BounceLayer Privacy Policy
Last updated: October 5, 2026 • Effective immediately
1. Zero Data Retention Architecture
BounceLayer evaluates email address deliverability in-flight via real-time RFC 5321 protocol socket dialogue. We do not build, sell, rent, or leak verified contact lists. Your customer and lead data belongs exclusively to you.
Verification query results are held in an ephemeral encrypted Redis cluster for 7 days strictly for billing deduplication and idempotency, after which they are permanently and irrecoverably purged.
2. Information We Collect
- Account Credentials: Name, work email address, and hashed passwords for dashboard authentication.
- Billing Information: Payment processing is handled securely by Stripe/Dodo Payments. BounceLayer does not store full credit card numbers.
- Telemetry & Logs: API key usage counts, verification latency, and endpoint response status for infrastructure maintenance and rate limiting.
3. Zero Email Dispatch Guarantee
During verification, BounceLayer connects directly to recipient Mail Exchangers (MX hosts) and issues the standard HELO, MAIL FROM, and RCPT TO dialogue commands. Immediately upon receiving recipient existence confirmation (e.g. 250 OK or 550 User Unknown), BounceLayer issues the QUIT command. Zero message body is ever transmitted or queued into the recipient inbox.
4. GDPR & International Compliance
BounceLayer acts as a Data Processor under the European Union General Data Protection Regulation (GDPR). Customers act as Data Controllers. You retain full rights to request deletion of your account and associated billing logs at any time.
5. Contact Our Privacy Officer
For privacy inquiries, Data Processing Addendum (DPA) execution, or data deletion requests, email our engineering team at privacy@bouncelayer.com.