SmartSMTP Privacy Policy
1. SmartSMTP Privacy Policy
ThemeGrill (“we,” “our,” or “us”) develops and maintains the SmartSMTP WordPress plugin. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you install or use SmartSMTP on your WordPress website.
By installing and configuring SmartSMTP, including any email mailer integrations such as the Google Gmail mailer, you agree to the practices described in this policy.
This policy applies to:
- The SmartSMTP WordPress plugin and its settings interface
- Any OAuth authorization flows initiated through the plugin (e.g., connecting your Gmail account)
- Our website at https://themegrill.com/plugins/smart-smtp/ where you may download or manage the plugin
2. Information We Collect
2.1 Plugin Configuration Data
When you configure SmartSMTP, the following data is stored locally in your WordPress database:
- SMTP server settings (host, port, encryption type)
- Sender name and email address
- OAuth tokens (e.g., access tokens and refresh tokens for Gmail) — stored encrypted in your WordPress database
- Mailer-specific configuration (selected mailer, API keys, client credentials)
2.2 Email Logs (Optional)
If you enable email logging within SmartSMTP, the plugin may store sent email metadata — such as recipient address, subject line, send date/time, and delivery status — in your WordPress database. Email body content may also be logged depending on your settings. This data never leaves your server unless you explicitly export it.
2.3 Usage & Diagnostic Data (Optional)
With your explicit opt-in consent, SmartSMTP may send anonymized usage data (such as active mailer type and PHP/WordPress versions) to help us improve the plugin. This is entirely optional and can be declined during setup or disabled at any time in the plugin settings.
3. Google API & Gmail Permissions
Important: This section applies only if you choose to use the Google Gmail mailer within SmartSMTP. If you use a different mailer (e.g., SendGrid, Mailgun, or SMTP), this section does not apply to you.
3.1 Permissions Requested
When you connect your Google account to SmartSMTP via the Gmail mailer, you will be prompted to grant the following OAuth permission:
- Send email on your behalf – This allows SmartSMTP to send emails through your Gmail account when your WordPress site triggers an outgoing email (e.g., contact form notifications, order confirmations, password resets).
3.2 What We Access
SmartSMTP requests only the minimum permissions required to send email on your behalf. Specifically:
- We do not read, store, index, or process the contents of your Gmail inbox.
- We do not access your Google contacts, Google Drive, or any other Google service.
- We do not use your Gmail data for advertising, profiling, or any purpose other than delivering outgoing emails from your WordPress site.
3.3 How OAuth Tokens Are Stored
After you authorize the connection, Google provides an access token and a refresh token. These tokens are:
- Stored exclusively in your own WordPress database (wp_options table), encrypted at rest.
- Never transmitted to or stored on ThemeGrill’s servers.
- Used solely to authenticate outgoing email requests to Google’s Gmail API on your behalf.
3.4 Revoking Access
You can revoke SmartSMTP’s access to your Google account at any time by:
- Visiting your Google Account Permissions page and removing SmartSMTP, or
- Disconnecting the Gmail mailer directly within the SmartSMTP plugin settings in your WordPress dashboard.
SmartSMTP’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Information
We use the information collected solely for the following purposes:
- Delivering email: Authenticating and routing outgoing emails from your WordPress site through your chosen mailer.
- Plugin functionality: Storing configuration settings so SmartSMTP operates correctly between sessions.
- Support: If you contact our support team, we may use information you share to diagnose and resolve issues.
- Plugin improvement: If you opt in to usage data sharing, aggregated and anonymized data may help us prioritize features and fix bugs.
We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising or marketing purposes beyond our own product communications (with your consent).
5. Data Sharing & Third Parties
5.1 Email Service Providers
When SmartSMTP sends an email, it communicates with the email service you have configured (e.g., Google Gmail API, SendGrid, Mailgun). The data transmitted includes the email content, sender address, and recipient address — this is inherent to email delivery. Each service provider’s own privacy policy governs how they handle this data.
5.2 No Data Sales
ThemeGrill does not sell any personal data to third parties, ever.
5.3 Legal Requirements
We may disclose information if required to do so by law or in response to a valid legal process (e.g., a court order or government request), provided we are legally permitted to notify you.
6. Data Storage & Security
All plugin configuration data — including OAuth tokens — is stored within your own WordPress installation. ThemeGrill does not operate a central server that stores your credentials or email content.
We implement commercially reasonable technical and organizational measures to protect data handled by our plugin, including:
- Encryption of sensitive credentials (OAuth tokens, API keys) stored in the WordPress database
- Nonce-based request validation for all plugin admin actions
- Sanitization and escaping of all inputs and outputs per WordPress security best practices
You are responsible for maintaining the security of your WordPress installation, including keeping WordPress core, plugins, and themes updated.
7. Data Retention
Plugin configuration data is retained in your WordPress database for as long as the plugin is active. When you deactivate and delete SmartSMTP, you may also delete any stored settings via the plugin’s uninstall cleanup routine.
Email log data (if logging is enabled) is stored in your database and can be manually cleared from the SmartSMTP dashboard at any time.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Correction: Ask us to correct inaccurate data.
- Deletion: Ask us to delete your data, subject to legal obligations.
- Objection: Object to certain types of data processing.
- Portability: Request a machine-readable copy of your data where applicable.
Because most data is stored on your own server, you can exercise many of these rights directly through your WordPress dashboard. For data we may hold (e.g., support tickets or opt-in usage data), please contact us using the details in Section 11.
9. Children’s Privacy
SmartSMTP is intended for use by website administrators and is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or plugin features. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, notify users via the plugin or our website.
Continued use of SmartSMTP after changes are posted constitutes acceptance of the revised policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
ThemeGrill
Email: [email protected]
Website: https://themegrill.com and https://themegrill.com/plugins/smart-smtp/
