Privacy Policy
Inboxly is operated by Bilal Raza, Pakistan (“Inboxly”, “we”, “us”). This policy explains how we process personal data when businesses use Inboxly to manage Meta campaigns, messaging, leads, CRM workflows, and analytics.
Roles
For workspace account, billing, security, and service-usage data, Inboxly acts as controller. For contact, lead, campaign, message, and conversion data uploaded or connected by a customer, the customer is the controller and Inboxly acts as processor under the customer’s instructions.
Data we collect
- Account and workspace data: name, email, password hash, role, organization, and authentication records.
- Business and Meta asset data: business profiles, locations, Page, Ad Account, Instagram, WhatsApp Business Account, Pixel/dataset identifiers, campaign configuration, and access tokens.
- Contact and CRM data: names, phone numbers, channel identifiers, attributes, consent evidence, lead status, notes, and source attribution.
- Messages and automation data exchanged through connected channels.
- Campaign, event, conversion, audit, diagnostic, and security records.
- Pilot-request information you send to sales@inbox-ly.xyz.
How we use data
We use data to provide and secure the service; connect customer-owned Meta assets; draft, approve, publish, and measure campaigns; receive leads and events; support CRM and WhatsApp follow-up; provide customer support; prevent abuse; comply with law; and improve reliability. AI features process only the context needed for the enabled task. We do not sell personal data.
Legal bases
Where applicable, processing relies on performance of a contract, consent, compliance with legal obligations, and legitimate interests in securing and improving the service. Customers are responsible for establishing a lawful basis for their marketing, advertising, audience, and contact processing.
Service providers and transfers
- Meta Platforms: Facebook, Instagram, Messenger, WhatsApp Cloud API, Lead Ads, Marketing API, Pixel, and Conversions API.
- Cloudflare: DNS, content delivery, application hosting, database, queues, object storage, and email routing.
- Anthropic: task-scoped AI replies and classification when AI is enabled.
These providers may process data in other countries. We use provider contracts and other safeguards where required.
Retention and deletion
Workspace data is retained while the account is active. Customers may delete contacts or their entire workspace. Completed deletion requests are normally actioned within 30 days; limited security, legal, consent, and backup records may remain for up to 90 days or longer where law requires. Deletion details are available on our Data Deletion page.
Security
We use tenant isolation, role-based access, encrypted Meta tokens, signature-verified webhooks, audit logs, rate limits, and restricted production access. No internet service is completely secure, but we continuously work to reduce risk.
Your choices and rights
Subject to applicable law, you may request access, correction, export, restriction, objection, or deletion. Workspace owners can manage customer data in the app. Contact privacy@inbox-ly.xyz for privacy requests.
Children
Inboxly is a business service and is not intended for children under 18. Customers must not knowingly use it to collect children’s data without an appropriate legal basis and safeguards.
Changes and contact
We may update this policy and will publish the new effective date here. Privacy contact: Bilal Raza, Pakistan, privacy@inbox-ly.xyz.