Sestaro Sestaro

Privacy

Last updated: August 24, 2026

1. Data controller

Sestaro, operated by LaFactory, is the controller of the personal data described in this policy. For any question, contact us at the address shown on lafactory.online.

2. Data concerned

Two categories: on one hand our customers' account data (name, email, purchase and unlock history); on the other hand the B2B professional data in our prospecting database (name, job title, company, professional email and phone, public profile).

3. Sources of B2B data

Professional data is sourced from public and professional sources. Every email is technically verified before being made available. We do not process sensitive data.

4. Legal basis and purposes

Processing of B2B data relies on legitimate interest: enabling commercial prospecting between professionals. Account data relies on the performance of the service contract.

5. Recipients

A contact record is only disclosed to an identified customer who spent a sestaro to unlock it. We do not resell bulk lists and never publish any data publicly.

6. Retention

Account data is kept for as long as the account is active. B2B data is updated or deleted when it becomes obsolete or upon an objection request.

7. Your rights

You have the right to access, rectify, erase, restrict and object. To exercise the right to object, use the Remove my data form: your contact will no longer be unlockable. You may also lodge a complaint with your supervisory authority.

8. Technical device fingerprint and fraud prevention

To prevent the bulk creation of free accounts aimed at harvesting our database, we compute a technical fingerprint of the device used at sign-up and at unlock: graphics rendering characteristics, hardware configuration reported by the browser, IP address. Only hashed fingerprints are stored, never the underlying attributes, and they are used solely to detect that one device is opening an abnormal number of accounts. The legal basis is legitimate interest (service security and protection of our data), and the purpose is strictly fraud prevention: no reuse for analytics, advertising or commercial profiling. Retention: up to 180 days after the device was last active, and any new activity restarts that period from zero. A device left inactive for 180 days is deleted entirely. We keep only a minimal register: a one-way hash, a count of accounts and the dates of first and last activity. The technical detail attached to each event, including the IP address, is deleted after 4 days.

See every tracker in detail on the Cookies and trackers page

9. Google user data access

When a user chooses Connect Gmail, Sestaro requests openid, userinfo.email and https://www.googleapis.com/auth/gmail.send. Sestaro receives the connected Google Account email address and OAuth access and refresh tokens. The Gmail Send permission is used through the Gmail API users.messages.send endpoint to submit only the test messages and campaign messages that the user creates or schedules in Sestaro. Sestaro does not request or receive inbox messages, message history, attachments, contacts, drafts, labels or mailbox search results, and cannot read, modify or delete mailbox content.

10. How Sestaro uses Google user data

The Google Account email address identifies the connected sending mailbox in the interface and keeps the sender identity and daily sending limit aligned with that mailbox. OAuth tokens are used only to authenticate Gmail API calls for test messages and campaign messages explicitly created, scheduled or launched by that Sestaro user. Google user data is not used for advertising, profiling, credit decisions, data brokerage, AI or machine-learning model training, or any purpose unrelated to the visible Gmail sending feature. Sestaro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Read the Google API Services User Data Policy

11. Sharing, transfer and disclosure of Google user data

Sestaro does not sell Google user data and does not share it with advertisers, data brokers or unrelated third parties. The connected address and encrypted OAuth tokens are processed by Sestaro and its infrastructure hosting providers only as necessary to operate the user-facing Gmail sending feature, under confidentiality and security obligations. Message content created by the user is transmitted to Google Gmail and to the recipients selected by the user. Sestaro may disclose Google user data only when required by law, to investigate abuse or protect the service, or as part of a merger, acquisition or sale of assets after obtaining any consent required by Google policy. No human reads mailbox content because Sestaro never receives it.

12. Protection and retention of Google user data

All OAuth exchanges and Gmail API calls use HTTPS/TLS. Access and refresh tokens are encrypted at rest with application-level encryption, excluded from mass assignment and model serialization, and never displayed in the interface. Access to the Gmail connection is restricted to the authenticated Sestaro account. Tokens are not logged after successful authorization or sending. The connected email address, encrypted tokens and expiry metadata are retained until the user disconnects Gmail or replaces the connection. Disconnect Gmail revokes the grant at Google and immediately clears the stored address, tokens and expiry data. If Google revokes access, Sestaro stops sending and requires the user to reconnect.

Remove my data