Ránṣẹ́
DocsSign inStart free
On this page
  1. Who we are & scope
  2. Information we collect
  3. How we use information
  4. Legal bases
  5. Sharing & sub-processors
  6. International transfers
  7. Data retention
  8. Security
  9. Your rights
  10. Cookies & local storage
  11. Children
  12. Changes to this Policy
  13. Contact
Legal · Privacy Policy

Privacy Policy

Last updated: 2 July 2026

This Privacy Policy explains how Ránṣẹ́ collects, uses, shares, and protects personal data. It covers two roles: data we handle as a controller (personal data about our account holders and website visitors) and data we handle as a processor (the message content and recipient data you send through the Service on behalf of your own users). Our processing as a processor is governed by our Data Processing Agreement.

01Who we are & scope

Ránṣẹ́ provides a transactional and bulk email API. For personal data relating to your Ránṣẹ́ account (such as your name and email), we act as the controller. For personal data contained in the emails you send and the recipients you send to (“Customer Content”), you are the controller and we are your processor, acting on your instructions under the DPA.

02Information we collect

  • Account data — your name, email address, workspace/organisation name, team membership and roles, and authentication data (we support passwordless magic-link and OAuth sign-in).
  • Billing data — plan and subscription details, and limited payment metadata. Card payments are processed by Paystack; we do not store full card numbers. We retain only references and safe display details (such as a card’s last four digits) needed to operate billing.
  • Usage & log data — API requests, IP address, timestamps, message and delivery-event metadata (status, bounces, complaints), and dashboard activity, used to run, secure, and improve the Service.
  • Customer Content — the message content and recipient data you submit for sending, processed on your behalf under the DPA.

03How we use information

  • Provide, operate, and maintain the Service, including sending your email and reporting delivery events.
  • Authenticate you and secure accounts and API keys.
  • Process billing and payments.
  • Detect, prevent, and address abuse, spam, fraud, and security issues, and protect platform deliverability.
  • Provide support and send you service-related communications.
  • Improve and develop the Service, and comply with legal obligations.

04Legal bases

Where the Nigeria Data Protection Act 2023 or the GDPR applies, we rely on: performance of our contract with you (to provide the Service); our legitimate interests (to secure, operate, and improve the Service and prevent abuse); your consent (where required, for example certain communications); and compliance with legal obligations.

05Sharing & sub-processors

We do not sell personal data. We share it only as needed to run the Service:

  • Payment processing — Paystack, to take and manage payments.
  • Cloud hosting & email-delivery infrastructure — the providers that host the platform and transmit outbound email on our behalf.
  • Operational tooling — services we use for logging, analytics, and customer support, under confidentiality and data-protection obligations.
  • Legal & compliance — where required by law, or to protect rights, safety, and the integrity of the Service.

A current list of sub-processors that process Customer Content is maintained as part of the DPA. We require sub-processors to protect personal data to a standard consistent with this Policy.

06International transfers

We and our sub-processors may process personal data in countries other than your own. Where we transfer personal data across borders, we take steps to ensure it remains protected in accordance with applicable data-protection law, including using appropriate safeguards where required.

07Data retention

We retain account data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, and dispute-resolution needs. Message and event logs are retained according to your plan’s log-retention period. Customer Content is retained and deleted as described in the DPA. You can request deletion of your account and associated data as set out below.

08Security

We use technical and organisational measures to protect personal data, including encryption in transit, hashing of secrets such as API keys (we store only a hash, never the plaintext key), access controls, and tenant isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

09Your rights

Subject to applicable law, you have rights to access, correct, delete, restrict, and object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights, contact privacy@raanse.com.

If your personal data is contained in emails a Ránṣẹ́ customer sent, that customer is the controller — please direct your request to them; we will assist them as their processor.

If you are in Nigeria, you also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

10Cookies & local storage

The dashboard uses essential cookies and browser local storage to keep you signed in and remember your active workspace. We keep non-essential tracking to a minimum. You can clear this data through your browser, though doing so will sign you out.

11Children

The Service is not directed to children and is intended for users aged 18 and over. We do not knowingly collect personal data from children.

12Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date and, where appropriate, by additional notice.

13Contact

For privacy questions or to exercise your rights, contact privacy@raanse.com. Ránṣẹ́ is operated from Lagos, Nigeria.

© 2026 Ránṣẹ́. All rights reserved.
HomeTermsPrivacyDPA