Last updated: August 24, 2026
This Privacy Policy describes how TENX COLD EMAIL (a sole proprietorship registered in India, trading as OfflistMe; hereinafter "OfflistMe", "we", "our", "us") collects, uses, shares, and protects personal data through our website www.offlist.me (the “Platform”).
OfflistMe is available to users worldwide, including residents of the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). Where you are located in the EU, EEA, or UK, this policy is supplemented by the additional rights and obligations set out in the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Those rights prevail over any conflicting provision below to the extent required by law.
Data Controller: TENX COLD EMAIL, Plot no 51, Adinath Park 2, Naghedi, Jamnagar 361006, India. Email: support@offlist.me
EU / UK Representative: Whether an EU or UK representative is required depends on the scope and nature of the relevant processing. This page does not currently list an appointed representative. We are assessing the applicable requirements and will publish representative details here if an appointment is required. Until then, data-subject enquiries and regulator communications should be directed to support@offlist.me.
Important — the OfflistMe opt-out tool is privacy-first by design. The opt-out tool requires no personal information (name, email address, or physical address) to generate requests. You select the target data brokers, and pre-filled opt-out emails and direct portal links are generated locally in your browser. The name, physical address, and request-draft contents are not intentionally sent to our application servers as an opt-out profile. Payment, access, analytics, and operational records are separate processing activities described below.
When you make a payment, we collect:
Payment card details are handled by our payment processors (PayPal and Razorpay). We do not intentionally receive or store full payment-card numbers in the OfflistMe application.
Where EU GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6:
| Processing Activity | Lawful Basis |
|---|---|
| Processing payments and granting access | Art. 6(1)(b) — Performance of a contract |
| Sending transactional emails (payment confirmation, pass delivery) | Art. 6(1)(b) — Performance of a contract |
| Maintaining order records for legal / tax obligations | Art. 6(1)(c) — Legal obligation |
| Fraud prevention and security | Art. 6(1)(f) — Legitimate interests |
| Product analytics, operational telemetry, and security monitoring | Art. 6(1)(f) — Legitimate interests, where applicable, subject to necessity, minimisation, and your rights |
| Storing functional preferences in your browser (dark mode, privacy notice flag) | Strictly necessary or functional, depending on the value and applicable law |
We retain personal data only as long as necessary for the purposes for which it was collected or as required by applicable law.
| Data Category | Retention Period | Reason |
|---|---|---|
| User access records (email, name, plan) | During access; expired records are subject to scheduled cleanup after 12 months, subject to exceptions | Support, dispute resolution, fraud prevention, and legal obligations |
| Order records (payment details) | According to accounting, payment, dispute, fraud, and legal needs; the current operational target is up to 7 years for completed records | Tax, accounting, payment reconciliation, support, and legal obligations |
| Failed / abandoned orders | Up to 7 days for unverified, non-completed orders under the current cleanup job, subject to reconciliation, support, or legal exceptions | Fraud prevention, reconciliation, and operational support |
| User-action metadata (event type, counts, limited platform metadata, and optional order ID) | Up to 24 months where written to the audit table | Support and fraud prevention; request contents are not intended to be stored in this table |
| Crowdsourced data broker submissions | Indefinite (public catalog data; no user profile) | Public directory — contains no personal data |
| Browser and session storage (preferences, draft selections, and checkout/access state) | Until you clear browser data or the relevant state expires | Local functionality; some checkout, access, or recovery values may be read by the site and sent in those separate flows |
Scheduled cleanup jobs run regularly, including a daily job for stale orders, expired access records, old action-log rows, and expiring temporary entries. Aggregate statistics may be retained longer when they are not reasonably linkable to an individual; we aim to retain aggregate metrics without direct identifiers.
We do not use advertising or cross-site tracking. OfflistMe runs no Google Analytics, advertising pixels, or session-recording tools. We do use limited product analytics and operational telemetry, as described below.
We use PostHog, a third-party product-analytics service accessed through our same-origin proxy, configured as follows:
/ingest) and are forwarded server-side to PostHog; the browser is not configured to send these requests directly to a PostHog host.persistence: "memory" — it sets zero cookies and zero localStorage tracking identifiers in your browser.International transfer note: The current application routing points to PostHog's United States ingestion host. PostHog is configured to minimise client-side persistence and does not use session recordings or heatmaps here. The applicable provider terms and transfer arrangements should be checked for the current configuration.
The Platform may store functional and transaction-related state in your browser:
localStorage or sessionStorage. Checkout and access flows may also store an email address, order or provider state, access token, plan, or success state so the flow can resume.You can clear this site's storage at any time from your browser settings.
We share personal data only with the following categories of recipients, and only to the extent necessary:
| Recipient | Purpose | Safeguard |
|---|---|---|
| PayPal | Payment processing and related payment communications | Provider terms, privacy notice, and applicable transfer arrangements |
| Razorpay | Payment processing | Provider terms, privacy notice, and applicable transfer arrangements |
| Neon / Vercel | Database and hosting infrastructure | Provider terms, privacy notice, and applicable contracts |
| PostHog | Product analytics, funnel measurement, and manually captured error telemetry | Same-origin browser proxy; current routing to the United States ingestion host; provider terms and applicable transfer arrangements |
| Operational alerting provider | Support, fraud, security, and growth alerts | Limited event context may include email, IP or approximate location, device, referrer, selected broker counts, plan, and event details; access is restricted through application and provider controls |
| Law enforcement / regulators | Legal obligation, court order | Only where required by law |
We do not sell your personal data or use it for third-party advertising. We do share limited information with service providers and operational recipients when needed for the purposes described above.
Depending on your location, you may have the following rights regarding your personal data. EU/EEA and UK residents have rights under EU GDPR / UK GDPR; others may have rights under applicable local law (e.g. CCPA for California residents, PIPEDA for Canadian residents).
To exercise any of these rights, please visit our Data Rights Request page or email support@offlist.me with the subject line “Data Rights Request”. Response timing depends on your location and request. Under EU/UK GDPR, the usual period is one month, with a possible two-month extension where permitted and notified. Covered California requests have separate acknowledgement and response timelines under applicable CCPA/CPRA rules. We may ask you to verify your identity before processing your request.
Right to lodge a complaint: If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may complain to the Information Commissioner's Office (ICO).
We implement technical and organisational safeguards appropriate to the processing, including HTTPS/TLS in transit, access controls, and periodic security reviews. Our privacy-by-design approach means we minimise data collected in the first place — the best defence against a data breach is not having the data.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and affected individuals without undue delay.
Our service is not directed to individuals under 16 years of age (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately at support@offlist.me.
OfflistMe is operated from India. Your personal data may be transferred to and processed in countries outside the EU/EEA/UK, including India and the United States, where data protection laws may differ from those in your country.
Where we transfer personal data from the EU/EEA or UK to third countries, the applicable mechanism depends on the recipient and current legal and contractual arrangements. Depending on the transfer, this may include an adequacy decision, appropriate safeguards such as standard contractual clauses, or a specific derogation where its legal conditions are met. We do not treat any single provider mechanism as a blanket guarantee for every transfer.
We may update this Privacy Policy from time to time. Significant changes will be communicated via a notice on the Platform. The “Last updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
For any questions, data-rights requests, or concerns regarding this Privacy Policy or our data practices, please contact:
In accordance with the Information Technology Act, 2000 (India) and the Digital Personal Data Protection Act, 2023 (India), the above officer also serves as our grievance officer under Indian law.