Privacy Policy

Last updated: August 24, 2026

1. Introduction

This Privacy Policy describes how TENX COLD EMAIL (a sole proprietorship registered in India, trading as OfflistMe; hereinafter "OfflistMe", "we", "our", "us") collects, uses, shares, and protects personal data through our website www.offlist.me (the “Platform”).

OfflistMe is available to users worldwide, including residents of the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). Where you are located in the EU, EEA, or UK, this policy is supplemented by the additional rights and obligations set out in the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Those rights prevail over any conflicting provision below to the extent required by law.

Data Controller: TENX COLD EMAIL, Plot no 51, Adinath Park 2, Naghedi, Jamnagar 361006, India. Email: support@offlist.me

EU / UK Representative: Whether an EU or UK representative is required depends on the scope and nature of the relevant processing. This page does not currently list an appointed representative. We are assessing the applicable requirements and will publish representative details here if an appointment is required. Until then, data-subject enquiries and regulator communications should be directed to support@offlist.me.

2. Data We Collect and Why

2.1 Data you provide directly

Important — the OfflistMe opt-out tool is privacy-first by design. The opt-out tool requires no personal information (name, email address, or physical address) to generate requests. You select the target data brokers, and pre-filled opt-out emails and direct portal links are generated locally in your browser. The name, physical address, and request-draft contents are not intentionally sent to our application servers as an opt-out profile. Payment, access, analytics, and operational records are separate processing activities described below.

When you make a payment, we collect:

  • Name and email address — to issue and look up your access pass.
  • Order ID and payment status — for access verification, dispute resolution, and fraud prevention.
  • Currency and plan selected — for billing records.

Payment card details are handled by our payment processors (PayPal and Razorpay). We do not intentionally receive or store full payment-card numbers in the OfflistMe application.

2.2 Data collected automatically

  • Network and request context — IP address and approximate country, region, or city may be processed for security, abuse prevention, geo-based features, and operational alerts.
  • Product and funnel events — page views, interface interactions, payment and restore events, selected broker counts, plan and provider choices, success events, and error events may be sent to PostHog or operational alerting. Payment and restore events may include the checkout email or use it as an analytics identifier.
  • Search and error context — broker-directory search text may be included in search telemetry, and exception messages, names, and short stack or component-stack snippets may be captured to diagnose failures. These fields are not guaranteed to be free of personal information if the input or error itself contains it.

2.3 Data we do NOT collect

  • No Google Analytics, advertising pixels, or third-party advertising tracking.
  • No session recordings, heatmaps, autocapture, or surveys in the PostHog client configuration.
  • No cross-site advertising or ad-personalisation tracking. Limited product analytics and operational telemetry are still used as described above.
  • We do not intentionally request biometric data.
  • We do not intentionally request or use special-category data for the Platform. Do not enter sensitive information into optional fields or messages.

3. Lawful Basis for Processing (EU / UK GDPR)

Where EU GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6:

Processing ActivityLawful Basis
Processing payments and granting accessArt. 6(1)(b) — Performance of a contract
Sending transactional emails (payment confirmation, pass delivery)Art. 6(1)(b) — Performance of a contract
Maintaining order records for legal / tax obligationsArt. 6(1)(c) — Legal obligation
Fraud prevention and securityArt. 6(1)(f) — Legitimate interests
Product analytics, operational telemetry, and security monitoringArt. 6(1)(f) — Legitimate interests, where applicable, subject to necessity, minimisation, and your rights
Storing functional preferences in your browser (dark mode, privacy notice flag)Strictly necessary or functional, depending on the value and applicable law

4. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected or as required by applicable law.

Data CategoryRetention PeriodReason
User access records (email, name, plan)During access; expired records are subject to scheduled cleanup after 12 months, subject to exceptionsSupport, dispute resolution, fraud prevention, and legal obligations
Order records (payment details)According to accounting, payment, dispute, fraud, and legal needs; the current operational target is up to 7 years for completed recordsTax, accounting, payment reconciliation, support, and legal obligations
Failed / abandoned ordersUp to 7 days for unverified, non-completed orders under the current cleanup job, subject to reconciliation, support, or legal exceptionsFraud prevention, reconciliation, and operational support
User-action metadata (event type, counts, limited platform metadata, and optional order ID)Up to 24 months where written to the audit tableSupport and fraud prevention; request contents are not intended to be stored in this table
Crowdsourced data broker submissionsIndefinite (public catalog data; no user profile)Public directory — contains no personal data
Browser and session storage (preferences, draft selections, and checkout/access state)Until you clear browser data or the relevant state expiresLocal functionality; some checkout, access, or recovery values may be read by the site and sent in those separate flows

Scheduled cleanup jobs run regularly, including a daily job for stale orders, expired access records, old action-log rows, and expiring temporary entries. Aggregate statistics may be retained longer when they are not reasonably linkable to an individual; we aim to retain aggregate metrics without direct identifiers.

5. Analytics & Tracking

We do not use advertising or cross-site tracking. OfflistMe runs no Google Analytics, advertising pixels, or session-recording tools. We do use limited product analytics and operational telemetry, as described below.

We use PostHog, a third-party product-analytics service accessed through our same-origin proxy, configured as follows:

  • Browser PostHog requests use our own domain (/ingest) and are forwarded server-side to PostHog; the browser is not configured to send these requests directly to a PostHog host.
  • PostHog is configured with persistence: "memory" — it sets zero cookies and zero localStorage tracking identifiers in your browser.
  • Session recording, heatmaps, autocapture, and surveys are all disabled.
  • Events include more than page views: product interactions, funnel and payment events, restore attempts, selected broker counts, and manually captured error context may be sent. Some payment or restore events can include an email address or use it as a PostHog identifier.

International transfer note: The current application routing points to PostHog's United States ingestion host. PostHog is configured to minimise client-side persistence and does not use session recordings or heatmaps here. The applicable provider terms and transfer arrangements should be checked for the current configuration.

The Platform may store functional and transaction-related state in your browser:

  • Essential and draft state: Values such as theme and notice preferences, selected data brokers, locally drafted form fields, rate-limit markers, and wizard progress may be stored in localStorage or sessionStorage. Checkout and access flows may also store an email address, order or provider state, access token, plan, or success state so the flow can resume.
  • How that state is used: The site reads these values for local functionality and may send relevant checkout, access, recovery, or telemetry fields when you use those flows. Clearing browser storage does not delete payment or server-side records.
  • Transactional data: If you make a purchase, our payment providers (PayPal, Razorpay) may set their own cookies as required to process the payment. We don't control those cookies and you only interact with them when you choose to pay.

You can clear this site's storage at any time from your browser settings.

6. Sharing of Personal Data

We share personal data only with the following categories of recipients, and only to the extent necessary:

RecipientPurposeSafeguard
PayPalPayment processing and related payment communicationsProvider terms, privacy notice, and applicable transfer arrangements
RazorpayPayment processingProvider terms, privacy notice, and applicable transfer arrangements
Neon / VercelDatabase and hosting infrastructureProvider terms, privacy notice, and applicable contracts
PostHogProduct analytics, funnel measurement, and manually captured error telemetrySame-origin browser proxy; current routing to the United States ingestion host; provider terms and applicable transfer arrangements
Operational alerting providerSupport, fraud, security, and growth alertsLimited event context may include email, IP or approximate location, device, referrer, selected broker counts, plan, and event details; access is restricted through application and provider controls
Law enforcement / regulatorsLegal obligation, court orderOnly where required by law

We do not sell your personal data or use it for third-party advertising. We do share limited information with service providers and operational recipients when needed for the purposes described above.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data. EU/EEA and UK residents have rights under EU GDPR / UK GDPR; others may have rights under applicable local law (e.g. CCPA for California residents, PIPEDA for Canadian residents).

  • Right of access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): Request correction of inaccurate data.
  • Right to erasure / “Right to be forgotten” (Art. 17 GDPR): Request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction of processing (Art. 18 GDPR): Request that we limit how we use your data.
  • Right to data portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR): Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
  • Right not to be subject to automated decisions: We do not use solely automated decision-making that produces legal or significant effects.

To exercise any of these rights, please visit our Data Rights Request page or email support@offlist.me with the subject line “Data Rights Request”. Response timing depends on your location and request. Under EU/UK GDPR, the usual period is one month, with a possible two-month extension where permitted and notified. Covered California requests have separate acknowledgement and response timelines under applicable CCPA/CPRA rules. We may ask you to verify your identity before processing your request.

Right to lodge a complaint: If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may complain to the Information Commissioner's Office (ICO).

8. Security

We implement technical and organisational safeguards appropriate to the processing, including HTTPS/TLS in transit, access controls, and periodic security reviews. Our privacy-by-design approach means we minimise data collected in the first place — the best defence against a data breach is not having the data.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and affected individuals without undue delay.

9. Children's Privacy

Our service is not directed to individuals under 16 years of age (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately at support@offlist.me.

10. International Data Transfers

OfflistMe is operated from India. Your personal data may be transferred to and processed in countries outside the EU/EEA/UK, including India and the United States, where data protection laws may differ from those in your country.

Where we transfer personal data from the EU/EEA or UK to third countries, the applicable mechanism depends on the recipient and current legal and contractual arrangements. Depending on the transfer, this may include an adequacy decision, appropriate safeguards such as standard contractual clauses, or a specific derogation where its legal conditions are met. We do not treat any single provider mechanism as a blanket guarantee for every transfer.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated via a notice on the Platform. The “Last updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.

12. Contact & Grievance Officer

For any questions, data-rights requests, or concerns regarding this Privacy Policy or our data practices, please contact:

  • Name: Rahul K
  • Role: Compliance Officer & Grievance Officer
  • Company: TENX COLD EMAIL (trading as OfflistMe)
  • Email: support@offlist.me
  • Hours: Mon – Fri, 10:00 AM – 06:00 PM IST
  • Response time: We aim to respond as soon as practicable; statutory deadlines vary by location and request type.

In accordance with the Information Technology Act, 2000 (India) and the Digital Personal Data Protection Act, 2023 (India), the above officer also serves as our grievance officer under Indian law.