Security

Protecting account and campaign data.

An overview of VMailMerge security controls and how to report a vulnerability responsibly.

Authentication

Google OAuth is used for sign-in. VMailMerge never asks for or stores your Google password.

Payments

Paid checkout is handled by Stripe. Payment-card information is not collected by VMailMerge pages.

Access control

Account pages require an authenticated session, secure cookies and request-verification tokens for state-changing actions.

Data minimization

Only information required to operate sign-in, licensing, support and requested mail-merge functions should be retained.

Your responsibilities

Protect your Google account, review requested permissions and remove access from your Google Account if you stop using VMailMerge.

Report a concern

Email vmm@vmailmerge.com. Include reproduction steps but no unnecessary personal data.