1. INFORMATION WE COLLECT
We collect several types of information to provide and improve our Service:
(a) Information You Provide Directly
- Account registration information (name, email address, business name, phone number, company details)
- Social media account credentials, access tokens, and profile information (Instagram, Facebook)
- Payment and billing information (credit card details are processed and stored by third-party payment processors only)
- Communications with us (support requests, feedback, inquiries, complaints)
- Lead data, customer messages, and conversation history processed through your connected social media accounts
- Any other information you choose to provide
(b) Information Collected Automatically
- Device information (IP address, browser type and version, device type, operating system, screen resolution)
- Usage data (pages visited, features accessed, time spent on pages, click patterns, navigation paths, session duration)
- Log data (access times, error logs, referral URLs, exit pages)
- Location data (general geographic location inferred from IP address)
- Performance data (load times, response times, error rates)
(c) Cookies and Tracking Technologies
- Session cookies (required for Service functionality)
- Persistent cookies (for preferences and analytics)
- Local storage (for temporary data storage)
- Web beacons and pixels (for analytics and tracking)
- Similar tracking technologies
(d) Information from Third Parties
- Data from connected social media platforms (Instagram, Facebook) including profile information, message content, follower data, engagement metrics, and API access logs
- Information from payment processors regarding transaction status and billing
- Data from analytics providers and service infrastructure
- Information from your email provider if you contact us
- Publicly available information about your business
2. HOW WE USE YOUR INFORMATION
We use collected information for the following purposes:
Service Provision & Performance
- To provide, operate, maintain, and deliver the Service
- To process, route, and respond to messages on your behalf
- To configure, customize, and optimize automation workflows
- To manage your account, subscription, and billing
- To authenticate your identity and prevent unauthorized access
- To connect and integrate with third-party platforms
- To store and process lead data as directed by you
Communication & Support
- To send transactional messages (confirmations, receipts, invoices)
- To send service-related notifications and updates
- To respond to your requests and provide customer support
- To send administrative information (billing notices, account changes, security alerts, Terms or Privacy Policy updates)
- To communicate about new features, updates, or Service changes
Marketing (With Consent Where Required)
- To send promotional materials and offers (you may opt out at any time)
- To conduct surveys and request feedback
- To inform you of related services or features
Improvement, Analytics & Research
- To analyze usage patterns, trends, and behaviors
- To improve Service performance, features, and functionality
- To develop new products, services, and features
- To troubleshoot technical issues and bugs
- To conduct internal research and testing
- To optimize user experience
Legal, Security & Compliance
- To enforce our Terms of Service and other policies
- To comply with legal obligations, court orders, and regulatory requirements
- To protect against fraud, abuse, spam, or security threats
- To investigate and prevent violations of our policies
- To resolve disputes and enforce our agreements
- To protect our rights, property, safety, and the rights of our users
- To respond to lawful requests from public authorities
- To establish, exercise, or defend legal claims
Aggregated & Anonymized Data
- To create aggregated, de-identified, or anonymized data that does not identify you personally
- Such data may be used for any lawful business purpose without restriction
3. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or lease your personal information to third parties for their marketing purposes.
(a) Service Providers & Subprocessors
We share information with third-party service providers who perform services on our behalf under contractual obligations to protect your information:
- Payment processors (Stripe and other payment gateways)
- Messaging automation platforms (ManyChat and similar services)
- Cloud hosting and infrastructure providers (AWS, Google Cloud, or similar)
- Email service providers
- Customer relationship management (CRM) tools
- Analytics and monitoring services (Google Analytics and similar)
- Customer support and ticketing platforms
- Security and fraud prevention services
- Marketing and communication tools
- Database and data storage providers
- Content delivery networks (CDNs)
These providers are contractually required to use information only for specified purposes, implement appropriate security measures, comply with applicable data protection laws, and not use information for their own purposes.
(b) Social Media Platforms
When you connect your Instagram, Facebook, or other social media accounts:
- We access and process data through those platforms' APIs
- We share information necessary to provide messaging automation services
- Platform providers may receive data about Service usage
- Such sharing is governed by the platforms' terms and privacy policies
You are responsible for reviewing and complying with third-party platform policies.
(c) Legal Requirements & Protection of Rights
We may disclose information if required or permitted by law, including to comply with legal obligations, respond to lawful requests from public authorities, enforce our Terms of Service, protect our rights and safety, and establish or defend legal claims.
(d) Business Transfers & Corporate Transactions
In the event of a merger, acquisition, consolidation, restructuring, sale of assets, bankruptcy, or other corporate transaction, your information may be transferred to the acquiring or successor entity. You will be notified of any change in ownership or control.
(e) With Your Consent or Direction
We may share information with third parties when you provide explicit consent or direct us to share information.
4. DATA RETENTION
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy and as required by law.
Account & Profile Data
Retained for the duration of your active subscription and up to 90 days after cancellation. May be retained longer to comply with legal obligations, resolve disputes, or enforce agreements.
Lead Data & Message Content
Processed in real-time for automation purposes. May be stored temporarily for operational and quality assurance purposes. You are responsible for independently managing and retaining your own lead data.
Financial & Transaction Data
Retained for accounting, tax, and regulatory compliance purposes for up to 7 years.
Upon Account Deletion or Termination
We will delete or anonymize your information within 90 days unless retention is required by law or to resolve disputes. You may request deletion at any time by contacting contact@inboxroute.net.
5. DATA SECURITY
We implement commercially reasonable administrative, technical, and physical security measures designed to protect your information from unauthorized access, disclosure, alteration, or destruction.
Technical Measures
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest
- Secure authentication mechanisms and multi-factor authentication options
- Regular security assessments and penetration testing
- Intrusion detection and prevention systems
- Firewall protection and network segmentation
Limitations
No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and promptly notifying us of any unauthorized access.
6. YOUR RIGHTS AND CHOICES
Depending on your location and applicable law, you may have certain rights regarding your personal information.
Access, Correction & Deletion
You may request access to, correction of, or deletion of your personal information by contacting contact@inboxroute.net. We will respond within 30 days.
Data Portability
You may request a copy of your personal information in a portable machine-readable format.
Opt-Out
You may opt out of marketing emails at any time by clicking "unsubscribe" in any email or contacting us. We will not discriminate against you for exercising your privacy rights.
7. COOKIES AND TRACKING TECHNOLOGIES
We and our third-party partners use cookies, web beacons, pixels, local storage, and similar tracking technologies to collect information about your use of the Service.
Types of Cookies
- Essential Cookies: Required for Service functionality (authentication, session management, security). Cannot be disabled without impacting the Service.
- Analytics Cookies: Used to understand how you use the Service (page views, navigation, feature usage, error tracking).
- Functionality Cookies: Enable enhanced features and remember your preferences.
- Marketing Cookies: Used for advertising purposes, if applicable.
Your Choices
You can control cookies through your browser settings. Disabling cookies may limit Service functionality. Google Analytics opt-out is available at https://tools.google.com/dlpage/gaoptout. We do not currently respond to Do Not Track (DNT) browser signals.
8. THIRD-PARTY LINKS, SERVICES & INTEGRATIONS
The Service may contain links to or integrate with third-party websites, platforms, or applications. We are not responsible for the privacy practices of third-party services. When you connect third-party accounts (Instagram, Facebook, Stripe, etc.), those platforms' privacy policies apply to information they collect and process.
We encourage you to review the privacy policies of all third-party services you interact with.
9. CHILDREN'S PRIVACY
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, contact us immediately at contact@inboxroute.net and we will promptly delete such information.
10. INTERNATIONAL DATA TRANSFERS
InboxRoute operates from the United States (Illinois). Your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your country of residence.
By using the Service, you acknowledge and consent to the transfer and processing of your information as described in this Privacy Policy. Contact contact@inboxroute.net for information about safeguards for international transfers.
11. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, you have specific rights under the CCPA and CPRA including the right to know, the right to delete, the right to correct, and the right to opt out of sale of personal information. We do not sell personal information.
To exercise your rights, email contact@inboxroute.net. We will respond within 45 days.
12. EUROPEAN PRIVACY RIGHTS (GDPR)
If you are located in the EEA, UK, or Switzerland, you have rights under the GDPR including rights of access, rectification, erasure, restriction, data portability, objection, and the right to lodge a complaint with your supervisory authority.
We process personal data based on contractual necessity, legitimate interests, legal obligations, and consent (where required). To exercise your GDPR rights, contact contact@inboxroute.net. We will respond within 30 days.
EU Supervisory Authorities: https://edpb.europa.eu | UK ICO: https://ico.org.uk
13. OTHER STATE PRIVACY RIGHTS
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have additional rights including rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising and sale of personal data.
To exercise your rights, contact contact@inboxroute.net. We will respond within 45 days and will not discriminate against you for exercising your rights.
14. NEVADA PRIVACY RIGHTS
Nevada residents have the right to opt out of the sale of certain covered information. We do not sell covered information as defined under Nevada law. Nevada residents may submit opt-out requests to contact@inboxroute.net with "Nevada Do Not Sell Request" in the subject line.
15. ADVERTISING & MARKETING COMMUNICATIONS
We may send you promotional emails about new features, special offers, and events. You may opt out at any time by clicking "unsubscribe" in any marketing email or contacting contact@inboxroute.net. Opting out does not affect transactional or administrative emails.
16. AUTOMATED DECISION-MAKING & PROFILING
We do not currently engage in automated decision-making or profiling that produces legal or similarly significant effects without human involvement. If we implement such features in the future, we will notify you and provide appropriate safeguards.
17. SENSITIVE PERSONAL INFORMATION
We do not intentionally collect, process, or store sensitive personal information including precise geolocation data, genetic or biometric data, health information, government-issued identification numbers, or information about racial or ethnic origin, religious beliefs, or sexual orientation. If you inadvertently provide such information, contact contact@inboxroute.net immediately.
18. DATA BREACH NOTIFICATION
In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities as required by law, without undue delay and where feasible within 72 hours of becoming aware of the breach. Notifications will be sent via email and/or prominent notice on our website.
19. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date, notify you via email (if applicable), and post notice on our website. For material changes, we may require your affirmative consent. Continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
20. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:
InboxRoute
Email: contact@inboxroute.net
We will respond to inquiries within 30 days. You also have the right to file a complaint with your local data protection authority or supervisory authority.
21. INTERPRETATION & SEVERABILITY
If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions will remain in full force and effect. This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and InboxRoute regarding the subject matter herein. This policy is written in English; in the event of conflicts between the English version and any translation, the English version prevails.
22. ADDITIONAL DISCLOSURES
Certain features or services may have additional privacy practices. When you use third-party integrations (Instagram, Facebook, Stripe, ManyChat, etc.), those services' privacy policies apply to information they collect. You are responsible for ensuring that information you provide is accurate and up-to-date.
By using the Service, you consent to data transfers and processing across multiple systems and jurisdictions as necessary for service provision. This Privacy Policy does not create any contractual rights beyond those stated in our Terms of Service.