Scope and who we are
SendInbox is a software product operated by SERUCES INFORMATION TECHNOLOGY PRIVATE LIMITED. In these policies, “SendInbox”, “we”, “us”, or “our” means that company. SendInbox is the current product name and may be changed without changing your contracting party.
This Policy applies to sendinbox.co, SendInbox accounts, workspaces, support, billing, and the software service. It does not replace a Customer’s own privacy notice to its contacts, and it does not govern Meta, Razorpay, or another third party operating under its own terms.
For workspace users, billing, product security, and our direct business operations, we decide why and how data is used and act as the relevant Data Fiduciary or controller. For contacts, message content, campaign audiences, and other data processed on a Customer’s instructions, Customer is the Data Fiduciary or controller and we act as its Data Processor or processor.
Data we collect
- Account data: name, work email, password hash, email-verification state, role, membership, and security-factor state.
- Business data: workspace name, settings, team invitations, plan, entitlements, and account status.
- WhatsApp connection data: Meta business, WABA and phone identifiers, encrypted access token, template metadata, and connection state.
- Customer-controlled data: contacts, phone numbers, attributes, tags, consent evidence, imports, campaign content, messages, replies, attachments, and status events.
- Billing data: Razorpay customer, subscription, payment, invoice, and webhook identifiers and states. We do not store full card or bank credentials.
- Usage and security data: timestamps, feature actions, IP-derived request data, user agent, sessions, audit events, delivery errors, and redacted application logs.
- Support data: correspondence and information you choose to provide while asking for help or exercising a right.
We receive data from you, workspace administrators, imported files, Meta’s APIs and webhooks, Razorpay’s checkout and webhooks, and ordinary browser requests. Please do not send data that is unnecessary for the service or support request.
Why we use data
We use personal data to:
- create accounts, authenticate users, manage roles, and secure sessions;
- connect Customer-owned WhatsApp assets and provide campaigns, templates, inbox, imports, and analytics;
- deliver messages through Meta on Customer instructions and process message-status and reply webhooks;
- manage trials, subscriptions, entitlements, invoices, cancellations, and payment reconciliation;
- answer support, investigate errors, maintain audit records, prevent abuse, and protect the service;
- comply with valid legal obligations, enforce agreements, and resolve disputes; and
- understand aggregate reliability and feature usage without selling personal data or using Customer message content for advertising.
Depending on the relationship and applicable law, processing is based on performing a contract, consent, legitimate or permitted business use, compliance with law, protection of users and systems, or Customer’s documented instructions. Customer is responsible for selecting a lawful basis for its contact and messaging data.
Retention and deletion
We keep data only while needed for the service, Customer instructions, security, disputes, and legal or accounting duties. Current application defaults redact processed Meta raw payloads after 30 days, message content after 365 days, processed Razorpay payloads after 365 days, import objects and reports after 30 days, and import-row details after 90 days. Unattached campaign uploads are removed after 24 hours. Plan analytics settings may be 90, 365, or 730 days, although factual records may be retained for a shorter operational or longer legally required period.
Deleting a contact anonymizes direct identifiers and associated message content in the live service while preserving non-personal operational and audit relationships. Workspace closure is handled through a verified request. Backups are currently retained locally for 14 days and age out on their normal schedule. Some transaction, security, consent, and audit facts may remain where law, fraud prevention, or dispute handling requires it.
See Data Deletion for request steps.
Security and international processing
We use administrative and technical measures proportionate to the service, including encrypted transport, Argon2id password hashing, short-lived access tokens, rotating refresh sessions, optional TOTP multi-factor authentication, encrypted Meta tokens, signed webhooks, tenant-scoped authorization, private object storage, audit records, and structured log redaction. No internet service is risk-free. Details and current limitations are on our Security page.
Meta and service providers may process data outside Customer’s or a contact’s state or country. Where personal data is transferred internationally, we use contractual and technical safeguards appropriate to the provider and comply with applicable transfer restrictions. We do not promise that all data remains in India unless a signed order expressly says so.
Choices and privacy rights
Depending on applicable law, a person may request access to or a summary of personal data, correction, completion, erasure, withdrawal of consent, grievance handling, or nomination of another person to exercise rights. A workspace user may update some data in the service. Contacts should ordinarily exercise rights through the business that messaged them because that Customer controls the contact data and purpose.
You can also email support@sendinbox.co. We will verify identity and authority, route processor requests to the relevant Customer, and respond within the period required by applicable law. Withdrawing consent does not affect earlier lawful processing. You may complain to the competent privacy authority after using the grievance process where required.
Children and sensitive use
The service is for businesses and is not directed to children. Account holders must be at least 18. Customers must not knowingly use the service to target children or process a child’s data without satisfying applicable parental-consent and child-protection rules.
Customers should not use ordinary WhatsApp campaigns to transmit passwords, payment-card credentials, government identifiers, medical records, or other highly sensitive data unless the use is lawful, necessary, secured, and permitted by Meta’s policies.
Changes and contact
We may update this Policy when the service, providers, or law changes. We will update the date above and provide additional notice for material changes where reasonably possible.
Privacy and grievance requests may be addressed to “Privacy & Grievance Contact, SendInbox” at support@sendinbox.co. The contracting operator is SERUCES INFORMATION TECHNOLOGY PRIVATE LIMITED. Requests for its registered communication details or applicable tax particulars can be sent through the same address.
This Policy is informed by India’s Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025, including their staged commencement.