Teaminbox

Privacy Policy

1. Introduction

Tech Fusioncodes Technologies Private Limited ("Company", "TeamInbox", "we", "us" or "our") operates TeamInbox, a business communication, shared inbox, customer relationship management, lead management and automation platform available through https://teaminbox.xyz/ , its dashboards, applications, APIs, widgets and related services (collectively, the "Service").

This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when a person visits our website, creates or uses a TeamInbox account, contacts us, uses our support services, or communicates with a business that uses TeamInbox.

TeamInbox is intended primarily for businesses and authorised business users. By accessing or using the Service, you acknowledge this Privacy Policy. If you use TeamInbox on behalf of an organisation, that organisation is responsible for ensuring that its use of the Service complies with applicable privacy, marketing and communications laws.

2. Scope and Roles

This Policy applies to personal data processed through the Service, including:

  • website visitor and enquiry data;
  • customer account, billing and authorised-user data;
  • WhatsApp Business Account and other connected-channel information;
  • customer contacts, leads, conversations, messages, media, notes and CRM records processed through TeamInbox; and
  • technical, security and usage data generated by the Service.

For account, website, billing and support data that we collect for our own business purposes, TeamInbox generally acts as the data fiduciary, controller or equivalent responsible entity.

For contacts, leads, messages, media and other data uploaded, received or generated by a customer through the Service ("Customer Data"), the customer generally determines why and how the data is processed. In that context, the customer acts as the data fiduciary/controller and TeamInbox acts as its data processor/service provider. The customer must provide all required notices, establish a lawful basis, obtain valid opt-ins or consents, and respond to requests from its contacts. A person whose data was submitted by a TeamInbox customer should ordinarily contact that customer first.

3. Personal Data We Collect

Depending on how the Service is used, we may collect the following categories of data.

3.1 Account and business data

  • name, business name, job title and authorised-user details;
  • email address, mobile number, address and support contact details;
  • login credentials in protected form, authentication information and account preferences;
  • organisation, team, role, permission and agent-seat information; and
  • information supplied for onboarding, account verification, Meta Business or WhatsApp Business setup and customer support.

3.2 Connected-platform data

When a customer connects WhatsApp Business Platform, WhatsApp Business App coexistence, Meta services or another integration, we may process identifiers and configuration data such as business account identifiers, WhatsApp Business Account identifiers, phone-number identifiers, display names, templates, quality or messaging status, webhook events, permissions and access tokens. We use these only to provide, secure and support the requested integration.

3.3 Customer communication and CRM data

  • contact names, phone numbers, email addresses and profile information;
  • message content, media, documents, template messages and conversation history;
  • opt-in, opt-out and consent records;
  • lead source, lead status, tags, custom fields, assignments, internal notes and follow-up history;
  • chatbot inputs, automation events, scheduled messages and broadcast or sequence data;
  • website-widget submissions and chat transcripts; and
  • delivery, read, failure and engagement events made available by connected platforms.

The customer, not TeamInbox, decides which Customer Data to submit and what communications to send.

3.4 Billing and transaction data

We may collect plan, subscription, invoice, tax, payment-status and transaction-reference information. Card, banking or payment credentials may be collected and processed directly by an authorised payment gateway. TeamInbox does not intentionally store complete card numbers, CVVs, UPI PINs or online-banking passwords.

3.5 Device, log and usage data

We may collect IP address, browser type, device and operating-system information, time zone, referring URL, session identifiers, login history, API usage, feature activity, audit logs, error logs, diagnostic information and approximate location derived from IP address. We use this information to operate, secure, troubleshoot and improve the Service.

3.6 Cookies and similar technologies

We may use cookies, local storage and similar technologies for authentication, session continuity, security, preferences, analytics and performance. Essential cookies are required for the Service to operate. Where required by law, non-essential cookies will be used only after the relevant choice or consent. Browser settings can block cookies, but doing so may prevent parts of the Service from functioning.

3.7 Support and correspondence

We collect information included in demonstrations, enquiries, support tickets, calls, emails, feedback and other communications with us. Support sessions may include screenshots, diagnostic logs or account configuration supplied by the customer.

4. How We Obtain Data

We receive personal data:

  • directly from visitors, customers, authorised users and customer contacts;
  • from a customer's administrators, agents, uploaded lists, forms, websites, applications and CRM systems;
  • from Meta, WhatsApp and other services connected by the customer;
  • automatically through use of the website, dashboard, apps, APIs and widgets; and
  • from payment providers, implementation partners or referral partners where lawful.

Customers must not upload purchased, scraped, unlawfully obtained or non-consensual contact lists.

5. How and Why We Use Data

We process personal data only for lawful purposes, including to:

  • create, authenticate and administer accounts;
  • provide the shared inbox, CRM, lead-management, broadcast, template, chatbot, automation, scheduling, reporting, coexistence, API, widget and integration functions requested by customers;
  • transmit communications through WhatsApp, Meta and other customer-selected channels;
  • process subscriptions, invoices, taxes and payments;
  • provide onboarding, verification assistance, training, support and incident response;
  • monitor usage limits, platform health, security, fraud, spam and abuse;
  • maintain audit logs, prevent unauthorised access and enforce our terms;
  • diagnose errors, improve performance and develop features;
  • send service notices, security alerts, billing messages and support communications;
  • send our own marketing communications where permitted, with an available opt-out;
  • comply with legal duties, lawful requests and dispute-resolution requirements; and
  • establish, exercise or defend legal claims.

Depending on the applicable law and context, processing may be based on consent, performance of a contract, compliance with law, specified legitimate uses, protection against fraud or security threats, or another lawful basis. Where consent is the basis, it may be withdrawn, but withdrawal does not affect processing already carried out lawfully.

6. Customer Messaging, Consent and Opt-Outs

Each customer is responsible for:

  • having a valid and documented basis to collect each contact's data;
  • obtaining WhatsApp and legally compliant opt-in before initiating messages where required;
  • clearly identifying itself and accurately describing the messages a person will receive;
  • using approved templates where required;
  • honouring STOP, unsubscribe and other opt-out requests promptly;
  • maintaining suppression lists and not re-importing opted-out contacts for messaging;
  • limiting messages to the purpose and frequency reasonably expected by the recipient; and
  • complying with applicable privacy, consumer-protection, telemarketing and anti-spam requirements.

TeamInbox may provide tools to record consent or manage opt-outs, but those tools do not transfer the customer's legal responsibility to TeamInbox.

7. AI, Chatbots and Automated Processing

If a customer enables AI-assisted replies, lead qualification, chatbots or automated workflows, Customer Data may be processed to generate responses, summaries, classifications, routing decisions or suggested actions. Automated output may be incomplete or inaccurate and should be reviewed where it could materially affect a person. Customers must not use TeamInbox automation to make unlawful, discriminatory or solely automated high-impact decisions.

We do not use Customer Data to train a generally available artificial-intelligence model unless the customer has expressly agreed to that use. A connected third-party AI provider may process data under its own terms and the configuration selected by the customer.

8. How We Share Data

We do not sell Customer Data or message content. We may disclose data only as reasonably necessary to:

  • Meta, WhatsApp and other communication channels selected by the customer for account connection and message delivery;
  • cloud hosting, storage, content-delivery, monitoring, security, support and backup providers;
  • payment gateways, billing, accounting and tax-service providers;
  • email, SMS, analytics or customer-support providers used to operate the Service;
  • CRM, e-commerce, advertising, productivity or other integrations expressly enabled by the customer;
  • professional advisers, auditors, insurers and financing or transaction advisers subject to confidentiality obligations;
  • a successor in a merger, acquisition, reorganisation or transfer of business, subject to appropriate protection; or
  • courts, regulators, law-enforcement bodies or other persons where disclosure is legally required or reasonably necessary to protect rights, safety and security.

Service providers may process data only for the contracted purpose and subject to appropriate confidentiality and security obligations. We may use aggregated or de-identified information that does not reasonably identify a person for analytics, capacity planning and service improvement.

9. Meta, WhatsApp and Other Third-Party Services

TeamInbox uses official WhatsApp Business Platform interfaces and may connect with services operated by Meta Platforms, Inc. and its affiliates. Meta and other connected providers are independent third parties and may process data under their own terms and privacy policies. Their platform availability, approval decisions, messaging limits, quality ratings, template reviews, pricing, data practices and account restrictions are outside TeamInbox's exclusive control.

Customers should review the WhatsApp Business Terms, WhatsApp Business Messaging Policy, Meta terms and privacy information, and the terms of every integration they enable. TeamInbox is not responsible for a third party's independent processing or policy changes.

10. International Processing and Transfers

TeamInbox is based in India. Depending on the customer's configuration and the locations of Meta, cloud or integration providers, personal data may be processed in India or another country. Where applicable, we use contractual, organisational or other lawful measures for cross-border processing and comply with restrictions notified under applicable law.

11. Data Retention

We retain account, billing, support and Customer Data only for as long as reasonably necessary to provide the Service, meet contractual commitments, secure the platform, resolve disputes and comply with legal, tax, accounting or regulatory requirements.

During an active subscription, retention may depend on the plan, product settings and connected platform. Following account termination, Customer Data will ordinarily be deleted or de-identified from active systems within 90 days unless a shorter period is agreed, the customer deletes it earlier, or continued retention is required by law, for fraud prevention, dispute resolution or enforcement. Residual copies may remain in encrypted backups until they are overwritten in the normal backup cycle. Aggregated or irreversibly de-identified data may be retained.

Customers should export required contacts and records before termination. TeamInbox is not a permanent archive or legal recordkeeping service.

12. Security

We use reasonable administrative, technical and organisational safeguards designed to protect data, including access controls, authentication, logging, network and application protections, and encryption where appropriate. Access to Customer Data is limited to authorised personnel and service providers with a business need.

No internet service, transmission or storage system is completely secure. Customers must protect credentials, configure permissions appropriately, keep devices secure, promptly remove former users and notify us of suspected unauthorised access. TeamInbox does not guarantee absolute security.

13. Personal Data Breaches

We maintain procedures to identify, assess and respond to personal-data incidents. Where required by applicable law or contract, we will notify affected customers or authorities and provide information reasonably available to us. Customers remain responsible for notifying their contacts or regulators where the customer acts as the data fiduciary/controller.

14. Rights and Choices

Subject to applicable law, a person may have the right to:

  • request a summary of personal data and processing activities;
  • request correction, completion or updating of inaccurate data;
  • request erasure of data no longer required for a lawful purpose;
  • withdraw consent where processing is based on consent;
  • opt out of our promotional communications;
  • raise a grievance; and
  • nominate another person to exercise applicable rights in the event of death or incapacity.

To exercise a right concerning TeamInbox account or website data, contact [email protected]. We may verify identity and authority before acting. If the request concerns data controlled by a TeamInbox customer, we may direct the requester to that customer or assist the customer as required.

Rights are not absolute. We may retain or decline to delete data where processing is required by law, needed to establish or defend claims, necessary for security or fraud prevention, or otherwise permitted by law.

15. Children's Data

TeamInbox is a business service and is not directed to persons under 18. A person under 18 must not create an account. Customers must not use the Service to process children's personal data unless they have all legally required authority and verifiable parental consent and have configured the Service appropriately. If we learn that a child directly supplied account data without proper authority, we may delete it and suspend the relevant account.

16. Marketing Communications

We may send information about TeamInbox products, webinars or offers where permitted. Recipients may unsubscribe through the message instructions or by contacting us. Opting out of marketing does not stop essential account, security, billing or service communications.

17. Changes to this Policy

We may update this Privacy Policy to reflect legal, technical or business changes. The revised version will be posted with an updated date. If a change materially affects how we process personal data, we will provide additional notice where reasonably practicable or legally required.

18. Privacy and Grievance Contact

For privacy questions, grievances or rights requests, contact:

Privacy and Grievance Contact
Tech Fusioncodes Technologies Private Limited
CP/140, Viraj Khand-4, Gomti Nagar
Lucknow, Uttar Pradesh 226010, India
Email: [email protected]
Phone: +91 7311155211

We will acknowledge and address grievances within the period required by applicable law.