Privacy Policy

Last updated: June 4, 2026

This Privacy Policy explains how Zellbox ("Zellbox", "we", "us", or "our") collects, uses, and protects information when you use our CRM and communication platform. Zellbox is operated by Blockchain Web Services (registered in Delaware, United States; address: 2055 Limestone Rd Ste 200C, Wilmington, DE 19808). For purposes of Meta's Platform Terms, Blockchain Web Services is the entity behind the Zellbox Meta App.

Zellbox iterates frequently. This policy reflects our current practices; we will publish updated versions as the product evolves and will notify registered users by email of any material changes.

1. Information we collect

Account data. When you sign up we collect your email address, your authenticated identity from Google OAuth (if you use that), and the password hash if you sign up with email + password. We never store passwords in plain text.

Customer records. The customer information you create in Zellbox — names, phone numbers, custom fields — is stored on your account. You're the controller of that data; we're the processor.

Conversation history. Inbound and outbound WhatsApp messages exchanged through Zellbox are retained on your account so your team has a complete conversation history per customer.

Calendar data. When you connect Google Calendar, Zellbox uses the https://www.googleapis.com/auth/calendar.events scope to read events on your primary calendar so you can see appointments and visits inside the app, and — for actions you take inside Zellbox — to create, update, or delete events on that same calendar so both surfaces stay in sync. We do not access calendars you have not explicitly connected. Refresh tokens issued by Google are encrypted at rest using a dedicated AWS KMS key. You can disconnect at any time from your Zellbox account settings; disconnecting revokes the refresh token and stops all further access.

Usage data. We collect standard logs (IP address, browser, request paths, timestamps) for operational purposes — debugging, abuse prevention, and capacity planning. AWS CloudFront and API Gateway generate these logs.

Billing data. Stripe handles all payment information directly. We never see your card number — we only see Stripe customer IDs and subscription status.

2. How we use information

We use the data above to: deliver the Zellbox service to you, deliver outbound WhatsApp messages through Meta's WhatsApp Business API, sync your team's Google Calendars, respond to support requests, send transactional emails (account verification, password resets, billing), and detect and prevent abuse.

We do not sell your data. We do not use customer records or conversation content for advertising. We do not train AI models on your data without your explicit consent.

3. Service providers

To deliver Zellbox we rely on these subprocessors:

  • Amazon Web Services (AWS) — hosting, databases (DynamoDB), authentication (Cognito), email (SES). Region: us-east-1.
  • Meta Platforms (WhatsApp Business Platform / Cloud API) — message delivery and webhook receipt. Meta sees message content and recipient phone numbers; refer to Meta's WhatsApp Business policies. See the dedicated section below for how Zellbox handles data received from the WhatsApp Business Platform.
  • Google — OAuth sign-in and Google Calendar API. See the dedicated section below for how Zellbox handles data received from Google APIs.
  • Stripe — payment processing.
  • Anthropic (Claude API) — content generation for our marketing channels (does not process your customer data).

4. Google user data and Limited Use

This section describes how Zellbox handles information received from Google APIs (sign-in profile, Google Calendar, and Gmail).

Scopes we request. For sign-in we request openid, email, and profile. For the Google Calendar integration we request https://www.googleapis.com/auth/calendar.events, which is the minimum scope that lets us read and modify individual events on your primary calendar without granting access to manage entire calendars or other people's data. For the Gmail integration we request https://www.googleapis.com/auth/gmail.send (to deliver outbound emails on your behalf) and https://www.googleapis.com/auth/gmail.readonly (to read inbound customer emails for the in-app email panel). These are the two narrowest Gmail scopes that together cover the implemented features described below — we do not request the broader gmail.modify scope and we do not call any endpoint that modifies labels, drafts, filters, trash, or the vacation responder.

How we use Google user data. Strictly to provide the user-visible features in the Zellbox app: displaying your upcoming Google Calendar events alongside your CRM data, creating or modifying calendar events when you act on them inside Zellbox, scheduling reminders you have configured, syncing inbound customer emails from your Gmail inbox into the relevant customer record so your team has conversation history in one place, searching your Gmail mailbox by customer email address to surface prior correspondence, and sending replies and new customer emails through Gmail when you click Send inside Zellbox. Google data is shown only to the Zellbox user who connected the account.

What we read from Gmail. The Gmail API calls Zellbox makes against your mailbox are limited to: users.messages.send (send and reply), users.messages.list (search by customer email address), users.messages.get (fetch full payload for sync), users.history.list (incremental sync of new messages), users.getProfile (initial sync baseline), and users.messages.attachments.get (download attachment bytes on inbound customer emails). Synced email subject, body, headers (Message-Id, threadId, References for threading), and attachments are stored on your Zellbox account so your team can view the customer's email history without re-fetching from Gmail.

How we do not use Google user data. We do not use Google user data to serve advertising, train or improve generalized or non-personalized AI/ML models, or for any purpose unrelated to the user-visible features above. We do not sell Google user data, and we do not transfer it to third parties except (a) when necessary to provide or improve the user-facing features above, and only with our subprocessors listed in section 3, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets, with notice to you.

Storage and retention. Refresh tokens issued by Google are encrypted at rest using a dedicated AWS KMS key (rotation enabled), partitioned per Zellbox user, and never shared across workspaces. Mirrored Calendar event metadata and synced Gmail messages (subject, body, headers, attachments re-hosted in Zellbox's S3 bucket) are stored only while you keep the relevant integration connected and your Zellbox account is active. Disconnecting from Settings → Google Sync calls Google's oauth2/revoke endpoint to revoke the refresh token, deletes the local token row, and stops all further access. Previously-synced rows remain visible in the customer panel after disconnect (since they live in Zellbox's database, not Gmail); deleting the customer record or your Zellbox account removes them. Account-deletion retention windows are described in section 7.

Limited Use disclosure. Zellbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. WhatsApp Business Platform data

This section describes how Zellbox handles information received from Meta's WhatsApp Business Platform (also known as WhatsApp Cloud API). Zellbox operates as a Tech Provider for the WhatsApp Business Platform, which means we offer two distinct operating modes depending on your subscription tier:

Free (Starter) tier — shared Zellbox number. Outbound WhatsApp messages are sent from a WhatsApp Business Account (WABA) and phone number that Zellbox itself owns and operates. In this mode Zellbox is the data controller of the message metadata (sender/recipient, timestamps, delivery status); message content you send is processed on your behalf as your processor.

Pro / Top tiers — your own WABA. You connect your own WhatsApp Business Account through Meta's Embedded Signup. Outbound messages are sent from your phone number, billed by Meta directly to your account. In this mode Zellbox is a processor acting on your behalf; you are the controller of all messaging data.

Permissions Zellbox requests. When you connect a WABA through Embedded Signup, Zellbox requests the following Meta permissions on your behalf, strictly for the user-visible features described below:

  • whatsapp_business_messaging — send and receive messages on your WhatsApp Business number.
  • whatsapp_business_management — manage the templates registered on your WABA (create, list, sync approval status), read your phone number metadata (display name, quality rating, messaging tier).
  • business_management — read your Meta Business Portfolio structure during the Embedded Signup dialog so you can pick the right portfolio and WABA. We do not write to your Business Portfolio.

Data we receive from Meta. Your WhatsApp Business Account ID, phone number ID, display phone number, verified business name, quality rating, messaging-limit tier, message templates and their approval status, and — for each incoming or outgoing message — the conversation participants' phone numbers, message content (text, media, button replies), Meta-issued message IDs, and delivery status webhooks.

How we use WhatsApp data. Strictly to provide the user-visible features in the Zellbox app: sending appointment reminders and other messages you have explicitly configured or composed, receiving customer replies into your team inbox, surfacing template approval status, and displaying account-health signals (quality rating, messaging tier) so you can act on Meta warnings.

How we do not use WhatsApp data. We do not sell WhatsApp data, use it for advertising, or use it to train generalized AI/ML models. We do not access or transmit message content to any third party except (a) AWS as our hosting subprocessor (see section 3), (b) Meta itself for delivery, (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets, with notice to you.

Storage and retention. The access token Meta issues when you complete Embedded Signup is stored encrypted at rest using a dedicated AWS KMS key (rotation enabled). WhatsApp message logs are retained on your account for as long as your account is active so your team has a complete conversation history per customer. Message metadata (sender, recipient, timestamps) and content are deleted within 30 days of account deletion. Some operational logs (webhook delivery diagnostics) may be retained for up to 90 days for security/audit purposes, then deleted.

How to revoke Zellbox's access. You can disconnect your WABA at any time from the Zellbox WhatsApp settings page — this revokes our access token and stops further messaging from your account. You can additionally remove Zellbox as a partner directly from Meta: go to Meta Business Settings → WhatsApp Accounts → open WhatsApp Manager → Remove partner. Disconnecting on either side stops all messaging immediately. Existing message history remains in your Zellbox account unless you also delete the account.

Meta Platform Terms compliance. Zellbox's use of the WhatsApp Business Platform and information received via it adheres to the Meta Platform Terms, Meta Developer Policies, and the WhatsApp Business Messaging Policy. Customers using Zellbox to send WhatsApp messages are responsible for complying with those policies, including obtaining recipient opt-in and respecting messaging-window rules (24-hour customer service window for free-form, templates outside the window).

6. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AWS-managed keys; OAuth refresh tokens use a dedicated, rotation-enabled AWS KMS key). Cognito-issued JWTs are signed and time-limited. API requests require a valid JWT or API key. We follow AWS security best practices and review access regularly.

No system is perfectly secure. If we discover a breach affecting your account we will notify you within 72 hours where required by law.

7. Data retention

We retain your account and customer data for as long as your account is active. If you delete your account, we cascade-delete customer records, visits, conversations, and account metadata within 30 days. Some operational logs (CloudWatch, billing records) may be retained for up to 90 days for security/audit purposes, then deleted.

If you cancel your subscription but don't delete your account, your data drops to free-tier limits but is not deleted.

8. Your rights (GDPR & CCPA)

You can: access all data on your account, export it as JSON or CSV, correct inaccuracies, request deletion, and revoke OAuth permissions for Google at any time. Disconnecting Google Calendar or Gmail from your Zellbox account (Settings → Google Sync → Disconnect) calls Google's oauth2/revoke endpoint and deletes the refresh token Google issued to us. You can additionally remove Zellbox from your Google Account permissions page.

Exercise these rights from your account settings, or email hello@support.zellbox.com.

9. Cookies and local storage

We use a minimum set of cookies and localStorage entries: an authentication session cookie (after sign-in), the language preference (i18nextLng), and CloudFront's cache cookies. We do not use third-party advertising cookies.

10. Children

Zellbox is not intended for users under 18. We do not knowingly collect data from minors.

11. Changes to this policy

We'll publish updates to this page and notify registered users by email of material changes. The "Last updated" date at the top reflects the current version.

12. Contact

Privacy questions, data export requests, or anything else: hello@support.zellbox.com.