SameDayNotice.Verified recipient access. Timestamped records. USPS Certified Mail available.
CONFIDENTIAL DRAFT — NOT FOR PUBLICATION
# SameDayNotice Privacy Policy — Draft for Counsel Review (Not for Publication)
CONFIDENTIAL DRAFT — NOT FOR PUBLICATION. Draft date: October 3, 2026. Status: Prepared for licensed-counsel review only. This draft must not be posted, distributed to customers, or relied upon until the facts, vendor contracts, retention schedule, Terms of Service, and applicable legal requirements have been reviewed and approved.
Information Needed Before Publication — the following facts must be confirmed and incorporated before publication: 1. Legal entity and business name: Confirm whether the publishing entity is Certified Mail Envelopes, Inc., doing business as SameDayNotice, and identify any other entity that owns, operates, or provides the SameDayNotice service. 2. Mailing address: [Company Mailing Address]. 3. Privacy contact: [Privacy Contact Email] and [Privacy Request URL, if applicable]. 4. Vendor names and roles: confirm the identity, location, contractual role, and data-processing terms for providers of cloud hosting and storage; email delivery; SMS or one-time-code delivery; identity verification and authentication; print and mail fulfillment; postage and USPS-related services; payment processing; customer support and ticketing; security monitoring, malware scanning, and logging; analytics, cookies, and website functionality. 5. Hosting and processing locations: [Hosting and Processing Locations]. 6. Analytics and advertising tools: confirm whether any analytics, advertising, retargeting, session-recording, heat-map, social-media, or similar tools operate on the marketing website. The current product design does not use open or click tracking, tracking pixels, or link rewriting in document-invitation emails; this must be verified against the deployed configuration. 7. Retention periods: confirm retention periods for account information, uploaded documents, portal activity, consent records, postal records, billing records, support records, security logs, backups, and legal holds. 8. International users: confirm whether SameDayNotice serves or intentionally targets individuals in the European Economic Area, the United Kingdom, Switzerland, Canada, or other jurisdictions outside the United States. 9. Regulated data: confirm whether customers may upload or transmit health, financial, government-identification, biometric, employment, litigation, or other sensitive information, and identify any applicable sector-specific obligations. 10. State-law applicability: confirm which U.S. state privacy laws apply based on the company's revenue, data volume, business activities, and customer locations. 11. Terms of Service: reconcile this Policy with the final Terms of Service, customer agreement, data-processing addendum, security addendum, and service-level commitments. 12. Consumer-request procedures: confirm the personnel, systems, verification process, response deadlines, appeal process, authorized-agent process, and recordkeeping procedures for privacy requests.
1. Introduction — Certified Mail Envelopes, Inc., doing business as SameDayNotice ("SameDayNotice," "we," "us," or "our"), provides a legal and regulatory communications platform that supports verified electronic notice, recipient authentication, consent tracking, evidence records, and sender-ordered physical mailing services. This Privacy Policy describes how SameDayNotice collects, uses, discloses, retains, and protects personal information through: the SameDayNotice website, including www.samedaynotice.com; the SameDayNotice portal and related software services; customer accounts and billing activities; notice, document, identity, consent, postal, and fulfillment workflows; and communications with customers, recipients, and other individuals who interact with us. This Policy is a draft for counsel review and does not become effective until published with an approved effective date.
2. Roles and Scope — 2.1 Customer-controlled notice information: In most cases, the SameDayNotice customer—the organization sending a notice—is responsible for determining: which individuals receive a notice; what information is uploaded; the purpose and legal basis for sending the notice; the applicable retention period; whether a physical or electronic communication is legally appropriate; the sender's disclosure and consent obligations; and how recipient privacy requests should be handled. For these customer-controlled activities, the customer generally acts as the controller, business, or comparable decision-maker for notice and recipient information. SameDayNotice generally acts as the customer's service provider, processor, or comparable data processor, processing information according to the customer's instructions and applicable agreement. A recipient who has received a notice should generally direct questions about the notice, its content, the sender's legal authority, and the sender's use of recipient information to the organization that sent the notice. SameDayNotice may assist with routing the request to that organization where appropriate. 2.2 SameDayNotice-controlled information: SameDayNotice acts as a business, controller, or comparable decision-maker for information relating to our own activities, including: visitors to the marketing website; SameDayNotice account administrators and users; billing and payment administration; customer support; security, fraud prevention, and service reliability; website operation and communications about our services; legal, regulatory, and compliance obligations; and corporate administration and business transactions. The applicable role may depend on the nature of the information, the relationship with the individual, the customer agreement, and applicable law.
3. Personal Information We Collect — 3.1 Sender and account information: we may collect name; business email address; business telephone number; organization, department, and job title; username and account identifiers; login credentials, stored using hashing or comparable protective measures; authentication and account-recovery information; account preferences and permissions; customer-service communications; contract and order information; billing and invoicing information; and payment information handled by our payment processor. We do not intend to store complete payment-card information when that information is handled directly by a third-party payment processor. The payment processor's privacy practices and terms may also apply. 3.2 Recipient and notice information: when a customer uses SameDayNotice to send a notice, the customer may provide recipient name; sender-supplied email address; postal address; relationship between the sender and recipient; organization or representative information; the uploaded notice or other document; document versions and document metadata; sender-supplied information about the source, provenance, authority, or permitted use of the information; and information necessary to identify the intended recipient or authorized representative. SameDayNotice does not independently determine whether the sender has legal authority to use recipient information or whether a particular notice method satisfies applicable law. Uploaded documents may contain personal, confidential, financial, health, employment, litigation, or other sensitive information. Customers should upload only information reasonably necessary for the intended notice and should follow their own legal, regulatory, and security obligations. 3.3 Portal activity and consent information: depending on the service configuration, we may collect registration and account-verification events; multifactor-authentication events; authentication method and result; identity-verification method and result; account, session, and access-permission information; disclosures presented to the recipient; disclosure version and timestamp; affirmative consent and its scope; consent withdrawal and related timestamps; PDF-format access-test results; document display events; download requests and completed downloads, where observable; print requests; replies and attachments; malware-scanning results for uploaded attachments; relationships among documents, replies, attachments, and accounts; and related event, source, and ingestion timestamps. Portal activity records describe system events. For example, a document-display event does not necessarily establish that a person reviewed or interpreted, agreed with, or acted upon the contents of a document. 3.4 Postal and fulfillment records: we may collect or generate sender-approved postal destination; original address and standardized address; address-update or change-of-address provenance, where used; physical-job and production identifiers; print and insertion records; page counts and document-version information; USPS tracking references; USPS acceptance, delivery, attempted-delivery, and Return Receipt information, where available; fulfillment-provider handoff records; affidavit or declaration information; and corrections, exceptions, and related operational records. Postal address information is used for authorized physical fulfillment, support, evidence, and related business purposes. Postal address information is not provided to the invitation-generation or email-delivery services except where separately approved and necessary for a documented purpose. 3.5 Technical and security information: we may collect IP address; device type and operating system; browser type and version; session identifiers; approximate location derived from IP address, if available; log-in and log-out events; security-event data; error reports; network and connection information; audit logs; fraud-prevention signals; and information concerning suspected unauthorized access or misuse. 3.6 Cookies and similar technologies: the marketing website may use cookies and similar technologies for necessary functionality, security, preferences, and—if confirmed and approved—analytics. The final published Policy must identify the actual cookies and similar technologies used on the website and provide any required choices or opt-out mechanisms. The current SameDayNotice document-invitation design is intended to disable: open tracking; click tracking; tracking pixels; personalized tracking redirects; link rewriting; and document-specific links or access tokens in invitation emails. These implementation statements must be confirmed against the deployed email configuration before publication.
4. How We Use Personal Information — We may use personal information for the following purposes: providing, operating, maintaining, and securing the SameDayNotice service; creating and administering customer accounts; processing sender-authorized orders and physical-mailing instructions; storing, protecting, and making uploaded documents available to authorized users; authenticating users and controlling access; conducting identity verification and multifactor authentication; presenting disclosures and managing consent and withdrawal; recording portal, postal, fulfillment, and evidence events; supporting replies and attachments within authorized portal conversations; processing payments, invoices, refunds, and account administration; providing customer support; detecting, preventing, investigating, and responding to fraud, abuse, security incidents, and unauthorized access; maintaining backups, business continuity, and disaster recovery; complying with applicable law, regulation, legal process, and contractual obligations; establishing, exercising, or defending legal claims; evaluating and completing a merger, financing, acquisition, reorganization, sale of assets, or similar corporate transaction; and communicating with customers about service changes, account matters, security issues, and other transactional or relationship matters. We do not use recipient information for advertising to recipients. We do not use recipient information to select a legal delivery method, determine whether a notice is legally sufficient, or independently determine whether a particular notice should be sent electronically or physically. 4.1 Legal bases: where applicable law requires a legal basis for processing, we may rely on performance of a contract or steps taken at the request of a customer or user; compliance with a legal obligation; consent; legitimate interests, including service security, fraud prevention, customer support, and business administration; and establishment, exercise, or defense of legal claims. The applicable basis may vary by jurisdiction, individual, data category, and processing activity.
5. How We Share Personal Information — 5.1 Customers and authorized users: recipients may see documents sent to them and the sender's approved display name after completing applicable authentication, consent, and access requirements. Senders and authorized customer users may see information concerning portal access and activity; consent and disclosure events; replies and attachments; postal and fulfillment status; evidence records; and other information permitted by the customer's account and service configuration. 5.2 Service providers: we may share information with service providers that process information on our behalf and under contractual restrictions. Provider categories may include cloud hosting and storage; email delivery; SMS and one-time-code delivery; identity verification and authentication; print and mail fulfillment; postage and postal-service support; payment processing; customer support and ticketing; security monitoring; malware scanning; logging and infrastructure management; backup and disaster recovery; and website functionality, cookies, or analytics, if confirmed and approved. The final version of this Policy must identify provider names or provide sufficiently specific categories as required by applicable law. 5.3 Professional advisers: we may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers when reasonably necessary for their professional services and subject to applicable confidentiality obligations. 5.4 Legal process and protection of rights: we may disclose information when reasonably necessary to comply with a subpoena, court order, warrant, or other legal process; respond to a governmental or regulatory request; enforce agreements; protect the rights, property, or safety of SameDayNotice, our customers, users, or others; investigate fraud, abuse, or security incidents; or establish, exercise, or defend legal claims. 5.5 Corporate transactions: personal information may be disclosed as part of a proposed or completed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate confidentiality and legal requirements. 5.6 No sale of personal information: SameDayNotice does not sell personal information for monetary consideration. The final version must confirm whether any disclosure could constitute "sale," "sharing," targeted advertising, or a comparable regulated disclosure under any applicable state privacy law. If applicable law treats any activity as a sale or sharing, the Policy and related opt-out mechanisms must be revised before publication.
6. Retention, Deletion, and Legal Holds — We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including: providing the service; maintaining evidence and audit records; meeting contractual and statutory obligations; resolving disputes; enforcing agreements; protecting the security and integrity of the service; complying with legal process; and establishing, exercising, or defending legal claims. The following retention periods must be confirmed before publication (all shown as [Retention Period]): customer account and user records; uploaded documents and document versions; portal access, identity, and consent records; replies and attachments; postal and fulfillment records; billing and payment records; customer-support records; security and audit logs; backups; and legal-hold information [until release of the applicable hold, subject to [Process]]. We may retain information longer when required by law, contract, legal hold, regulatory request, dispute, investigation, or a reasonable need to preserve evidence. Where permitted, corrections to evidence records are recorded as append-only corrections rather than by deleting or rewriting the original event history. This practice does not mean that records are tamper-proof or that a particular record will be accepted as evidence in court. Withdrawal of consent generally stops future electronic uses within the scope of the withdrawal, subject to applicable law and the customer's instructions. Withdrawal does not automatically delete historical evidence, consent, access, postal, or transaction records that SameDayNotice or the customer is authorized or required to retain.
7. Security — SameDayNotice maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction. Depending on the service and information involved, safeguards may include role-based access controls; account permissions and authentication; multifactor authentication; encryption in transit and at rest; restricted access to uploaded documents; malware scanning of uploaded documents and attachments; security monitoring and event logging; vulnerability and infrastructure management; backup and recovery procedures; segregation of postal, portal, invitation, and billing functions; personnel confidentiality and access procedures; and incident-response processes. We use the FTC's Start with Security guidance as a practical security reference point where appropriate. That guidance is not a guarantee, certification, or representation that any particular security standard has been satisfied. No system, transmission, storage method, or security program is perfectly secure. We do not claim that our records are tamper-proof. Users and customers are responsible for protecting their credentials, using authorized accounts, and notifying us promptly of suspected unauthorized access.
8. Privacy Choices and Rights — Subject to applicable law and exceptions, individuals may have rights to access or obtain a copy of personal information; correct inaccurate personal information; delete personal information; receive information about processing and disclosures; withdraw consent; restrict or object to certain processing; opt out of sale, sharing, targeted advertising, or comparable activities, where applicable; limit certain uses of sensitive personal information, where applicable; appeal a denied privacy request, where applicable; and avoid unlawful discrimination for exercising privacy rights. Rights may differ depending on the individual's location, role, relationship with SameDayNotice, the type of information involved, and applicable law. 8.1 Sender and account requests: account users may request access, correction, or deletion of account information by contacting [Privacy Contact Email] or using [Privacy Request URL]. Deletion may be limited where information is necessary to provide the service, maintain business records, preserve evidence, comply with law, resolve disputes, prevent fraud, or satisfy a customer's documented instructions. 8.2 Recipient requests: a recipient may contact SameDayNotice regarding account access; identity-verification issues; updating contact information; withdrawing electronic consent, where applicable; accessing or correcting information held in the recipient's portal account; or security concerns. Because the sending organization generally determines the purpose and content of a notice, a recipient's request concerning the notice, the sender's use of information, or the legal basis for the notice may need to be routed to the sending organization. 8.3 Marketing and transactional communications: a person may opt out of promotional or marketing communications through the unsubscribe mechanism provided in the communication or by contacting [Marketing Contact Email]. Opting out of marketing communications does not necessarily stop transactional, account, security, service, or notice-related communications that are necessary to provide the service or fulfill legal or contractual obligations. Document invitations and notice-related communications are not intended to function as promotional advertising. Their classification and required disclosures must be reviewed before publication and deployment. 8.4 Request submission and identity verification: to submit a privacy request, contact [Privacy Contact Email]; [Privacy Request URL]; or [Company Mailing Address]. We may need to verify the identity and authority of the requester before completing a request. Verification may include confirming account information, responding through an authenticated account, or requesting other information reasonably necessary to prevent unauthorized disclosure. We will not request unnecessary passwords, authentication codes, or identity documents through an unsecured email message. If an authorized agent submits a request on another person's behalf, we may require proof of authorization and may verify the requester's identity directly, as permitted or required by law.
9. U.S. State Privacy Disclosures — This section is intended to summarize categories and rights that may apply under U.S. state privacy laws. Counsel must revise this section based on the states in which SameDayNotice is subject to applicable thresholds and obligations. 9.1 Categories of personal information: depending on the service used, we may collect or disclose the following categories — Identifiers (name, email address, postal address, account identifier, IP address); Professional or employment information (organization, job title, business contact details); Commercial information (orders, service selections, billing history, transaction records); Internet or network activity (login events, portal activity, browser and device information, security logs); Geolocation information (approximate location derived from IP address, if collected); Audio, electronic, visual, or similar information (uploaded documents, replies, attachments, and related files); Inferences (account permissions, security-risk indicators, or service preferences derived from activity); Sensitive personal information (information contained in an uploaded document or supplied by a customer, depending on the document and applicable law). The final Policy must be reconciled with actual collection and disclosure during the applicable lookback period. 9.2 Sources: we may collect information from the individual; a SameDayNotice customer or sender; an authorized representative; service providers; identity-verification providers; postal and fulfillment providers; payment processors; customer-support interactions; devices and browsers; security and fraud-prevention systems; and public or legally available sources, where applicable. 9.3 Purposes and disclosures: we collect and disclose information for the purposes described in Sections 4 and 5, including service delivery, authentication, consent management, evidence records, fulfillment, billing, security, support, legal compliance, and corporate administration. SameDayNotice does not sell personal information. SameDayNotice does not use recipient information for targeted advertising. 9.4 State privacy rights: subject to applicable law, eligible residents may request access to personal information and information about its collection and disclosure; correction of inaccurate personal information; deletion of personal information; information about categories of third parties and service providers; opt-out of the sale or sharing of personal information; opt-out of targeted advertising; limitation of certain uses or disclosures of sensitive personal information; appeal of a denied request; and non-discrimination for exercising privacy rights. We will not discriminate against an individual for exercising a privacy right, except as permitted by law. The final Policy must state the applicable response deadlines, appeal procedure, opt-out preference signals, and other jurisdiction-specific requirements. 9.5 Appeals: if we deny a privacy request, the requester may appeal by contacting [Privacy Appeals Email or URL] and identifying the original request, the reason for the appeal, and any information supporting the appeal. We will respond within the period required by applicable law. If an appeal remains unresolved, the requester may contact the applicable state attorney general or other regulator where permitted.
10. International Data Transfers and Rights — Counsel must confirm before publication whether this section applies. SameDayNotice is currently described as a U.S.-based service. Personal information may be transferred to, stored in, or accessed from the United States and other countries where SameDayNotice or its service providers operate. If SameDayNotice offers services to individuals in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with comparable privacy requirements, the final Policy must identify: the applicable controller, processor, or data-protection roles; the legal bases for processing; the applicable transfer mechanism; any standard contractual clauses or other safeguards; the applicable data-protection contact or representative; rights of access, rectification, erasure, restriction, objection, and portability; the right to withdraw consent where processing is based on consent; the right to lodge a complaint with a supervisory authority; and any automated decision-making or profiling information required by law. No representation about international data transfers, adequacy decisions, certification, or GDPR compliance should be published until the applicable facts and legal requirements are confirmed.
11. Children's Privacy — SameDayNotice is not directed to children and is not intended for use by children under 13. We do not knowingly collect personal information directly from children under 13. If we learn that we have collected personal information directly from a child under 13 without legally required authorization, we will take reasonable steps to delete it, subject to legal, security, evidence, and customer-instruction requirements. Customers are responsible for ensuring that their use of the service does not improperly involve children's information or violate applicable children's privacy laws.
12. Changes to This Policy — We may update this Privacy Policy from time to time to reflect changes in our services, data practices, legal obligations, vendors, or security measures. When we make material changes, we will post the updated Policy and revise the "Last Updated" date. Where required by law, we will provide additional notice or obtain consent. The final published Policy must include: Effective date: [Effective Date]; Last updated: [Last Updated Date]; Policy version: [Version Number].
13. Contact Us — Questions about this Privacy Policy or privacy requests may be submitted to: Certified Mail Envelopes, Inc. dba SameDayNotice. Mailing address: [Company Mailing Address]. Privacy email: [Privacy Contact Email]. Privacy-request form: [Privacy Request URL]. Telephone: [Privacy Telephone Number].
14. Counsel Review and Publication Conditions — Before publication, counsel must reconcile this Policy with: actual website and portal functionality; current vendor contracts and data-processing terms; hosting and processing locations; cookie, analytics, and email configurations; customer agreements and data-processing addenda; Terms of Service; security policies and incident-response procedures; retention schedules and legal-hold procedures; applicable U.S. state privacy laws; any sector-specific requirements; international data-protection obligations; and the company's actual privacy-request and appeal procedures. This document is informational, is not legal advice, and has not been approved for publication. A licensed attorney should review and approve the final Policy before reliance or use.