indian tax, company, and accounting law.
  • API keys and webhook secrets are deleted when revoked or when the associated domain/endpoint is removed.
  • On account deletion, we delete or anonymize account and mailbox data within a reasonable period, except what we are legally required to retain (e.g. billing records, or data under an active legal hold).

SECURITY

How we protect data.

API keys are stored as one-way bcrypt hashes, never in plaintext. Webhook signing secrets are encrypted at rest with AES-256-GCM. Webhook deliveries are signed with HMAC-SHA256 so recipients can verify authenticity. Organization data is isolated at the database layer so one customer cannot query another's mailboxes, keys, or logs. No system is perfectly secure, and we cannot guarantee absolute security, but we apply industry-standard safeguards and continue to improve them.

YOUR RIGHTS

Rights available under the DPDP Act, 2023.

If you are an individual whose personal data we hold as Data Fiduciary (i.e. our own account holder, not a customer's end recipient — see “Two roles” above), you may:

  • Request access to a summary of the personal data we hold about you.
  • Request correction or updating of inaccurate or incomplete data.
  • Request erasure of your personal data, subject to our legal retention obligations.
  • Withdraw consent for any processing that relies on consent, at any time.
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Lodge a complaint with the Data Protection Board of India if you are not satisfied with our response.

To exercise any of these rights, write to support@mailkaka.in. We will verify your identity before acting on the request and respond within a reasonable time as required by law.

If your data appears inside a customer's mailbox or was sent to you by a MailKaka customer, direct your request to that business first, since it is the Data Fiduciary for that data; we will support them in fulfilling it as required by law.

SESSIONS

Cookies and session data.

MailKaka uses strictly necessary session cookies to keep you signed in and to protect authentication (including OAuth sign-in flows). We do not currently use third-party advertising or cross-site tracking cookies on the marketing site or dashboard.

ELIGIBILITY

Children's data.

MailKaka is a business-to-business product intended for use by organizations and their authorized personnel. It is not directed at, and we do not knowingly collect account data from, individuals under the age of 18.

UPDATES

Changes to this policy.

We may update this policy from time to time to reflect changes to the product or applicable law. We will update the “Last updated” date above when we do, and material changes will be communicated to account holders by email or an in-product notice.

IT RULES, 2021

Grievance Officer.

In accordance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer for MailKaka is:

Paul Zacharia

Director, POLARA VENTURE STUDIO (OPC) PRIVATE LIMITED

Email: support@mailkaka.in

Phone: +91 94960 92638

The Grievance Officer will acknowledge complaints and work to resolve them within the timelines prescribed under applicable law.

Privacy Policy | MailKaka