1. Who we are
FishyMails is operated by Second Legacy (Chamber of Commerce number 87263467, VAT number NL003693078B03), located in the Netherlands.
For any privacy-related questions, data requests, or complaints, you can contact us at martijn@second-legacy.com.
2. What data we process
FishyMails is an API-first service for real-time email, phone number and IP-address verification. Depending on how you use the service, we process the following categories of data:
- Account data: email address, name, company name, billing details and authentication credentials created when you sign up or manage your account.
- Payment data: subscription selections, invoice history and credit balance. We do not store full credit-card numbers; payments are handled by Stripe.
- Verification data: the email addresses, phone numbers and/or IP addresses you submit for verification, together with the returned verification result and a timestamp.
- Usage and technical data: API request metadata, HTTP logs, error telemetry and analytics events used to operate, secure and improve the service.
3. Legal basis for processing
We process personal data on the basis of performance of a contract (to deliver the verification service you signed up for), legitimate interest (fraud prevention, service security, product improvement) and, where required, your consent (for example for marketing cookies or optional analytics).
4. How we use verification data
We use the data you submit exclusively to perform the verification request and to maintain the integrity of the service. This includes:
- Checking syntax, MX records, deliverability, line type and IP reputation.
- Detecting disposable email providers, VPNs, Tor exit nodes and known fraud signals.
- Calculating credit usage, preventing abuse and supporting billing disputes.
- Generating anonymised, aggregated statistics such as the public leaderboard.
We do not sell verification data, use it to build marketing profiles of your end users, or share identifiable submissions with third parties beyond the subprocessors listed below.
5. Subprocessors and integrations
To run the service, we rely on a limited set of third-party providers that process data on our behalf:
- Supabase / Lovable Cloud — cloud hosting, database, authentication and storage.
- Stripe — payment processing, subscription management and invoicing.
- Google Analytics 4 — anonymous website usage analytics (cookie-based, can be refused through your browser settings).
- Perplexity — used only to generate public insights and tips articles; no customer verification data is sent to Perplexity.
We use publicly available data sources (DNS, WHOIS, IP geolocation databases) to verify data in real time. These are queried at the moment of verification and are not shared with us as stored records.
6. Cookies and analytics
Our website uses functional cookies required for authentication and security, and analytics cookies through Google Analytics 4 to understand how visitors use the site. You can disable analytics cookies through your browser settings or by using an ad/cookie blocker.
7. Data retention
Verification logs and API request metadata are stored for 30 days, after which they are automatically deleted or anonymised. Account data and billing records are kept for as long as your account is active and for the period required by tax and accounting law.
8. Security measures
We apply standard security controls including encryption in transit (TLS), API-key based access control, row-level security in the database, least-privilege server functions and regular dependency updates. These are app-level controls; customers are also responsible for keeping their API keys secret and using the service lawfully.
9. Your rights
Under the GDPR and applicable privacy laws, you have the right to access, rectify, erase, restrict or export your personal data, and to object to certain processing. To exercise these rights, or to request a copy of the data we hold about you, email us at martijn@second-legacy.com. We will respond within one month, or longer if permitted by law.
10. Changes to this policy
We may update this Privacy Policy as the service evolves. We will publish the latest version on this page with an updated “Last updated” date. Significant changes will be communicated by email or through the dashboard.