Effective: September 1, 2026
Tangible Post LLC (“Tangible Post,” “we,” “us”) operates a platform that turns customer data into real, handwritten direct mail. This policy explains what personal information we handle, why, who we share it with, and the choices you have.
Tangible Post is offered to businesses in the United States. Our services are not directed to individuals outside the U.S.
This is the most important section in this policy, because Tangible Post handles two kinds of personal information that the law treats very differently.
When we are the business making the decisions (a “controller”), this policy governs. That covers information about our own customers — the businesses and people who sign up for Tangible Post — and visitors to our website.
When we are simply carrying out a customer’s instructions (a “processor” or “service provider”), this policy does not govern how that data is used. That covers the mailing lists our customers upload or sync to us: the names and addresses of their customers. We hold that data on their behalf, use it only to produce and mail what they ask us to produce and mail, and never for our own purposes. The business that gave us that data decides what happens to it, and their own privacy policy applies.
| Information | Our role |
|---|---|
| Your account, login, and contact details | Controller — this policy applies |
| Your business profile and return address | Controller |
| Billing and payment records | Controller |
| Website and in-app activity, cookies, device data | Controller |
| Support, sales, and marketing communications with you | Controller |
| Recipient lists you upload or sync — names, mailing addresses, and any custom fields | Processor / service provider — we act on your instructions only |
| Message content and artwork you supply for a mail piece | Processor / service provider |
| Order and campaign results tied to individual recipients | Processor / service provider |
If you are a Tangible Post customer, you are responsible for having the right to give us the recipient data you upload, and for telling those people how you use their information. Section 9 of our Terms of Service covers this in detail.
You may be reading this because a handwritten card arrived and you looked us up. Here’s the plain version:
We didn’t choose to mail you. A business you have some relationship with used our platform to send it. They provided your name and address; we printed, wrote, stamped, and mailed the piece on their behalf. We do not own that list, we do not sell it, and we do not use your address to market anything of our own to you.
To stop receiving mail, the fastest route is to contact the business whose name is on the card — they control the list and can remove you directly.
You can also contact us at terms@tangiblepost.co. If you tell us the business that mailed you (their name is on the piece), we will forward your request to them, ask them to honor it, and help them do so. Where the law gives you rights directly against us for data we hold, we will honor those too — see Section 10.
When a customer builds an audience — by uploading a CSV or syncing a segment from their own Klaviyo account — we receive and store, for each recipient: first and last name, company, street address (lines 1 and 2), city, state, and ZIP code, plus any custom fields they choose to include (for example, a last order date or a pet’s name to personalize the note).
When an order is paid, we take a frozen snapshot of exactly who that order mails. That snapshot is what production reads — never the live list — so a later edit to the audience can’t change what has already been printed. Snapshots are stored in a restricted area that customers cannot query directly.
Where a customer connects their own Klaviyo account, we may also receive conversion events (such as a purchase) so we can report back which orders their mail drove. We automatically strip anything that looks like a credential from imported custom fields.
We do not knowingly collect, and customers must not send us, Social Security numbers, payment card numbers, driver’s license or passport numbers, or information regulated by HIPAA, GLBA, FERPA, or COPPA.
As a controller, we use information about our customers to:
As a processor, we use recipient data only to produce and deliver the mail our customer ordered, to report results back to that customer, and to meet legal requirements. We do not use it to build our own marketing lists, we do not sell it, and we do not use it to train models.
We do not sell personal information. We share it only as described here.
We rely on a small number of established third-party providers to run the platform — for hosting and data storage, payment processing, transactional email, background processing, error monitoring, and our own website analytics and marketing. Each is bound by contract to use the information only to provide services to us, and not for its own purposes.
Two limits are worth stating plainly:
We maintain a current list of the providers that handle personal information on our behalf. If you would like it, write to terms@tangiblepost.co and we will send it to you.
If you are a customer and you connect your own Klaviyo account, we exchange data with your Klaviyo account at your direction — reading the lists and codes you point us at, and writing back campaign results. That is your account and your data, under your agreement with Klaviyo.
Postal carriers. To deliver mail, recipient names and addresses are physically printed on envelopes and handed to the United States Postal Service or another carrier. This is unavoidable — it is how mail works.
We use a third-party error-monitoring service to find and fix problems. When something goes wrong, it receives a report of the error itself — the error message, the page it happened on, the browser and device, and a short trail of the actions leading up to it — along with performance timings so we can find slow pages.
We do not record your screen or your session. Some monitoring tools offer a session-replay feature that captures video-like recordings of what a user sees and types. We have deliberately not enabled it, because the signed-in application displays customer mailing lists, and we would rather that content never leave our systems at all.
Before an error report is transmitted, we strip email addresses out of it and remove one-time tokens and credentials from any web addresses it contains.
We want to be unambiguous about the thing that matters most to our customers:
We do not share recipient names, mailing addresses, message content, artwork, or payment information with any third party for that third party’s own marketing purposes. We do not sell it. We do not rent it. We do not add it to any list of our own.
The only parties that receive recipient data are the service providers described above, who process it on our behalf under contract, and the postal carrier that delivers the mail.
We use cookies and similar technologies for authentication, preferences, referral attribution, and analytics. Our full disclosure, including the categories we use, the two analytics providers we rely on, and how to control them, is in our Cookie Policy.
We do not currently respond to browser “Do Not Track” signals, as there is no common standard for them. We do honor Global Privacy Control (GPC) signals as an opt-out of sale or sharing where applicable law requires it.
As a general rule, we keep information for the life of your account. When you close your account, the data associated with it is deleted.
Four things sit outside that general rule, and they are the ones worth knowing:
We never store payment card details at all. Where we retain anything after an account closes, we keep only what the law requires, or keep it in de-identified form that cannot be linked back to any individual.
You can access and correct most of your information directly in your account settings. You may also request access, correction, deletion, or a copy of your data by writing to terms@tangiblepost.co. You can export any audience as a CSV from within the product at any time.
Under the CCPA/CPRA you have the right to:
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
In the twelve months before the effective date of this policy, we collected the categories described in Section 3 — identifiers, commercial information, internet and network activity, and, for customers, limited financial information — for the business purposes described in Section 4, and disclosed them to the service providers listed in Section 5.
Under California’s “Shine the Light” law you may request information about disclosures to third parties for their direct marketing purposes; as stated, we make none.
Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others with comparable laws in force have similar rights — to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Some of these states also give you the right to appeal a denied request; if we deny yours, our response will explain how to appeal.
Email terms@tangiblepost.co with the subject line “Privacy Request.” Tell us what you want and enough information for us to find your records. We will verify your identity before acting — usually by confirming control of the email on the account. We respond within 45 days, and will tell you if we need a permitted extension. An authorized agent may submit a request on your behalf with written permission we can verify.
If we hold your information because one of our customers uploaded it — that is, you received mail rather than signed up — see Section 2. We will forward your request to the business responsible and support them in honoring it.
We maintain administrative, technical, and physical safeguards designed to protect personal information. These include encryption of data in transit, encrypted storage of any integration credentials you connect, access controls that scope data to the account that owns it, private storage for uploaded artwork, role-based permissions with optional multi-factor authentication, logging of any support access to an account, and protections against automated attacks on sign-in.
We review these controls as the product changes, and we test them as part of our regular development process.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.
Tangible Post is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. Customers must not upload recipient data about individuals they know to be under 16. If we learn we have collected such information, we will delete it promptly.
Our site and product link to third-party services. This policy does not cover them, and we are not responsible for their practices. Review their policies before providing information.
We review this policy at least annually. If we make material changes, we will update the effective date above and notify you — by email to your account address, or by a prominent notice on the site — before the changes take effect. Continued use after that means you accept the updated policy.
Privacy questions and requests: terms@tangiblepost.co
General support: handson@tangiblepost.co
This policy works together with our Terms of Service, Cookie Policy, and The Tangible Promise.