Compliance and security

Built for responsible outbound operations.

CarcMail combines product-level sender safeguards, secure account access patterns, and clear data handling practices for teams running production outreach.

Sender safeguards

Daily send limits, spam checks, warmup support, and unsubscribe workflows help teams run safer campaigns.

OAuth inbox access

Google and Microsoft inbox connections use secure authorization flows and account-level sending controls.

Billing controls

Payments and subscription changes are handled through Paddle-hosted checkout and verified billing events.

Data handling

Lead, campaign, and account data are separated by user context and protected through application authorization checks.

Recipient respect

Outreach workflows support unsubscribe handling and responsible messaging practices.

Operational visibility

Campaign analytics, reply states, and logs make outbound activity easier to review and manage.

For security reviews

  • Share the compliance page with procurement or security reviewers.
  • Contact us for enterprise onboarding, account setup, and data handling questions.
  • Use the policy links below for privacy, terms, cookies, and refunds.