Mailway is email infrastructure: applications send email through our SMTP relay and HTTP API, and we route it to the email provider accounts our customers connect. This policy explains what personal data we handle, in which role, and what rights you have. It is written to be read, not skimmed past — if anything is unclear, write to us via the contact form.
1. Who we are
The service at mailway.net, console.mailway.net, smtp.mailway.net,api.mailway.net and mailway.to is operated by Mailway Ltd., Budapest, Hungary ("Mailway", "we"). Contact: hello@mailway.net or the contact form.
2. Two roles: controller and processor
Under the GDPR we act in two distinct roles, and your rights run differently in each:
- Controller — for the data of people who visit this site, create an account, or belong to a team: account details, billing records, security and usage logs. Sections 3–10 cover this.
- Processor — for the content of email our customers relay through Mailway. That mail belongs to the customer; we process it only on their instructions, under our Data Processing Agreement. If you received an email sent through Mailway and have questions about it, the sender is the controller — contact them first; we will assist them with any data-subject request they pass to us.
3. Data we collect as a controller
- Account data — name, email address, hashed password (we never store the plaintext), two-factor authentication enrollment (TOTP secrets, WebAuthn public keys), team membership and role.
- Billing data — plan, subscription state, invoices, and the card brand / last four digits as mirrored from Stripe. Full card numbers never touch Mailway's systems; payment collection is handled entirely by Stripe.
- Security and usage logs — IP addresses, user agents, sign-in and security events (the same audit trail we surface to team admins in the console), API and SMTP authentication events.
- Correspondence — anything you send us by email or through the contact form (your name, email address, topic and message).
- Waitlist data — while Mailway is in private beta: the email address you submit, the country your request arrived from (from our CDN's country header — we do not store the IP), the campaign parameters that first brought you to the site if any (see Cookies & analytics), and a record of the consent checkbox you ticked, so we can show what you agreed to and when.
We do not buy, rent, or enrich personal data from third-party sources.
4. Data we process as a processor
When a customer relays mail through Mailway we process the full message content (headers, body, attachments), recipient addresses, delivery metadata and provider delivery events, and the provider credentials the customer connects (stored encrypted). The scope, retention and safeguards for this data are set by the customer's plan and the DPA — not by this policy.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service — accounts, teams, routing, the console | Account, billing | Contract (Art. 6(1)(b)) |
| Security — authentication, abuse prevention, audit logging | Security logs | Legitimate interest (Art. 6(1)(f)) — keeping the platform and your account safe |
| Billing and tax compliance | Billing records | Legal obligation (Art. 6(1)(c)) |
| Service announcements (security, availability, terms changes) | Account email | Contract / legitimate interest |
| Product news (if we ever send it) | Account email | Consent (Art. 6(1)(a)) — opt-in, revocable anytime |
| The private-beta waitlist — sending your invite and launch news | Waitlist email, country, campaign parameters, consent record | Consent (Art. 6(1)(a)) — the checkbox on the form, revocable anytime by writing to us |
6. Retention
- Account data — for the life of the account, deleted with it.
- Relayed mail content — per the plan's retention window, then removed by our retention process. See the documentation for the current windows per plan.
- Security and audit logs — kept as long as needed for security purposes.
- Billing records — 8 years, as required by Hungarian accounting law.
- Waitlist entries — until you're invited and 12 months after, or until you ask us to remove you, whichever comes first. Ask via the contact form and we'll delete the entry.
7. Sub-processors and recipients
We use a small set of infrastructure providers, listed with their roles and locations on the Trust page. We give 30 days' notice before adding or replacing a sub-processor that touches customer data. We do not sell personal data, and we disclose it to authorities only where legally required.
8. International transfers
Mail is ingested, routed, and archived inside the European Union (Germany). Some supporting sub-processors (payments, error monitoring, CDN, code hosting) may process limited data outside the EEA; where they do, transfers rely on adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.
9. Your rights
You can access, rectify, erase, restrict, or object to the processing of your personal data, request portability, and withdraw consent at any time (Arts. 15–21 GDPR). Most account data is directly editable in the console; for the rest, use the contact form — we respond within 30 days. You may lodge a complaint with the Hungarian supervisory authority (NAIH, naih.hu) or your local data protection authority.
10. Cookies & analytics
This website uses Plausible for aggregate, cookieless web analytics — an EU company processing on EU servers. It sets no cookies, stores no personal data, and cannot follow you across sites; we see counts, not people. The website sets one first-party cookie of its own, mw_attr: if you arrived from a campaign link, it remembers which one (UTM parameters, referrer) for 180 days, so that if you later create an account we know what brought you here. It is readable only by our own domains and, today, is shared with no one. The console (console.mailway.net) sets strictly necessary cookies only: a session cookie and a CSRF token, both required for signing in. None of that requires consent.
What does require consent: we advertise on Google and Reddit, and measuring whether those ads work uses one cookie each from them. So the site asks first — the cookie banner — and nothing ad-related loads unless you say yes. Your decision is remembered in a first-party cookie (mw_consent), recorded on our side as an anonymous receipt, and changeable any time via "Cookie choices" in the footer. Declining changes nothing else about the site. Durations:mw_attr and mw_consent live for 180 days; the Google and Reddit cookies (set only after you accept) follow their own policies. If your browser sends theGlobal Privacy Control signal, we treat it as a standing "no" — the banner won't even ask.
11. Security
TLS on every connection, encrypted storage for provider credentials and archived payloads, two-factor authentication, role-based access, and a full audit trail. The current posture is documented on the Trust page.
12. Children
Mailway is a developer tool for businesses and is not directed at children under 16.
13. Changes to this policy
We will announce material changes by email to account holders and update the date at the top of this page. Prior versions are available on request.