Scope of this policy
This policy explains how Infrabox ("we", "us"), collects, uses, discloses and safeguards information when you use our website, dashboard, API and related services (together, the "Service"). It applies to account holders, the individuals they authorize, and visitors to our marketing pages.
It does not cover the content of email you send through mailboxes you provision, or data your organization holds in the CRMs, sequencers, and other third-party tools you connect. Those are governed by your agreement with your own customers and with those tool providers.
Information we collect
We collect information in three broad categories: information you give us, information generated by your use of the Service, and information we receive from connected tools.
Information you provide
- Account details: name, work email, password hash, company name, and billing contact.
- Domain and mailbox configuration you enter, including local parts, sender names, and warmup preferences.
- Payment details, which are collected and stored by our payment processor, not by us directly.
- Support requests, survey responses, and anything you send us by email or through a contact form.
Information generated automatically
- Usage data: pages viewed, features used, timestamps, and general session activity inside the dashboard.
- Technical data: IP address, browser type, device type, and operating system, collected via standard server logs.
- Deliverability telemetry: send volume, bounce codes, authentication status, and blocklist signals tied to domains you manage.
Information from connected tools
If you connect a sequencer, CRM, or analytics tool from our integrations directory, we receive the fields necessary to keep sends and events in sync, typically contact identifiers, sequence status, and reply metadata. We do not request more than the connection needs to function.
How we use your information
- Provide the Service: provisioning domains and mailboxes, publishing DNS records, running warmup schedules, and surfacing deliverability data.
- Maintain security: detecting abuse, fraud, and violations of our acceptable use terms across the sending network.
- Support and communicate: responding to requests, sending service notices, and, where you have opted in, product updates.
- Improve the Service: understanding aggregate usage patterns to prioritize what we build next.
- Meet legal and accounting obligations, including billing records and tax reporting.
Legal bases for processing
Infrabox is based in India, and the Digital Personal Data Protection Act, 2023 (the "DPDP Act") is the primary law governing how we handle personal data. For the account and configuration data whose purposes we decide, we act as a Data Fiduciary; for the contact data you upload or connect, we act on your instructions as a Data Processor and you remain the Data Fiduciary. Under the DPDP Act we process personal data on the basis of consent given in response to a clear notice at the point of collection, or on one of the certain legitimate uses the Act allows, such as data you voluntarily provide for a purpose you have not objected to, and processing needed to comply with a legal obligation or an order of an Indian court.
Because our customers send email to recipients across the world, we also comply with the GDPR and the UK GDPR where they apply to individuals in the EU or the UK. For that processing we rely on performance of our contract with you, our legitimate interest in operating and securing a reliable sending platform, your consent where we ask for it directly (for example, marketing email), and compliance with legal obligations such as tax and accounting rules.
You may withdraw consent at any time, and as easily as you gave it, where consent is the basis for a particular use; this does not affect processing carried out before the withdrawal.
Sub-processors
We use a small number of vetted service providers to operate the Service. We do not name individual vendors in this policy since our provider list changes over time; instead, each is described by the role it performs, the general region it operates in, and the category of data it can access. A current, itemized list is available on request.
Role
Cloud hosting provider
- Region
- India / EU
- Function
- Runs the application, databases, and mailbox infrastructure.
Role
Payment processor
- Region
- India
- Function
- Handles billing, invoicing, and card data. We never store full card numbers.
Role
Error monitoring
- Region
- EU
- Function
- Captures crash and performance diagnostics to fix issues quickly.
Role
Email delivery relay
- Region
- India / US
- Function
- Routes transactional notifications such as password resets and alerts.
Role
Customer support platform
- Region
- EU / US
- Function
- Stores support tickets and conversation history with our team.
Role
Analytics provider
- Region
- EU
- Function
- Aggregated, privacy-respecting measurement of product usage.
| Role | Region | Function |
|---|---|---|
| Cloud hosting provider | India / EU | Runs the application, databases, and mailbox infrastructure. |
| Payment processor | India | Handles billing, invoicing, and card data. We never store full card numbers. |
| Error monitoring | EU | Captures crash and performance diagnostics to fix issues quickly. |
| Email delivery relay | India / US | Routes transactional notifications such as password resets and alerts. |
| Customer support platform | EU / US | Stores support tickets and conversation history with our team. |
| Analytics provider | EU | Aggregated, privacy-respecting measurement of product usage. |
Data retention
We keep account and configuration data for as long as your account is active, and for a limited period afterward to allow reactivation, satisfy legal obligations, resolve disputes, and enforce our agreements. Deliverability telemetry is generally retained for up to 24 months on a rolling basis to support trend analysis. Billing records are kept for as long as required by Indian accounting, company and tax rules. You can request earlier deletion as described in "Your privacy rights" below.
International data transfers
Personal data is processed primarily in India, and our sub-processors operate in India and other regions. Where personal data leaves India, we transfer it only to countries that the Central Government has not restricted for such transfers under the DPDP Act, and we apply appropriate safeguards (contractual protections equivalent to standard contractual clauses, or reliance on a recipient's recognized certification) so that it stays protected to a standard consistent with this policy. Personal data reaching us from the EU or the UK is transferred to India under the applicable standard contractual clauses, with supplementary measures where required.
Your privacy rights
Depending on where you live, you may have some or all of the following rights over the personal data we hold about you. If you are in India, these are the rights the DPDP Act gives you as a Data Principal; if you are in the EU or the UK, they follow from the GDPR.
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate or incomplete information.
- Erasure: request deletion of personal data we no longer need to retain.
- Portability: receive a structured export of data you provided to us.
- Objection: object to certain processing, including for direct marketing at any time.
- Restriction: ask us to limit processing while a request is under review.
- Nomination: under the DPDP Act, nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
- Grievance redressal: raise a complaint with our grievance officer and receive a reasoned response.
To exercise any of these rights, contact us using the details at the end of this policy. We will verify your request and respond within the timeframe required by applicable law. We may decline requests that are manifestly unfounded, excessive, or that conflict with our own legal obligations, and we will explain why if that happens.
If you are a California resident, you may additionally have rights under California privacy law, including to know what personal information we collect and to ask us to delete it. We do not sell personal information, and we will not discriminate against you for exercising any of these rights.
Security measures
- Encryption of data in transit using TLS, and encryption of sensitive fields at rest.
- Role-based access controls and audit logging across internal systems that touch customer data.
- Independent access reviews and least-privilege provisioning for staff accounts.
- Continuous monitoring for unusual access patterns across the sending network.
- A documented incident response process, including notification to affected customers, and to the Data Protection Board of India or another regulator, without undue delay where required by law.
No method of transmission or storage is completely secure. We work to protect your information but cannot guarantee absolute security.
Children's data
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from anyone under 18, the age below which the DPDP Act treats an individual as a child; in the EU and the UK the equivalent threshold is 16. If you believe a minor has provided us with personal data, contact us and we will delete it promptly.
Marketing communications
We may send product updates, deliverability research, and occasional offers to the email address on your account. Every marketing message includes an unsubscribe link, and opting out takes effect immediately. Service notices related to your account, billing, or security are not marketing and will continue regardless of your marketing preferences.
Changes to this policy
We may update this policy as the Service, our vendors, or applicable law change. If a change is material, we will notify account owners by email or an in-dashboard notice at least 14 days before it takes effect. The "Last updated" date at the top of this page always reflects the current version.
Contact us
Questions, requests, or complaints about this policy can be sent to [email protected], or through the contact form linked below. They are handled by our Data Protection Officer, who also acts as our grievance officer under the DPDP Act and can be reached at that address or by post at our registered office in New Delhi. We aim to respond to every privacy request within 30 days.
If you are not satisfied with how we have handled a request, you may escalate it to the Data Protection Board of India. If you are in the EU or the UK, you may instead complain to your local supervisory authority.
