Privacy Policy

Last updated: 27 July 2026 · Draft

Draft notice. This is a starting-point policy, not legal advice. Because inboxroot connects to your Microsoft 365 tenant and Postmark account, have a qualified lawyer review and adapt it before you rely on it.

inboxroot (“we”, “us”) helps you provision and manage email across your own domains using your own Microsoft 365 and Postmark accounts. This policy explains what we collect, why, and your choices.

What we collect

  • Account data: your name and email from the identity provider you sign in with (Microsoft or Google).
  • Connection data: the identifier of the Microsoft 365 tenant you connect and the Postmark account you link, plus tokens needed to provision on your behalf.
  • Provisioning metadata: the domains you onboard and their status (DNS, mailbox, sending). We do not read, store, or process the contents of your email.
  • Operational logs: request and error logs used to run and secure the service.

What we do not do

  • We do not access, store, or scan the contents of your mailboxes.
  • We do not sell your data or share it with advertisers.
  • We do not resell Microsoft licenses or mailboxes — you operate your own tenant.

How we protect it

Connection credentials are encrypted at rest, scoped to your organization, and never exposed to the browser. Access is over TLS. We follow least-privilege for the permissions we request from your providers.

Data retention & deletion

You can disconnect a provider or delete your organization at any time, which removes the associated credentials and provisioning metadata. Operational logs are retained for a limited period for security and debugging.

Sub-processors

We use Microsoft (Graph & Exchange Online) and Postmark to perform provisioning and sending that you direct, and infrastructure providers to host the service.

Contact

Questions about this policy: privacy@inboxroot.com.