Skip to main content

Legal & trust

Privacy Policy

Last updated: July 31, 2026

Launch draft: this document uses Brand My Inbox as the operator name. Before accepting payments, insert the legal entity name, registration number, registered address, privacy contact, accessibility coordinator, governing-law details, and obtain review by qualified Israeli and international counsel. No template can guarantee protection in every jurisdiction.

1. Scope and roles

This policy explains how Brand My Inbox handles personal information on its public site, accounts, domain workflows, support, and future billing. For account administration, sales, security, and product operations, Brand My Inbox generally acts as controller. For organization-directed routing configuration, Brand My Inbox may act as a processor and the customer remains responsible for lawful instructions.

2. Information we collect

We collect account identity and contact details; organization, role, and invitation data; submitted domains and destination addresses; DNS and provider configuration; aliases and routing settings; website source text, logos, images, generated concepts, edited site content, and legal-page drafts; support and lead-form content; consent choices; security, audit, incident, backup, and usage records; device and request information needed to operate and protect the service; and billing details supplied to Stripe when billing is enabled.

Brand My Inbox is designed not to store message bodies or attachments in application logs. Providers involved in delivery process email as necessary to route it under their own roles and terms.

3. Sources

Information comes from you, authorized organization administrators, public DNS, connected providers, security and service logs, and optional integrations you choose to authorize. We do not knowingly purchase consumer profiles.

4. Purposes and legal bases

We use information to provide contracted services; verify authority and destinations; secure accounts; perform requested DNS and routing operations; monitor health; maintain backups and audit evidence; provide support; process payments; comply with law; prevent abuse; improve reliability; send service communications; and invite customers to publish an independent review of the service.

Review invitations are sent to the account email, either by us or by a review platform acting on our instructions, and carry only the name, email address, and account or transaction reference needed to issue and deduplicate the invitation. Participation is voluntary and refusing has no effect on the service. Where GDPR applies we rely on legitimate interests in obtaining honest feedback about a service already supplied, or on consent where local law requires it; you can object or unsubscribe at any time. We do not select who is invited based on expected sentiment and offer nothing in exchange for a review. See section 15 of the Terms of Use.

Where GDPR applies, bases may include contract, legitimate interests in secure and reliable operations, legal obligation, and consent for optional analytics or marketing. Consent can be withdrawn without affecting prior lawful processing.

5. Processors and disclosures

Data may be shared with Base44 for application infrastructure and requested AI generation, Cloudflare for supported DNS/routing/Workers/KV/Pages, Google when a user connects a Google service, Stripe when billing launches, an independent review platform such as Trustpilot solely to issue review invitations, communication and security vendors, professional advisers, and authorities where legally required. Access is limited to the purpose and appropriate agreements or safeguards.

Brand My Inbox does not sell personal information. It does not use cross-context behavioural advertising at launch. If that changes, this policy and consent controls must be updated before deployment.

6. International transfers

Global providers may process information outside your country. Where required, Brand My Inbox will use recognized transfer mechanisms, contractual protections, and supplementary safeguards. Final entity location and transfer disclosures must be completed before launch.

7. Retention

Account and configuration data is retained while needed for the service and a documented offboarding period. Audit, security, tax, dispute, and backup records may be retained longer where necessary or legally required. Consent records are refreshed at least every 180 days in the current implementation. Final retention periods must be documented in a production retention schedule.

8. Security and incidents

Brand My Inbox uses role-based access, restricted provider credentials, private backups, time-limited downloads, pre-change snapshots, provider read-back checks, audit logs, and monitoring. No system is perfectly secure. Material incidents will be assessed, contained, documented, and notified as required by applicable law, including Israeli data-security obligations.

9. Your privacy rights

Depending on location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about disclosures. Israeli law, GDPR/UK GDPR, and applicable US state laws provide different rights and exceptions. Identity and authority may be verified before fulfillment.

California users may exercise applicable rights to know, delete, correct, limit, and opt out of sale or sharing without unlawful discrimination. Brand My Inbox honors Global Privacy Control for marketing sharing. Because Brand My Inbox does not sell or share personal information for cross-context behavioural advertising at launch, the opt-out is also reflected in the consent system.

10. Cookies and similar storage

Essential storage supports authentication, security, service delivery, and consent memory. Optional preference, analytics, and marketing categories remain off until selected. Choices can be changed from Cookie settings in the footer. See the Cookie Policy for the current inventory.

11. Children and educational use

Direct individual accounts are not intended for people under 18. Schools or institutions serving minors must establish the required authority, notices, contracts, data-minimization controls, and parental or guardian permissions before providing access. Brand My Inbox does not knowingly target behavioural advertising to children.

12. Requests, complaints, and regulators

A production privacy-request channel, operator address, response workflow, and representative or data-protection contact where required must be inserted before launch. You may also complain to the competent privacy authority, including Israel’s Privacy Protection Authority or an EU/UK supervisory authority where applicable.

13. Policy changes

We will date updates and provide additional notice for material changes where required. Prior versions and consent evidence should be retained. Contact details remain a launch blocker in this draft.

Official references