Information Security Policy

Effective June 24, 2026

MailPanda (“MailPanda”, “we”, “us”) is an AI email marketer for e-commerce brands. To do that job we are trusted with your account, your brand content, and data about your store’s customers. This policy describes the safeguards — technical, organizational, and procedural — we use to protect that information. It covers mailpanda.ai, app.mailpanda.ai, and the MailPanda integrations (including our Klaviyo and Shopify apps), and it is the security companion to our Privacy Policy. Questions or reports any time: support@mailpanda.ai.

Our security principles

Governance & ownership

Security is owned by MailPanda’s engineering leadership, not delegated to a single individual or treated as an afterthought. Access to production systems is restricted to authorized personnel, granted on a need-to-know basis, and reviewed periodically. Security-relevant changes go through code review before they reach production.

Encryption

All traffic between you, your browser, and MailPanda is encrypted in transit using TLS (HTTPS). Data stored in our managed database and object storage (Supabase) is encrypted at rest by the provider. Integration access tokens and other secrets are stored encrypted and are never exposed in client-side code, logs, or URLs.

Authentication & access control

Tenant isolation

MailPanda is multi-tenant. Each workspace’s data is isolated at the database layer using row-level security, so queries are constrained to the authenticated workspace and one customer cannot reach another customer’s records. This isolation is enforced by the database itself, not only by application code.

Integration & token security

When you connect a platform such as Klaviyo or Shopify, we use scoped OAuth wherever the platform supports it — you grant only the permissions a feature needs, rather than handing over master credentials. Access tokens are stored encrypted, scoped to your workspace, and are revocable: disconnecting an integration deletes its tokens. Inbound webhooks from connected platforms (and our own email transport) are signature- or HMAC-verified before we act on them.

Infrastructure & hosting

MailPanda runs on reputable, security-conscious cloud providers in the United States. Our application and APIs are hosted on Vercel; our primary database and storage are managed by Supabase; payments are processed by Stripe. We rely on these providers’ physical, network, and platform security controls and do not operate our own data centers. We keep dependencies and runtimes current to take up security patches.

Application security

Payment security

Card payments are handled entirely by Stripe, a PCI-DSS Level 1 certified payment processor. MailPanda never receives or stores your full card number — we retain only your plan, subscription status, and invoice references needed to operate billing.

AI processing safeguards

MailPanda uses large language and image models (via OpenRouter) solely to generate your marketing content. We do not train our own models on your data, and we do not permit model subprocessors to use your content for advertising. Prompts and brand content are sent only to produce your results.

Subprocessors & vendor management

We share data only with the service providers that run MailPanda — such as Vercel (hosting), Supabase (database & storage), Clerk (authentication), Stripe (payments), PostHog (product analytics), OpenRouter and its model providers (AI generation), and the platforms you explicitly connect (such as Klaviyo and Shopify). Each is bound to process data solely for us. The current list, and how to reach us about it, lives in our Privacy Policy.

Monitoring & logging

We use our hosting and platform providers’ logging and monitoring to detect errors, abuse, and anomalous activity, and to aid investigation if something goes wrong. We aim to log what we need to operate the service securely while minimizing the collection of sensitive data in logs.

Resilience & backups

Our managed database is backed up by the provider to support recovery, and our application is deployed across managed, redundant infrastructure. We rely on our providers’ durability and availability guarantees and design the product to fail safe.

Incident response & breach notification

If we become aware of a security incident affecting your data, we will investigate promptly, take steps to contain and remediate it, and — where a breach is likely to affect you — notify affected customers and any required authorities without undue delay and consistent with applicable law. We will share what we know, what we’re doing, and what (if anything) you should do.

Data retention & deletion

We keep your data while your account is active. Disconnecting an integration deletes its access tokens; “Start over” in Settings deletes your brand workspace. To delete your account and associated data entirely, email support@mailpanda.ai; we’ll complete it within 30 days, except records we must keep for legal or accounting reasons. Full details are in our Privacy Policy.

Your responsibilities

Security is shared. Please use a strong, unique password (and enable multi-factor authentication), keep your sign-in credentials and connected-platform access secure, invite only trusted teammates to your workspace, and tell us right away if you suspect unauthorized access to your account.

Reporting a vulnerability

We welcome reports from security researchers and customers. If you believe you’ve found a vulnerability or a security issue, email support@mailpanda.ai with the subject “Security” and enough detail to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn’t yours. We will not pursue legal action against good-faith research conducted under these guidelines.

Changes to this policy

As our practices and infrastructure evolve we may update this policy. We’ll post the new version here and update the effective date — and for significant changes, we’ll notify you by email or in the product.

Contact

MailPanda · support@mailpanda.ai