Home · Pricing · Help centre · Terms · Privacy · Cookies · Acceptable use · Sign in
Privacy Policy
What Rondinemail collects, why, and how long we keep it. No ads, no selling data, spy pixels removed, and mail stored encrypted in Bologna and Milan under EU law.
Who we are
This Privacy Policy is provided by Rondinemail S.r.l., with its registered office at Via dell’Indipendenza 44, 40121 Bologna (BO), Italy, VAT number (P.IVA) IT04567890371 (“Rondinemail”, “we”, “us” or “our”). Rondinemail is the controller of the personal data described in this policy for the purposes of Regulation (EU) 2016/679 (the “GDPR”) and Legislative Decree no. 196/2003, as amended (the “Italian Privacy Code”). This policy is the information notice required by Article 13 GDPR and, for people whose personal data we receive from others, by Article 14 GDPR.
This policy applies to the Rondinemail email service, including @rondinemail.com addresses, custom domains connected to Rondinemail, the web application and every feature described below (together, the “Service”), and to our website at rondinemail.com (the “Website”). It also applies when you contact our support team or leave feedback in our help centre.
Where this policy refers to “you”, it means anyone whose personal data we process in connection with the Service or the Website: account holders, members of Stormo plans, visitors to the Website and people who write to, or receive mail from, Rondinemail users. For any question about this policy or about your personal data, write to privacy@rondinemail.com.
Information you give us
Account details. When you create an account, we collect your name, your chosen @rondinemail.com address and your password. We never store your password in readable form; we keep only a cryptographic hash of it. If you sign in with a passkey, we store only its public key, and the private key never leaves your device. You may also give us a recovery email address or a recovery phone number, so that you can regain access to your account if you lose it.
Billing details. If you subscribe to Casa (€3 per month) or Stormo (€5 per person per month), we collect the billing details needed to charge you and to issue invoices, such as your billing name and address, your plan and your payment history. Card payments are handled by a payment provider certified under the Payment Card Industry Data Security Standard (PCI DSS). You enter your card details directly with that provider, and we never see or store your full card number. Nido, our free plan, requires no payment details.
Support conversations and feedback. When you write to aiuto@rondinemail.com or otherwise contact our support team, we keep the conversation and any information you choose to include, so that we can resolve your request and refer back to it if the problem recurs. If you leave feedback in our help centre, we keep what you tell us so that we can act on it.
Settings and choices. We store the settings you choose, such as your aliases, custom domains, Away mode messages and scheduled messages, so that the Service works the way you have asked it to.
Providing your account details is a contractual requirement: without a name, an address and a means of signing in, we cannot create or operate your account. Recovery details are optional, but without them we may be unable to restore your access if you lose your password or your device. Billing details are required only for paid plans.
Your mail and contacts
Mail and contacts. We store the messages you send and receive, their attachments, your folders and the contacts you keep in Rondinemail. We process this content solely to provide the Service to you: to deliver, store, sync, search and display your mail and contacts, and to run the features described in this section.
Come home. If you choose to import your mail, contacts and folders from Gmail, Outlook, iCloud or Yahoo, you grant us access through your previous provider. We use that access only to carry out the import you have requested, and we revoke it as soon as the import is complete. We do not keep ongoing access to your other account, and nothing is imported without your authorisation.
Return to sender. Before a message leaves Rondinemail, we check the recipient’s domain and address so that, if the message cannot be delivered, it comes back to you within seconds with a plain explanation of what went wrong. The check relies on the recipient address and on information about the recipient’s mail domain; it does not involve reading the content of your message.
Away mode. When you turn on Away mode, we send the automatic reply you have written to the people who write to you, and we hold newsletters and notifications until you return. To do this, incoming messages are recognised and sorted automatically by our systems, without any human involvement. You decide when Away mode starts and ends and what your automatic reply says.
Aliases, custom domains and scheduled sending. If you create aliases or connect a custom domain, we store the alias addresses, the domain name and the configuration needed to route mail to and from them. If you schedule a message, we store it until the time you have chosen and then send it.
Protection from trackers, spam and malware. We remove spy pixels and other tracking elements from incoming mail before a message opens, so that senders cannot use them to learn whether or when you read their message. We also apply automated filtering to incoming and outgoing mail, which examines messages, including their headers, content and attachments, solely to detect spam, phishing and malware. This filtering runs on our systems in Italy and involves no human review.
Information collected automatically
Delivery metadata. To route mail to and from your mailbox, our systems necessarily process delivery metadata: sender and recipient addresses, the IP addresses of the servers sending mail to us, timestamps and message sizes. We record this information in delivery logs, which we use to deliver mail, to investigate delivery problems and to detect and stop abuse. Delivery logs are kept for 30 days.
Security logs. When you sign in or use the Service, we record the time of each sign-in, the IP address used and the type of device and browser. We use these logs to protect your account and to detect and stop unauthorised access and abuse. Security logs are kept for 12 months.
Aggregated statistics. We compile statistics about the operation of the Service, such as message volumes, delivery rates and system performance. These statistics are aggregated, never include the content of your mail and are never used to build a profile of any individual.
The Website. The Website sets no cookies and uses no analytics, advertising or third-party tracking tools.
Information from others
People who write to you. When someone sends mail to a Rondinemail address, we receive the personal data contained in the message and its headers. We process it only to filter, deliver and store the message for its recipient and to run the features that the recipient has chosen, such as Away mode. If you write to a Rondinemail user, this policy explains how we handle your data.
Providers you import from. When you use Come home, your previous provider makes your mail, contacts and folders available to us on the basis of the access you grant. We receive only what the import requires.
Stormo administrators. If you join a Stormo plan, the administrator who adds you may give us your name and the address to be created for you.
Payment provider. Our payment provider tells us whether a payment has succeeded and gives us limited information about the payment method used, which never includes your full card number.
Cookies
The Website sets no cookies and uses no analytics. When you sign in, the web application sets one strictly necessary cookie, named “rm_session”, which keeps you signed in and protects your session. Because this cookie is strictly necessary to provide the Service you have asked for, it does not require your consent under Article 122 of the Italian Privacy Code.
We use no advertising, analytics, social media or other third-party cookies, and no similar tracking technologies. Full details are set out in our Cookie Policy at rondinemail.com/cookies.
How we use your data and why
Providing the Service. We use your account details, mail, contacts, delivery metadata and settings to create and operate your account; to send, receive, store, sync and search your mail; to carry out imports you request through Come home; to run Return to sender, Away mode, aliases, custom domains, shared addresses, scheduled sending and family administration; to remove trackers from incoming mail; to send you essential messages about your account, such as security alerts, billing notices and notice of changes to this policy; and to answer your support requests. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
Billing. We use your billing details to take payment, issue invoices and handle refunds. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR). We keep invoices and accounting records for 10 years, as required by Article 2220 of the Italian Civil Code and applicable tax law. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
Security and abuse prevention. We use security logs, delivery metadata and automated filtering to protect accounts, to detect and stop spam, phishing, malware and unauthorised access, and to keep the Service reliable. Legal basis: our legitimate interests, and those of our users and of the wider email community, in keeping mail secure and free of abuse (Article 6(1)(f) GDPR).
Mail from people who are not our users. We process the personal data of people who write to our users in order to deliver and protect that mail. Legal basis: the legitimate interests of our users in receiving, organising and replying to their own mail, and our legitimate interest in providing the Service to them (Article 6(1)(f) GDPR).
Improving the Service. We use aggregated statistics that do not include the content of your mail to understand how the Service performs and to improve it. Legal basis: our legitimate interest in maintaining and improving the Service (Article 6(1)(f) GDPR). We have weighed these interests against your rights and freedoms, and you may object to this processing at any time, as described under “Your rights”.
Product news. With your consent, we send you occasional emails about new features and changes to Rondinemail. You can withdraw your consent at any time using the unsubscribe link in each email or by writing to privacy@rondinemail.com. Legal basis: consent (Article 6(1)(a) GDPR).
Support access to your mailbox. If you ask our support team for help with a problem that requires looking at your mail and you explicitly grant time-limited access, we use that access only to resolve the problem you have described. Legal basis: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
Legal compliance and legal claims. We process personal data where necessary to comply with the law, including valid requests from competent authorities and our obligations in the event of a personal data breach, and to establish, exercise or defend legal claims. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR) and our legitimate interest in protecting our rights (Article 6(1)(f) GDPR).
What we never do
We do not show advertising in the Service or on the Website. We do not sell or rent your personal data to anyone. We do not track you across other websites or services, and we do not profile you, or anyone who writes to you, for marketing or any other purpose.
We never use the content of your mail or your contacts for advertising, to build profiles or for any purpose other than providing the Service to you.
No person at Rondinemail reads your mail. There are only two exceptions: where you ask our support team for help and explicitly grant time-limited access, in which case access is limited to what you authorise and ends when that period expires; and where the law requires it, as described under “Who we share it with”.
Shared addresses and Stormo plans
Family administration. On the Stormo plan, an administrator manages the plan on behalf of its members. The administrator can add and remove members, manage members’ accounts and handle billing for the plan, and for that purpose can see members’ names, addresses and the status of their accounts. The administrator cannot read members’ mail, contacts or folders, and the Service gives administrators no means of doing so.
Shared addresses. On the Stormo plan, an address can be shared between several members. Messages sent to or from a shared address, and the related delivery information, are visible to every member who has access to that address. Please bear this in mind before using a shared address for personal correspondence.
Each member of a Stormo plan has the same rights under this policy as any other Rondinemail user, and may exercise them directly with us.
Who we share it with
We disclose personal data only to the categories of recipient described in this section. Providers that process personal data on our behalf act as our processors: they act only on our documented instructions, under a written agreement that meets the requirements of Article 28 GDPR, and are bound by obligations of confidentiality and security.
Our processors fall into the following categories: data-centre providers in Italy, which host the infrastructure in Bologna and Milan where your mail and account data are stored; our payment provider, which is certified under PCI DSS and processes card payments for paid plans; a transactional email delivery provider, which delivers account notices such as security alerts and billing notices; and a customer support tool hosted in the European Union, which stores support conversations so that we can answer them. A current list of our processors is available on request from privacy@rondinemail.com.
To the extent that our payment provider processes personal data for its own purposes, such as preventing fraud and meeting its own legal obligations, it does so as an independent controller under its own privacy notice.
Authorities. We disclose personal data to courts, law enforcement agencies or other public authorities only where we are required to do so by applicable law, in response to a valid request or order from a competent authority. We examine every request, and we disclose only the data that the request specifically and lawfully requires.
Other disclosures. We may disclose personal data to professional advisers, such as lawyers, auditors and accountants, who are bound by professional secrecy or confidentiality. If Rondinemail is involved in a merger, acquisition or sale of all or part of its business, personal data may be transferred to the entity that takes over the Service, which will remain bound by this policy, and we will tell you in advance.
When you send an email, the Service necessarily delivers it, together with its headers, to the recipients you choose and to their mail providers. That is a disclosure you direct, not one we make on our own initiative.
Where your data lives
Your mail and account data are stored in data centres in Bologna and Milan, Italy. They are encrypted at rest and in transit and remain subject to the law of the European Union and of Italy.
We do not routinely transfer personal data outside the European Economic Area (EEA). If one of our processors ever transfers personal data to a country outside the EEA, the transfer is made only to a country covered by an adequacy decision of the European Commission under Article 45 GDPR, or under the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, together with any supplementary measures required.
When you send mail to someone whose mail provider is located outside the EEA, we deliver the message to that provider because you have asked us to. Such deliveries are necessary for the performance of our contract with you (Article 49(1)(b) GDPR).
You may request a copy of the safeguards that apply to any transfer by writing to privacy@rondinemail.com.
How long we keep it
While your account is open, we keep your account details, mail, contacts and settings for as long as you keep them in the Service. Messages you delete are moved to the Bin and permanently deleted 30 days later. Access granted for Come home is revoked as soon as the import is complete.
Delivery logs are kept for 30 days. Security logs are kept for 12 months. Support conversations and help-centre feedback are kept while your account is open and are deleted with your account data.
If you close your account, your mail and account data are deleted from our live systems within 30 days. Copies held in our backups are removed as the backups rotate, within a further 30 days, so that all copies are gone within 60 days of closure.
There are two exceptions. First, we keep your @rondinemail.com address and the forwarding destination you choose, so that we can forward your mail for life and so that your address is never reassigned to anyone else. We keep them until you ask us to stop, which you can do at any time by writing to privacy@rondinemail.com. Second, we keep billing records for 10 years, as required by Article 2220 of the Italian Civil Code.
We may keep specific data for longer only where this is necessary to establish, exercise or defend a legal claim, and only for as long as that need lasts.
How we protect it
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. Your mail and account data are encrypted at rest and in transit, using TLS for connections to and from our systems wherever the other party supports it.
Our staff’s access is granted on a least-privilege basis: each person can reach only the systems and data needed for their role, and administrative access is recorded in audit logs. Our security is tested regularly by independent specialists.
You can strengthen the protection of your account by signing in with a passkey, turning on two-step sign-in and keeping your recovery details up to date.
No system is entirely immune to attack. If a personal data breach occurs, we will notify the Garante per la protezione dei dati personali within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms, and we will inform affected users without undue delay where the breach is likely to result in a high risk to them, as required by Articles 33 and 34 GDPR.
Your rights
Under the GDPR you have the right to access your personal data and receive a copy of it (Article 15); to have inaccurate or incomplete data rectified (Article 16); to have your data erased (Article 17); to restrict our processing of it (Article 18); to receive the data you have provided to us in a structured, commonly used and machine-readable format and to have it transmitted to another controller (Article 20); to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Article 21); and to withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Article 7(3)).
You also have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22). We make no such decisions. Spam filtering, Return to sender and the sorting used by Away mode are automated, but they do not have effects of this kind, and you can always review the messages filtered as spam.
In Settings → Privacy you can access, export and delete your data yourself. Mail can be exported in MBOX or EML format and contacts in vCard format. You can exercise any of your rights there or by writing to privacy@rondinemail.com. We may need to confirm your identity before acting on a request, normally by asking you to make it while signed in or from your Rondinemail address. Exercising your rights is free of charge.
We answer every request within one month of receiving it. Where a request is particularly complex, or we receive a large number of requests, the GDPR allows us to extend this period by up to two further months; if we need to do so, we will tell you within the first month and explain why. Some rights are subject to limits set by law: for example, we cannot erase billing records that we are required to keep.
If you live outside the European Union, your data is still stored in Italy and protected under EU law, and you can exercise all the rights described in this section. If the law of the place where you live gives you further rights, such as the rights of California residents under the California Consumer Privacy Act, we honour them. We do not sell or share personal information, as those terms are defined under California law, and we use sensitive personal information only to provide the Service.
How to complain
You have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). Our supervisory authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy (www.garanteprivacy.it).
If you live or work in another country of the European Union, or believe that an infringement took place there, you may instead complain to the data protection authority of that country. You also have the right to an effective judicial remedy against us before the competent courts (Article 79 GDPR).
We would welcome the chance to put things right first, so please write to privacy@rondinemail.com if you have a concern.
Children
You must be at least 14 years old to create or use a Rondinemail account, in line with Article 2-quinquies of the Italian Privacy Code (Legislative Decree no. 196/2003, as amended). This applies to every account, including accounts created within a Stormo plan. The Service and the Website are not directed at children under 14, and we do not knowingly collect their personal data.
If we discover that an account belongs to a child under 14, we close the account and delete its data in line with this policy. If you believe that a child under 14 is using Rondinemail, please write to privacy@rondinemail.com.
Changes to this policy
This version of the Privacy Policy was last updated on, and takes effect from, 1 September 2026. We may update it to reflect changes in the Service, in our practices or in the law, and the date at the top of this page always shows when it was last revised.
If we make a material change, we will notify you by email at least 30 days before the change takes effect, unless the law requires the change to apply sooner. Where a change requires your consent under applicable law, we will ask for it.
Contact us
The controller of your personal data is Rondinemail S.r.l., Via dell’Indipendenza 44, 40121 Bologna (BO), Italy, VAT number (P.IVA) IT04567890371.
For questions about this policy or to exercise your rights, write to privacy@rondinemail.com. For help with your account, write to aiuto@rondinemail.com.
You may also contact the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma (www.garanteprivacy.it), or the data protection authority in your own EU country.