Privacy Policy

Last updated: 16 February 2026

1. Who We Are

Mezze is a financial newsletter service operated from the United Kingdom. This policy explains how we collect, use, and protect your personal data when you use our service at mezze.xyz.

2. What We Collect

Account information: Your email address. If you sign up via Google or Apple, we receive only your email address from those providers. Passwords are handled entirely by our authentication provider (Supabase) — we never see or store your password.

Newsletter preferences: Your selected modules, delivery time, timezone, and days of the week you want to receive newsletters.

Referral data: If you join via a referral link, we record which user referred you. If you share your referral link, we track how many users signed up through it.

Email delivery data: Our email provider (Mailgun) tracks whether emails are delivered, opened, and clicked. We use this data to monitor delivery health and identify issues — not for marketing profiling. This data is automatically deleted after 90 days.

Website analytics: We collect basic website traffic data from server access logs (CloudFront), including IP addresses, pages visited, and browser user agent strings. We use this to understand traffic patterns and filter out bot traffic. We do not use any third-party analytics services (no Google Analytics, no tracking pixels, no fingerprinting).

3. What We Do Not Collect

  • Your name, phone number, or physical address
  • Payment or financial information (the service is free)
  • Your browsing activity outside of mezze.xyz
  • Device fingerprints or advertising identifiers

4. How We Use Your Data

  • Email address: To send you your configured newsletter and essential service communications
  • Preferences: To personalise your newsletter content and delivery schedule
  • Delivery data: To monitor email deliverability, detect issues (such as IP blocklisting), and maintain sender reputation
  • Website logs: To understand traffic patterns and maintain the service

5. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase — Authentication and user data storage. Handles password security, OAuth flows, and session management.
  • Mailgun — Email delivery. Processes your email address to send newsletters and tracks delivery events.
  • Cloudflare Turnstile — CAPTCHA verification during signup to prevent abuse. Cloudflare may process limited device data for bot detection.
  • Google Fonts — Font delivery via CDN. Google may collect basic request metadata.
  • Amazon Web Services (AWS) — Infrastructure hosting, including CloudFront CDN and server-side processing.
  • X (Twitter) Conversion Tracking — We measure the effectiveness of our advertising campaigns on X using two methods: (1) a client-side conversion pixel that may set a cookie when you visit after clicking an X ad, and (2) a server-side integration that sends a one-way hash (SHA-256) of your email address to X's Conversion API. The server-side integration only fires if you arrived at mezze.xyz from X (detected via referrer or campaign parameters) — users who arrive from other sources are not included. Neither method tracks your browsing activity on other websites. See X's Privacy Policy for details.

We do not sell, rent, or share your personal data with advertisers or data brokers.

6. Data Retention

  • Account data: Retained until you delete your account
  • Email delivery events: Automatically deleted after 90 days
  • Website access logs: Retained for up to 30 days

7. Account Deletion

You can request account deletion from your profile settings at any time. There is a 7-day grace period during which you can cancel the request. After 7 days, your account and all associated data (preferences, email events, referral data) are permanently deleted.

8. Your Rights

Under UK data protection law (UK GDPR), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to processing of your data
  • Request a portable copy of your data

To exercise any of these rights, contact us at support@mezze.xyz.

9. Security

We take reasonable measures to protect your data, including encrypted connections (HTTPS), secure authentication via Supabase, and access controls on our infrastructure. However, no system is perfectly secure, and we cannot guarantee absolute security.

10. International Users

Our service is hosted on AWS infrastructure primarily in the United States (us-east-1). If you access the service from outside the US, your data will be transferred to and processed in the US. By using the service, you consent to this transfer.

11. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact

For privacy-related questions or requests, contact us at support@mezze.xyz.