Last updated 2026-07-24
[not configured — set the LEGAL_* environment variables] ("we", "us") operates mixenger, a shared team inbox that lets a business answer its customers' messages from WhatsApp, Facebook Messenger, Facebook and Instagram comments, Instagram Direct and Telegram in one place, and record the orders that come out of those conversations.
Registered address: [not configured — set the LEGAL_* environment variables]. Privacy contact: privacy@mixenger.com.
mixenger is sold to businesses. When a business connects one of its own channels, that business decides what is collected and why — it is the data controller. We only process that data on the business's instructions to run the inbox for them: we are a data processor / service provider.
If you are a customer who messaged a business through mixenger and you want your data changed or deleted, the fastest route is to ask that business directly. You can also contact us at privacy@mixenger.com or use the data deletion page and we will act on it.
| Category | Examples | Where it comes from |
|---|---|---|
| Business account data | Team member name, email address, hashed password, session records, workspace name, language, time zone | Entered by the business when signing up |
| Platform Data (Meta) | Message and comment content; attachments (images, audio, video, documents); the sender's platform-scoped identifier (PSID, IGSID, WhatsApp ID); the sender's display name and profile picture reference; message delivery, read and failure events; connected Page / Instagram account / WhatsApp Business Account identifiers and their status, quality rating and messaging limits; message template definitions and their approval status | Received from the Meta Platform through webhooks and the Graph API, only for accounts the business itself connected and authorised |
| Telegram data | Message content, attachments, chat and user identifiers, display names | Telegram Bot API, for bots the business connected |
| Business records created in the product | Orders (items, amount, cash-on-delivery flag, delivery address, delivery phone, courier and tracking number, status history), contact notes and custom fields, tags, saved replies, internal notes between team members | Typed by the business's own team |
| Operational records | Server logs, raw webhook payloads kept briefly for delivery troubleshooting, error reports | Generated automatically while the service runs |
We use the data only to provide the inbox to the business that connected the channel: delivering and sending messages, threading conversations, showing history and media, attributing messages to team members, tracking orders, producing that business's own reports, and keeping the service secure and working.
We do not:
Access is limited to the business that owns the connection — its own team members, subject to the roles and per-channel access controls that business configures — and to the subprocessors below, which act only on our instructions under written data-protection terms.
| Subprocessor | Purpose | Data reached |
|---|---|---|
| Cloud hosting and managed database provider | Runs the application and stores its data | All stored data |
| Object / file storage provider | Stores message attachments | Attachments |
| Error and uptime monitoring | Detects faults | Diagnostic metadata; no message content |
| Payment processor | Collects subscription fees from the business | Billing contact and payment status; no Platform Data |
The current named list is published at data deletion and available on request from privacy@mixenger.com. We will also disclose data where we are legally required to, and to Meta where its platform terms require it.
| Data | Retention |
|---|---|
| Messages, conversations, contacts, orders | For as long as the workspace is active. Deleted when the workspace is deleted. |
| Message attachments | Per-workspace setting chosen by the business (Settings → Data & retention). When set, expired files are permanently removed and the message keeps a placeholder. When unset, kept for the life of the workspace. |
| Raw webhook payloads (troubleshooting copies) | 30 days, then automatically deleted. |
| Deletion request records | Kept as proof that a deletion was carried out. Contains the confirmation code and counts only — not the erased content. |
| Closed accounts | Erased on deletion. Residual copies in encrypted backups roll off within 30 days. |
Three routes, all of which really erase data rather than hiding it:
One deliberate exception: if a customer's record is attached to orders the business has already recorded, we strip the personal details (name, phone, notes, profile references) but keep the order itself. Those are the merchant's own commercial and tax records, and destroying them would damage a third party rather than protect you.
We operate from Bangladesh and use cloud infrastructure that may store and process data in other countries. Where data moves across borders we rely on the safeguards our providers offer, including standard contractual clauses where applicable.
mixenger is a business tool and is not directed at children. We do not knowingly collect data from children under 13 (or the minimum age in your country). If you believe we hold such data, contact privacy@mixenger.com and we will delete it.
Depending on where you live, you may have rights to access, correct, export, restrict or delete your data, and to object to processing. Because we act for the business, we will normally forward your request to it and support it in responding — but we will act directly where the law requires or where it is faster for you. Contact privacy@mixenger.com.
We will post any change here and update the date at the top. Material changes affecting connected businesses will be notified in-product or by email.
Privacy and data-deletion enquiries: privacy@mixenger.com
Support: support@mixenger.com
Postal: [not configured — set the LEGAL_* environment variables]