Sender
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Lithuanian-founded budget email marketing tool with a generous free tier (2,500 subscribers, 15,000 emails/month).
Sender is a European service hosted in Lithuania, with at most minor, transient US exposure under the CLOUD Act. It is listed under Email marketing.
Assessment notes
Lithuanian UAB Sender.lt with a generous free tier and large customer base, but the public privacy policy does not name sub-processors, disclose hosting location, or document SCC/DPF for US transfers, and dedicated DPA / sub-processors / security pages return 404. EU-owned legal entity but significant transparency gaps: no public DPA, no named sub-processors, no disclosed hosting region.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Sender
Sender is a Lithuanian-founded email marketing platform operated by UAB Sender.lt (Lvivo st. 25, Vilnius; company code 302820904, VAT LT100008985714). It targets SMBs, e-commerce, non-profits, and event organizers as a low-cost MailerLite alternative, with a Free Forever tier covering 2,500 subscribers and 15,000 emails/month, automation, landing pages, signup forms, a 1,600+ template library, and integrations for WordPress/WooCommerce/Shopify/PrestaShop/Zapier. The vendor reports more than 180,000 customers worldwide.
Where Sender falls short for procurement-grade buyers is transparency. The public privacy policy does not name specific sub-processors, does not disclose the hosting provider or data-centre location, and does not document a Standard Contractual Clauses or Data Privacy Framework basis for any US transfers; it only mentions "third parties...such as a credit card processing company" without identifying them, and the two third parties it does name, Google reCAPTCHA and Cloudflare Turnstile, are both US-owned and scoped to the website rather than to subscriber data. Dedicated /dpa/, /sub-processors/, /security/ and /gdpr/ paths all return 404. For a Lithuanian-incorporated vendor that is structurally EU-owned, this lack of disclosure is the single biggest compliance-score limiter.
Pricing is quoted in USD with the currency picker switching only client-side: above the Free Forever tier, Standard is US$7/month for 1,000 subscribers and 12,000 emails (US$4.90 on annual billing), Professional US$14 or US$9.80, and Enterprise on quote. Best fit: solopreneurs, small e-commerce shops, and creators who want a generous free tier and EU-incorporated billing, and don't require enterprise-grade compliance documentation. Mid-market and procurement-led buyers should look at MailerLite (LT, broader transparency), Brevo (FR, public DPA), or rapidmail (DE, German servers with no public-cloud hyperscaler) instead until Sender publishes a sub-processors list and DPA.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Sender
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Servicewww.sender.net/terms-and-conditions…
Alternatives in this category
-
France · €8/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €15/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
United Kingdom · €0/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€8/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€15/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€0/mo |