1. Who we are
DearFax is operated by SF VENTURES ("DearFax", "we", "us"). Contact us about privacy at privacy@dearfax.com. Our privacy contact can be reached at the same email address.
This policy explains how we handle personal information through dearfax.com and the DearFax service, including accounts, workspaces, fax preparation, transmission, receipt, and support.
We are the data controller for information we use to manage our business, accounts, billing, security, and customer relationships. When we handle fax content and related personal information on behalf of a business customer, we generally act as its processor, or as its subprocessor if that customer acts for another organisation. That processing is governed by our Data Processing Agreement. The customer's own privacy notice explains its purposes and legal grounds for using that information.
For personal-use customers, we act as controller when providing the service directly to you. Before signup, we process the information needed to prepare your requested draft as a step towards providing that service. We use information needed to prepare, send, receive and store your faxes to perform our contract with you. Where documents contain information about other people, we rely on legitimate interests in carrying out your lawful communications, subject to their rights. Sensitive information requires an additional legal condition; an ordinary service contract alone is not sufficient.
2. Information we handle
Depending on how you use DearFax, we handle:
- Account and workspace information: name, email address, authentication identifiers, workspace name, membership, role, preferences, and invitations.
- Fax content: uploaded documents, scans, cover pages, drafts, and received faxes. These may contain information about you or other people, including sensitive information if included in a document.
- Fax and number records: sender and recipient numbers, page counts, transmission times, delivery status, errors, assigned numbers, and number-porting documents where porting is offered.
- Billing information: billing contact, address, tax details, purchased plan, invoices, payment status, and payment references. Stripe processes payments. DearFax uses customer, subscription, invoice, payment-status and transaction references to administer billing. Card details are entered through Stripe’s payment interface.
- Technical and usage information: IP address, device and browser details, request logs, security events, and page visits, product events, performance measurements, sanitised errors, account and workspace identifiers, campaign attribution, page counts and subscription-related properties.
- Communications: support requests, feedback, and correspondence.
We receive information directly from you, from other workspace members, from people sending faxes to your number, and from providers involved in authentication, payments, and fax transmission.
Before signup: when you prepare a fax without an account, we store your uploaded documents, recipient number, cover information and page selections in a private temporary draft on our servers. An essential cookie lets the same browser reopen that draft and attach it to your workspace after sign-in. Closing the editor keeps the draft; clearing the cookie removes your browser’s access but does not immediately delete the server copy. Anonymous drafts expire 24 hours after the last edit or upload and are deleted, together with their files, by our daily cleanup job. Once attached to a workspace, the draft follows workspace retention rules instead. Phone scanning requires an account. This notice applies before account creation as well as afterwards.
The draft cookie is renewed for 24 hours when you edit or upload. Merely opening a draft does not renew its server retention period. It contains a random access credential, not your fax content. Do not share a browser session with someone who should not have access to your draft.
3. Why we use information
For processing where we are the controller, the following purposes and GDPR legal bases apply where relevant:
| Purpose | Information | Legal basis |
|---|---|---|
| Create and operate an individual customer's account and provide requested services | Account, transaction, and necessary service information | Performance of our contract with that individual, or steps requested by them before entering that contract |
| Manage business accounts and communicate with their representatives | Business contact and workspace information | Legitimate interests in providing services to our business customers |
| Process payments and administer subscriptions | Billing and transaction information | Contract performance, or legitimate interests for business representatives; legal obligation for mandatory records |
| Provide support | Contact details, correspondence, relevant diagnostics | Contract performance or legitimate interests in resolving customer issues |
| Prevent fraud, abuse, and security incidents | Technical records and relevant account or transaction information | Legitimate interests in protecting users and the service; legal obligation where applicable |
| Understand and improve product use | Page visits, product events, performance measurements, sanitised errors, account/workspace identifiers and campaign attribution; excluding document contents | Consent |
| Send optional marketing | Contact details and communication preferences | Consent where required; otherwise an applicable lawful basis with an opt-out |
| Meet legal duties and handle disputes | Information relevant to the duty or dispute | Legal obligation or legitimate interests in establishing, exercising, or defending legal claims |
Fax content processed for business customers is used according to their documented instructions, not on the basis of our own independent marketing purposes. We access fax content only as necessary to deliver the service, respond to an authorised support request, investigate security or abuse, or comply with law. We do not use fax content to train AI models.
Some information is necessary to provide the requested service, such as a recipient number to send a fax or billing information to take payment. Without it, we cannot provide the affected feature. Optional fields and choices are identified where collected.
4. Who receives information
We share information as necessary with:
- Advertising measurement: Google Ads and OpenAI Ads receive the limited conversion data described in section 7 when you accept optional measurement.
- Service providers supporting hosting, storage, authentication, fax transmission, payments, email, support, security, and analytics. See our subprocessor register for providers processing customer data on our behalf. Some providers may act as independent controllers for their own legal or payment obligations, as explained in their notices.
- Your workspace: administrators and authorised members can access information according to their permissions. Workspace members share access to workspace faxes. Administrators manage workspace membership and billing.
- Fax recipients and communications providers: sending a fax discloses its content to the selected destination and involves telephone networks and receiving systems. We cannot control how the intended recipient subsequently uses it.
- Integrations you enable: information needed for the requested integration or forwarding destination.
- Authorities and professional advisers: where required by law or reasonably necessary to protect rights, investigate abuse, or obtain confidential advice.
- A successor business: where necessary for a proposed or completed merger, acquisition, or asset transfer, subject to appropriate protections and legally required notice.
We do not sell personal information. Product analytics is used to understand and improve DearFax.
5. International processing
DearFax’s primary application hosting and storage are in the United States. Provider processing locations, transfer arrangements and limitations are described in our subprocessor register.
Where GDPR-regulated information is transferred outside the European Economic Area, we use an applicable lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses with additional safeguards where necessary. For transfers to our US service providers, we rely on the European Commission’s Standard Contractual Clauses incorporated into the applicable provider data processing agreements, with the appropriate controller-to-processor or processor-to-processor terms and supplementary safeguards where required. We do not claim that DearFax is certified under the EU–US Data Privacy Framework. You can request information about applicable safeguards and a copy, subject to necessary redactions, at privacy@dearfax.com.
6. Retention
We keep information for the periods below, unless a specific legal obligation requires longer retention. Business-customer content is also subject to the DPA and agreed instructions.
Account and fax data. We retain account information and stored faxes to provide the service and maintain the records you keep in your workspace. Your plan determines how long files can be accessed in the app; expiry of that access window does not itself delete them. You can request an export, deletion of stored information, or account closure by emailing privacy@dearfax.com. We verify your identity and, for shared workspace data, your authority to make the request. We explain any information that must be retained by law or for a specific unresolved matter.
When an account or workspace closes, we arrange the return or deletion of its data with the authorised customer. Information no longer needed for the service or a documented legal purpose is deleted or anonymised. Requests are handled within the applicable legal time limits described under “Your rights”; deletion does not depend on purchasing another plan.
Service records. We retain transmission metadata for 12 months after transmission, porting documents for 90 days after transfer completion or number release, and support correspondence for 12 months after resolution. Unnecessary document attachments are removed sooner. Unclaimed anonymous drafts become inaccessible 24 hours after the last edit or upload. The daily cleanup job then deletes their database records and uploaded files, including incomplete uploads. A failed deletion is retried; it does not restore access. Security rate-limit records use a daily pseudonymous identifier and are removed by the cleanup job after two days. Workspace drafts are excluded from anonymous cleanup.
Security and analytics. We retain security logs for six months and identifiable analytics for 12 months from the recorded event.
Legal and accounting records. Accounting records and supporting evidence are retained for 10 years from the close of the relevant financial year. Other records subject to a specific legal retention requirement are kept for the applicable period. Accounting obligations do not justify retaining fax document contents.
A documented legal obligation, dispute, security investigation or pending rights request may require limited records to be preserved longer. Those records are restricted to the relevant purpose and deleted when that need ends. We send deletion instructions to relevant service providers and track completion. If a provider must retain specific records by law, we explain the exception and restrict further use to that purpose. Copies already delivered to fax recipients or their email systems are outside your DearFax account; deleting an account does not recall them.
7. Cookies and similar technologies
We use PostHog to measure page visits, product events, performance and errors. Our analytics filters exclude document contents, filenames, fax numbers, email addresses, payment methods and access tokens.
We use cookies and browser storage to keep you signed in, protect your account, remember requested preferences, and reopen your temporary server draft. These technologies support the service you request.
Optional website analytics, performance/error diagnostics and ad conversion measurement remain off until you accept them, in every region. We honour Global Privacy Control as an opt-out. You can accept or reject measurement in the cookie controls and withdraw your choice at any time through cookie preferences. Refusing measurement does not prevent you from using DearFax. Our campaign attribution cookie lasts for 90 days. PostHog cookies and cookie preferences last up to 180 days.
With your permission, we use Google Ads and OpenAI Ads to measure whether ad interactions lead to a first paid workspace. We send the relevant ad click identifier, first-payment time, amount and currency, and an opaque identifier to avoid counting a payment twice. Google receives these conversions through PostHog; OpenAI receives them from our server. These uploads do not include your email address, phone number, fax documents, filenames or payment method. Withdrawal stops future forwarding; it cannot recall data already sent.
Product analytics and operational totals
Cookie choices do not disable product analytics. We send PostHog events for signups, workspace creation, product interactions, payments, and fax activity, including delivered and received page counts. These events use internal account or workspace identifiers when available. Background activity uses the workspace identifier; anonymous interactions use a separate identifier per event, without a persistent analytics cookie. This allows us to measure product use, conversion and retention. Product events exclude document contents, filenames, fax numbers and email addresses. Campaign data is attached only with permission.
We also calculate aggregate service totals from retained records and send daily totals without user or workspace identifiers or advertising attribution. These totals are independent of cookie preferences. Optional website analytics and advertising measurement remain subject to your choice. Your rights described below continue to apply.
8. Your rights
Depending on applicable law and the circumstances, you may request access, correction, deletion, restriction, or a portable copy of your information, and object to certain processing. You may withdraw consent without affecting processing already lawfully carried out. You may object to direct marketing at any time.
Contact privacy@dearfax.com. We may request proportionate information to verify your identity. Where we hold your information for a business customer, we will direct the request to that customer or assist it in responding.
You may complain to the French supervisory authority, the CNIL, or another competent authority. Under GDPR, requests are normally answered within one month; a permitted extension of up to two further months will be explained within the first month.
Where applicable US state privacy laws grant additional rights, these may include access, correction, deletion, portability, an appeal, and opt-outs of certain sale, sharing, targeted advertising, or profiling activities. Send requests and appeals to privacy@dearfax.com. To appeal a decision, identify the request and explain why you believe it should be reconsidered. We respond within the deadline required by the applicable law and explain any further complaint options. Where applicable law requires us to recognise a browser-based opt-out preference signal, we treat it as a request to opt out of the activities covered by that signal. You may also email us to exercise applicable opt-out rights. We do not retaliate against you for exercising legally protected privacy rights.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
9. Security and sensitive documents
We use technical and organisational safeguards appropriate to the information and risks. These include private document storage, server-side workspace access checks, time-limited document links, and two-factor authentication for the operator’s provider accounts. Fax delivery also depends on carriers and recipient systems; do not assume that the entire transmission path is end-to-end encrypted.
We are working toward support for HIPAA-regulated workflows. This support is not yet available.
Only upload information you are entitled to use. Additional contractual and technical arrangements may be required for regulated information. A privacy policy or DPA does not itself establish HIPAA compliance.
10. Children
DearFax is intended for adults and does not knowingly offer accounts to children under 18. Information about children may nevertheless appear in documents lawfully submitted by customers; that content is handled under the relevant customer instructions and applicable law. Contact us if you believe a child has created an account.
11. Changes
We will update the last updated date when this policy changes and provide additional notice where appropriate or legally required. A revised notice does not by itself authorise a new use of information that requires consent or new customer instructions.