Privacy Policy
Effective September 24, 2026
MessageFuel sends marketing messages on behalf of the businesses that use it. This policy covers both halves of that: the information we hold about our customers, and the information we hold for them about the people they message.
1. Overview, and the two roles we play
Vadelis Labs Inc. (“Vadelis Labs”, “we”, “us”) operates MessageFuel, an SMS and email marketing platform. This policy explains what personal information we handle, why, who else sees it, how long we keep it, and what you can ask us to do about it.
MessageFuel is a product of Vadelis Labs Inc.. The company is the data controller for the information described in this policy, and it is Vadelis Labs Inc. that a privacy request, complaint or regulatory enquiry should be addressed to.
Almost every question about privacy here turns on which of two roles we are in, so it is worth being blunt about the difference:
- Account data — we decide. Information about the businesses and people who use MessageFuel: your application for access, your account, your settings, your billing contact, your support conversations, and the logs our servers keep. For this we are the controller, and this policy describes what we do with it.
- Campaign data — our customer decides. The contact lists, message content and engagement records our customers bring to or create in the platform. We hold and process that on their instructions only. For this we are a processor (a “service provider” under US state law), the customer is the controller, and their privacy policy — not this one — governs why they hold your information. Our Data Processing Addendum sets out the terms.
If a business texted or emailed you
We delivered that message; we did not choose to send it to you. Reply STOP to a text or use the unsubscribe link in an email and the opt-out is recorded immediately against that business’s list. To ask what information is held about you or to have it deleted, contact the business that messaged you — they hold the data and can act on it directly. If you cannot identify or reach them, write to Info@messagefuel.com with a copy of the message and we will pass your request to them and help where we can. See section 11.
2. Information we collect
Information you give us as a customer
- Your access request. Name, job title, work email, phone number, company name, website, industry, company size, the channels you plan to use, expected sending volume, how you collect consent, and what you intend to send. We ask about consent because we decline applications that describe purchased or scraped lists.
- Account and organisation details. Your login credentials (stored as a salted hash, never in plain text), the teammates you invite and their roles, your brand settings, your physical mailing address for CAN-SPAM footers, and your business registration details.
- Provider credentials. The API keys and authorisation tokens for the Twilio, SendGrid, Google Ads and Meta accounts you connect. These are held per organisation, are only ever read by our servers, and are never exposed to a browser. Advertising authorisation tokens are held under a stricter rule than anything else in the platform: no user-level database access to them exists at all.
- 10DLC and sender registration. If you register a messaging campaign through the platform, the business information carriers require — legal entity name, EIN or tax ID, address, website, and authorised contact — which we transmit to Twilio and on to The Campaign Registry and mobile carriers.
- Support and correspondence. What you write to us, and our replies.
Information we collect automatically
- Log data. IP address, browser and device type, pages requested, timestamps, referring page and error traces, kept by our hosting provider and our own application logs to run, secure and debug the Service.
- Session cookies. Strictly necessary cookies that keep you signed in. We do not run advertising or cross-site tracking cookies on our own site. See the Cookie Statement.
- Abuse signals. Rate-limit counters, honeypot hits and submission origins, kept so that public forms and the access-request form can be defended against automated abuse.
Information our customers bring to the platform
On behalf of our customers we store and process contact records and everything attached to them: name, mobile number, email address, custom fields the customer defines, group and label membership, inferred time zone, opt-in and opt-out status, and a consent history that records when consent was given or revoked, through what source, the exact wording shown at the time, and the IP address and browser user agent captured with it. We keep that consent record deliberately — it is the evidence a telemarketing complaint turns on.
We also store what the customer sends and what happened to it: message content, subject lines and designs, the send log per recipient, delivery receipts, carrier and mailbox provider error codes, bounces, opens, clicks, and unsubscribes.
Information we retrieve from a customer’s own systems
A customer can connect an outside system they control — a CRM, for example — and authorise us to read their contacts from it on a schedule. Where they do, we hold the credential they issue us, and we retrieve contact records and the do-not-contact status attached to them. That connection is one way: we read from their system and never write to it, and the credential is used for nothing else. They can disconnect it at any time, which deletes the credential.
A do-not-contact status retrieved this way is applied as an opt-out and is treated as permanent, per channel. Withdrawing consent in a connected system stops us contacting that person; restoring it there does not resume contact, because only the person themselves can give consent again.
Signup form submissions
Our customers can embed signup forms on their own websites. When someone submits one, we record the fields they filled in, the IP address, the browser user agent, the referring page, the consent wording displayed, and whether the submission was accepted, blocked or held for confirmation. That data belongs to the customer whose form it is.
3. How we use information
We use account data to:
- review applications, create and administer accounts, and authenticate you;
- provide, maintain, secure and support the Service, and to fix it when it breaks;
- register your brand and campaigns with carriers and authenticate your sending domains with mailbox providers;
- bill you and keep financial records;
- send account and service messages — approvals, invitations, password resets, security notices and material changes to these policies. These are not marketing and you cannot opt out of them while you hold an account;
- detect, investigate and prevent abuse, fraud, spam and security incidents, and to enforce our Acceptable Use Policy;
- understand aggregate usage in order to improve the product, and to comply with legal obligations and defend legal claims.
We use campaign data only to perform the Service for the customer it belongs to: to send the messages they compose, to the people they select, and to report back what happened. We do not use one customer’s contact list to build a product for another, we do not add their contacts to any list of our own, and we do not market to their contacts.
Legal bases, if you are in the UK, EU or EEA
Where the UK GDPR or EU GDPR applies to our processing of account data, we rely on: performance of a contract with you; our legitimate interests in securing the Service, preventing abuse and improving the product, balanced against your rights; compliance with a legal obligation; and consent where we ask for it, which you may withdraw at any time.
4. Message tracking and engagement measurement
Email sent through the platform can include an invisible one-pixel image and rewritten links, which is how an “open” and a “click” are recorded. Whether that tracking is switched on is our customer’s configuration decision, made in their own sending account. When it is on, we record that a message was opened or a link was clicked, and when.
Open figures are approximate on purpose. Mail apps with privacy protection pre-fetch images for messages the recipient never read, and image blocking hides reads that did happen. We describe opens as an estimate everywhere they appear in the product, and no decision we make about a person relies on them.
SMS carries no tracking pixel. What we record for a text is what the carrier tells us: queued, sent, delivered, undelivered or failed, with an error code where one is given.
When a customer turns on link tracking for a text, each link in it is rewritten to a MessageFuel short link unique to the recipient. Opening it records that the link was clicked and when, the browser’s user-agent string (shortened) and a one-way hash of the IP address — enough to spot automated traffic, not enough to recover the address. Link previews and security scanners that fetch the link are redirected but not counted as clicks.
6. How we protect information
- Isolation between tenants. Customer data is separated at the database level by row-level security tied to organisation membership, so a query made by one customer cannot return another customer’s rows even if the application layer is wrong.
- Encryption. Traffic is encrypted in transit with TLS; data at rest is encrypted by our database and storage providers.
- Credential handling. Provider API keys and OAuth tokens are read only by server-side code and never sent to a browser. Advertising authorisation tokens are held in a table with no user-facing read access at all; the only shape of that record which can reach a browser has the token stripped out.
- Access control. Roles limit what a teammate can see inside your organisation. Internal access to production data is limited to what is needed to operate and support the Service, and administrative access by our staff to a customer account is logged.
- Passwords. Stored as salted hashes by our authentication provider. Nobody at Vadelis Labs can read your password.
No system is perfectly secure, and we cannot guarantee that a determined attack will never succeed. If we become aware of a breach affecting your data, we will notify you without undue delay and give you what you need to meet your own notification obligations. Report a suspected vulnerability or compromise to Info@messagefuel.com.
7. How long we keep information
- Account data. For as long as your account is open, and for a reasonable period afterwards to close out billing, resolve disputes and meet record-keeping obligations.
- Campaign data. For as long as the customer keeps it. Customers can delete a contact, a campaign or an asset at any time; deletion propagates out of backups over the ordinary backup cycle.
- Consent and opt-out records. Kept after the related contact is deleted, and deliberately so. An opt-out record is what stops someone being messaged again after their contact row is gone, and a consent record is the evidence that a message was permitted when it was sent. These are held in a form that cannot be edited after the fact.
- Message logs and delivery receipts. Retained as the audit trail for a send, subject to the customer’s own deletion.
- Declined access requests. Kept so that we can recognise a repeat application and explain a prior decision.
- Server logs. Kept on a short rolling window for operations and security.
After termination, and unless you ask for an export within the window set out in the Terms of Use, we delete or de-identify customer data in the ordinary course, except where retention is required by law or by the suppression rule above.
8. Your privacy rights
Depending on where you live, you may have the right to know what personal information is held about you, to get a copy of it, to correct it, to have it deleted, to limit certain uses, to opt out of sale or targeted advertising (we do neither), and not to be discriminated against for exercising any of these. Rights under the Florida Digital Bill of Rights, the California Consumer Privacy Act as amended, and the comprehensive privacy laws of other US states are all covered here.
If the UK or EU GDPR applies to you, you additionally have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your supervisory authority.
How to exercise them
- If you have a MessageFuel account, much of it is self-service in the dashboard. For anything else, write to Info@messagefuel.com from your account address.
- If a business messaged you through us, your request belongs with that business — they decide what is held about you and why. See section 11.
We will verify a request before acting on it, usually by confirming control of the email address or phone number in question, and we will respond within the period the applicable law sets — 45 days under most US state laws, one month under the GDPR — extending it only where the law allows and telling you if we do. An authorised agent may act for you with written permission we can verify. There is no charge unless a request is manifestly unfounded or excessive.
9. If you received a message and want it to stop
You do not have to write to anyone to stop marketing messages. Both channels honour an opt-out immediately and permanently:
- Text messages. Reply STOP to the number that texted you. The opt-out is recorded the moment we receive it and applies to that business.
- Email. Use the unsubscribe link at the bottom of the message, or the one-click unsubscribe control your mail app shows. Every marketing email sent through MessageFuel is required to carry both, along with the sender’s postal address.
- Preference centre. Some emails include an “update your preferences” link, which lets you change your details and consent choices directly.
An opt-out applies to the business that messaged you, because each business holds its own list. If messages continue after you opted out, tell us at Info@messagefuel.com — include the message or the sending number or address — and we will investigate under the Acceptable Use Policy, which permits us to suspend a sender.
10. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16, and our customers must not use the platform to message children or upload their data. If you believe a child’s information has reached the platform, write to Info@messagefuel.com and we will delete it and notify the customer responsible.
11. Where information is stored
MessageFuel is operated from the United States by Vadelis Labs Inc., a Florida corporation, and our infrastructure providers store data in the United States. Delivery providers may route a message through infrastructure in the recipient’s country — that is inherent in sending a text or an email abroad.
If you are outside the United States, using the Service means your information is transferred to and processed in the United States, where privacy laws differ from those in your country. Where a transfer is subject to the UK or EU GDPR, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated by our Data Processing Addendum.
12. Other websites and embedded forms
Our customers embed signup forms on their own websites. A form is served by us and the data goes to the customer whose form it is, but the page around it is theirs, and their privacy policy governs it — including any analytics or advertising technology running on that page. Links from our site or from a message to a third-party site take you outside this policy, and we are not responsible for what those sites do.
13. Changes to this policy
We may update this policy as the platform and the law change. The effective date at the top always reflects the current version. If a change materially affects how we handle personal information, we will give account holders reasonable notice by email or in the dashboard before it takes effect. Continuing to use the Service after that date means you accept the updated policy.
14. Contact us
For privacy questions, a rights request, or to reach the person responsible for data protection at Vadelis Labs:
Vadelis Labs Inc.Attn: MessageFuel1784 NW Madrid WayBoca Raton, FL 33432United StatesInfo@messagefuel.comPlease put “Privacy” in the subject line so it is routed correctly, and tell us which email address or phone number your request concerns.