Privacy Policy
Last updated: July 29, 2026
1. Who we are and what this policy covers
InboundX ("we," "us") provides a business-to-business platform for running inbound phone-call campaigns. This policy explains what personal data we process, why, and the choices you have. It covers our websites (inboundx.io and app.inboundx.io, including customer-branded portal domains) and the platform itself.
Two roles matter throughout. For the account data of the business customers who use the platform (workspace owners, admins, and agents), InboundX decides how the data is used — we are the data controller. For the call data that flows through a customer's campaigns (callers' phone numbers, call recordings, call outcomes), the customer running the campaign decides why it is collected — the customer is the controller and InboundX processes it on the customer's behalf. Callers who want to know how their call data is used should contact the business that received their call; we assist our customers in meeting those obligations.
2. Information we collect
- Account data — name, work email address, hashed password, role, and workspace membership, provided when an administrator invites you or you activate your account.
- Billing data — wallet balances, transaction ledger entries, and payment-method references (card brand and last four digits). Full card numbers are handled by our payment processors and never touch our servers.
- Call and campaign data (processed for our customers) — caller phone numbers, tracking-number assignments, call timing and duration, routing decisions, dispositions, and, where the customer enables it, call recordings.
- Technical data — server logs, IP addresses used for security controls such as rate limiting, and audit-log entries recording sensitive actions (who changed what, when).
We do not buy, rent, or scrape personal data from third parties.
3. How we use information
- to provide the Service: authentication, call routing, billing, and support;
- to secure it: rate limiting, abuse prevention, audit trails, and incident investigation;
- to meet legal obligations, including financial record-keeping;
- to communicate with you about the Service (see the next section).
We do not sell personal data, and we do not use it for third-party advertising.
4. Emails we send
We send transactional email only, each message triggered by a specific action: account invitations (sent when a workspace administrator invites you), password resets (sent when you request one), and operational notices about your account or billing. We do not send marketing email or newsletters, and there are no mailing lists. If an email to you hard-bounces or you mark one as spam, we stop emailing that address.
5. How information is shared
We share personal data only with the service providers that run the platform, under their own contractual data-protection obligations:
- Amazon Web Services — hosting, storage, and email delivery (United States);
- Telnyx — telephony: phone numbers, call control, and in-browser calling;
- payment processors — Commas (Fanbasis) for platform billing, and the processor a customer connects (for example Stripe or Whop) for that customer's own buyer payments;
- Sentry — error monitoring.
Within the platform, your account data is visible to the administrators of your own workspace. Workspaces are isolated from one another. We may disclose data where the law requires it, or in a merger or acquisition, in which case this policy continues to apply to the transferred data.
6. Call recordings
Call recording is a feature our customers may enable for their own campaigns. The customer is responsible for obtaining any consent the law requires from call participants, including in jurisdictions that require every party's consent. Recordings are stored securely, are accessible only to authorized members of the workspace that owns them, and are processed by us solely to provide the Service.
7. Data retention
Account data is kept for the life of the account. Financial ledger entries and audit logs are append-only by design and retained for as long as needed to meet bookkeeping, dispute-resolution, and legal obligations. Call logs and recordings are retained according to the owning customer's configuration and obligations. When data is no longer needed, it is deleted or de-identified.
8. Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored only as salted scrypt hashes. Connected payment credentials are sealed with AES-256-GCM encryption. Money movements are recorded in an append-only ledger with immutable audit trails, and access to production systems is restricted and logged. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you as the law requires.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing — including rights under the California Consumer Privacy Act (CCPA/CPRA) and, for individuals in the European Economic Area or United Kingdom, the GDPR. We do not sell or share personal data as those laws define it. To exercise any right, email privacy@inboundx.io; we will verify the request and respond within the time the law allows. Requests about call data collected by one of our customers will be forwarded to that customer.
10. Cookies
The platform uses only strictly necessary cookies: a signed session cookie that keeps you logged in. We do not use advertising or cross-site tracking cookies.
11. Children
The Service is for business use and not directed to children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We will post updates here and revise the date above. For material changes we will notify workspace administrators before the changes take effect.
13. Contact
Privacy requests: privacy@inboundx.io. General support: support@inboundx.io. Abuse reports: abuse@inboundx.io.
© 2026 InboundX · Home · Terms of Service