Privacy Policy

Last updated 2026-07-24

[not configured — set the LEGAL_* environment variables] ("we", "us") operates mixenger, a shared team inbox that lets a business answer its customers' messages from WhatsApp, Facebook Messenger, Facebook and Instagram comments, Instagram Direct and Telegram in one place, and record the orders that come out of those conversations.

Registered address: [not configured — set the LEGAL_* environment variables]. Privacy contact: privacy@mixenger.com.

1. Our role: we act for the business, not for ourselves

mixenger is sold to businesses. When a business connects one of its own channels, that business decides what is collected and why — it is the data controller. We only process that data on the business's instructions to run the inbox for them: we are a data processor / service provider.

If you are a customer who messaged a business through mixenger and you want your data changed or deleted, the fastest route is to ask that business directly. You can also contact us at privacy@mixenger.com or use the data deletion page and we will act on it.

2. What we process

CategoryExamplesWhere it comes from
Business account data Team member name, email address, hashed password, session records, workspace name, language, time zone Entered by the business when signing up
Platform Data (Meta) Message and comment content; attachments (images, audio, video, documents); the sender's platform-scoped identifier (PSID, IGSID, WhatsApp ID); the sender's display name and profile picture reference; message delivery, read and failure events; connected Page / Instagram account / WhatsApp Business Account identifiers and their status, quality rating and messaging limits; message template definitions and their approval status Received from the Meta Platform through webhooks and the Graph API, only for accounts the business itself connected and authorised
Telegram data Message content, attachments, chat and user identifiers, display names Telegram Bot API, for bots the business connected
Business records created in the product Orders (items, amount, cash-on-delivery flag, delivery address, delivery phone, courier and tracking number, status history), contact notes and custom fields, tags, saved replies, internal notes between team members Typed by the business's own team
Operational records Server logs, raw webhook payloads kept briefly for delivery troubleshooting, error reports Generated automatically while the service runs

3. What we use it for — and what we never do

We use the data only to provide the inbox to the business that connected the channel: delivering and sending messages, threading conversations, showing history and media, attributing messages to team members, tracking orders, producing that business's own reports, and keeping the service secure and working.

We do not:

4. Who we share it with

Access is limited to the business that owns the connection — its own team members, subject to the roles and per-channel access controls that business configures — and to the subprocessors below, which act only on our instructions under written data-protection terms.

SubprocessorPurposeData reached
Cloud hosting and managed database providerRuns the application and stores its dataAll stored data
Object / file storage providerStores message attachmentsAttachments
Error and uptime monitoringDetects faultsDiagnostic metadata; no message content
Payment processorCollects subscription fees from the businessBilling contact and payment status; no Platform Data

The current named list is published at data deletion and available on request from privacy@mixenger.com. We will also disclose data where we are legally required to, and to Meta where its platform terms require it.

5. How long we keep it

DataRetention
Messages, conversations, contacts, ordersFor as long as the workspace is active. Deleted when the workspace is deleted.
Message attachmentsPer-workspace setting chosen by the business (Settings → Data & retention). When set, expired files are permanently removed and the message keeps a placeholder. When unset, kept for the life of the workspace.
Raw webhook payloads (troubleshooting copies)30 days, then automatically deleted.
Deletion request recordsKept as proof that a deletion was carried out. Contains the confirmation code and counts only — not the erased content.
Closed accountsErased on deletion. Residual copies in encrypted backups roll off within 30 days.

6. Deleting your data

Three routes, all of which really erase data rather than hiding it:

One deliberate exception: if a customer's record is attached to orders the business has already recorded, we strip the personal details (name, phone, notes, profile references) but keep the order itself. Those are the merchant's own commercial and tax records, and destroying them would damage a third party rather than protect you.

7. Security

8. International transfers

We operate from Bangladesh and use cloud infrastructure that may store and process data in other countries. Where data moves across borders we rely on the safeguards our providers offer, including standard contractual clauses where applicable.

9. Children

mixenger is a business tool and is not directed at children. We do not knowingly collect data from children under 13 (or the minimum age in your country). If you believe we hold such data, contact privacy@mixenger.com and we will delete it.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict or delete your data, and to object to processing. Because we act for the business, we will normally forward your request to it and support it in responding — but we will act directly where the law requires or where it is faster for you. Contact privacy@mixenger.com.

11. Changes

We will post any change here and update the date at the top. Material changes affecting connected businesses will be notified in-product or by email.

12. Contact

Privacy and data-deletion enquiries: privacy@mixenger.com
Support: support@mixenger.com
Postal: [not configured — set the LEGAL_* environment variables]