Ritto Mail

Privacy Policy

Questions or requests: help@ritto.software.

1. Who we are

Ritto LLC, 412 W 7th St STE 1072, Clovis, NM 88101, United States. Product website: ritto.email. Contact: help@ritto.software (privacy and support) and admin@ritto.email (product).

2. Our role: controller and processor

  • Controller. For data about our customers and website visitors (account, billing, support, security and website usage), Ritto is the controller and decides how the data is used, as described in this Policy.
  • Processor. For the contacts, recipient addresses and email content that customers send or store through the Service, Ritto acts as a processor (“operador” under Brazil’s LGPD) on behalf of the customer and following the customer’s instructions. The customer is the controller and is responsible for having a legal basis (such as consent) to send each message and for informing recipients. A Data Processing Agreement is available on request.

3. Data we collect as controller

  • Account: name, email, company, team members and roles, authentication data (password hashes, passkey public keys), preferences.
  • Billing: plan, billing country, currency, billing address and tax ID where applicable, invoices and payment status. Payments are processed by Stripe; we do not store your card number.
  • Usage and security logs: API requests and responses, SMTP and MCP activity, IP addresses, user agent, timestamps, errors and audit events in the dashboard.
  • Support: messages you send us and related metadata.
  • Website: IP address, approximate country (used to show prices in the right currency), language choice and the cookies described below.

4. Data we process for our customers

When a customer uses the Service, we process on their behalf:

  • Contacts and audiences (email addresses, names and custom properties provided by the customer).
  • Email content: subject, body, attachments, headers and metadata.
  • Delivery events: sent, delivered, delayed, bounced, complained and unsubscribed; and, when tracking is enabled by the customer, opens and clicks, which may involve the recipient’s IP address and user agent.
  • Suppression lists (addresses that bounced, complained or unsubscribed).

We use this data only to provide the Service to that customer, keep it secure, prevent abuse and comply with the law. We do not sell it and do not use it for our own marketing.

5. How we use data

  • Provide, operate and improve the Service: sending email, logs, webhooks, dashboard and support.
  • Authenticate users and protect accounts, the platform and recipients against fraud, spam and abuse, including monitoring bounce and complaint rates.
  • Process subscriptions, overage and payments, and keep accounting and tax records.
  • Send service communications (billing, security, incidents, changes to terms) and, where permitted, product news that you can opt out of.
  • Produce aggregated statistics that do not identify individuals.
  • Comply with legal obligations and respond to lawful requests.

7. Subprocessors and sharing

We share data only with providers that help us run the Service, under contracts that require confidentiality and appropriate security:

  • Amazon Web Services: email sending through Amazon SES in the South America (São Paulo) region, and queues and notifications for delivery events.
  • Stripe: payment processing, subscriptions and invoices.
  • Cloudflare: DNS, email routing, Turnstile anti-bot protection and storage of encrypted backups on R2.
  • Vercel: hosting of the ritto.email website.
  • Cloud infrastructure providers: servers that run the dashboard and the API.

We may also disclose data to authorities when required by law or court order, to protect rights and safety, or to a successor in a merger, acquisition or reorganization, with appropriate safeguards. We do not sell personal data.

8. International transfers

Ritto LLC is based in the United States, and our providers may process data in the United States, Brazil and other countries. When data is transferred internationally, we rely on appropriate safeguards, such as standard contractual clauses and our providers’ security commitments, as permitted by the LGPD and the GDPR.

9. Retention

  • Email and API logs: available for consultation according to the plan, from 3 to 30 days (Enterprise by contract), and then deleted.
  • Email bodies: encrypted at rest and kept for a limited period, only as needed to show them in the dashboard, support troubleshooting and prevent abuse, then deleted.
  • Backups: encrypted daily backups kept for 30 days.
  • Suppression lists: kept while the account is active, to avoid sending again to people who bounced, complained or unsubscribed.
  • Account and billing data: kept while the account is active and afterwards for the period required by tax, accounting and legal obligations, or to exercise rights in legal proceedings.

10. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, restricted and logged administrative access, hashed credentials, support for passkeys, API keys with limited permissions, and encrypted backups. No system is completely secure; if we become aware of a security incident that affects your data, we will notify you and the authorities as required by law.

11. Your rights

Depending on where you live, you have rights over your personal data. Under the LGPD you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or unlawful data, portability, information about sharing, information about the possibility of refusing consent, withdrawal of consent and review of automated decisions. Under the GDPR / UK GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests, and you may lodge a complaint with your data protection authority (in Brazil, the ANPD).

To exercise your rights, email help@ritto.software. We may need to confirm your identity. We will respond within the time limits set by applicable law.

12. If you received an email sent through Ritto Mail

Emails sent through Ritto Mail are sent by our customers, who decide who receives them and why. If you have questions about how your data is used, want to know how the sender got your address, or want your data deleted, please contact the sender directly; they are the controller of that data. To stop receiving messages, use the unsubscribe link or the unsubscribe option in your email client. If you believe an email sent through our platform is spam or abuse, write to help@ritto.software and we will investigate and, where appropriate, forward your request to the sender.

13. Cookies

The ritto.email website uses only essential and preference cookies: a cookie with your approximate country (to show prices in USD, EUR or BRL), a cookie with your language choice, and local storage to remember dismissed notices. The dashboard uses essential cookies to keep you signed in and secure, and Cloudflare Turnstile may process technical data to block bots. We do not use advertising cookies. You can clear or block cookies in your browser, but some features may stop working.

14. Children

The Service is intended for businesses and is not directed to people under 18. We do not knowingly collect data from children as controller. If you believe a minor has provided us with data, contact us and we will delete it.

15. Changes to this Policy

We may update this Policy from time to time. We will communicate material changes by reasonable means, such as email or a notice in the dashboard, and update the date at the top of this page.

16. Contact and data protection officer

Back to top ↑