Data & Compliance

Last updated: June 5, 2026

MailVue Data & Compliance

MailVue is committed to data security, regulatory compliance, and protecting the privacy of operators and their customers. This page describes our compliance posture, data hosting practices, subprocessors, and security measures.

Our Compliance Posture

MailVue provides software to Commercial Mail Receiving Agencies (CMRAs) — independent mail center operators who are registered with the United States Postal Service. We take compliance with USPS regulations, applicable privacy laws, and industry security best practices seriously. Our platform is designed to help operators maintain proper documentation, enforce data isolation between stores, and protect customer information.

USPS CMRA Compliance

  • USPS Form 1583 is collected from customers and retained per USPS regulations — typically a minimum of 4 years from the date of last service
  • Each operator (CMRA) is independently responsible for their own USPS registration and compliance obligations
  • MailVue facilitates Form 1583 documentation storage and identity verification workflows but is not itself a CMRA
  • Operators are responsible for ensuring customers present valid government-issued photo ID at the time of Form 1583 signing, per USPS regulations

Data Hosting & Infrastructure

  • Primary platform hosted via Base44 on Render infrastructure
  • Database management provided by Base44 — data stored in North America regions
  • Private file storage (mail scans, photos, signatures) managed via Base44's file storage with signed URL access controls
  • Optional Google Drive integration available for operators who configure it for mail scan storage

Subprocessors

The following third-party subprocessors may process customer data as part of providing the MailVue service:

Base44

Platform hosting, database management, and application infrastructure

Render

Cloud compute infrastructure

Resend

Transactional email delivery

Telnyx

SMS notification delivery

Stripe

Payment processing and subscription billing

Google Drive

Mail scan file storage (optional, operator-configured)

Security Practices

  • Encryption in transit — all data transmitted over TLS (HTTPS)
  • Encryption at rest — managed by Base44 infrastructure
  • Private file storage — scans, photos, and signature files are stored privately and accessed only via time-limited signed URLs
  • Per-store data isolation — Row-Level Security (RLS) enforced at the database level; one store cannot access another store's data
  • Audit logging — sensitive operations (pickup releases, ID verification, billing changes) are logged with actor identity and timestamp
  • Access controls — role-based access (admin, staff, customer) with least-privilege defaults

Data Retention

Mail item scan & photo files

Auto-deleted 30 days after item pickup or completion (configurable per plan via scan_retention_days)

USPS Form 1583 records

Retained minimum 4 years per USPS CMRA regulations (39 CFR §111.2)

Pickup signature images

Retained 90 days, then auto-deleted (record kept for audit)

Account & subscription data

Retained for the duration of the account and a reasonable period after closure for compliance and dispute resolution

Payment records

Retained as required by applicable financial regulations (typically 7 years)

Customer Rights

  • Request data access — email cs@bluebonnetmail.com
  • Request data deletion — email cs@bluebonnetmail.com. Note: certain records may be retained to satisfy legal obligations
  • Opt-out of SMS — reply STOP to any SMS message. See our SMS Policy
  • Opt-out of email notifications — update preferences in the MailVue app or contact your store operator

Reporting Security Incidents

If you become aware of a security incident or suspected data breach involving MailVue, please report it immediately to cs@bluebonnetmail.com. Confirmed breaches affecting personal data will be reported to affected parties within 72 hours of confirmation.