Last updated: March 2026
Your Privacy, Plainly Stated.
We believe privacy policies should be readable by humans, not just lawyers. Here's exactly what data we collect, why we collect it, and how you can control it.
Plain Language Summary
InboxROI collects data to operate its email marketing platform. We do not sell your personal data to third parties. We do not use your data to train AI models. You can request deletion of your data at any time. The sections below explain everything in detail.
Information We Collect
Name, email address, company name, billing address, and password (stored as a one-way hash). Collected when you register or update your profile.
Account Information
Name, email address, company name, billing address, and password (stored as a one-way hash). Collected when you register or update your profile.
Payment Information
Credit card details are processed and stored by Stripe, Inc. InboxROI only stores the last 4 digits and card type for display purposes. We never see or store your full card number.
Email Campaign Data
Content of emails you create, subscriber lists you upload, campaign configuration settings, and automation rules. This data is yours — we process it solely to provide the service.
Usage & Analytics Data
Pages visited, features used, clicks, session duration, and error logs. Collected automatically via our analytics infrastructure to improve platform performance.
Device & Technical Data
IP address, browser type, operating system, device identifiers, and timezone. Used for security, fraud prevention, and service delivery.
Integration Data
When you connect third-party services (Shopify, Klaviyo, HubSpot), we receive the data scopes you authorise during the OAuth flow. You can revoke access at any time from Settings → Integrations.
How We Use Your Data
We use the information we collect for specific, legitimate purposes. We do not use your data for any purpose not listed below without first obtaining your explicit consent.
Providing, operating, and maintaining the InboxROI platform and all its features
Processing payments and managing your subscription, including billing notifications
Sending transactional emails: account confirmations, password resets, and invoices]
Sending product updates, feature announcements, and newsletters (you can unsubscribe any time)
Analysing aggregate usage patterns to improve platform performance and user experience
Detecting, investigating, and preventing fraudulent activity and security breaches
Complying with legal obligations including tax records and regulatory requirements
Responding to support requests, complaints, and legal enquiries
What we never do
We do not sell your personal data. We do not use your data to train machine learning models. We do not use your subscriber lists for our own marketing. We do not allow third parties to use your data for their own purposes.
Sharing & DisclosureTaxes
We share your data only with trusted service providers who help us operate the platform, and only under strict data processing agreements. We never sell your data, and we never allow third parties to use your data for their own commercial purposes.
Infrastructure & Hosting — Amazon Web Services
All platform data is stored on AWS servers located in the EU (Frankfurt) and US (N. Virginia). AWS operates under a Data Processing Agreement with us.
Payment Processing — Stripe, Inc.
Stripe handles all payment card data. They are PCI DSS Level 1 certified. We share only the minimum billing details required to process transactions.
Transactional Email — Amazon SES
Account emails (confirmations, password resets) are sent via Amazon Simple Email Service. Message content is encrypted in transit and at rest.
Analytics — Plausible Analytics
We use Plausible for privacy-respecting website analytics. Plausible does not use cookies and does not collect personal identifiers. All data is aggregated and anonymous.
Customer Support — Intercom
Support conversations are managed via Intercom. Only your name, email, and conversation history are shared. You can request deletion of support records at any time.
Integration Data
When you connect third-party services (Shopify, Klaviyo, HubSpot), we receive the data scopes you authorise during the OAuth flow. You can revoke access at any time from Settings → Integrations.
What we never do
We do not sell your personal data. We do not use your data to train machine learning models. We do not use your subscriber lists for our own marketing. We do not allow third parties to use your data for their own purposes.
Your Rights
Depending on your location, you have a number of rights regarding your personal data. We honour these rights for all users globally, not just those in jurisdictions where they are legally mandated.
Right to Access
Request a copy of all personal data we hold about you, in a portable format.
Right to Rectification
Correct any inaccurate or incomplete information we hold about you.
Right to Erasure
Request deletion of your personal data. We will delete within 30 days, subject to legal obligations.
Right to Object
Object to processing of your data for marketing purposes at any time.
Right to Restriction
Request we limit how we use your data while you contest its accuracy or our basis for processing it.
Right to Portability
Receive your data in a structured, machine-readable format (JSON or CSV) to transfer to another provider.
How to Exercise Your Rights
Email privacy@inboxroi.com with your request. We will respond within 30 days (GDPR) or 45 days (CCPA). Identity verification may be required for security purposes. There is no charge for exercising your rights.
Security
Encryption in Transit and at Rest
All data is encrypted using TLS 1.3 in transit and AES-256 at rest. Database backups are encrypted using the same standard.
Access Controls
Employee access to production systems is role-based, logged, and requires hardware MFA. Only engineers with operational need can access production infrastructure.
Penetration Testing
We conduct annual penetration tests with independent third-party security firms. Results and remediation timelines are reviewed by our board.
Breach Notification
In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, as required by GDPR. We will include details of what was affected and steps taken.
International Transfers
InboxROI is headquartered in the United States, but our primary data processing infrastructure is located in the EU (AWS Frankfurt). If you are accessing the service from the European Economic Area, your data may be transferred to or processed in the US.
We ensure such transfers comply with GDPR through the following mechanisms:
Standard Contractual Clauses (SCCs) approved by the European Commission with all US-based sub-processors
Transfer Impact Assessments (TIAs) completed for all third-country transfers
EU representative appointed under Article 27 GDPR: DataRep, Dublin, Ireland
UK IDTA addenda for transfers to the UK post-Brexit
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your data, please contact us through any of the following channels.
Data Protection Officer
privacy@inboxroi.com — Response within 48 business hours. For GDPR and CCPA requests, include "Data Request" in the subject line
Postal Address
InboxROI Inc., 340 Pine Street, Suite 800, San Francisco, CA 94104, United States
EU Representative (GDPR Art. 27)
DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland. eu@inboxroi.com
Supervisory Authority
EU residents have the right to lodge a complaint with their national data protection authority. A list of authorities is available at edpb.europa.eu.











