Plain English summary: We collect only what we need to run the service. We do not sell your data. We do not share it with advertisers. Your contact lists belong to you. We encrypt your email credentials. You can delete your data any time. We comply with GDPR, and we answer privacy questions within 30 days.
This Privacy Policy describes how Inboxrise ("we", "us", or "our") collects, uses, stores, and shares information when you use our platform at inboxrise.com and associated services ("Service").
We are committed to protecting your privacy and handling your data with transparency. This policy applies to all users of Inboxrise, including free trial users, paid subscribers, and visitors to our website.
For users in the European Union, we act as a data processor for the personal data of your contacts, and as a data controller for your own account data. We are committed to full compliance with the General Data Protection Regulation (GDPR).
We collect the following categories of information:
Account information
Email infrastructure data
Contact data
Usage and technical data
We use the data we collect for the following purposes:
We do not: sell your data to third parties, use your data for advertising, share your contact lists with other users, or use your email content to train machine learning models.
For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following legal bases:
For your contacts' personal data (names, email addresses you import), you are the data controller and we act as a data processor under Article 28 of the GDPR. A Data Processing Agreement (DPA) is available on request at privacy@inboxrise.com.
We share your data only in the following limited circumstances:
We do not share, sell, rent, or trade your personal data or your contacts' data with any third party for their own marketing or commercial purposes.
When you connect a Google (Gmail or Google Workspace) mailbox to Inboxrise using "Sign in with Google", you grant access to your Google account through Google's OAuth 2.0 consent flow. This section describes exactly what we access and how we handle it.
What we access. With your explicit consent, we request the Gmail scope https://mail.google.com/, which lets Inboxrise send email on your behalf and read messages in the connected mailbox. We use this access solely to (a) send the outreach emails and follow-ups you configure, and (b) read incoming messages to detect replies — so we can pause sequences, capture responses, and surface them in your unified inbox and pipeline.
What we store. We store the OAuth access and refresh tokens Google issues, encrypted at rest. We store metadata and the content of detected replies (sender, subject, snippet, timestamps) so the product can function. We do not create or retain a copy of your entire mailbox.
Limited Use. Inboxrise's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
Your control. You can disconnect a Google mailbox at any time from the Inboxes page, or revoke Inboxrise's access directly in your Google Account at myaccount.google.com/permissions. On disconnection we delete the stored OAuth tokens for that mailbox.
We use the following third-party sub-processors to operate our Service. Each is bound by a data processing agreement and appropriate safeguards:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting (PostgreSQL) and background job queue | South Asia (Mumbai) |
| Hostinger | Application hosting, VPS infrastructure, and transactional email (account notifications) | India / EU |
| Lemon Squeezy | Payment processing and merchant of record (subscription billing and sales tax) | USA (SCCs applied) |
We review our sub-processors regularly and will update this list when changes occur. You may request notification of sub-processor changes by emailing privacy@inboxrise.com.
We retain different types of data for different periods based on the purpose for which they were collected:
You may request early deletion of your data at any time (subject to legal retention obligations) by contacting privacy@inboxrise.com.
We take data security seriously and implement the following technical and organisational measures:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware, as required by GDPR Article 33.
To report a security vulnerability, please email security@inboxrise.com. We take all reports seriously and respond within 48 hours.
Depending on your location, you have the following rights regarding your personal data. We respond to all valid requests within 30 days.
To exercise any of these rights, email privacy@inboxrise.com with your request. We may need to verify your identity before processing. If you are unhappy with our response, you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU).
We use a minimal set of cookies to operate the Service:
We do not use third-party advertising cookies. We do not place tracking pixels in emails we send on your behalf without your explicit configuration to do so.
You can control cookies through your browser settings. Disabling essential cookies will prevent you from logging in to the Service.
Inboxrise is headquartered in India. Our primary database infrastructure is hosted in South Asia (Mumbai). Some sub-processors are located in the United States or European Union.
For transfers of personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission. Our sub-processors in the USA have signed SCCs or are covered by equivalent safeguards.
You may request a copy of the relevant transfer mechanisms by contacting privacy@inboxrise.com.
The Service is not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children.
If you believe we have inadvertently collected data from a child, please contact us at privacy@inboxrise.com and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:
We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
We respond to all privacy-related enquiries within 30 days. For complex requests involving data access or erasure, we may take up to 3 months and will notify you of any extension within the initial 30-day period.