Legal
Privacy Policy
Effective date September 9, 2026
This Privacy Policy explains how Rainmaker LLC d/b/a LettersByLetter.com (“Rainmaker,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with lettersbyletter.com and the LettersByLetter print-and-mail service.
It is intended to provide CCPA/CPRA-style consumer disclosures and to describe tracking, vendor sharing, and disclosures to authorities. Our Terms of Use govern use of the Service.
1. Who we are
LettersByLetter.com is a print-and-mail software service operated by Rainmaker LLC, a Connecticut limited liability company doing business as LettersByLetter.com. Office and mailing address:
Rainmaker LLC d/b/a LettersByLetter.com7 Elm St 2R, New Haven, CT 06510
hello@lettersbyletter.com
Privacy and consumer requests: hello@lettersbyletter.com. General support: hello@lettersbyletter.com.
2. Scope
This Policy applies to personal information we process as a business when you visit the website, create an account, send mail, use the API or MCP tools, or communicate with us. If we process information solely as a service provider to a business customer, that customer’s instructions and privacy notice also apply to the data they submit (for example, their recipient lists).
3. Categories of personal information we collect
We collect the following categories, depending on how you use the Service:
| Category | Examples | Sources |
|---|---|---|
| Identifiers and account data | Name, email address, organization name, account IDs, hashed API keys | You; authentication providers |
| Contact and commercial information | Billing email, credit ledger, transaction descriptions, support messages | You; payment processors |
| Payment tokens and crypto metadata | Processor tokens or last-four references; wallet address, network, asset, and transaction hash for x402/USDC. We do not store full card numbers or private keys | You; payment processors; facilitators |
| Mailing addresses and recipients | Sender and recipient names, companies, streets, cities, states, ZIP codes, and related address-book fields | You; your agents or CSV uploads |
| Documents and user content | PDFs, composed letter text, images, and job options you submit for print and mail | You |
| Internet and device information | IP address, browser type, device type, pages viewed, referring URL, approximate location derived from IP, and similar usage data | Your device; logs; analytics |
| Cookies and similar technologies | Session cookies, preference cookies (such as theme), and analytics or pixel identifiers if enabled | Your browser; our systems; vendors |
| Inferences and security signals | Fraud, abuse, and authentication risk signals derived from account and usage data | Our systems; security vendors |
We do not require government ID in the ordinary course. If we ever collect it for verification or legal compliance, we will use it only for that purpose.
4. Cookies, pixels, analytics, and tracking
We use cookies and similar technologies that are necessary to operate the Service, such as session cookies that keep you signed in and preference cookies that remember theme or similar settings. We may also use analytics, performance, session-replay or support tools, and advertising or measurement pixels now or in the future (for example, first-party analytics, Firebase or other cloud telemetry, or third-party tags). Those tools may set cookies, read device identifiers, or collect usage data.
You can control cookies through your browser settings, including blocking or deleting cookies. Blocking strictly necessary cookies may prevent sign-in or other features from working. Where a vendor offers an opt-out or consent tool, we will honor it as implemented.
Do Not Track. Some browsers send a “Do Not Track” (DNT) signal. There is no consistent industry standard for responding to DNT. The Service does not currently respond to DNT signals. California residents may use the request methods in Section 16 to exercise CCPA/CPRA rights, including opt-out of sale or sharing if those activities apply.
5. Purposes of processing
We use personal information to:
- provide, operate, and maintain the Service, including accounts, APIs, and job status;
- compose, store, transmit, print, and mail documents through print-and-mail vendors;
- validate or normalize addresses and communicate about jobs;
- process payments, credits, invoices, and fraud screening;
- secure the Service, debug errors, and prevent abuse;
- analyze usage to improve reliability and product design;
- communicate support, product, and service messages;
- comply with law, enforce our Terms, and respond to legal process; and
- establish, exercise, or defend legal claims.
In demo mode, documents typically remain on our systems or local store and are not sent to a printer. In live mode, contents needed to fulfill a mailing are transmitted to the print-and-mail provider (currently LetterStream or a successor).
7. Legal process, government requests, and cybersecurity
We will disclose personal information, account data, mailing records, uploaded documents, and related logs when we believe in good faith that disclosure is required by law or a lawful request — including a subpoena, court order, warrant, national security process, or similar compulsory process. We may disclose without notice to you when notice is legally forbidden or would risk interfering with an investigation.
We also cooperate with lawful cybersecurity and government information-security requests, including requests associated with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and similar authorities, when we are legally required to do so or reasonably believe cooperation is necessary to protect the Service, our users, or the public.
8. California Consumer Privacy Act / CPRA-style disclosures
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, “CCPA/CPRA”) provides additional rights. This section is designed to meet those disclosure requirements in plain language. In the prior 12 months we have collected the categories listed in Section 3. We collect them from you, your devices, authentication and payment providers, and (for recipient data) from the files you upload.
California residents may request to:
- Know / access the categories and specific pieces of personal information we have collected, the categories of sources, our business or commercial purposes, and the categories of third parties with whom we disclose it;
- Delete personal information we collected from you, subject to legal exceptions (for example, completing a transaction, security, or legal compliance);
- Correct inaccurate personal information we maintain;
- Opt out of sale or sharing of personal information, as those terms are defined by CCPA/CPRA (see Section 9);
- Limit use of sensitive personal information to purposes permitted by CPRA if we use it beyond those purposes; and
- Not be discriminated against for exercising these rights.
We will verify requests using the email on your account and additional information reasonably necessary to confirm your identity. We will respond within the time CCPA/CPRA requires, generally 45 days, with one extension when reasonably necessary.
9. Sale, sharing, and cross-context advertising
We do not sell personal information for money. We do not currently share personal information for cross-context behavioral advertising as those terms are defined by CCPA/CPRA. If we begin to sell personal information or to share it for cross-context behavioral advertising, we will update this Policy and provide a “Do Not Sell or Share My Personal Information” method.
Some analytics or advertising cookies, if enabled in the future, could be treated as “sharing” under California law. You may use browser controls and the request methods in Section 16 to opt out. We do not have actual knowledge that we sell or share the personal information of consumers under 16.
10. Sensitive personal information
Depending on what you upload, User Content or addresses could include sensitive information (for example, contents of a legal or medical letter). We use that information to provide the Service you requested — transmitting it to print-and-mail vendors so the piece can be produced and delivered — and for security, fraud prevention, and legal compliance. We do not use sensitive personal information to infer characteristics for cross-context advertising.
Account log-in credentials are processed to authenticate you. Payment card data, when collected, is handled by payment processors; we receive tokens or limited metadata, not full PAN/CVV.
11. Data retention
We retain personal information for as long as needed to provide the Service, maintain your account, and fulfill the purposes in this Policy, then for a longer period if required or permitted by law (tax, accounting, dispute resolution, security, and legal holds).
- Account and billing records: for the life of the account and a commercially reasonable period afterward.
- Mailing jobs, addresses, and documents: as needed to fulfill, track, support, and evidence a mailing, then deletion or archival according to our then-current retention schedule.
- Security and server logs: for a limited operational period unless needed for an investigation.
- Demo workspaces: may be reset or deleted as we operate the demo environment.
When we delete information, residual copies may remain in backups for a limited time until those backups cycle.
12. Security
We use administrative, technical, and organizational measures designed to protect personal information, including access controls, hashed API keys, and a practice of not logging LetterStream credentials, wallet private keys, or payment-signature secrets. No method of transmission or storage is completely secure. We cannot guarantee absolute security.
13. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We do not knowingly sell or share personal information of consumers under 16. If you believe a child has provided us information, contact hello@lettersbyletter.com and we will take appropriate steps to delete it.
14. International users and U.S. processing
The Service is operated from the United States. If you access it from another country, you understand that your information will be processed in the United States, where privacy laws may differ from those in your jurisdiction. By using the Service, you acknowledge that transfer. We do not represent that the Service complies with every non-U.S. privacy regime (including GDPR) unless we have agreed in a separate written addendum.
15. Your choices
- Update profile and organization fields in account settings.
- Revoke API keys from the developers page.
- Control cookies in your browser.
- Opt out of non-essential promotional email using the unsubscribe link or by writing us. Transactional mail about jobs, security, and billing may still be sent.
- California residents may exercise the rights in Sections 8–10 using Section 16.
16. How to submit privacy requests
Email hello@lettersbyletter.com with the subject line “Privacy Request,” or write to:
Rainmaker LLC d/b/a LettersByLetter.com7 Elm St 2R, New Haven, CT 06510
hello@lettersbyletter.com
Tell us which right you want to exercise and the email on the account. We may need additional information to verify you. If we deny a request, we will explain the reason and how to appeal by replying to our decision.
17. Authorized agents
You may designate an authorized agent to submit a CCPA/CPRA request. The agent must provide written authorization signed by you, and we may still require you to verify your identity directly and confirm that you authorized the agent, unless the agent presents a valid power of attorney under California law.
18. Non-discrimination
We will not discriminate against you for exercising CCPA/CPRA rights, including by denying goods or services, charging a different price, or providing a different level of quality, except as permitted by law (for example, a reasonably related difference if you ask us to delete data that is required to provide a feature).
19. Changes to this Policy
We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Material changes will be posted on this page and, where appropriate, communicated by email or in-product notice. This Policy is effective September 9, 2026.
20. Contact
Privacy questions and consumer requests:
Rainmaker LLC d/b/a LettersByLetter.com7 Elm St 2R, New Haven, CT 06510
hello@lettersbyletter.com