Privacy Policy
This Privacy Policy explains how InboxIt (“InboxIt”, “we”, “us”) collects, uses, shares, and protects information. It covers the website at inboxit.io and the InboxIt application at app.inboxit.io (together, the “Service”). InboxIt is a done-for-you cold outreach platform. By using the Service, you agree to this policy.
Information we collect
From the website. If you use the form on the home page, we collect the email address you enter and, if you add one, your company website. Your email is stored as soon as you have typed a whole address, even if you close the tab without pressing the button. We use it to reply to you. We do not add you to an automated sequence.
From customers who use the app. When InboxIt staff create a workspace for a customer, we hold account details (name, work email, the workspace and its settings), the campaign content a customer sends, and the contact lists a customer or InboxIt uploads on the customer’s behalf. Those lists may include the names, email addresses, company details, and public professional information of the people a customer chooses to contact.
From a connected Google account. A customer may connect a Google or Google Workspace account so InboxIt can send and manage outreach from that mailbox. When they do, we access Google data through Google’s APIs. See Google user data and API scopes below.
Automatically. Our servers and our hosting providers keep request logs, which normally include an IP address, a timestamp, the page or endpoint requested, and basic device and browser information. We use these to run and secure the Service.
Google user data and API scopes
When a customer connects a Google account, InboxIt requests only the access needed to run their outreach. Depending on the features in use, this can include permission to:
- read the account’s basic profile, such as the email address and name, to identify the connected mailbox;
- send email on the customer’s behalf, so campaigns go out from their own address;
- read email metadata and messages only as needed to detect, thread, and route replies to the customer’s outreach.
The exact scopes requested are always shown to you on the Google consent screen before you approve them, and you can withdraw that access at any time (see Your choices and rights).
Limited Use. InboxIt’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not use it to train generalized or standalone AI or machine learning models, and humans do not read it except where you give explicit consent, where needed for security or to comply with the law, or where the data has been aggregated and anonymized.
How we use information
We use the information we collect to:
- provide, operate, and maintain the Service;
- send, schedule, and manage a customer’s outreach and route the replies it receives;
- respond to enquiries and provide support;
- keep the Service secure, prevent abuse, and meet legal obligations;
- improve the reliability and quality of the Service.
How we share information
We do not sell personal information. We share it only with service providers who help us run the Service, and only as needed for them to do so. These include our hosting and infrastructure providers, Google (for accounts a customer connects), and the email-delivery services used to send outreach. We may also disclose information where the law requires it, to protect our rights or the safety of others, or as part of a merger or acquisition, in which case we will give notice.
Data retention
We keep information for as long as needed to provide the Service and for a reasonable period afterward to meet legal, accounting, and security needs. When a customer closes a workspace or disconnects a Google account, we delete or de-identify the associated data within a reasonable time, except where we are required to keep it.
Security
We use administrative, technical, and physical safeguards to protect information, including access controls, encryption in transit, and per-workspace isolation. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
Your choices and rights
You may ask us to access, correct, or delete personal information we hold about you, and depending on where you live you may have further rights under laws such as GDPR or the CCPA. To make a request, contact us at the address below.
You can disconnect a Google account from within the InboxIt app, and you can revoke InboxIt’s access to your Google account at any time from your Google Account permissions page. Revoking access stops all further access and, unless we are required to keep it, we delete the Google data we held for that connection.
Cookies and analytics
The inboxit.io marketing site sets no cookies and runs no analytics. The InboxIt app uses only the cookies strictly needed to keep you signed in and to keep the app secure. If we add analytics later, we name it here first.
International users
We operate the Service from the United States and may process information there and in other countries where our providers operate. By using the Service you understand your information may be transferred to and processed in those countries.
Children
The Service is for business use and is not intended for anyone under 18. We do not knowingly collect information from children.
Changes to this policy
We may update this policy from time to time. When we do, we change the date at the top of this page, and, for material changes, we take reasonable steps to let affected customers know.
Contact us
If you have any question about this policy or your information, email us at info@inboxit.io. The Service is operated by InboxIt, and this policy is governed by the laws of the United States.