Skip to content
Legal

Privacy Policy

Last updated 12 March 2026

Plain English summary

We collect the account, configuration, and deliverability data needed to run your sending infrastructure. We never sell it, we share it only with the vetted providers listed below, and you can access, export, or delete your data at any time.

On this page15 sections
  1. 1Scope of this policy
  2. 2Information we collect
  3. 3How we use your information
  4. 4Legal bases for processing
  5. 5Cookies and tracking technologies
  6. 6How we share your information
  7. 7Sub-processors
  8. 8Data retention
  9. 9International data transfers
  10. 10Your privacy rights
  11. 11Security measures
  12. 12Children's data
  13. 13Marketing communications
  14. 14Changes to this policy
  15. 15Contact us
1

Scope of this policy

This policy explains how Infrabox ("we", "us"), collects, uses, discloses and safeguards information when you use our website, dashboard, API and related services (together, the "Service"). It applies to account holders, the individuals they authorize, and visitors to our marketing pages.

It does not cover the content of email you send through mailboxes you provision, or data your organization holds in the CRMs, sequencers, and other third-party tools you connect. Those are governed by your agreement with your own customers and with those tool providers.

2

Information we collect

We collect information in three broad categories: information you give us, information generated by your use of the Service, and information we receive from connected tools.

Information you provide

  • Account details: name, work email, password hash, company name, and billing contact.
  • Domain and mailbox configuration you enter, including local parts, sender names, and warmup preferences.
  • Payment details, which are collected and stored by our payment processor, not by us directly.
  • Support requests, survey responses, and anything you send us by email or through a contact form.

Information generated automatically

  • Usage data: pages viewed, features used, timestamps, and general session activity inside the dashboard.
  • Technical data: IP address, browser type, device type, and operating system, collected via standard server logs.
  • Deliverability telemetry: send volume, bounce codes, authentication status, and blocklist signals tied to domains you manage.

Information from connected tools

If you connect a sequencer, CRM, or analytics tool from our integrations directory, we receive the fields necessary to keep sends and events in sync, typically contact identifiers, sequence status, and reply metadata. We do not request more than the connection needs to function.

3

How we use your information

  • Provide the Service: provisioning domains and mailboxes, publishing DNS records, running warmup schedules, and surfacing deliverability data.
  • Maintain security: detecting abuse, fraud, and violations of our acceptable use terms across the sending network.
  • Support and communicate: responding to requests, sending service notices, and, where you have opted in, product updates.
  • Improve the Service: understanding aggregate usage patterns to prioritize what we build next.
  • Meet legal and accounting obligations, including billing records and tax reporting.
5

Cookies and tracking technologies

We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the marketing site and dashboard are used. You can control non-essential cookies through the preference banner or your browser settings; blocking essential cookies may prevent parts of the Service from working.

Category

Essential

Purpose
Keeps you signed in and secures your session across the dashboard.
Typical lifespan
Session, or up to 30 days

Category

Preferences

Purpose
Remembers settings such as dashboard layout and dismissed notices.
Typical lifespan
Up to 1 year

Category

Analytics

Purpose
Aggregated measurement of which pages and features are used.
Typical lifespan
Up to 13 months

Category

Marketing

Purpose
Set only with consent, to measure the performance of our own campaigns.
Typical lifespan
Up to 90 days
6

How we share your information

We do not sell personal information. We share it only in the following circumstances: with sub-processors who help us run the Service (see the table below), with the third-party tools you explicitly connect, with professional advisors under confidentiality obligations, in connection with a merger, acquisition or asset sale, or where required to comply with law, enforce our terms, or protect the rights and safety of Infrabox and our customers.

7

Sub-processors

We use a small number of vetted service providers to operate the Service. We do not name individual vendors in this policy since our provider list changes over time; instead, each is described by the role it performs, the general region it operates in, and the category of data it can access. A current, itemized list is available on request.

Role

Cloud hosting provider

Region
India / EU
Function
Runs the application, databases, and mailbox infrastructure.

Role

Payment processor

Region
India
Function
Handles billing, invoicing, and card data. We never store full card numbers.

Role

Error monitoring

Region
EU
Function
Captures crash and performance diagnostics to fix issues quickly.

Role

Email delivery relay

Region
India / US
Function
Routes transactional notifications such as password resets and alerts.

Role

Customer support platform

Region
EU / US
Function
Stores support tickets and conversation history with our team.

Role

Analytics provider

Region
EU
Function
Aggregated, privacy-respecting measurement of product usage.
8

Data retention

We keep account and configuration data for as long as your account is active, and for a limited period afterward to allow reactivation, satisfy legal obligations, resolve disputes, and enforce our agreements. Deliverability telemetry is generally retained for up to 24 months on a rolling basis to support trend analysis. Billing records are kept for as long as required by Indian accounting, company and tax rules. You can request earlier deletion as described in "Your privacy rights" below.

9

International data transfers

Personal data is processed primarily in India, and our sub-processors operate in India and other regions. Where personal data leaves India, we transfer it only to countries that the Central Government has not restricted for such transfers under the DPDP Act, and we apply appropriate safeguards (contractual protections equivalent to standard contractual clauses, or reliance on a recipient's recognized certification) so that it stays protected to a standard consistent with this policy. Personal data reaching us from the EU or the UK is transferred to India under the applicable standard contractual clauses, with supplementary measures where required.

10

Your privacy rights

Depending on where you live, you may have some or all of the following rights over the personal data we hold about you. If you are in India, these are the rights the DPDP Act gives you as a Data Principal; if you are in the EU or the UK, they follow from the GDPR.

  • Access: request a copy of the personal data we hold about you.
  • Correction: ask us to fix inaccurate or incomplete information.
  • Erasure: request deletion of personal data we no longer need to retain.
  • Portability: receive a structured export of data you provided to us.
  • Objection: object to certain processing, including for direct marketing at any time.
  • Restriction: ask us to limit processing while a request is under review.
  • Nomination: under the DPDP Act, nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
  • Grievance redressal: raise a complaint with our grievance officer and receive a reasoned response.

To exercise any of these rights, contact us using the details at the end of this policy. We will verify your request and respond within the timeframe required by applicable law. We may decline requests that are manifestly unfounded, excessive, or that conflict with our own legal obligations, and we will explain why if that happens.

If you are a California resident, you may additionally have rights under California privacy law, including to know what personal information we collect and to ask us to delete it. We do not sell personal information, and we will not discriminate against you for exercising any of these rights.

11

Security measures

  • Encryption of data in transit using TLS, and encryption of sensitive fields at rest.
  • Role-based access controls and audit logging across internal systems that touch customer data.
  • Independent access reviews and least-privilege provisioning for staff accounts.
  • Continuous monitoring for unusual access patterns across the sending network.
  • A documented incident response process, including notification to affected customers, and to the Data Protection Board of India or another regulator, without undue delay where required by law.

No method of transmission or storage is completely secure. We work to protect your information but cannot guarantee absolute security.

12

Children's data

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from anyone under 18, the age below which the DPDP Act treats an individual as a child; in the EU and the UK the equivalent threshold is 16. If you believe a minor has provided us with personal data, contact us and we will delete it promptly.

13

Marketing communications

We may send product updates, deliverability research, and occasional offers to the email address on your account. Every marketing message includes an unsubscribe link, and opting out takes effect immediately. Service notices related to your account, billing, or security are not marketing and will continue regardless of your marketing preferences.

14

Changes to this policy

We may update this policy as the Service, our vendors, or applicable law change. If a change is material, we will notify account owners by email or an in-dashboard notice at least 14 days before it takes effect. The "Last updated" date at the top of this page always reflects the current version.

15

Contact us

Questions, requests, or complaints about this policy can be sent to [email protected], or through the contact form linked below. They are handled by our Data Protection Officer, who also acts as our grievance officer under the DPDP Act and can be reached at that address or by post at our registered office in New Delhi. We aim to respond to every privacy request within 30 days.

If you are not satisfied with how we have handled a request, you may escalate it to the Data Protection Board of India. If you are in the EU or the UK, you may instead complain to your local supervisory authority.

Questions about this policy?

Our support team can walk through any clause, or connect you with someone who can.

Contact us