Privacy Policy
What UCN Mail collects, why we collect it, who else sees it, how long we keep it, and the control you have over all of it.
Last updated Aug 29, 2026
Who We Are
The company behind UCN Mail, and how to reach us about privacy.
UCN Mail is a managed email hosting service operated by UCNHUB LLC, a limited liability company formed under the laws of the State of Delaware, United States. Where this policy says “we”, “us”, or “UCN Mail”, it means UCNHUB LLC.
For the personal data described in this policy, UCNHUB LLC is the entity that decides why and how the data is processed, except where we act as a processor on your behalf — see Our Two Roles below.
- Legal entity
- UCNHUB LLC
- Entity type
- Delaware limited liability company
- File number
- 10710550
- Registered office
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - Privacy contact
- [email protected]
- Support
- ucnmail.com/contact-us
Scope of This Policy
What this policy covers, and what it does not.
This Privacy Policy applies to the UCN Mail platform: the ucnmail.com website, the customer dashboard, the webmail application at web.ucnmail.com, our Android and iOS apps, Drive, calendar and contacts, and the mail servers and SMTP, IMAP, and POP3 endpoints we operate.
It describes how we handle personal data about you as our customer or as a visitor to our website. It also describes how we handle the content inside your mailboxes, which we treat differently — see Your Content.
What this policy does not cover
The mail providers of the people you write to and receive mail from; websites we link to; your own website or the services you connect to your domain; and any third-party mail client you choose to use, such as Outlook, Apple Mail, or Thunderbird. Once a message leaves our servers for a recipient elsewhere, that recipient's provider handles it under its own policies.
If you use a mailbox someone else pays for
Where your employer or another organisation holds the UCN Mail account and created your mailbox, that organisation — not UCN Mail — decides what happens to the mail in it, including whether it can be accessed, exported, or deleted. Direct your privacy questions to them in the first instance.
Our Two Roles
Controller for your account, processor for your mail.
Data protection law distinguishes between the party that decides why data is processed (the controller) and the party that processes it on someone else's instructions (the processor). We are both, depending on the data.
We are the controller of your account data
The email address you register with, your billing records, the domains you connect, your support messages, and the logs and analytics generated when you use our website and dashboard. We decide what we collect and why, and this policy is our notice to you about it.
We are a processor of your mailbox content
The messages in your mailboxes, the files in your Drive, and your calendar and contacts entries. You decide what goes in and what comes out; we store, route, filter, and deliver it on your instruction. We do not decide what your mail says or who receives it.
Note
This distinction matters in practice: if you ask us to delete your account, we act on it. If a person who emailed one of your mailboxes asks us to delete their message from it, we will point them to you, because the message is in your mailbox and the decision is yours.
Information We Collect
Everything we hold, and where it comes from.
We collect only what the service needs to run. Most of it comes directly from you; some is generated automatically when you use the platform.
Account information
Your email address and a password stored only as a salted cryptographic hash. We never hold your account password in a readable form and cannot recover it for you — we can only reset it. If you sign in with Google, we receive your email address and basic profile details from Google instead of a password.
Domain and DNS configuration
The domain names you connect, the MX, SPF, DKIM, and DMARC records we generate for them, our verification results, and the public DNS lookups we perform to check propagation. Domain registration data is public by nature; we only read what is already published.
Mailbox configuration
For each mailbox you create: the address, the display name, the plan tier, its storage quota and sending limits, and its status. Mailbox passwords are stored in the form our mail servers require in order to authenticate IMAP, SMTP, and POP3 connections.
Billing information
Your plan, billing period, invoice history, amounts charged, and the payment-method token, card brand, and last four digits returned to us by Stripe. Full card numbers, expiry dates, and security codes go directly to Stripe and never reach our servers.
Support and contact form data
When you write to us through the contact form or by email, we receive your name, email address, subject, and message, along with anything you choose to include in it. We keep the correspondence so we can follow up and so we have a record of what was asked and answered.
Technical and log data
IP address, browser and device type, operating system, referring page, and timestamps for requests to our website and dashboard; authentication events such as sign-in, sign-out, password change, and failed sign-in attempts; and the connection logs our mail servers write for IMAP, SMTP, and POP3 sessions. These records are how we detect abuse, investigate incidents, and diagnose delivery problems.
Analytics data
If you allow analytics cookies, we collect aggregate usage measurements about the pages you visit on our public website. See Cookies, Tag Manager, and Analytics for exactly what runs and when.
Note
We do not buy personal data from data brokers, we do not build advertising profiles, and we do not enrich your account with information bought from third parties.
Your Content
Mail, Drive files, calendar, and contacts.
Running a mail server means handling mail. There is no way to accept, filter, store, and deliver a message without processing it — envelopes, headers, and bodies alike. We want to be plain about that rather than promise something the technology cannot deliver.
What we do not do is read your mail for our own purposes. We do not scan mailbox content to build advertising or marketing profiles, we do not sell it, we do not train machine-learning models on it, and we do not use it to decide what to show you.
Message content and attachments
Stored on our servers so your mailbox works, and kept until you delete it or the mailbox is closed. Deleting a message removes it from your mailbox immediately; it may persist in encrypted backups for a limited period afterwards.
Spam and threat filtering
Incoming and outgoing mail passes through automated filters that examine sender reputation, authentication results, headers, and content patterns. This is machine processing carried out to protect deliverability and block malware and phishing. Filter verdicts, and quarantined messages, are retained for a limited period so a false positive can be recovered.
Delivery logs
For every message we accept or deliver we record the sender, recipient, timestamp, size, connecting IP address, authentication result, and delivery outcome. Subject lines and message bodies are not written to these logs. Delivery logs are how we answer “why did this message bounce?”, and they are also required evidence in abuse investigations.
Drive files
Files and folders you upload to Drive are stored so you can access and share them. When you create a share link, that file becomes reachable by anyone holding the link — that is what the link is for, and it is your decision to create one. We record when share links are created, and we log access to them for abuse and bandwidth purposes.
Calendar and contacts
Events, invitations, and contact records you create or sync are stored so they are available across your devices. Sending a calendar invitation transmits the event details to the people you invite and to their calendar providers.
Staff access
Our staff do not read your mailbox content, Drive files, calendar, or contacts in the ordinary course of running the service. Access happens only when you ask us to look at something to resolve a support request, when it is strictly necessary to investigate a security incident or an abuse report, or where the law compels us. Such access is limited to the staff who need it and is recorded.
How We Use Information
Every purpose we process data for.
We use the information described above for the following purposes, and no others:
- Providing the service — creating and authenticating your account, provisioning domains and mailboxes, and routing, filtering, storing, and delivering your mail.
- Billing — charging your subscription, issuing invoices, handling failed payments, and keeping the financial records the law requires us to keep.
- Support — answering your questions, investigating problems you report, and following up on them.
- Security and abuse prevention — detecting and blocking spam, phishing, malware, credential stuffing, and unauthorised access, and investigating reports of misuse.
- Deliverability — monitoring bounce rates, complaint rates, and sender reputation so mail from your domain keeps reaching inboxes.
- Service communications — sending you account, billing, security, and outage notices. These are not marketing and you cannot opt out of them while you hold an account.
- Improving the product — understanding, in aggregate, which parts of the site and dashboard are used, so we know what to fix and build next.
- Legal compliance — meeting our tax, accounting, and regulatory obligations and responding to lawful requests.
Legal Bases for Processing
Why each use is lawful under the GDPR and UK GDPR.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we must have a lawful basis for each purpose. Ours are:
- Performance of a contract (Art. 6(1)(b)) — running your account, provisioning and operating your mailboxes and domains, delivering your mail, taking payment, and providing support. Without this data there is no service to provide.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse and fraud, protecting deliverability, maintaining logs, and understanding aggregate product usage. Our interest is in operating a safe and reliable mail service; we have weighed it against your rights and limited what we collect accordingly.
- Consent (Art. 6(1)(a)) — analytics and marketing cookies, and any optional marketing email. You give consent through the cookie banner or by opting in, and you can withdraw it at any time without affecting processing carried out before you did.
- Legal obligation (Art. 6(1)(c)) — retaining financial and tax records, and responding to valid legal process.
Note
Where we process your mailbox content, calendar, contacts, and Drive files, we do so on your documented instructions as your processor — the lawful basis for that content is yours to hold, as the controller of it.
Google Tag Manager
How third-party tags are loaded, and how consent gates them.
We use Google Tag Manager (“GTM”), a tag management service provided by Google Ireland Limited, to load and control the measurement scripts that run on our public website. GTM is a container rather than a tracker: it sets no analytics or advertising cookies of its own and does not, by itself, collect personal data about you. What it does is decide which other tags load, and when.
The tags we load through the container are analytics tags used to measure use of our public website. We do not load GTM, or any tag inside it, on the customer dashboard or the webmail application.
Loading GTM involves a request to Google's servers, which necessarily discloses your IP address and browser details to Google as part of any web request. Google acts as a processor for the measurement data collected through our tags, under Google's data processing terms, and as an independent controller for its own operational purposes. Google's own practices are described in its Privacy Policy.
Consent comes first
Analytics and marketing tags stay switched off until you allow them. Your choice in our cookie banner is passed to Google using Google Consent Mode, which sets the analytics_storage, ad_storage, ad_user_data, and ad_personalization signals. Where a signal is denied, the corresponding tag either does not run or runs without storing or reading cookies.
What the analytics tag measures
Pages viewed and the order they were viewed in, approximate location derived from a truncated IP address, referring source, device and browser type, and rough session duration. It does not receive your name, your email address, your domain configuration, your billing details, or anything from inside your mailboxes.
Changing your mind
Use the cookie preferences button in the corner of any page on our public website to change or withdraw your choices at any time. Withdrawing consent stops further collection; it does not erase measurements already recorded, though you can ask us to delete those too.
Blocking it entirely
You can also block these tags at the browser level by rejecting third-party cookies, using a content blocker, or installing Google's Analytics opt-out add-on. Doing so has no effect on your ability to use UCN Mail.
Note
Analytics measures our public marketing website. It is not present in the dashboard or the webmail app, and no measurement tag ever sees the contents of a mailbox.
Signing In With Google
What Google tells us, and what it does not.
You can create an account and sign in using Google. If you do, Google confirms your identity to us and passes us your email address and basic profile information. We use it to create or match your UCN Mail account and for nothing else.
We never receive your Google password, and signing in this way does not give us access to your Gmail, your Google Drive, or any other Google service. You can disconnect UCN Mail from your Google account at any time in your Google account's security settings; if you do, set a UCN Mail password first so you do not lock yourself out.
Payments
Card data goes to Stripe, not to us.
Payments are processed by Stripe, Inc. Your card details are entered into fields hosted by Stripe and transmitted directly to Stripe's PCI DSS Level 1 certified systems. We never see or store your full card number, expiry date, or security code.
What we receive back and store is a payment-method token, the card brand, the last four digits, and the outcome of each charge — enough to show you which card is on file, to charge it for your subscription, and to reconcile your invoices. Stripe processes your payment data as an independent controller for fraud prevention and its own legal obligations, under its Privacy Policy.
International Transfers
Where your data is stored and processed.
UCNHUB LLC is established in the United States, and our infrastructure and service providers may process data in the United States and other countries. If you are in the EEA, the United Kingdom, or Switzerland, this means your personal data may be transferred outside the region in which you live, to countries whose data protection laws differ from your own.
Where such a transfer takes place, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where applicable, together with the technical and organisational measures described in Security. You may request a copy of the relevant transfer safeguards by writing to us.
How Long We Keep Things
Retention periods, category by category.
We keep personal data only for as long as we need it for the purpose it was collected for, or for as long as the law requires.
- Mailbox content, Drive files, calendar, and contacts — for as long as your account is open. You control this: what you delete is deleted.
- Account records — for as long as your account is open, then deleted or anonymised within 90 days of closure, except where we must keep something longer.
- Billing and tax records — retained for the period required by applicable tax and accounting law, typically seven years, regardless of account closure.
- Delivery and connection logs — a rolling window sufficient for troubleshooting and abuse investigation, after which they are deleted or aggregated.
- Security and authentication logs — retained long enough to investigate incidents and detect patterns of abuse.
- Support correspondence — retained while it remains useful for context and for the period in which a related dispute could arise.
- Backups — encrypted backups are held on a rolling schedule and expire on their own cycle, so deleted data may persist in a backup for a limited period after it disappears from the live system.
- Analytics data — retained for the period configured in the analytics tool, and only ever in aggregate form.
Important
Closing your account is permanent. Once your mailboxes are deleted, the mail, files, calendar entries, and contacts in them cannot be recovered by us or by you. Export anything you want to keep before you close the account.
Security
The measures protecting your account and your mail.
We apply technical and organisational measures appropriate to the risk of running a mail platform:
- TLS encryption for connections to our website, dashboard, and API, and for IMAP, SMTP, and POP3 sessions with your mail clients.
- Opportunistic TLS for mail in transit between servers, so messages are encrypted wherever the receiving server supports it.
- Encryption of stored data at rest, including backups.
- Account passwords stored only as salted cryptographic hashes, never in a readable form.
- Least-privilege internal access controls, so staff can reach only the systems their role requires.
- Network isolation, firewalling, and monitoring of our mail and application infrastructure.
- Rate limiting and abuse detection on authentication endpoints and outbound sending.
Note
Security is shared work. Use a strong, unique password on your UCN Mail account, keep the devices you read mail on up to date, and tell us straight away at [email protected] if you think an account has been compromised.
Important
No system is perfectly secure. Mail sent between servers can only be encrypted if the receiving server supports it, and a message that reaches its destination is subject to whatever protections the recipient's provider applies. If you need guaranteed end-to-end confidentiality, encrypt the message content itself before you send it.
If Something Goes Wrong
How we handle a data breach.
If we become aware of a personal data breach that is likely to affect you, we will investigate it, contain it, and notify you without undue delay. Where the law requires it, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
Our notice will tell you what happened, what data was involved, what we have done about it, and what we recommend you do — in plain terms, not in a way designed to minimise it.
Your Rights
What you can ask us to do, and how.
Depending on where you live, you have some or all of the following rights over your personal data. We honour these requests for everyone, not only for people whose local law grants them.
- Access — ask what personal data we hold about you and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your account, domains, and mailbox data, subject to records we are legally required to keep.
- Portability — receive your data in a structured, machine-readable format. Your mail is portable by design: connect any IMAP client and download everything.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection — object to processing we carry out on the basis of legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent — change your cookie preferences or unsubscribe from optional email at any time, without affecting processing that already took place.
- Freedom from discrimination — exercising any of these rights will never cost you service, price, or quality.
How to make a request
Write to [email protected] or use the contact form. We respond within 30 days, and will tell you if we need longer for a complex request. To protect your data we will verify that the request comes from the account holder before we act on it; we may ask you to confirm from the registered email address.
Requests about mail in someone else's mailbox
If you emailed a UCN Mail customer and want that message deleted, the decision belongs to the customer who holds the mailbox, not to us. Contact them directly. We will help you identify the right route where we reasonably can.
Complaints
We would rather hear from you first, but you have the right to complain to your data protection supervisory authority — in the EEA, the authority in your country of residence or work; in the UK, the Information Commissioner's Office.
United States Privacy Rights
California and other state privacy laws.
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect and why, to access and delete it, to correct it, to limit the use of sensitive personal information, and to be free from discrimination for exercising those rights. Residents of other US states with comparable laws have equivalent rights, and we extend the same treatment to all of them.
The categories of personal information we collect, and the purposes we collect them for, are set out in Information We Collect and How We Use Information. The categories we disclose to service providers are set out in Sharing and Sub-processors.
Exercise these rights the same way as any other: write to [email protected]. You may use an authorised agent, in which case we will ask for proof of their authority.
Note
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.
For Business Customers
Data processing terms and sub-processors.
If you use UCN Mail to handle personal data belonging to your own customers, employees, or users, you are the controller of that data and we are your processor. In that case you may need a data processing agreement with us covering the subject matter of the processing, our obligations of confidentiality and security, our use of sub-processors, our assistance with your obligations, and deletion or return of data at the end of the contract.
Ask for one at [email protected] and we will put one in place.
Important
Some categories of data carry obligations we are not set up to meet. Do not use UCN Mail to store or transmit protected health information subject to HIPAA, cardholder data subject to PCI DSS, classified or export-controlled material, or anything else requiring a compliance regime we have not agreed to in writing.
Children
UCN Mail is not for children.
UCN Mail is a paid service intended for adults and for organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 16, or under 13 in the United States.
If you believe a child has given us personal data, write to [email protected] and we will delete the account and its data.
Automated Decision-Making
Where machines decide, and where they do not.
We do not make decisions about you that produce legal or similarly significant effects using automated processing alone, and we do not carry out profiling of that kind.
Our spam and threat filters are automated, and they can classify a message as spam or refuse to accept it. Automated limits can also throttle sending from a mailbox that exceeds its plan's rate. These affect individual messages rather than your legal standing, and a person will review any filtering or limiting decision if you ask us to.
Changes to This Policy
How we tell you when this page changes.
We may update this Privacy Policy as the service changes or the law does. When we do, we revise the “Last updated” date at the top of this page.
If a change materially affects how we handle your personal data — a new purpose, a new category of recipient, or a materially different retention period — we will tell you by email to your account address before it takes effect, so that you can review it and, if you disagree, close your account.
Contact Us
Privacy questions, requests, and complaints.
Write to us about anything in this policy, to exercise your rights, or to raise a concern. We read every message and we will tell you what we can and cannot do.
- Entity
- UCNHUB LLC
- Address
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - [email protected]
- Support
- ucnmail.com/contact-us
Questions about this policy? We're happy to clarify anything.
Contact us