Skip to content
Independent printing & mailing

Privacy

Your mailing information stays tied to your order

Agent Postal Service is operated by Ludicrous. This page explains what the service handles when you ask it to print and mail a document.

Last updated October 3, 2026.

Information we handle

A mailing can include the selected PDF, sender and recipient names and addresses, your email address, the quote and order status, relevant timestamps, a PDF hash, and identifiers from payment and email providers.

An account is not required. Anyone with an order’s private review link can view its PDF and addresses and manage the unpaid mailing. Keep that link confidential.

How we use it

  • Inspect, print, package, and manually fulfill the mailing.
  • Show the document, addresses, price, and status for review.
  • Send order and handoff updates to the email you provide.
  • Provide support, prevent fraud, and reconcile the order.

Service providers and the mail carrier

Documents and order records use Convex storage and backend services. The hosting provider may process operational request logs. Cloudflare receives the email, order and address details needed for a message, and the private review link; PDFs are not attached to those emails. Stripe handles card details, so Agent Postal Service does not receive your card number. WorkOS is used only for administrator sign-in.

PostHog may receive administrator identity and operational diagnostics where configured. Guest document pages do not use automatic analytics capture or session recording. USPS receives the physical address and document contents required to deliver the piece of mail.

Retention and privacy requests

Abandoned unpaid mailings, their PDFs, and associated order records are deleted after 7 days. Fulfilled mailings are deleted 90 days after mailing. Cleanup runs daily. Paid orders waiting to be mailed and orders with unresolved payments are kept until they can be resolved. Unattached uploads are deleted after 24 hours.

To ask about access or deletion, contact support with the order ID and the email used for the mailing so we can verify the request. Some payment records held by Stripe or support correspondence may need to remain for legal or accounting reasons. Request-limit records contain a daily keyed hash of the network address, not the raw address, and are removed after their limit window has been closed for 24 hours.

Please keep sensitive information out

Do not upload Social Security numbers, government IDs, payment card numbers, health records, passwords, access keys, or other restricted sensitive information. Your agent and any third-party providers you use may have their own privacy policies.