inboxy

Privacy policy

last updated October 6, 2026

This privacy policy explains how INBOXY OÜ, a company registered in Estonia (registry code 16039091), Viru väljak 2, 10111 Tallinn, Estonia ("inboxy", "we", "us") collects, uses and protects personal data when you visit inboxy.io, use our dashboard and API, or otherwise use our Services.

1. Scope

This policy covers personal data we handle as a controller: data about our website visitors, customers, account users and prospects. It does not cover Customer Data we process on a customer's behalf as a processor, such as email content in mailboxes and recipient data; for that data, our customer is the controller and their own privacy notice applies.

2. Personal data we collect

2.1 Information you give us

  • account details: name, email address, company, password and team members you invite;
  • billing details: billing name and address, VAT number and payment information (card details are handled by our payment processor; we do not store full card numbers);
  • order details: domains, mailbox names and settings you choose;
  • messages you send us, including support requests and demo bookings.

2.2 Information collected automatically

  • device and log data such as IP address, browser, pages visited and timestamps;
  • usage data about how you use the dashboard, API and features.

2.3 Information from connected services

  • when you connect an inbox for Warmup, we access that inbox to send, open, reply to and move warmup messages, and we process related metadata;
  • when you connect a sequencer or DNS provider, we receive the data needed to make that connection work;
  • from our payment processor, confirmation of payments and limited card details such as type and last four digits.

3. How we use personal data

  • to create and run your Account and provide the Services, including provisioning mailboxes, configuring DNS, connecting sequencers and running Warmup;
  • to take payments, handle renewals and keep billing records;
  • to provide support and respond to requests;
  • to keep the Services secure, prevent fraud and abuse, and enforce our terms;
  • to understand and improve the Services, including using aggregated or de-identified data;
  • to send service messages, such as renewal notices and alerts, and, where allowed, product updates and marketing you can opt out of;
  • to comply with legal obligations and protect our rights;
  • in connection with a merger, acquisition or sale of our business.

4. Legal bases

Under the GDPR we rely on: contract (to provide the Services you ordered), legitimate interests (to secure, improve and market the Services, balanced against your rights), legal obligation (for example, accounting and tax records) and consent (where required, such as for certain marketing; you can withdraw it at any time).

5. Who we share personal data with

  • service providers that help us run the Services, such as cloud hosting (Amazon Web Services), email delivery, payment processing, scheduling (Calendly) and support tools, under contracts that protect your data;
  • third-party providers you use with us, such as Google for Workspace mailboxes, and the sequencers and DNS hosts you connect;
  • members of your Account: owners and administrators can see activity and data within the Account;
  • professional advisers, such as lawyers and accountants;
  • authorities, where required by law or to protect rights and safety;
  • a buyer or successor in a business transfer.

We do not sell personal data.

6. Cookies

Our website uses only what is needed for it to work. Some pages embed third-party services, such as Calendly on our demo page and YouTube videos on blog posts, which may set their own cookies. See our cookie policy.

7. Marketing choices

You can unsubscribe from marketing emails using the link in any of them or by contacting us. We will still send service messages about your Account, billing and renewals.

8. Retention

We keep personal data while your Account is active and as long as needed for the purposes above. Billing and accounting records are kept for the period required by Estonian law (currently seven years). Mailboxes deleted under our renewal policy or after termination are removed from our systems and Google within a reasonable time, apart from backups that expire on their normal cycle.

9. International transfers

We are based in the EU. Some providers process data outside the European Economic Area, including in the United States. Where they do, we rely on adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses to protect your data.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and infrastructure hosted on AWS. No system is fully secure, so please keep your credentials safe and tell us about any suspected breach.

11. Customers' responsibilities

If you use inboxy to send email, you are responsible for having a lawful basis to contact your recipients and for giving them the information the law requires. Account administrators can see data within the Account they manage.

12. Children

The Services are for businesses and are not directed at anyone under 18. We do not knowingly collect children's personal data.

13. Your rights

13.1 EEA, UK and Switzerland

You have the right to access, correct, delete or port your personal data, to restrict or object to processing, and to withdraw consent. You can also complain to a supervisory authority; in Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

13.2 United States

Depending on your state, you may have rights to know, access, correct or delete personal data and to opt out of certain processing. We do not sell or share personal data for cross-context behavioural advertising.

To exercise any right, email info@inboxy.io. We may need to verify your identity. If your data is Customer Data controlled by one of our customers, we will refer your request to them.

14. Do Not Track

Our website does not respond to Do Not Track signals, as there is no common standard for them. We do not track you across other websites.

15. Third-party links

Our website links to other sites and services. Their privacy practices are their own; please read their policies.

16. Changes

We may update this policy. We will post the new version here with a new date and, for material changes, let customers know by email or in the dashboard.

17. Contact

INBOXY OÜ, a company registered in Estonia (registry code 16039091), Viru väljak 2, 10111 Tallinn, Estonia. Email: info@inboxy.io.