StartMail

StartMail is a paid email service made by the people behind Startpage.com.

This page is not published. While you can access it via its direct link, it is not yet displayed on the website.

Transparency

Does the policy require users to be notified in case of a data breach? N/A (the service collects so little personal data that notification would not be possible)

7/7

Decided May 22, 2020 (revision history). This question accounts for 8% of the final score.

Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.

Possible Options

No0/7
Yes, eventually5/7
Yes, within 72 hours7/7
N/A (the service collects so little personal data that notification would not be possible)7/7

Note

This service doesn't collect any contact information, thus it cannot reasonably contact a user in the event of a data breach except via its own service

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Will affected users be notified when the policy is meaningfully changed? Yes

5/5

Decided May 22, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Yes5/5
N/A (no personal data—or contact information—collected)5/5

Citation

We may change our Privacy Policy from time to time. Any changes to our Privacy Policy will be posted on this page, and we will provide a more prominent notice, such as an email message, if we believe a change significantly affects your privacy. You may also review older versions of our Privacy Policy through our Website.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is the policy's history made available? Only the date it was last modified

3/5

Decided May 22, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Only the date it was last modified3/5
Yes, with revisions or a change-log5/5

Citation

Last Modified: April 8th 2020

Effective: April 15th 2020

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy outline the service's general security practices? Yes, including independent audits

3/3

Decided May 22, 2020 (revision history). This question accounts for 4% of the final score.

Independent "reviews," "monitoring," etc. also count as independent audits.

Possible Options

No0/3
Somewhat1/3
Yes2/3
Yes, including audits2.5/3
N/A (no personal data collected)3/3
Yes, including independent audits3/3

Citation

On the Technical Side, we use state-of-the-art cryptography to protect your data. For example:

Traffic between the User and our servers is encrypted with SSL, and perfect forward secrecy is applied. We only store passwords in hashed form on our servers. Your StartMail inbox and its folders are stored in your own encrypted User Vault. Your User Vault is only opened when you login. When it is closed it is inaccessible to anyone. When you are logged out of StartMail, your entire inbox is encrypted. When you are logged in, your unencrypted emails are unencrypted, but all of your PGP-encrypted emails are still encrypted unless you open an encrypted email by submitting your PGP-passphrase. Users can encrypt emails via OpenPGP. The users’ key-pair is stored in the User Vault. Additionally, the private key is encrypted by means of the passphrase. Without the passphrase the private key it can’t be decrypted or used. We only use validated encryption algorithms that are considered safe by respected cryptographers. For more detailed information about our technical security measures, please read our Security White Paper.

On the Organizational Side we have strict protocols in place to ensure the safety of your data. For example:

At each level, access to our systems is restricted to authorized staff with a legitimate need to know. This access is tightly limited, and is only for the purpose of providing the StartMail Service to you. Any individual, who is given access to the StartMail system, is required to sign a confidentiality agreement. No third party, contractor, or sub-contractor of StartMail is given access to the system, except for the purpose of enabling us to provide the StartMail Service to you. All such parties must sign a data processing agreement, containing confidentiality provisions and stringent security protocols.

Note

Their security whitepaper (https://www.startmail.com/en/whitepaper/) describes how they hire independent third party auditors to review their service

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Collection

Is it clear why the service collects the personal data that it does? Yes

10/10

Decided May 22, 2020 (revision history). This question accounts for 12% of the final score.

This question deals with transparency. Even if the service uses data for reasons that aren't ideal for privacy, provided they list all of those uses, the service can still receive full credit for this question. However, if they are not explicit about their uses (by employing language like "such as"), a lower score is assigned.

Possible Options

No0/10
Somewhat4/10
Mostly7/10
Yes10/10
No personal data is collected10/10

Citation

When signing up for the StartMail Service you are asked to provide:

A name that you choose (optional and may be an alias or pseudonym, but see also our Terms of Service), → to be able to address you when we communicate with you. Verification email address, → This address is used to send you an activation link to activate your StartMail trial account. To maintain the integrity of the StartMail service, StartMail must take measures to avoid the automatic creation of accounts by spammers. This is because if spammers use StartMail to send messages, StartMail’s IP addresses can become blocked by major mail providers such as Gmail, Yahoo, Outlook, etc. Your desired email address (required), → to provide you with your StartMail email address A password (required), → to provide authentication for your Account. A Recovery Email Address (optional, see also our ToS), → to communicate with you in the event that you need to recover access to your StartMail Account should you ever lose your password. An invite code (optional, if you have one), → to give you the benefit of a promotional offer. Your preference as to whether you would like to subscribe to our newsletter(s), → to send you our newsletters only if you want to receive them. Information collected as a result of you answering prompts, such as image labeling data, text converted from audio files played to you, → in order for us to protect our website from spam and abuse, we use hCaptcha. Intuition Machines can deduce if we are dealing with a legitimate website visitor or a robot. We have a legitimate interest to know this. For more information, please read hCaptcha’s Privacy Statement.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy list the personal data it collects? Yes, generally

7/10

Decided May 22, 2020 (revision history). This question accounts for 12% of the final score.

All general categories of collected personal data are listed, though not all types of personal data are explicitly mentioned (for example, the list might use a phrase like 'such as' when listing types of personal data).

Possible Options

No0/10
Only summarily3/10
Yes, generally7/10
Yes, exhaustively10/10
N/A (no personal information is collected)10/10

Citation

A name that you choose (optional and may be an alias or pseudonym, but see also our Terms of Service), → to be able to address you when we communicate with you. Verification email address, → This address is used to send you an activation link to activate your StartMail trial account. To maintain the integrity of the StartMail service, StartMail must take measures to avoid the automatic creation of accounts by spammers. This is because if spammers use StartMail to send messages, StartMail’s IP addresses can become blocked by major mail providers such as Gmail, Yahoo, Outlook, etc. Your desired email address (required), → to provide you with your StartMail email address A password (required), → to provide authentication for your Account. A Recovery Email Address (optional, see also our ToS), → to communicate with you in the event that you need to recover access to your StartMail Account should you ever lose your password. An invite code (optional, if you have one), → to give you the benefit of a promotional offer. Your preference as to whether you would like to subscribe to our newsletter(s), → to send you our newsletters only if you want to receive them. Information collected as a result of you answering prompts, such as image labeling data, text converted from audio files played to you, → in order for us to protect our website from spam and abuse, we use hCaptcha. Intuition Machines can deduce if we are dealing with a legitimate website visitor or a robot. We have a legitimate interest to know this. For more information, please read hCaptcha’s Privacy Statement.

[...]

You may send us feedback or a support request. StartMail processes personal data to offer you support. For this purpose, we use the information provided by you, such as your email address and your feedback or request. We need this information for the performance of a contract: to respond to your feedback or support request.

We use Zendesk to process your feedback or support request. Zendesk is located in the US and has a Privacy Shield certificate. This means that appropriate safeguards have been taken to protect your privacy. Nevertheless, If you do not want that, then you can send an e-mail to [email protected] Note that it may take slightly longer for an agent to pick up your request. We store any communications up to a maximum of two years.

Note: if your message is abusive in language or content, we may block further messages from you.

[...]

For payment processing, StartMail relies on third parties such as Stripe and Paypal to process payment details such as credit card information to process your payments or refunding such payments. In accordance with Payment Card Industry Security Standards (PCI DSS), which our payment and subscriptions providers all adhere to, they are not permitted to use your information for anything other than processing your payment. For subscription management, StartMail relies on Chargebee to manage customer lifecycle operations such as managing trials, assigning credits, issuing refunds and making mid-cycle subscription Our subscription management provider processes data only as our ‘processor’ (as intended in the GDPR). Through our data processing agreement, we have bound this provider to only process data in order to provide their services to us and not for other purposes. In addition, we pseudonymize your data before providing it to our subscription management provider.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service collect personal data from third parties? No

10/10

Decided May 22, 2020 (revision history). This question accounts for 12% of the final score.

This includes the use of data brokers and independent verification authorities (such as background check providers).

Possible Options

Yes0/10
Only for critical data7/10
No10/10

Note

There is no information of the service collecting personal data from third parties.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow the user to control whether personal data is used or collected for non-critical purposes? N/A (no data used for non-critical purposes)

5/5

Decided May 22, 2020 (revision history). This question accounts for 6% of the final score.

Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.

Possible Options

No0/5
On an opt-out basis, but only for some non-critical data/uses1.5/5
On an opt-out basis, for all non-critical data/uses3/5
N/A (no data used for non-critical purposes)5/5
On an opt-in basis5/5

Note

Data is only used for required purposes

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Handling

Does the policy allow personally-targeted or behavioral marketing? No

10/10

Decided May 22, 2020 (revision history). This question accounts for 12% of the final score.

Possible Options

Yes0/10
Yes, but you can opt-out3.5/10
Yes, but you must opt-in7/10
No10/10

Citation

We therefore don’t track your behaviour online and we don’t build any personal profiles of you. The StartMail Service is strictly ad-free.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow third-party access to private personal data? Yes, all parties specified (only to critical service providers)

8/10

Decided May 22, 2020 (revision history). This question accounts for 12% of the final score.

This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).

Note that whether the policy allows sharing aggregated user data does not affect this question.

If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).

If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).

Possible Options

Yes, not all parties specified0/10
Yes, all parties specified (including non-critical service providers such as advertisers)3/10
Yes, not all parties specified (but only to critical service providers)7/10
Yes, all parties specified (only to critical service providers)8/10
No10/10

Citation

Chargebee

The information that you provide through Chargebee is subject to the Chargebee Privacy Policy. In addition to the payment details, an e-mail address which functions as an alias which is generated when you register at StartMail will be shared with Chargebee to help you and StartMail manage your subscription for example: you can receive notification when a charge is about to be incurred or has failed.

Stripe

The information that you provide through Stripe such as your credit card number, credit card expiration date, card security code is subject to the Stripe Privacy Policy.

PayPal

StartMail supports PayPal as a payment processing provider. If you choose to pay with Paypal you agree with their privacy policy. You can find their privacy policy here: To make payments as easy and user-friendly as possible, StartMail sends your name and e-mail address to Paypal during a payment process. All this information would be requested by the provider anyway.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow you to permanently delete your personal data? Yes, by contacting someone

3/5

Decided May 22, 2020 (revision history). This question accounts for 6% of the final score.

Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.

Possible Options

No0/5
Yes, by contacting someone3/5
Yes, using an automated mechanism5/5
N/A (no personal information collected)5/5

Citation

If you inform us that you withdraw your consent to process your information, we will delete your information, unless we are legally required to keep it (e.g. invoices, as explained below under retention periods).

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


When does the policy allow law enforcement access to personal data? Only when required by a court order or subpoena

4/5

Decided May 22, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

Always0/5
Not specified0/5
When reasonably requested3/5
Only when required by a court order or subpoena4/5
N/A (no personal data to share)5/5
Never (special legal jurisdiction)5/5

Citation

While we respect and try to protect your privacy to the best of our abilities, your use of StartMail does not place you above the law. But neither do we place authorities above the law. ONLY if we receive a request from Dutch judicial authorities to hand over information about one of our Users, we will have our lawyers check the validity of the request and determine whether we are obliged to comply. We will NOT comply with such requests unless we are convinced that the request is legally valid and we believe that it is undeniably our legal obligation to comply.

We will NOT comply with requests from any authorities other than Dutch authorities. If we receive a request from any foreign government, we will refuse to comply and will instead instruct the requestor to place a formal request to the Dutch authorities for mutual assistance.

StartMail will never cooperate with any voluntary surveillance programs. Under the strong laws that protect the right to privacy in Europe, European governments cannot legally force service providers like StartMail to implement a blanket-spying program on their users.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.



Warnings

StartMail has no warnings published on PrivacySpy. PrivacySpy publishes warnings when it learns a service has announced a data breach or is found misusing user data. If you believe a warning should be published for StartMail, submit one here.


Highlighted Policy Snapshot ALPHA

No highlighted policy snapshot has been created for this privacy policy. To view the policy at its original location, click here.

8.8/10

How we calculate ratings →


Version Added

May 22, 2020

Ratings Updated

May 22, 2020

Warnings

0

Maintained by

doamatto

Original Location
Open in New Tab
Other Versions