What we hold, and why
Version 2026-09-06-draft
This wording is a working draft and has not yet been reviewed by a Greek lawyer. It describes how the service actually operates today. Final terms will replace it before launch, and we'll ask you to read and accept those when they're ready.
Who we are
Meraki Mail is run by [Company legal name], [Registered office address]. Business register (ΓΕΜΗ) number [GEMI number]; tax number (ΑΦΜ) [AFM tax number]. We decide what happens to your data, which makes us its “controller” under the GDPR.
For anything in this policy — a question, a request or a complaint — write to [privacy@your-domain]. You can also use our contact form; both reach a person.
What we hold
- About you — your name, email address, phone number, home address (street, city, region and postcode) and the username you chose. If you give them: your company name, VAT number and the country it is registered in. We ask for your home address so that it can go on your invoices once we issue Greek tax invoices (myDATA). We do not issue them yet, so until then your address is only kept with your account and is not passed to Stripe or anyone else.
- Your parcels — when each arrived, who sent it, its size and weight, photographs of the unopened item (which show its label), where it is kept and what happened to it. Forwarding requests (the recipient’s name, address and phone number), returns (the sender’s address, your reason, and the customs description and value you give for parcels leaving the EU), combining requests, and the reason if a parcel is held.
- Collections — the collections you book, the person you allow to collect for you (their name, phone number and your note), and the name of whoever actually collected each parcel and how they know you.
- Your plan and payments — your plan and its status, what you have been charged and why, and copies of your Stripe invoices (with the name, tax number and billing address Stripe has on them) kept for our tax records.
- Emails we send you — when each was sent, its subject, the address it went to and whether it was delivered — and, for a message a member of staff writes to you, its full text (kept with our staff activity records).
- Notes our staff write about your account.
- Sign-in and security records — when you asked for a sign-in code and the IP address it was asked from; failed sign-ins (a scrambled form of the email or username typed, and the IP address); which signed-in device has entered its code; and the version of our terms and of this policy you accepted, when, and the IP address and browser it was accepted from; and when your password was changed or reset, and the IP address it was done from.
- A change history — the system records which fields of a record changed and when, with the personal contents hidden.
- Ask Meraki — how many questions you asked today. The conversation itself is not stored (see below).
- Contact-form messages — the name, email address, phone number, property location and message you send us.
- People who are not our customers — the collectors and recipients above, and, if a parcel arrives that we cannot match to a customer, a photograph of it and the name and details written on its label, so that we can find who it is for.
You can download your data from your Settings page, at any time, without asking us. That includes the staff notes. For anything the download does not cover, write to us.
What we do not hold
Your card details. Payments are handled by Stripe and we never see the full number. The contents of your post — we do not open it, so we do not know what is inside, apart from what you tell us for a customs form.
Why we hold it, and on what basis
- To run the service you signed up for (our contract with you): matching parcels to you, storing, photographing, forwarding and handing them over, working out what you owe, telling you when something arrives, and answering questions about what happened. This covers your account details, your parcels, collections, emails about them and staff notes.
- Because the law requires it: tax records — what you were charged, and the copies of your Stripe invoices described above.
- For the Greek tax invoices we will issue (myDATA): your home address, and your company and VAT number if you gave them. We do not issue these invoices yet; until we do, these details are only kept with your account and are not passed to Stripe or anyone else.
- Our legitimate interests: keeping accounts safe (sign-in records and IP addresses), being able to show what you agreed to and when we told you something (terms records, email records, staff activity records and the change history), and getting each parcel to the right person — which is also why we hold the names of collectors, recipients and people named on parcels we could not match. You can object to these (see below).
- To answer you: contact-form messages, at your request.
- Only if you choose to: Ask Meraki. You never have to use it.
We do not sell your data and we do not use it for advertising.
How long
Our current periods:
- Your account, if you sign up but never subscribe — six months after you signed up, your login and account details are deleted.
- Your account, once it is closed — when nothing is owed and nothing of yours is still with us, twenty-four months after the last activity on it (your cancellation or your last parcel), your details are removed exactly as if you had asked us to delete them (see below). Invoices are kept. While your account is open, we keep it.
- Package photographs — twelve months after the package leaves us (for a parcel we combined into one box, after that box leaves).
- Parcels we could not match to anyone — their photographs and the text of their label, twelve months after the item was returned, disposed of or matched to its owner.
- Records of emails we sent — twenty-four months, because it is how we can show you were told something.
- Staff activity records (including the text of messages staff write to you, and password-change records) — thirty-six months.
- Notes about you, and saved addresses — removed within six months of your account closing.
- Sign-in codes — seven days. Failed sign-ins — one day. Which device entered its code — while your account is open.
- Ask Meraki question counts — two days.
- Records of the terms you accepted — kept as proof of what you agreed to, including after your account is closed.
- The change history — kept as a permanent audit trail; your entries are cleaned when your account is deleted.
- Enquiries from the “register your interest” form — twelve months after you sent it.
- Invoices — kept as long as Greek tax law requires, which is longer than any of the above and is not something we can waive.
Sign-in codes, failed sign-ins and question counts are deleted automatically every night. Everything else is deleted from our staff portal by a senior member of staff, who first checks a preview of exactly what will go.
Who can see it
Our staff, and only what their role needs. Someone running a reception centre sees the packages at that centre. Company figures and billing are limited to administrators. Every action staff take is recorded.
Outside the company, these services work for us and see what they need, and nothing more:
- Supabase — stores our database and the photographs (in [Supabase region of the live project]).
- Vercel — hosts this website. Every page you open passes through its servers, and it keeps short-lived technical logs (your IP address, the page and the time).
- Stripe — takes payments and issues invoices. Stripe also uses payment data under its own privacy policy, for example to prevent fraud.
- Resend — sends our emails, so it sees your email address and what we write.
- OpenAI — only if you use Ask Meraki (see below).
- Cloudflare — only while our check against automated sign-ins (Turnstile) is switched on: the sign-in, sign-up and password-reset pages load it from Cloudflare, which sees your IP address and browser.
- Couriers — when we forward or return a parcel, the courier carrying it (for example ACS, ELTA, Speedex, DHL or UPS) receives the name, address and phone number on its label.
- Public authorities — such as the tax authority or customs, only when the law requires it.
Outside the European Union
Supabase, Vercel, Stripe, Resend, OpenAI and Cloudflare are companies based in the United States, so your data may be processed there. Each of these transfers is protected either by the EU–US Data Privacy Framework, for companies certified under it, or by the European Commission’s Standard Contractual Clauses in that company’s data processing agreement with us. Write to us for a copy of the safeguard that applies.
Ask Meraki (the assistant in your dashboard)
If you use Ask Meraki, your questions and the last few messages of the conversation are sent to OpenAI so it can understand what you are asking. When you ask about your own account, a short summary of the records needed to answer is sent too: package references, senders, dates, sizes, status and storage rent, forwarding stages and prices, tracking numbers, collection booking times, your plan and account standing, and recent invoice dates, status and amounts.
Your name, email, phone number, postal and saved addresses, your collection contact, the text of staff condition notes and payment-card details are never sent; they are shown to you directly from our systems. OpenAI is asked not to store the requests. Do not type passwords, sign-in codes or card details into the chat.
The conversation is kept only in your browser tab and clears when you clear it, reload the page or sign out. Ask Meraki can book or cancel a collection only after you confirm it on screen; it cannot take payments, send parcels or change your account. You never have to use it.
What you can ask us to do
- Get a copy — from Settings, immediately, in a form you can read or pass to somebody else.
- Correct something wrong — tell us and we will fix it.
- Delete your data. We can do this once nothing of yours is still with us and nothing is outstanding. ⚠️ Your name, contact details, saved addresses, package photographs and staff notes are removed. Records of what happened and when we wrote to you are kept but stripped of anything identifying you. The record of the terms you accepted is kept as proof of the agreement. Invoices are kept, because tax law requires it. We will tell you exactly what was removed and what was kept.
- Restrict — ask us to stop using your data, apart from keeping it, while a question about it is settled.
- Object — to anything we do on the basis of our legitimate interests. We will stop unless we have a strong reason the law recognises.
- Take it elsewhere — the download in Settings is a file another service can read.
To ask for any of these, write to [privacy@your-domain] or use the contact form. We answer within one month.
Complaints
If you think we have handled your data badly, tell us first at [privacy@your-domain]. You also have the right to complain to the Hellenic Data Protection Authority (www.dpa.gr).
Last updated 2026-09-06-draft. When this changes we will ask you to read and accept the new version.