Skip to content

Privacy notice

This notice covers mailhail.com and its MailHail account management, webmail and email services. It explains processing when you visit the website, create an account or use the services.

1. Controller and contact

ROOTSTA – Daniel Kürschner
Schwarzkreuzstr. 12
68526 Ladenburg, Germany
Telephone: +49 (0) 6203 9302119
Email: hallo@rootsta.de
Privacy enquiries: datenschutz@rootsta.de

ROOTSTA is the controller for website operations, customer accounts, contract administration and its own security measures. Where we process mailbox content solely on a customer's instructions, ROOTSTA acts as a processor; the customer determines the purposes and legal bases of that processing. This type of processing requires a data processing agreement under Article 28 GDPR. For a mailbox managed by your employer or another provider, you may contact that organisation; we can help identify the appropriate contact.

2. Website access and hosting

Website access involves processing IP addresses, timestamps, requested addresses, HTTP status, transferred volume and browser or referring-page information supplied by your browser. This enables page delivery, troubleshooting and protection against attacks. The basis is Article 6(1)(f) GDPR: our legitimate interest in secure, reliable operations.

Our technical infrastructure is hosted with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Connection data and data stored on the systems may be processed as part of providing that infrastructure. See Hetzner's privacy information.

The public MailHail pages use locally served design assets. We do not use advertising trackers, Google Analytics, Google Maps or reCAPTCHA on those pages. Linked websites are accessed when you select their links and have their own privacy notices.

3. Cookies and local display preferences

For sign-in requested by you, we use mh for webmail and mh_admin for account management. These cookies contain session identifiers, not passwords, and are valid for up to 14 days. The server associates the identifiers with an account; signing out ends the respective session.

When you change the display, your choice is saved locally: mh_color_mode for light/dark mode and mh_ui_scale for display size are cookies valid for up to 365 days. Corresponding Local Storage keys are mailhail-color-mode and mailhail-ui-scale; the selected message-list width uses mailhail-mail-list-width. Local Storage remains until changed or cleared in your browser. Merely loading a page does not create or renew these preferences.

This storage provides the sign-in or display explicitly requested by you, under section 25(2)(2) of the German TDDDG. Subsequent processing is based on Article 6(1)(b) GDPR for the requested service or Article 6(1)(f) for a secure, usable interface. You can clear or block cookies and website data in your browser; sign-in and saved preferences may then be unavailable.

4. Registration, account management and enquiries

We process your email address, optional display and organisation names, selected plan, verification status, authentication data, roles and settings. Passwords are stored as hashes. Sessions and verification links use time-limited identifiers. Account provision and contract-related enquiries rely on Article 6(1)(b) GDPR; organisation contacts and general enquiries rely on Article 6(1)(f), our interest in reliable communication.

Fields marked as required are needed for the relevant function, such as verifying an account or allocating a payment. Optional information may be omitted. When you contact us by email or telephone, we process your contact details and enquiry to respond.

5. Email, webmail and API

Receiving, storing, searching and sending email involves sender and recipient details, subjects, timestamps, technical message identifiers, content and attachments. We also process folders, read status, preferences, storage usage and delivery information. Data comes from you, authorised account administrators and senders contacting a managed mailbox.

When sending, we transmit the message to the selected recipient's mail server. Domain and authorisation checks require DNS queries. The server currently uses Google Public DNS, which receives queried domain names and technical query data, including our server's IP address; email content is not transmitted as a DNS query. See Google Public DNS privacy information. Technical name resolution relies on Article 6(1)(f) GDPR, our interest in reliable, secure communication.

For API access, we store permissions, a hashed access token and technical usage data such as last access and IP address. Providing the service relies on Article 6(1)(b) GDPR; the roles described in section 1 also apply to processing on customer instructions.

External email images are blocked by default. If you choose to load external media, your browser may disclose its IP address and access time to the respective provider. The choice applies to the requested retrieval and can be disabled again. Consider whether you trust the sender before loading external media.

6. Security and technical records

We process connection and event data such as IP addresses, client information, protocol, account/domain associations, timestamps, authentication outcomes, delivery status and error reasons. Administrative actions are recorded for accountability. Error or security events can include affected email addresses, message identifiers and subjects. These records support troubleshooting, access protection and abuse prevention under Article 6(1)(f) GDPR.

We use local malware and spam checks to protect the service. Automatic rules may flag or reject messages or restrict access. To request a review of a block or rejection, contact hallo@rootsta.de. Authentication and permissions limit access to accounts and administration. The web interface is provided over HTTPS. Transport encryption between mail servers also depends on support by the other server and does not provide end-to-end encryption of message content.

7. Payments through Stripe

Paid plans use a checkout page hosted by Stripe. To set up and process payment, we transmit information such as email address or customer identifier, organisation or registration identifier, plan and billing interval. You enter payment details on Stripe's page. We receive transaction/subscription identifiers and payment status and store billing events. Processing relies on Article 6(1)(b) GDPR for the transaction and Article 6(1)(c) for statutory record-keeping.

Stripe Payments Europe, Limited, Ireland, is involved for European contractual customers; other Stripe entities may act as controllers or processors depending on the service. Stripe also processes payment data for its own legal obligations and fraud prevention. Details of entities, recipients, international transfers and safeguards are in Stripe's privacy policy and the Stripe Privacy Center.

8. Recipients and international communication

Access is available as needed to responsible personnel at ROOTSTA, authorised administrators of your organisation and providers supporting hosting, payment and technical communication. Further processing by your message recipients and external services you select is subject to their privacy notices and processing terms. Disclosure to authorities or other parties takes place where legally required or necessary to establish, exercise or defend legitimate legal claims.

Email to foreign recipients, loading external media and international providers such as Stripe or Google may involve processing outside the EU/EEA, including the United States. For email, the selected recipient determines the communication destination. Provider services must meet the applicable conditions of Articles 44 onwards GDPR, such as an applicable adequacy decision or suitable safeguards including EU standard contractual clauses. You can request information about safeguards applicable to a particular provider service through our privacy contact; the linked provider information also applies.

9. Retention and deletion

Retention depends on the function, contractual relationship, your or your administrator's settings and legal record-keeping obligations. The following criteria apply separately:

To request account deletion or information about retained data, contact datenschutz@rootsta.de. A valid deletion request requires consideration of other stored copies and applicable retention duties. For customer-managed mailboxes, we coordinate with the responsible controller.

10. Your rights

Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction and data portability. You can withdraw consent for the future.

Where processing relies on legitimate interests, you may object on grounds relating to your particular situation under Article 21 GDPR. You may object to processing for direct marketing at any time.

Send requests to datenschutz@rootsta.de. You can also complain to a supervisory authority, particularly where you live or work or where a suspected infringement occurred. For our registered location, the authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany; see its contact and complaint options.

Last updated: 10 September 2026