Last updated: July 19, 2026
This Privacy Policy describes how TENX COLD EMAIL (a sole proprietorship registered in India, trading as OfflistMe; hereinafter "OfflistMe", "we", "our", "us") collects, uses, shares, and protects personal data through our website www.offlist.me(the “Platform”).
OfflistMe is available to users worldwide, including residents of the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). Where you are located in the EU, EEA, or UK, this policy is supplemented by the additional rights and obligations set out in the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Those rights prevail over any conflicting provision below to the extent required by law.
Data Controller: TENX COLD EMAIL, Plot no 51, Adinath Park 2, Naghedi, Jamnagar 361006, India. Email: support@offlist.me
EU / UK Representative: We are in the process of formally appointing an EU and UK representative as required under Article 27 EU GDPR and equivalent UK GDPR provision. Until that appointment is complete, all data-subject enquiries and regulator communications should be directed to support@offlist.me. This page will be updated once the representative is appointed.
Important — the OfflistMe opt-out tool is privacy-first by design. The opt-out tool requires no personal information (name, email address, or physical address) to generate requests. You simply select the target data brokers, and pre-filled opt-out emails and direct portal links are generated locally in your browser. We do not store, log, or transmit any user profile data to our servers.
When you make a payment, we collect:
Payment card details are handled entirely by our payment processors (PayPal, Razorpay) and are never transmitted to or stored on our servers.
Where EU GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6:
| Processing Activity | Lawful Basis |
|---|---|
| Processing payments and granting access | Art. 6(1)(b) — Performance of a contract |
| Sending transactional emails (payment confirmation, pass delivery) | Art. 6(1)(b) — Performance of a contract |
| Maintaining order records for legal / tax obligations | Art. 6(1)(c) — Legal obligation |
| Fraud prevention and security | Art. 6(1)(f) — Legitimate interests |
| Anonymised analytics (PostHog page-view events) | Art. 6(1)(f) — Legitimate interests (privacy-preserving, no cross-site tracking) |
| Storing functional preferences in your browser (dark mode, privacy notice flag) | Strictly necessary — no consent required |
We retain personal data only as long as necessary for the purposes for which it was collected or as required by applicable law.
| Data Category | Retention Period | Reason |
|---|---|---|
| User account (email, name, plan) | Duration of access + 12 months | Support, dispute resolution |
| Order records (payment details) | 7 years | Tax and legal obligation |
| Failed / abandoned orders | 6 months | Fraud prevention |
| Audit log (user actions, non-PII) | 24 months | Support and fraud prevention |
| Crowdsourced platform submissions | Indefinite (no PII stored) | Public directory — contains no personal data |
| Browser local storage (preferences) | Until you clear browser data | Functional necessity; never sent to us |
Automated deletion runs monthly. Anonymised aggregate statistics (e.g. total opt-outs sent — a single integer) may be retained indefinitely as they contain no personal data.
We do not track you. OfflistMe runs no Google Analytics, no advertising pixels, no session-recording tools, and no cross-site trackers.
We use PostHog, a privacy-preserving first-party analytics tool, configured as follows:
/ingest) so no data is sent directly from your browser to a third-party domain.persistence: "memory" — it sets zero cookies and zero localStorage tracking identifiers in your browser.International transfer note: PostHog's cloud infrastructure is currently hosted in the United States. As an operator of a privacy-first tool, we have configured PostHog to minimise data collected (no persistent identifiers, no session recordings). We are evaluating migration to PostHog's EU (Frankfurt) hosting to keep all analytics data within the EEA. This page will be updated when that migration is complete.
The only data stored in your browser is what the Platform itself needs to function:
localStorage to remember your functional preferences (dark mode and payment status), and a flag that records you've seen our privacy notice. These values are read only by the OfflistMe site and are never sent to a third party.You can clear this site's storage at any time from your browser settings.
We share personal data only with the following categories of recipients, and only to the extent necessary:
| Recipient | Purpose | Safeguard |
|---|---|---|
| PayPal | Payment processing | Binding Corporate Rules; GDPR DPA in place |
| Razorpay | Payment processing | India-based processor; governed by India DPDP Act; no EU adequacy decision — users acknowledge international transfer at checkout |
| Neon / Vercel | Database and hosting infrastructure | US-based; SCCs in provider agreements |
| PostHog | Anonymised analytics | US-based; DPA available; migration to EU hosting under review |
| Law enforcement / regulators | Legal obligation, court order | Only where required by law |
We do not sell your personal data. We do not share it for advertising or marketing purposes.
Depending on your location, you may have the following rights regarding your personal data. EU/EEA and UK residents have rights under EU GDPR / UK GDPR; others may have rights under applicable local law (e.g. CCPA for California residents, PIPEDA for Canadian residents).
To exercise any of these rights, please visit our Data Rights Request page or email support@offlist.me with the subject line “Data Rights Request”. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.
Right to lodge a complaint: If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may complain to the Information Commissioner's Office (ICO).
We implement industry-standard security measures including 256-bit TLS encryption in transit, access controls, and regular security reviews. Our privacy-by-design approach means we minimise data collected in the first place — the best defence against a data breach is not having the data.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and affected individuals without undue delay.
Our service is not directed to individuals under 16 years of age (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately at support@offlist.me.
OfflistMe is operated from India. Your personal data may be transferred to and processed in countries outside the EU/EEA/UK, including India and the United States, where data protection laws may differ from those in your country.
Where we transfer personal data from the EU/EEA or UK to third countries, we rely on the following transfer mechanisms:
We may update this Privacy Policy from time to time. Significant changes will be communicated via a notice on the Platform. The “Last updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
For any questions, data-rights requests, or concerns regarding this Privacy Policy or our data practices, please contact:
In accordance with the Information Technology Act, 2000 (India) and the Digital Personal Data Protection Act, 2023 (India), the above officer also serves as our grievance officer under Indian law.