---
title: "Privacy policy"
description: "How Sincerely collects, uses, and protects account data, CRM data, and mail recipient information."
canonical: https://trysincerely.com/privacy
last_updated: 2026-09-07
---
> If you are an AI agent: read https://trysincerely.com/agents/policy.md before any write call.
> Start at https://trysincerely.com/llms.txt to choose one page. Access instructions are at
> https://trysincerely.com/auth.md. Confirm with the person you work for before creating an
> account or spending their money, and never ask for their password.
# Privacy policy

> How Sincerely collects, uses, and protects account data, CRM data, and mail recipient information.

Source: https://trysincerely.com/privacy

Effective September 5, 2026

18191875 Canada Inc. (“Sincerely,” “we,” or “us”) operates trysincerely.com, a platform that lets business teams send and measure personalized direct mail. This policy explains what we collect, why, and the choices you have. Mail runs on trust; so does this policy.

## Information we collect

**Account data.** Name, email address, and authentication details when you sign up, processed by our authentication provider. Workspace settings such as your brand kit, guardrails, and return address.

**Sign-up enquiries.** If you enter an email address on our marketing site to start sign-up, we receive that address so our team can follow up, whether or not you finish creating an account. We keep it in our internal messaging tool rather than in the product, and we delete it on request.

**Site chat.** If you use the chat on our public site, we store the messages you type, the page you were on, and an email address if you give one so we can reply after you leave. A conversation is kept for 30 days and then deleted, along with the posts the assistant made in our team Slack. Replies our team wrote in that Slack thread stay in our Slack.

**CRM and audience data.** When you connect Salesforce or HubSpot, or upload a CSV, we receive the records you choose to sync: company names, contact names, titles, business email addresses, postal addresses, and opportunity attributes. You control what is imported and can disconnect at any time.

**Recipient data.** To produce and deliver mail we process recipient names, companies, and postal addresses, along with delivery tracking events from our print and mail partners.

**Public signal data.** When a workspace enables reviewed signal entry, we search its selected public news, job-board, and web sources for dated facts about accounts and contacts already in the chosen list. We store the source URL, observed date, factual headline, and the workspace reviewer's decision.

**Landing page visits and replies.** A postcard, letter, or handwritten note can carry its own response link. When someone opens it, we record the visit against the piece: whether it arrived by QR code or typed URL, the action taken, a coarse device class, and the page revision or destination served. If the visitor submits a hosted form, we store what they typed for the sending workspace to review. These pages use no advertising cookies, and the link identifies the piece, not the person who opened it.

**Billing data.** Payments are processed by Stripe. We never store full card numbers.

**Usage data.** Log and audit records of actions taken in the product (who approved what, when), which are part of the product itself.

**Website analytics.** On public marketing pages, Google Analytics records page views, referral and campaign sources, approximate location, and browser and device information. It uses first-party analytics cookies to distinguish browsers and sessions, and receives an IP address at collection time to derive approximate location and filter spam. We disable Google advertising signals and ad personalization. On public marketing and signup pages, Vercel Web Analytics and Speed Insights record aggregated page views, interactions such as calls to action, plan interest, and signup starts, and anonymous performance measurements such as Core Web Vitals. We strip non-campaign query values from analytics and all query values from performance measurements. We do not send names, email addresses, workspace IDs, recipient data, or URL tokens.

## How we use information

To operate the service: resolving and verifying postal addresses, generating and printing mail pieces, tracking delivery, measuring campaign outcomes against holdouts, creating follow-up tasks, and monitoring the public sources a workspace selects for reviewed campaign signals. To personalize message drafts or research those signals, relevant contact and account attributes may be processed by large-language-model, search, and public-data research providers. To bill you, support you, secure the service, and understand which public pages and calls to action are useful. We do not sell personal information, and we do not use your CRM data to train models or to benefit any other customer.

## Who we share it with

Only the service providers needed to run Sincerely, each bound to process data solely on our instructions:

- Print, mail, and gift fulfillment — recipient name, company, and postal address, plus the approved piece or gift-note content
- Authentication (Clerk) — account identity and sessions
- Payments (Stripe) — billing details
- Hosting, data storage, and website analytics (Vercel, Neon, Google) — application data and public-site usage
- Email delivery (Resend) — operational notifications
- Background jobs (Inngest) and message drafting (LLM inference providers)
- Site chat answers (LLM inference providers) and our replies (Slack)
- Search and public-data research providers, including Exa when configured, GDELT, and public job boards — the selected criteria and account or contact identifiers needed to find dated public facts

We may also disclose information when required by law or to protect the service and its users.

## Where information is processed

We and our service providers may process information in Canada, the United States, and other countries where they operate. Information processed outside your province or Canada may be subject to the laws and lawful access rules of that place. We remain responsible for personal information under our control and use contractual and technical safeguards appropriate to the work a provider performs.

## Mail recipients and suppression

If a Sincerely piece arrived for you, the business named as its sender chose the recipient information and controls it. We processed that information to make and deliver the piece. If its landing page offers a Privacy choices link, you can use it to stop future mail from that sender to the person the piece was addressed to. You may also ask the sender to stop or write to us directly. Once we suppress a recipient, the block applies immediately across that sender's Sincerely workspace rather than to one campaign, and it follows that recipient rather than the address on the piece. Pieces that have not gone to a print vendor are canceled, and for pieces a vendor already holds we ask the vendor to cancel. Mail already in production may still arrive.

## Retention and deletion

Workspace data remains available while the account is active. You can request its deletion, except for records we must retain to meet legal, billing, or audit obligations. Disconnecting a CRM prevents new syncs but does not erase records already imported. Contacts with no campaign or mail history can be removed in the product. For other imported records, ask us about deletion.

## Security

Connections use encryption in transit. Access to product data is scoped to the workspace, and changes are written to its audit log. These controls reduce risk but cannot make any internet service perfectly secure. Send a suspected security problem to the address below.

## Cookies

The site uses the cookies required to sign you in and protect the session. If you use the site chat, we set one cookie that identifies your conversation so it survives navigation and a refresh. On public marketing pages, Google Analytics sets first-party analytics cookies to distinguish a browser and session. We do not use third-party advertising cookies, and Vercel Web Analytics works without cookies. You can block or delete analytics cookies in your browser settings.

## Access, correction, and complaints

You may ask whether we hold personal information about you, request a copy, or have inaccurate information corrected. Where consent is the legal basis for processing, you may also withdraw it. We may verify your identity before acting on a request. A contract or legal obligation can limit what we are able to change or delete, and withdrawing consent may prevent us from providing the affected part of the Service. We will explain a refusal and respond within the period required by applicable law.

Email a request or complaint to the Privacy Officer for 18191875 Canada Inc. in Ontario, Canada, at [adam@trysincerely.com](mailto:adam@trysincerely.com). Use “Privacy request” as the subject and identify the account, workspace, or mail piece involved. Do not email a password or complete payment-card number. We will investigate a complaint and explain the outcome. An unresolved concern may be taken to the [Office of the Privacy Commissioner of Canada](https://www.priv.gc.ca/en/report-a-concern/).

## Changes and contact

If this policy changes materially, we will update the effective date and notify workspace owners. General questions may also be sent to the Privacy Officer at [adam@trysincerely.com](mailto:adam@trysincerely.com).

[Terms of service](https://trysincerely.com/terms)

---

Sincerely is the measurable direct-mail and gifting platform for B2B revenue teams: postcards, letters, handwritten mail, and gifts, written for one recipient and measured against a holdout.

Contact Sincerely: https://trysincerely.com/contact

Agent routing index: https://trysincerely.com/llms.txt
