Privacy Policy
Last updated 12 July 2026
This policy explains how The Empire Holding B.V. handles personal data in connection with the hosted editions of Messy and the messy.sh website. The self-hosted, open-source edition runs on your own infrastructure and we never see what passes through it.
1. Who we are
The controller for the personal data described in this policy is The Empire Holding B.V. (Netherlands Chamber of Commerce / KvK no. 76281310), Coolhaven 238A, Rotterdam, the Netherlands. For any privacy question or to exercise your rights, contact privacy@messy.sh.
2. Our two roles
It matters in which capacity we handle data:
- As controller for the data we decide how to use: your account and billing details, website visitors, and support communications. This policy governs that data.
- As processor for the personal data inside your Customer Content (your contacts, recipients, and message data), which we process only on your instructions. That processing is governed by our Data Processing Agreement, where you are the controller.
3. What we collect (as controller)
- Account data: name, email, organisation, and the credentials needed to sign you in (we use passwordless magic-link login).
- Billing data: plan, subscription status, and the billing details and tax IDs needed for invoicing. Card details are handled by Stripe; we do not store full card numbers.
- Usage and technical data: log, device, and diagnostic data such as IP address, timestamps, and actions taken, used to operate and secure the Service.
- Support and communications: messages you send us and our replies.
- Website data: limited analytics and essential cookies on messy.sh.
4. Why we use it and our legal bases
- To provide the Service and perform our contract with you (Art. 6(1)(b) GDPR).
- To secure, maintain, and improve the Service, prevent abuse, and for analytics, on the basis of our legitimate interests (Art. 6(1)(f)).
- To bill you and keep records, to perform our contract and to meet legal and tax obligations (Art. 6(1)(b) and (c)).
- To communicate with you about the Service, and, where required, with your consent (Art. 6(1)(a)).
5. What we do not do
We do not sell your personal data. We do not use the contents of your messages or your contacts to advertise, or to train machine-learning models. Your data is used to run the Service for you.
6. Recipients and subprocessors
We share personal data only with the service providers (subprocessors) that help us operate the Service, under contracts that require them to protect it and use it only on our instructions. The providers we currently use are:
- Hetzner Online GmbH (Germany): the servers and managed PostgreSQL database, hosted in the European Union, that run the Service.
- Cloudflare: DNS, CDN, TLS, and hosting of the messy.sh website.
- Stripe: subscription billing and invoicing. Card details are entered with and held by Stripe; we do not store full card numbers.
- Amazon Web Services (Amazon SES): transactional and campaign email delivery (EU region).
- Twilio: SMS delivery.
- Meta Platforms (WhatsApp Cloud API): WhatsApp delivery.
- Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service): mobile and web push delivery.
On Bring-Your-Own-Keys plans, the messaging providers above are accessed through your own provider accounts and credentials, so your relationship with them is governed by their terms. A current, named list of subprocessors, including their roles and locations, is available on request at privacy@messy.sh. We may also disclose data where required by law or to protect our rights, and to a successor in connection with a merger, acquisition, or sale of assets.
7. The self-hosted edition
Messy is also available as open-source software you run on your own infrastructure. When you self-host, you (or your organisation) are the independent controller for all data in that deployment, including account, usage, and Customer Content. The Empire Holding B.V. operates no servers for it, receives no data from it, and has no access to it. This policy and our subprocessor list cover only the hosted editions we run; a self-hosted operator is responsible for its own privacy notice and its own choice of email, SMS, push, and hosting providers.
8. International transfers
We aim to keep data within the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with additional measures where needed.
9. Retention
We keep account and billing data for as long as your account is active and afterwards as needed to meet legal, tax, and accounting obligations (invoices are typically retained for the period required by law). Logs and diagnostic data are kept for a limited period. Customer Content is retained per your account settings and deleted as described in the DPA after termination, except where we must retain records by law.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, network protections, and rate limiting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on it. To exercise these rights, contact privacy@messy.sh; you can also export or delete account data from within the Service. We will respond within the time limits the law requires.
If you are in the EEA and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
Where personal data relates to your own end-users (your contacts and recipients), please direct rights requests to the customer who controls that data; we will assist that customer as their processor.
12. Cookies
The website uses essential cookies needed to operate it and limited analytics to understand usage. The application uses storage necessary to keep you signed in and to remember your preferences. You can control cookies through your browser settings.
13. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
14. Changes
We may update this policy from time to time. If a change is material, we will notify you by email or in the app. The “last updated” date above shows when it last changed.
15. Contact
The Empire Holding B.V., Coolhaven 238A, Rotterdam, the Netherlands · privacy@messy.sh.