This Privacy Policy explains how InboxMates (the service name used by the legal entity identified on your order form or invoice, “InboxMates,” “we,” “us”) collects, uses, discloses, and protects personal information when you visit inboxmates.co or use our WhatsApp Business inbox, CRM, automation, analytics, AI, support, and related services (the “Service”). It also explains your privacy rights. This Policy does not replace a customer’s own privacy notice to its contacts.
1. Our Roles and Scope
We are a controller or “business” for website visitors, account users, billing contacts, and information used for security, support, analytics, and our own marketing. For contacts, messages, media, notes, and other data that a customer places in a workspace (“Customer Data”), the customer is generally the controller/business and InboxMates is its processor/service provider. We process Customer Data only under the customer’s instructions, our agreement, and law. If you are a contact of an InboxMates customer, direct your request to that customer first.
Meta, WhatsApp, payment providers, and customer-selected integrations process information under their own terms and privacy notices. InboxMates is not affiliated with or endorsed by WhatsApp LLC or Meta Platforms, Inc.
2. Information We Collect
Depending on how the Service is used, we collect:
- Account and commercial data: name, business contact details, organization, role, login and authentication data, plan, seats, orders, invoices, tax details, payment status, trial, renewal, cancellation, and refund records. Payment processors receive card or bank details; we generally receive only limited payment tokens and transaction information.
- Customer Data: WhatsApp Business and CRM identifiers, phone numbers, contact profiles, messages, media, templates, consent and opt-out records, labels, notes, assignments, conversation status, and imported or synchronized records.
- Integration and technical data: connected-account identifiers, access tokens, permissions, webhooks, API and delivery logs, IP address, browser/device data, approximate location derived from IP, timestamps, usage, diagnostics, security events, and cookie identifiers.
- Support and AI data: tickets, communications, attachments, feedback, prompts, drafts, outputs, and related usage metadata.
We obtain information from you, workspace administrators and users, contacts who communicate with a customer, Meta/WhatsApp and connected services, payment and identity providers, and automatically from use of the Service. Please do not provide data that is unnecessary for your permitted use.
3. How and Why We Use Information
We use information to provide, configure, and operate the Service; authenticate users; route messages; synchronize contacts; run authorized automations and AI features; administer workspaces, subscriptions, taxes, and payments; provide support; detect abuse, fraud, and security incidents; monitor reliability; improve and develop features; enforce agreements; comply with law; and send service communications. Subject to consent and applicable law, we may send marketing and measure campaigns.
Where GDPR or UK GDPR applies, our legal bases are performance of a contract, compliance with legal obligations, consent, and our legitimate interests in operating, securing, supporting, and improving a business service. Where we rely on legitimate interests, we balance those interests against affected rights. Customer Data is processed under the customer’s instructions and legal basis.
We do not use private Customer Data to train general-purpose or shared AI models unless the customer affirmatively enables that use after receiving legally required notice and choice. AI providers may process prompts and outputs only to provide the configured feature and under contractual restrictions.
We use strictly necessary cookies or local storage for login, security, preferences, and core functions. Where required, non-essential analytics or advertising technologies are disabled until consent. You can use our consent tool and browser settings to change choices. Withdrawing consent does not affect prior lawful processing. Global Privacy Control or other legally recognized opt-out signals are honored where applicable.
5. How We Disclose Information
We disclose only what is reasonably necessary to:
- hosting, database, content delivery, logging, security, communications, customer support, analytics, AI, payment, and professional-service providers acting under contract;
- Meta/WhatsApp, telecommunications providers, and integrations selected by the customer;
- workspace owners, administrators, and authorized members;
- regulators, courts, law enforcement, or other parties when required by law or necessary to protect rights, safety, and the Service; and
- an acquirer, investor, or successor in a merger, financing, reorganization, or sale, subject to appropriate safeguards.
We do not sell personal information for money. We do not “sell” or “share” Customer Data for cross-context behavioral advertising. If our website activity ever constitutes a sale, sharing, or targeted advertising under applicable U.S. state law, we will provide the required notice and opt-out mechanism and will not discriminate for exercising that choice.
6. International Transfers
Information may be processed where we or our providers operate, including outside your country. For transfers from the EEA, United Kingdom, or Switzerland, we use applicable adequacy decisions, the European Commission Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another lawful mechanism, together with supplementary measures where appropriate. Customers may request relevant transfer information or our Data Processing Addendum at [email protected].
7. Retention and Deletion
We retain account, Customer Data, and technical records only as long as needed for the purposes above, the customer’s instructions, and legal, tax, accounting, security, backup, and dispute requirements. Active workspace data is retained while the account is active. Following termination or a verified deletion request, production data is deleted or de-identified within a commercially reasonable period, normally within 90 days, unless a contract or law requires otherwise; encrypted backups are isolated and expire on their ordinary cycle. Billing and transaction records may be retained for up to seven years or the period required by local law. Security logs are generally retained for up to 12 months. Different periods may apply where stated in an order, product setting, or Data Processing Addendum.
8. Security and Incidents
We use risk-appropriate administrative, technical, and organizational controls, including access restrictions, encryption in transit, secrets and token protection, logging, backups, vulnerability management, and provider review. No system is completely secure. Customers must configure roles, integrations, devices, and messaging practices securely. We investigate suspected incidents and notify affected customers or authorities as required by contract and law.
9. Your Rights and Choices
Depending on your location, you may request access, confirmation, correction, deletion, restriction, objection, portability, or withdrawal of consent; opt out of marketing, sale/sharing, or targeted advertising; limit certain sensitive-data uses; and appeal a denied request. You may also complain to your local data protection authority. California and other covered U.S. residents may request the categories and specific pieces of information collected, sources, purposes, recipients, and deletion or correction, and may use an authorized agent. We do not discriminate for exercising privacy rights.
Submit requests to [email protected]. We may verify identity, authority, and jurisdiction and will respond within applicable deadlines. For Customer Data, contact the relevant customer; we assist customers with valid requests. Marketing messages include an unsubscribe option, although operational messages may continue.
10. Sensitive Data and Automated Decisions
Do not use the Service to process sensitive or special-category data—including health, precise location, biometric, government-ID, financial-account, or highly confidential information—unless you have a lawful basis, required consent, and appropriate safeguards. InboxMates does not make solely automated decisions about individuals that produce legal or similarly significant effects. Customers are responsible for human review and any notices or rights required for their automations and AI use.
11. Children
The Service is a business tool and is not directed to children under 16. We do not knowingly collect children’s personal information for our own purposes. Customers may not use the Service to target children or process their data without all legally required parental authorization and safeguards. Contact us if you believe a child’s data was provided improperly.
12. Customer Responsibilities and Data Processing
Customers must provide lawful privacy notices, establish a legal basis, honor messaging opt-outs and privacy rights, minimize data, configure retention and access, and enter into any required Data Processing Addendum. Customers must not instruct us to process data unlawfully. A DPA, including processor terms required by Article 28 GDPR/UK GDPR and applicable U.S. service-provider/contractor restrictions, is available on request.
13. Changes and Contact
We may update this Policy to reflect product, provider, or legal changes. We will post the updated date and give additional notice of material changes where required. The legal entity and address shown on your order form or invoice is the responsible contracting entity. For privacy requests, DPA requests, or questions, contact [email protected].
Operated by LITEMOB PTE. LTD.