Privacy Policy
FAZLEY (fazley.online) is an email marketing and cold outreach service operated by Active Lead Expert, owned by Fazley Rabbi. This policy explains exactly what we collect, why, how long we keep it, and how to get it back or have it deleted.
We do not sell your data. We do not use the contents of your mailbox to train any model. We access only what the service needs to do the job you asked it to do.
Contents
- Who we are
- What we collect
- Google user data and the Gmail API
- Limited Use disclosure
- How we use your information
- People you send email to
- Open and click tracking
- Who we share data with
- How we protect it
- How long we keep it
- Your rights and choices
- Deleting your data
- Cookies and analytics
- Children
- Changes to this policy
- Contact us
1. Who we are
FAZLEY is operated by Active Lead Expert, a business owned and run by Fazley Rabbi.
| Service | FAZLEY, at fazley.online |
|---|---|
| Operated by | Active Lead Expert, www.activeleadexpert.com |
| Owner | Fazley Rabbi, www.fazley.bd |
| Data controller contact | info@fazley.org |
Where this policy says "we", "us" or "our", it means Active Lead Expert operating the FAZLEY service. Where it says "you", it means the person or organisation holding a FAZLEY account.
2. What we collect
Information you give us
- Account details. Your name and email address. If you sign in with a password, we store a scrypt hash of it and never the password itself. If you sign in with Google, we store your Google account email, name and profile picture URL.
- Mailbox credentials. For Google mailboxes we store an OAuth refresh token. For SMTP and IMAP mailboxes we store the host, port, username and password. Passwords are encrypted at rest with AES-256-GCM and are never returned to your browser.
- Contacts and leads. Email addresses and any fields you upload or push in through the API, such as name, company, job title, phone number and your own notes.
- Campaign content. The subject lines, message bodies, templates and follow-up sequences you write.
- Files you upload. Attachments and files you host for linking. These are stored on our server and served only to whoever holds the unguessable link.
- Billing information. The plan you request and the reference you supply when you tell us you have paid. We do not collect or store card numbers. Bank transfer details are shown to you inside the app; payment happens at your own bank.
Information we generate
- Sending records. Which message went to which address, from which mailbox, at what time, and whether it was delivered, bounced, opened, clicked, replied to or unsubscribed.
- Replies. Messages received in reply to campaigns you sent, so they can be shown in your unified inbox and matched to the right lead.
- Technical logs. IP address, browser user agent and timestamps for sign-ins, API calls and tracking-pixel loads.
3. Google user data and the Gmail API
If you connect a Google or Google Workspace mailbox, FAZLEY uses Google APIs. We request the narrowest set of permissions that lets the product work, and each one is used only for the purpose given below.
| Scope | What it allows | Why FAZLEY needs it |
|---|---|---|
openid, email, profile |
Your email address, name and profile picture | To create and identify your account when you sign in with Google. |
gmail.send |
Send mail as you | To send your campaigns and follow-ups from your own mailbox, so they come from your address rather than a shared pool. |
gmail.readonly |
Read your mail | To detect replies to the campaigns you sent, so a sequence stops when somebody answers and the reply appears in your unified inbox. |
gmail.modify |
Change labels and read state | Used only by the warm-up feature, to move warm-up messages between your own connected mailboxes out of spam and mark them read. Without it, warm-up can measure where a message landed but cannot improve it. |
We read only the conversations FAZLEY itself started. The service looks up messages by the thread and Message-ID of email it has sent on your behalf. Your unrelated personal or business correspondence is not read, indexed, searched or stored.
Reply content that we do store is stored so that you can read and answer it inside FAZLEY. It is never used for advertising, never sold, and never used to train artificial intelligence or machine learning models.
4. Limited Use disclosure
FAZLEY's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, FAZLEY does not:
- use Google user data for serving advertisements;
- transfer or sell Google user data to third parties, data brokers, information resellers or advertising platforms;
- allow humans to read Google user data, except where you give explicit permission for a specific support request, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised;
- use Google user data to develop, improve or train generalised artificial intelligence or machine learning models.
Google user data is used solely to provide and improve the features described in section 3, which are the features you connected the mailbox in order to use.
5. How we use your information
- To send the campaigns, follow-ups and replies you tell the service to send.
- To pace sending so your mailbox and domain keep a good sending reputation.
- To show you what happened to each message: delivered, opened, clicked, replied, bounced or unsubscribed.
- To detect replies so that sequences stop automatically for anybody who has answered.
- To enforce unsubscribes and your blocklist, so somebody who opts out is never contacted again through FAZLEY.
- To operate your account: authentication, plan limits, billing requests and support.
- To keep the service secure and to investigate abuse.
We do not use the contents of your mailbox, your contacts or your campaigns for advertising, and we do not sell any of it.
6. People you send email to
When you upload contacts or push leads through the API, you are the controller of that data and we process it on your behalf. You are responsible for having a lawful basis to contact those people and for complying with the marketing and privacy laws that apply to you and to them, including GDPR, the CAN-SPAM Act, CASL and any local equivalents.
We provide the tools that make compliance possible: a one-click unsubscribe link and
List-Unsubscribe header on every campaign that has it enabled, an account-wide
suppression list that survives re-import, and a domain blocklist. Using them is your
responsibility.
If somebody who received your email contacts us directly and asks to be removed or to see what we hold, we will act on it and tell you.
7. Open and click tracking
When open tracking is enabled for a campaign, each message contains a small invisible image. When a mail client loads that image we record the time, the IP address the request came from and the user agent string, and we attribute it to the recipient the message was sent to. Click tracking works the same way by routing links through a redirect.
Two honest limitations worth stating. Gmail loads images through Google's own proxy, so the IP address recorded for those opens belongs to a Google datacentre and does not indicate where the recipient is. Apple Mail Privacy Protection loads images whether or not anybody read the message. FAZLEY labels proxy opens as such rather than presenting them as a location.
You can turn tracking off per campaign. When it is off, no pixel is added and no opens are recorded.
8. Who we share data with
We do not sell personal data. We share it only with the following, and only as far as needed:
| Recipient | Purpose |
|---|---|
| Google LLC | Sending and reading mail through the Gmail API, when you connect a Google mailbox, and sign-in. |
| Your own SMTP and IMAP providers | Sending and reading mail through mailboxes you configure yourself. |
| Hostinger | Hosting the application and its database. |
| Google Analytics | Aggregate visitor statistics on our public marketing pages only. The signed-in application carries no analytics tag. |
| Email verification provider | Checking whether an address is deliverable, when you use the verification feature. Only the address is sent. |
| Your own webhook endpoints | Event notifications you configure and control. |
We may also disclose information where we are legally required to, or to protect the rights, safety and property of Active Lead Expert, our users or the public.
9. How we protect it
- All traffic to the service is encrypted in transit with HTTPS.
- SMTP and IMAP passwords are encrypted at rest with AES-256-GCM.
- Account passwords are stored as scrypt hashes and are never recoverable, by us or anybody else.
- API keys are shown only to the account that owns them and can be revoked at any time.
- Every query in the application is scoped to a single account. Administrators of the service can manage accounts and see operational activity, but cannot read another account's campaign content, contacts or message bodies.
- Uploaded files are stored under names derived from their own content hash, and are served only to somebody holding the unguessable link.
No service can promise perfect security. If a breach affects your personal data we will tell you and the relevant authority without undue delay.
10. How long we keep it
- Account data is kept while your account is open.
- Campaigns, contacts, replies and sending records are kept until you delete them or close your account, because they are the record of what you sent and who answered.
- Unsubscribe records are kept even after you delete the contact. This is deliberate: it is the only way to guarantee somebody who opted out is never emailed again, and it is what the law expects.
- Technical logs are kept for as long as they are useful for security and troubleshooting.
11. Your rights and choices
Depending on where you live you may have the right to access, correct, export, restrict or delete the personal data we hold about you, and to object to certain processing. You can exercise most of these yourself inside the application, and for anything else you can email us.
- Access and export. Contacts, campaign results and open logs can be exported to CSV from the application at any time.
- Correction. Account details and contact records can be edited directly.
- Disconnect a mailbox. Remove it under Senders at any time. You can also revoke FAZLEY's access from your Google Account at myaccount.google.com/permissions. Revoking access stops all sending and reply detection for that mailbox immediately.
- Complain. If you are in the UK, EU or another region with a data protection authority, you may lodge a complaint with it. We would appreciate the chance to address your concern first.
12. Deleting your data
You can delete individual contacts, campaigns and uploaded files from inside the application.
To delete your entire account and everything in it, email info@fazley.org from the address on the account. We will confirm and then delete your account, mailbox credentials, contacts, campaigns, uploaded files and message records. Suppression records of people who unsubscribed are retained as described in section 10, and backups are overwritten on their normal cycle.
13. Cookies and analytics
FAZLEY sets one cookie, mw_session, which keeps you signed in. It is strictly
necessary for the service to work and carries no advertising identifier.
Our public marketing pages use Google Analytics 4 to count visits and understand which pages are useful. The signed-in application is deliberately not tagged, because application URLs can contain your customers' details and those must not be sent to a third party. You can opt out of Google Analytics with the Google Analytics opt-out add-on.
14. Children
FAZLEY is a business tool and is not directed at children. We do not knowingly collect personal data from anybody under 16. If you believe a child has given us personal data, contact us and we will delete it.
15. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell account holders by email before it takes effect.
16. Contact us
For any privacy question, data request or complaint:
| info@fazley.org | |
| Business | Active Lead Expert, www.activeleadexpert.com |
| Owner | Fazley Rabbi, www.fazley.bd |
We aim to answer every request within 30 days.