Terms of Service
Last updated: 23 August 2026
1. The service
Postbox (“the service”, postbox.help) is a hosted support inbox: it receives messages from your website’s contact form and forwarded email, stores them as tickets, and sends your replies as email on your behalf. The service is currently provided on an invite-only basis.
Postbox is also a mailing-list product. It hosts a double opt-in signup form for your workspace, keeps the subscribers who confirm through it, and is built to send newsletters and campaigns to those lists. Sections 5 and 6 set out the terms for that.
2. Accounts
You are responsible for activity under your account and for keeping your sign-in method secure. You must provide accurate information and be authorised to act for the business your workspace represents.
3. Acceptable use
Don’t use Postbox to send spam or unlawful content, to violate others’ privacy, or to attempt to access other tenants’ data. We may suspend workspaces that threaten the service’s integrity or email deliverability.
Deliverability is shared. Postbox sends from infrastructure used by every workspace, so one sender’s spam complaints degrade everyone’s mail — including support replies from businesses with nothing to do with it. That is why the marketing rules below are conditions of use rather than advice.
4. Your data, and who controls it
Your tickets, contacts, messages, subscribers and campaigns remain yours. We process them only to operate the service, as described in the Privacy Policy. You can request deletion of your workspace and its data at any time, and that deletion is complete: it removes the tickets, messages, contacts, subscribers, lists, suppressions, campaigns and send logs together.
Two limits on that, stated here rather than left to be discovered. There is no way to delete an individual subscriber, contact or ticket from the dashboard; removing one person is a manual operation we carry out on request. And the self-service export covers tickets, messages and support contacts only — not subscribers, lists or campaigns. Ask us and we will produce those.
In data-protection terms: you are the controller of the people in your workspace — those who contact you and those on your lists — and Postbox is your processor. We act on your instructions and use your data for no purpose of our own. The consequence is that the legal duties owed to those people are yours: establishing a lawful basis for contacting them, answering their access and erasure requests, and being able to show a regulator why each address is on your list. We will help you meet them and will pass on any request that reaches us, but we cannot discharge them for you.
5. Sending marketing email
When you use Postbox to send campaigns, you confirm on each send that every recipient has given you permission you can evidence, or otherwise falls within a lawful basis you have identified for direct marketing. Specifically, you must not upload or mail:
- purchased, rented, scraped or otherwise third-party lists;
- addresses whose origin you cannot account for, including imports where the consent record is guessed or backfilled;
- your Postbox support contacts, unless they separately opted in to marketing. Raising a ticket is not consent, which is why the two are kept in separate lists with no way to copy between them.
As things stand, those rules are easier to keep than they sound, because Postbox gives you no way to break them: there is no import feature and no way to add a subscriber by hand. The only route onto one of your lists is someone entering their address on your signup form and then confirming it from their own mailbox. If we add an import, these rules are what will govern it, and the consent evidence it demands will not be optional.
The system also enforces two of these conditions itself rather than trusting the confirmation. A subscriber with no recorded consent timestamp is dropped from the audience and not mailed, and the composer shows you how many were dropped for that reason. And a campaign cannot be sent at all until your workspace has a legal name and a physical postal address on file, because a commercial message has to identify its sender and we would rather refuse the send than produce a message that does not.
You are responsible for the content of your campaigns, including accurate sender identification and any disclosures your jurisdiction requires.
6. Unsubscribes and suppression
Every campaign sent through Postbox carries an unsubscribe link, added by the system to both the plain-text and HTML versions of the message, plus one-click unsubscribe headers. This is not configurable and must not be circumvented — removing, obscuring or breaking it, or mailing an address after it has opted out, is grounds for immediate suspension.
An unsubscribe takes effect in the same request that carries it, and it applies across your whole workspace, not just the list the campaign drew from. Addresses that unsubscribe, hard bounce, or report a message as spam are added to your workspace’s suppression list and are skipped on every subsequent send regardless of list membership: they are excluded when a campaign’s audience is built, swept out again if they are suppressed after that, and checked once more immediately before each message is handed to the provider. Re-importing or re-signing-up a suppressed address does not clear the suppression, and asking us to clear one for a person who opted out is a request we will refuse.
Temporary delivery failures are treated differently and do not suppress anyone: a full mailbox is recorded against that message in your report and nothing is blocked.
We may throttle, pause or stop a campaign that is generating bounces or complaints at a rate that threatens delivery for other workspaces, and we will tell you when we do.
7. Availability & changes
The service is provided “as is”, without warranty of uninterrupted availability. Features may change as the product evolves; material changes to these terms will be notified to the account email. Email delivery depends on third parties and on receiving mail servers, so we cannot guarantee that any individual message arrives or reaches an inbox rather than a spam folder.
8. Liability
To the maximum extent permitted by law, our liability for any claim arising from the service is limited to the amount you paid for it in the preceding 12 months. Nothing here limits liability that cannot lawfully be limited. Claims arising from marketing you chose to send — to recipients you selected, with content you wrote — are yours, and you will cover us for penalties or third-party claims caused by a breach of sections 3, 5 or 6.
9. Contact
Questions about these terms: reply to any Postbox email, or contact your account provider.