MailVue is committed to data security, regulatory compliance, and protecting the privacy of operators and their customers. This page describes our compliance posture, data hosting practices, subprocessors, and security measures.
Our Compliance Posture
MailVue provides software to Commercial Mail Receiving Agencies (CMRAs) — independent mail center operators who are registered with the United States Postal Service. We take compliance with USPS regulations, applicable privacy laws, and industry security best practices seriously. Our platform is designed to help operators maintain proper documentation, enforce data isolation between stores, and protect customer information.
USPS CMRA Compliance
USPS Form 1583 is collected from customers and retained per USPS regulations — typically a minimum of 4 years from the date of last service
Each operator (CMRA) is independently responsible for their own USPS registration and compliance obligations
MailVue facilitates Form 1583 documentation storage and identity verification workflows but is not itself a CMRA
Operators are responsible for ensuring customers present valid government-issued photo ID at the time of Form 1583 signing, per USPS regulations
Data Hosting & Infrastructure
Primary platform hosted via Base44 on Render infrastructure
Database management provided by Base44 — data stored in North America regions
Private file storage (mail scans, photos, signatures) managed via Base44's file storage with signed URL access controls
Optional Google Drive integration available for operators who configure it for mail scan storage
Subprocessors
The following third-party subprocessors may process customer data as part of providing the MailVue service:
Base44
Platform hosting, database management, and application infrastructure
Render
Cloud compute infrastructure
Resend
Transactional email delivery
Telnyx
SMS notification delivery
Stripe
Payment processing and subscription billing
Google Drive
Mail scan file storage (optional, operator-configured)
Security Practices
Encryption in transit — all data transmitted over TLS (HTTPS)
Encryption at rest — managed by Base44 infrastructure
Private file storage — scans, photos, and signature files are stored privately and accessed only via time-limited signed URLs
Per-store data isolation — Row-Level Security (RLS) enforced at the database level; one store cannot access another store's data
Audit logging — sensitive operations (pickup releases, ID verification, billing changes) are logged with actor identity and timestamp
Request data deletion — email cs@bluebonnetmail.com. Note: certain records may be retained to satisfy legal obligations
Opt-out of SMS — reply STOP to any SMS message. See our SMS Policy
Opt-out of email notifications — update preferences in the MailVue app or contact your store operator
Reporting Security Incidents
If you become aware of a security incident or suspected data breach involving MailVue, please report it immediately to cs@bluebonnetmail.com. Confirmed breaches affecting personal data will be reported to affected parties within 72 hours of confirmation.