This Privacy Policy explains how HarisLab Connect ("we", "us", or "our") collects, processes, and protects your data across our platform, dashboard, and email delivery services (collectively, the "Service").
By accessing or using HarisLab Connect, you agree to the collection and handling of your data in accordance with this Privacy Policy.
1. Information We Collect
A. Account Registration Information
When you create an account, we collect:
- Full Name (Required): To identify your account and address you in service notifications.
- Work Email (Required): To manage your account login, deliver transactional alerts, and send critical system updates.
- Password (Required - Minimum 6 characters): Used to secure your account access.
- Company / Project Name (Optional): Provided at your discretion to customize and organize your workspace and campaign headers.
B. Billing & Transaction Metadata
All payment transactions and subscriptions are processed by our third-party Merchant of Record (Lemon Squeezy). We do not store, process, or have access to your raw payment card details or banking numbers. We receive only non-sensitive transaction tokens, subscription tiers, renewal dates, and invoice statuses.
C. Subscriber & Form Data (You as the Controller)
- Subscriber Records: Email addresses, custom properties, and tags collected via your embeddable HarisLab Connect forms or imported directly by you.
- Form Submission Metadata: Timestamps and technical submission headers evaluated strictly to block automated bot submissions and protect your list quality.
D. Infrastructure & Campaign Data
- Custom SMTP Credentials (BYOK): Hostnames, ports, usernames, and passwords/API keys you provide to route emails through third-party providers (such as AWS SES, Mailgun, or Postmark).
- Email Content: Subject lines, HTML bodies, and plain-text drafts submitted for delivery or evaluation.
2. Cryptographic Security & Storage of Credentials
We apply strict cryptographic separation and protection mechanisms for all stored credentials:
- Account Passwords: User passwords are never stored in plaintext. They are salted and irreversibly hashed using Bcrypt prior to database insertion.
- Third-Party Credentials & API Keys: Custom SMTP passwords, API keys, and sensitive infrastructure secrets are encrypted at rest using AES-256-GCM (Advanced Encryption Standard in Galois/Counter Mode with 256-bit keys). This provides authenticated encryption to prevent tampering and unauthorized decryption.
3. How We Use Your Data
We process your information strictly for the following functional purposes:
- Authentication & Workspace Routing: Verifying account sessions and binding your campaigns to your authenticated workspace.
- Campaign Dispatching: Delivering email campaigns either through our managed sending infrastructure (
@hlcmail.online) or via your authenticated custom SMTP credentials. - AI Pre-Send Deliverability Screening: Analyzing draft copy and subject lines prior to dispatch to detect aggressive spam triggers, phishing patterns, and deliverability risks.
- Abuse & Disposable Domain Filtering: Automatically blocking burner, temporary, and disposable email addresses on your subscriber forms to preserve domain reputation and prevent server abuse.
- Delivery Rate Management: Enforcing queue pacing and throttled worker limits (such as smart drip delivery) to protect server performance and maintain primary inbox placement.
4. Subscriber List Protection & Non-Disclosure
- Your Contacts Remain Yours: We do not sell, rent, monetize, or lease your subscriber lists or customer contacts to data brokers, advertisers, or third parties.
- No Direct Marketing to Your Audience: We will never contact, solicit, or market to any email address contained within your subscriber lists or collected through your forms.
5. Third-Party Service Providers
We share data with third-party providers solely to facilitate platform infrastructure and payments:
- Merchant of Record: Lemon Squeezy (handles checkout billing, taxes, and subscription management).
- Hosting & Compute Infrastructure: Virtual Private Server (VPS) and cloud hosting providers powering our application servers, database instances, and message queues.
- AI Model APIs: Campaign copy sent through the pre-send spam auditor is evaluated by automated model endpoints strictly for deliverability diagnostics. Content processed through the scanner is not used to train public machine learning models.
6. Data Retention & Deletion
- Active Accounts: Your account profile, forms, and subscriber lists remain stored as long as your account remains open.
- Account Deletion: When you delete your account, your profile data, forms, and subscriber records are purged from active production databases within 30 days.
- Operational Logs: Outbound mail delivery logs, bounce receipts, and queue audit records are automatically rotated and deleted after 30 to 90 days for system diagnostic purposes.
7. Your Rights & Data Controls
You maintain full control over your platform assets:
- You may export your subscriber data and contact lists from the dashboard at any time.
- You may update your profile details, change your password, or modify your optional company/project settings directly within your account settings.
- You may remove or rotate your stored AES-256-GCM encrypted SMTP credentials at any time, which permanently purges the stored keys from our records.
8. Updates to This Policy
We may update this Privacy Policy from time to time to reflect operational or architectural adjustments. Material changes will be accompanied by an update notice displayed in your account dashboard.