Legal
Privacy Policy
Last updated: 16 August 2026
This Privacy Policy explains how the operator of InboxMon (InboxMon, we, us) handles personal data. It should be read with the Terms of Service. If the GDPR, UK GDPR, or a similar law applies to Customer Data you submit, the Data Processing Addendum also applies.
Contact: hello@inboxmon.com. Principal place of business: Thane, Maharashtra, India.
1. Two roles
Account data. When you sign up, we are the controller of your work email, name, company label, authentication data, billing identifiers, and product-usage logs needed to run the account.
Customer Data. When you connect an ESP, add a VIP pattern, use list hygiene, or cause mail to be sent to a dedicated monitoring inbox, you are the controller of that personal data (for example recipient addresses in events, VIP whitelist entries, and message content delivered to an alias you created). We are the processor / service provider. We process Customer Data only on your instructions to provide the Service. Recipients and data subjects should contact you for those requests; we will assist you as described in the DPA.
2. What we collect
- Account: email, password hashes via our auth provider, company name, role, 2FA status, session metadata.
- ESP monitoring: webhook payloads your provider sends (event type, timestamps, domains, hashed or truncated recipient identifiers as stored by the product, raw payload as configured).
- Settings you enter: VIP emails or domains, hygiene block/allow lists, Slack webhook URLs, DKIM selectors.
- Dedicated monitoring inbox: messages addressed to an alias you create (headers, subject, HTML/text body). Previews are intended not to load remote tracking pixels. A third-party site may reject or block a subscription you place with that alias; we then have nothing to store for that send.
- Billing: Stripe customer and subscription IDs if checkout is used (card data stays with Stripe).
- Technical: IP, user agent, and security/audit logs.
We do not require payment-card PAN, government ID, or special-category data. Please do not send them.
3. Why we use it (legal bases)
For account data we typically rely on:
- Contract: to create the workspace, authenticate you, and provide the Service.
- Legitimate interests: security, fraud prevention, product reliability, aggregated metrics that do not identify you.
- Legal obligation: tax, accounting, or a binding request from a competent authority.
- Consent: where we ask for it (for example optional marketing from us, if any).
For Customer Data, you determine the purpose. Our basis as processor is your instructions under the Terms and DPA. You must have your own lawful basis to collect and share that data with us (including VIP addresses and mail you subscribe a monitoring alias to receive).
4. Subprocessors
We use infrastructure vendors to host and operate InboxMon. Current categories and typical providers:
- Hosting / application: Vercel
- Database and authentication: Supabase
- Background jobs: Inngest
- Monitoring-inbox routing: Cloudflare (email worker)
- Payments (if enabled): Stripe
- Optional alert delivery that you enable: Slack (your webhook), Resend or similar email, Twilio SMS
Your own ESPs (SendGrid, Postmark, Amazon SES) are your processors, not ours. We receive events they send to a URL you configure. A change of subprocessors will be reflected in this list or the DPA. EU/UK customers may object as described in the DPA.
5. International transfers
We and several subprocessors may process data outside your country (including the United States, India, and the EU). Where a GDPR/UK GDPR transfer tool is required, we rely on the vendor's Standard Contractual Clauses (or equivalent) plus the DPA. You authorize those transfers when you use the Service.
6. Retention
Account data is kept while the workspace exists and for a limited period afterward as needed for security and legal records. Customer Data follows plan caps and product retention (for example older monitoring-inbox captures may be deleted automatically). We may keep backups for a short window. After you close the account we delete or de-identify Customer Data except where we must retain it by law.
7. Your rights
If we are the controller (account data) and a data-protection law grants you rights of access, correction, deletion, restriction, portability, or objection, email hello@inboxmon.com. You may also complain to a supervisory authority.
If the request concerns Customer Data (VIP lists, ESP events, monitoring-inbox contents), we will point the individual to you as controller, or act on your documented instruction.
8. Security and incidents
We use commercially reasonable measures (access control, TLS in transit, tenant isolation in the application). No method is perfectly secure. Incident notice to customers is as described in the Terms and DPA.
9. Cookies
We use essential cookies/session storage to keep you signed in and protect the app. We do not use the Service as an advertising network. Third-party embeds you choose (for example opening Stripe Checkout) may set their own cookies under their policies.
10. Children
The Service is for business users. It is not directed at children under 16.
11. Changes
We may update this Policy by posting a new version with a new date. Material changes will apply going forward. Continued use after the date is acceptance where permitted.