Privacy Policy
Table of Contents
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing
- How We Share Your Information
- Third-Party Service Providers
- International Data Transfers
- Data Retention
- Your Privacy Rights
- California Privacy Rights (CCPA)
- Brazilian Privacy Rights (LGPD)
- Data Security
- Children's Privacy
- Channel and Plugin Data Practices
- AI and Automated Processing
- Cookies and Tracking
- Changes to This Policy
- Contact Us
Axel Business Solutions Ltd ("Company," "we," "us," or "our") operates Inboxxit, a customer engagement and relationship management platform. The Service includes our WhatsApp Business integration, hosted web chat widget, and downloadable WordPress plugins — including the standalone "Chat Lite" plugin, which you may run on your own website using your own AI provider key (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and complying with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR), the Brazilian Lei Geral de Proteção de Dados (LGPD), and the California Consumer Privacy Act (CCPA).
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1 Information We Collect
1.1 Information You Provide Directly
We collect information you voluntarily provide when registering for the Service, including:
| Category | Examples |
|---|---|
| Account Information | Name, email address, password, phone number, company name |
| Billing Information | Payment card details, billing address (processed by third-party payment processors) |
| Business Information | Business name, industry, team member details, business address |
| Communication Content | Messages, templates, notes, and other content you create within the Service |
| Support Communications | Information provided when contacting customer support |
1.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages viewed, features used, click patterns, session duration
- Log Data: Access times, error logs, referring URLs
- Performance Data: Load times, system performance metrics
1.3 Information from Third Parties
We receive information from third-party services you connect:
- WhatsApp (Meta): Incoming messages, delivery statuses, phone numbers, message metadata
- Google Calendar: Calendar events, availability, event details (when you connect)
- Microsoft Outlook: Calendar events, availability, event details (when you connect)
1.4 Information About Your Customers
When you use the Service to communicate with your customers via WhatsApp, we process:
- Customer phone numbers
- Customer names (as provided by you or extracted from messages)
- Message content between you and your customers
- Message delivery and read status
- AI-generated analysis (intent, sentiment, interests)
You are responsible for obtaining appropriate consent from your customers to collect and process their data through our Service. You must comply with WhatsApp's Business Policy and applicable privacy laws.
1.5 Advertising and Attribution Data
When a visitor uses the web chat widget on a business customer's website, we record how that visitor arrived, so the business can measure which of its marketing actually produces enquiries. This includes:
- Ad click identifiers present in the page address (Google's
gclid,wbraid,gbraid; Meta'sfbclid) - Meta advertising cookies already stored on that website by the business's own Meta Pixel (
_fbp,_fbc) - Campaign tags (
utm_source,utm_medium,utm_campaign,utm_content,utm_term) - Page context: the landing page address, the referring address, and the browser user agent
- Click-to-WhatsApp identifiers passed by Meta when a visitor reaches a business through a Click-to-WhatsApp ad
We do not set advertising cookies of our own and we do not operate an advertising network. We read advertising cookies only where the website operator has already placed them on their own site, and we use this data solely for the attribution and conversion reporting described in Section 4.5.
2 How We Use Your Information
2.1 Service Delivery
- Provide, maintain, and improve the Service
- Process and deliver WhatsApp messages on your behalf
- Manage your account and provide customer support
- Process payments and billing
- Sync appointments with connected calendars
2.2 AI-Powered Features
- Analyze message content for intent and sentiment
- Calculate lead temperature scores
- Generate automated chatbot responses
- Provide smart reply suggestions
- Detect appointment booking requests
2.3 Service Improvement
- Understand how users interact with the Service
- Identify and fix technical issues
- Develop new features and functionality
- Conduct research and analytics
2.4 Security and Compliance
- Detect, prevent, and address fraud and abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Protect the rights and safety of users
3 Legal Basis for Processing
For users in the European Economic Area (EEA), United Kingdom, Brazil, and other jurisdictions requiring a legal basis for processing, we rely on:
| Legal Basis | Processing Activities |
|---|---|
| Contract Performance | Providing the Service, processing payments, account management |
| Legitimate Interests | Service improvement, security, fraud prevention, analytics |
| Consent | Marketing communications, optional features, AI analysis of customer data |
| Legal Obligation | Tax records, responding to legal requests, compliance requirements |
You may withdraw consent at any time by contacting us or adjusting your account settings.
4 How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. Where a business customer connects its own advertising account, we do report that business's conversions to that business's own account — see Section 4.5.
4.1 Service Providers
We share information with third-party service providers who perform services on our behalf. All service providers are contractually obligated to protect your information and use it only for specified purposes.
4.2 WhatsApp (Meta)
To deliver WhatsApp messages, we share recipient phone numbers, message content, and media files. This sharing is governed by WhatsApp's Business API terms.
4.3 Legal Requirements
We may disclose information if required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations or valid legal process
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing
- Protect the personal safety of users or the public
4.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
4.5 Advertising and Measurement Platforms
If a business customer connects its own advertising account (currently Meta or Google Ads), we report that business's conversion events — a qualified lead, a booked appointment, or a won sale — back to that business's own advertising account, so it can measure and improve its own campaigns.
What we send with each conversion:
- The lead's email address and phone number, irreversibly hashed (SHA-256) before transmission — we do not send them in readable form
- The advertising identifiers described in Section 1.5 (click identifiers,
_fbp/_fbc, Click-to-WhatsApp identifier) - The event type and time, the landing page address, the browser user agent, and the deal value and currency where recorded
This reporting is off unless the business customer connects an advertising account. Each business's data goes only to that business's own account — we never send one business customer's data to another's. Meta and Google are contractually restricted to using this data to attribute and optimize that advertiser's own campaigns.
A business customer can stop this at any time by disconnecting the advertising account in Settings. If you are a visitor to a business customer's website and want to know whether that business has enabled this, contact the business directly — it decides whether conversion reporting is switched on.
5 Third-Party Service Providers
5.1 Cloud Infrastructure
| Provider | Purpose | Location |
|---|---|---|
| Railway | Application hosting, database, cache | United States |
| Amazon Web Services (AWS S3) | Media and file storage (private, signed URLs) | United States (us-east-2) |
5.2 Artificial Intelligence
| Provider | Purpose |
|---|---|
| OpenAI (GPT-4o-mini) | Message analysis, intent detection, scoring |
| Anthropic (Claude) | Chatbot responses, smart replies |
AI Data Practices:
- AI providers process data to generate responses in real time
- We configure AI provider APIs to minimize data retention
- Message content is not used to train AI models without explicit consent
- AI providers may retain limited data for a short period under their own terms (for example, abuse monitoring) unless a zero-retention agreement is in effect
5.3 Communication Services
| Provider | Purpose |
|---|---|
| Meta (WhatsApp) | WhatsApp Business API |
| SendGrid (Twilio) | Email delivery |
5.4 Calendar Integrations
| Provider | Purpose |
|---|---|
| Google Calendar sync | |
| Microsoft | Outlook Calendar sync |
5.5 Advertising and Measurement
Used only where a business customer has connected its own advertising account (see Section 4.5).
| Provider | Purpose |
|---|---|
| Meta | Conversions API — conversion reporting to the business's own Meta ad account |
| Google Ads API — conversion reporting to the business's own Google Ads account |
6 International Data Transfers
6.1 Data Location
Your data is primarily stored in the United States: application data, databases, and cache are hosted on Railway, and media files are stored in Amazon Web Services (AWS) S3 in the us-east-2 region.
6.2 Cross-Border Transfers
Some of our service providers operate in countries outside your jurisdiction. When we transfer data internationally, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms with service providers
- Adequacy Decisions: Transfers to countries with adequate data protection
- Binding Corporate Rules: For providers with approved BCRs
- Consent: Where other mechanisms are not available
7 Data Retention
| Data Type | Retention Period | Justification |
|---|---|---|
| Account information | Duration of account + 2 years | Contract performance, legal claims |
| Messages and conversations | 5 years | Business records, dispute resolution |
| Lead and customer data | 5 years | Business records, legal requirements |
| Billing records | 7 years | Tax and accounting requirements |
| Audit logs | 7 years | Security, compliance |
| Usage analytics | 2 years | Service improvement |
| Deleted data (soft delete) | 90 days | Recovery, mistake prevention |
7.2 Deletion
When you delete your account or request data deletion:
- Active data is marked for deletion immediately
- Soft-deleted data is permanently purged after 90 days
- Backup copies are purged within 30 days of backup rotation
- Some data may be retained as required by law
8 Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of your personal data |
| Correction | Request correction of inaccurate data |
| Deletion | Request deletion of your data — see our Data Deletion Instructions |
| Data Portability | Receive your data in a structured, machine-readable format |
| Withdraw Consent | Withdraw consent for processing based on consent |
| Complaint | Lodge a complaint with a supervisory authority |
How to Exercise Your Rights
To exercise your rights, you may:
- Self-Service: Use account settings to access, correct, or delete data
- Email: Contact us at privacy@inboxxit.com
- Written Request: Send a request to our mailing address
We will respond to requests within 30 days (or as required by applicable law).
9 California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the CCPA:
9.1 Right to Know
You may request disclosure of categories and specific pieces of personal information collected, sources, purposes, and third parties with whom we share data.
9.2 Right to Delete
You may request deletion of personal information we collected, subject to exceptions.
9.3 Right to Non-Discrimination
We will not discriminate against you for exercising CCPA rights.
9.4 Categories of Information
| Category | Collected | Sold | Shared for Advertising |
|---|---|---|---|
| Identifiers (name, email, phone) | Yes | No | Yes, in hashed form* |
| Commercial information | Yes | No | Yes* |
| Internet activity | Yes | No | Yes* |
| Professional information | Yes | No | No |
* Only where a business customer has connected its own advertising account, and only to that business's own Meta or Google Ads account, for measuring that business's own campaigns. Email addresses and phone numbers are irreversibly hashed before transmission. Nothing is shared for advertising if no advertising account is connected. See Section 4.5.
9.5 Right to Opt Out of Sharing for Advertising
You may opt out of the conversion reporting described in Section 4.5. We honor the Global Privacy Control (GPC) signal automatically — if your browser sends it, we stop reading advertising cookies from you and suppress every upload about you to an advertising platform, with no form to fill in. If you hold an Inboxxit account, disconnect the advertising account in Settings, which stops all such reporting for your business. If you are a visitor to a business customer's website, that business controls the setting, so contact it directly; you can also block advertising cookies in your browser. Full instructions, and a live check of whether we can see your GPC signal, are on our Do Not Sell or Share My Personal Information page. We will not discriminate against you for opting out.
10 Brazilian Privacy Rights (LGPD)
If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD):
- Confirmation: Confirm whether we process your data
- Access: Access your personal data
- Correction: Correct incomplete, inaccurate, or outdated data
- Anonymization: Request anonymization, blocking, or deletion of unnecessary data
- Portability: Receive your data in portable format
- Deletion: Delete data processed with consent
- Information: Know about entities with whom we share data
- Revocation: Revoke consent
You may file complaints with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.
11 Data Security
We implement technical and organizational measures to protect your data:
| Category | Measures |
|---|---|
| Encryption in Transit | TLS 1.3 for all connections |
| Encryption at Rest | AES-256 for sensitive data, encrypted database backups |
| Access Control | Role-based access, multi-factor authentication for admin |
| Network Security | Firewalls, DDoS protection (Cloudflare), VPC isolation |
| Monitoring | 24/7 security monitoring, intrusion detection |
| Auditing | Comprehensive audit logs for all data access |
Incident Response
In the event of a data breach, we will notify affected users within 72 hours (or as required by law) and notify relevant supervisory authorities as required.
12 Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@inboxxit.com. If we discover we have collected information from a child, we will delete it promptly.
13 Channel and Plugin Data Practices
The Service reaches your customers through several channels — WhatsApp, our hosted web chat widget, and our WordPress plugins. Data practices differ by channel, as described below.
13.1 WhatsApp
Our Service integrates with WhatsApp Business API provided by Meta. By using WhatsApp features:
- You agree to WhatsApp's Business Terms of Service
- You agree to WhatsApp's Business Policy
- Messages are transmitted through WhatsApp's infrastructure
Your Obligations
As a user of our Service to communicate via WhatsApp, you must:
- Obtain appropriate consent from your customers before messaging them
- Comply with WhatsApp's messaging policies and the 24-hour window rule
- Honor opt-out requests from your customers promptly
- Not send spam, unauthorized promotional messages, or messages to purchased contact lists
Data Retention for WhatsApp Conversations
WhatsApp message content, metadata, and AI analysis are retained for up to 5 years to provide the Service and meet legal obligations. You may request deletion at any time through your account settings or by contacting us.
Prohibited Data Collection
In compliance with WhatsApp Business Policy, you agree NOT to use our Service to collect, store, or transmit the following categories of sensitive information through WhatsApp:
- Payment card numbers (credit/debit card details, CVV, PIN)
- Government-issued identification numbers (passport, driver's license, national ID, Social Security Number)
- Financial account credentials (bank account numbers, login passwords)
- Protected health information (PHI) as defined by HIPAA or equivalent regulations
- Biometric data (fingerprints, facial recognition data)
- Information about minors under 13 (or higher age where applicable)
Our Service includes content filters to detect prohibited data, but you remain responsible for compliance. We reserve the right to remove prohibited content and suspend accounts that violate this policy.
Meta Reporting Obligations
We may share aggregated, non-personally-identifiable usage statistics with Meta as required by the WhatsApp Business API terms. This includes message volume, delivery rates, and quality metrics. We do not share individual message content with Meta beyond what is necessary to deliver messages.
13.2 Web Chat Widget and Connected Plugins
Our hosted web chat widget and connector plugins — which you install on your website, including WordPress — send visitor messages to our servers so they appear in your inbox and can be answered, scored, and tracked. This data is handled the same way as other Service data described in this Policy. As with WhatsApp, you are responsible for obtaining any consent required from your website visitors.
The widget also records how each visitor reached your site — ad click identifiers, campaign tags, the landing and referring addresses, the browser user agent, and any Meta Pixel cookies you have already placed on your own site (see Section 1.5). This lets you see which marketing produces enquiries, and, if you connect your own advertising account, lets us report your conversions back to that account (see Section 4.5). Because you decide whether to run a pixel and whether to connect an ad account, you are responsible for making sure your own website privacy notice and cookie consent cover this.
13.3 Standalone "Chat Lite" Plugin (Bring Your Own Key)
Our standalone Chat Lite WordPress plugin runs entirely on your own website using your own AI provider key (for example, OpenAI or Anthropic). In this mode, visitor conversations are processed directly between your website and your chosen AI provider under your account — they are not transmitted to or stored on Inboxxit's servers. For those conversations you are the data controller, and your AI provider's terms and privacy policy apply. We provide the plugin software and may collect limited license, activation, and diagnostic information (such as your site URL and plugin version), but not the content of your visitor conversations. If you later connect Chat Lite to your Inboxxit account, the "Web Chat Widget and Connected Plugins" practices above apply.
14 Artificial Intelligence and Automated Processing
14.1 AI Features
Our Service uses AI to provide:
- Temperature Scoring: Analyze lead readiness to purchase (OpenAI GPT-4o-mini)
- Intent Analysis: Understand customer message intent (OpenAI GPT-4o-mini)
- Chatbot Responses: Generate automated replies (Anthropic Claude)
- Smart Replies: Suggest response options for agents (Anthropic Claude)
- Booking Detection: Identify appointment requests (OpenAI GPT-4o-mini)
14.2 Automated Decision-Making
Our AI systems assist with lead prioritization, chatbot responses, and appointment status updates. You have the right to:
- Request human review of automated decisions
- Opt out of automated processing where legally required
- Understand the logic behind automated decisions
14.3 AI Data Practices
- Message content is sent to AI providers for real-time processing
- AI providers may retain limited data for a short period under their own terms (for example, abuse monitoring) unless a zero-retention agreement is in effect
- Your data is not used to train AI models without explicit consent
15 Cookies and Tracking Technologies
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, session management | Session |
| Functional | User preferences, language settings | 1 year |
| Analytics | Usage patterns, performance monitoring | 1 year |
| Advertising (read only) | Reading a business customer's existing Meta Pixel cookies (_fbp, _fbc) on their own website to attribute enquiries to their ads |
Not set by us |
You can control cookies through browser settings or account settings (analytics opt-out). Note: Blocking essential cookies may prevent access to the Service.
Advertising trackers. Inboxxit does not set advertising cookies, does not operate an advertising network, and does not track you across unrelated websites. Our web chat widget does read the Meta Pixel cookies (_fbp, _fbc) that a business has already placed on its own website, along with ad click identifiers in the page address, so that business can tell which of its ads produced an enquiry. Where the business has connected its own advertising account, that data is reported to the business's own Meta or Google Ads account, as described in Section 4.5. To limit this, turn on Global Privacy Control, which we honor automatically, or block advertising cookies in your browser, or contact the business operating the website. See Do Not Sell or Share My Personal Information.
16 Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be effective when posted, and the "Last Updated" date will be revised.
For material changes, we will:
- Notify you via email (if provided)
- Display a prominent notice within the Service
- Obtain consent where required by law
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
17 Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us: