Privacy Notice
Last updated 20 August 2026
Who we are
Postrider is operated by Chris White, trading as Postrider, as a sole trader based in the United Kingdom. For anything to do with this notice or your personal data, contact hello@postrider.uk.
Two kinds of personal data we handle
Postrider is a service that organisations (“tenants”) use to email their own members. That means we handle personal data in two different roles, and your rights differ depending on which one applies to you:
- Data controller — for the people who directly deal with us: tenant staff accounts, people who fill in the signup form on this site, and anyone who emails us for support. We decide why and how this data is processed.
- Data processor — for the members/subscribers on a tenant's mailing lists. If you receive email from an organisation using Postrider, that organisation is the controller of your data; we only process it on their instructions, under contract with them. If you want your data removed from a list, the fastest route is the unsubscribe link in the email itself, or asking that organisation directly — we can't act on a subscriber's request without going through the tenant that uploaded it.
What we collect, and why
As controller
- Tenant staff accounts — name, email address, a hashed password, and (if enabled) a two-factor authentication secret. Used to run your organisation's Postrider account. Legal basis: performance of our contract with your organisation.
- Signup enquiries — organisation name, your name and email, sending domain, and any notes you provide via the “Create your tenant” form. Used to set up and follow up on your enquiry. Legal basis: taking steps prior to entering into a contract, at your request.
- Abuse-prevention logs — the IP address, email address, and outcome (allowed or blocked) of every signup form submission, kept to detect and rate-limit automated abuse of the public form. Legal basis: our legitimate interest in keeping the service usable and free of spam signups.
- Support correspondence — anything you send to support@postrider.uk or hello@postrider.uk. Legal basis: legitimate interest in responding to you, or contract performance if you're an existing customer.
As processor (on a tenant's behalf)
- Subscriber email addresses and any other fields a tenant chooses to sync (e.g. a name field from their own membership system).
- List membership, subscribe/unsubscribe state, and digest-frequency preference, per list.
- Email delivery events — sent, delivered, bounced, complained, opened, clicked — reported back to us by Amazon SES so a tenant can see how their campaigns performed.
- Content of messages posted to a reflector-style mailing list (a member emailing the list's own address), which is redistributed to other subscribers on that list.
Automated content screening
Before a campaign is sent, its subject line and content are checked by an AI model (via the Anthropic API) for spam, phishing, or scam intent, as part of keeping the shared sending infrastructure usable for every tenant. This is an automated check on message content, not a decision made about an individual subscriber, and a flagged campaign is held for a human (Postrider staff) to review before it can send.
Who we share data with
We use a small number of specialist providers to run the service, each acting as a processor on our instructions. We don't sell personal data to anyone.
- Amazon Web Services (SES, S3) — sends and receives email, and stores inbound mail. Processed in AWS's London (eu-west-2) region.
- Stripe — processes subscription payments for paid plans. We never see or store full card details.
- Anthropic — provides the AI model used for the automated content check described above. Based in the United States.
- Neon — hosts our Postgres database.
- Vercel — hosts the application itself.
- Cloudflare — provides the Turnstile bot-check on our public signup form, which sees your IP address at submission time.
Some of these providers are based outside the UK/EEA (notably Anthropic and, depending on region routing, Stripe, Neon, and Vercel). Where that's the case, we rely on their own published data-transfer safeguards (typically UK/EU Standard Contractual Clauses) — we haven't yet had these individually reviewed by a solicitor, which is part of why this notice is still marked as a draft.
How long we keep data
Tenant staff accounts and subscriber data are kept for as long as the tenant's account is active, plus a reasonable period afterwards in case of dispute or legal requirement. Signup enquiries and abuse-prevention logs are currently kept indefinitely rather than on an automatic deletion schedule — we intend to set a formal retention period for these once this notice moves past draft status, and can delete specific records on request in the meantime.
Your rights
Under UK data protection law you have the right to ask us what data we hold about you, to correct it, to have it deleted, to object to or restrict certain processing, and to receive a copy in a portable format. To exercise any of these, email hello@postrider.uk. If you're not satisfied with our response, you can complain to the UK's Information Commissioner's Office at ico.org.uk.
Security
Passwords are stored hashed, never in plain text. Access to tenant data is scoped per tenant. Email content and subscriber data are stored in a managed, encrypted-at-rest Postgres database. We haven't yet had a formal third-party security audit — flagged here rather than glossed over.