Skip to content

Draft — requires review by qualified legal counsel before launch. This is a working template, not legal advice, and it is not yet in effect. Bracketed items are unconfirmed.

Legal

Privacy Policy

Last updated

We built imsgs for businesses that message people, so we hold ourselves to a simple standard: collect what the service needs, use it only to run the service, and make it easy to export or delete.

On this page

01Who we are and what this covers

imsgs is an outreach platform operated by [Company legal name] (“we”, “us”). Businesses use it to run iMessage-first conversations with SMS and WhatsApp fallback, manage replies in one inbox, and hand leads to their CRM or dialer. Our postal address is [Street address, City, State ZIP].

This policy explains how we handle personal information when:

  • you visit our website or request a demo;
  • you create or use an imsgs account (for example as an owner, admin, member or client viewer);
  • you are a lead: a person whose contact details one of our customers has uploaded so they can message you.

We treat these groups differently. For website visitors and account users, we decide how the information is used. For leads, our customer decides, and we act on their instructions (see Our role for lead data).

02Information we collect

Account data

Name, work email, company, role, phone number (if you provide one), login and two-factor authentication details handled by our authentication provider, your organization and workspace memberships, and your permissions. If you buy a subscription, our payment processor collects your card details; we receive only the card brand, last four digits, expiry date and billing address.

Workspace data

The configuration you create in the product: workspaces, sequences, message templates, routing and fallback rules, sending windows, integration settings (such as CRM and dialer connections and API keys, stored encrypted), uploaded do-not-contact lists, and audit logs of actions taken by users.

Lead data uploaded by customers

Contact records our customers upload by CSV, API or integration: typically name, phone number, email, company, title, location and any custom fields the customer chooses to include. We also generate data about each lead, such as whether a number appears to be reachable on iMessage, the inferred time zone used for quiet hours, and sequence and opt-out status.

Message content and metadata

The text, links, images and contact cards sent and received through a customer's lines, together with metadata: sender and recipient numbers, timestamps, the channel used (iMessage, SMS or WhatsApp), delivery and read receipts where the provider reports them, error codes, and reply classifications (for example “interested” or “opt-out”) produced by automated analysis of inbound replies.

Website and device data

When you use our website or app we collect standard log data (IP address, browser type, pages requested, referring URL, timestamps) and use strictly necessary cookies to keep you signed in and secure. [Analytics tooling TBD — if added, list it here and update the cookie disclosure.] We do not use advertising cookies or cross-site tracking.

Demo requests and correspondence

The details you submit on our demo form (name, work email, company, role, company type, expected number of lines, CRM, dialer and notes) and any emails or call notes from our conversations with you.

03How we use information

We use account, workspace, website and demo data to:

  • provide, operate and support the service, including provisioning lines and routing messages;
  • enforce platform guardrails such as quiet hours, opt-out handling, suppression and per-line limits;
  • bill you, prevent fraud and abuse, and secure accounts;
  • respond to demo requests and support questions, and send service and billing notices;
  • improve the product using aggregated or de-identified usage data;
  • comply with law, respond to lawful requests, and enforce our Terms and Acceptable Use Policy.

We use lead data and message content only to provide the service to the customer who uploaded it, to keep the platform compliant (for example, honoring an opt-out across that customer's whole organization), and as required by law. We do not sell lead data, use it to market our own services, or combine it across customers. We do not use message content to train general-purpose AI models.

04Our role for lead data

For lead data and the messages our customers exchange with their leads, the customer is the business that decides why and how the information is used (the “controller”). We process it on the customer's behalf as a processor and, under California law, a service provider, under a written agreement that restricts our use to providing the service.

Customers are responsible for having a lawful basis and the consents required to contact their leads (see our Acceptable Use Policy). If you received a message sent through imsgs and want to know how a business got your details, or want your information deleted, contact that business directly. You can always reply STOP to stop messages from that sender. If you contact us instead, we will pass your request to the relevant customer and help them respond.

05How we share information

We share personal information only as follows:

  • Sub-processors that help us run the service, under contracts that limit their use of the data (listed below).
  • Integrations a customer connects, such as a CRM (for example HubSpot or GoHighLevel) or a dialer (for example Nooks, Orum or SalesFinity). Data sent to these tools is sent at the customer's direction and is governed by the customer's agreement with that provider.
  • Messaging networks. Delivering a message necessarily passes its content and the recipient's number through our messaging provider and onward to Apple, mobile carriers or WhatsApp, depending on the channel.
  • Legal and safety reasons: to comply with law or legal process, to protect the rights, safety or property of our users, the public or us, or to investigate abuse reported by a carrier or provider.
  • Business transfers: in a merger, acquisition or sale of assets, subject to this policy.

Sub-processors

The categories below are current as of the date of this policy. [Exact vendor list TBD and to be confirmed before launch.] We will publish the final list and give customers [30 days'] notice of new sub-processors.

CategoryProviderPurpose
Messaging infrastructureLoopMessagePhone numbers and sending and receiving iMessage, SMS and WhatsApp messages
Hosting and compute[TBD]Running the website, app and background jobs in the United States
Database[TBD]Storing account, workspace, lead and message data in the United States
Authentication[TBD]Sign-in, sessions and two-factor authentication
Payment processing[TBD]Subscriptions, setup fees, invoices and card payments
Transactional email[TBD]Account invitations, alerts and billing notices
Error monitoring[TBD]Diagnosing failures; configured to minimize personal data
AI model provider[TBD]Classifying inbound replies; no training on customer data

06Retention and deletion

  • While your account is active, we keep account, workspace, lead and message data so the service works, including conversation history in the inbox.
  • Deletion requests. When a customer deletes a workspace, deletes leads, closes their account, or asks us to delete their data, we delete it from our production systems within 30 days of the request. Encrypted backups roll off on a [35-day] cycle.
  • Export. Customers can export their leads, conversations and opt-out lists at any time before deletion, in CSV format, from the app or by request.
  • Opt-out records. To keep honoring opt-outs, we retain the minimum needed (the phone number, or a one-way hash of it, and the date) in the customer's suppression list even after other data is deleted, unless the customer instructs otherwise and the law allows it.
  • Legal and billing records such as invoices are kept for as long as tax and accounting law requires, and data subject to a legal hold is kept until the hold ends.
  • Demo request data is kept for [24 months] after our last contact, then deleted.

07Your California privacy rights

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:

  • know the categories and specific pieces of personal information we collected about you, the sources, the purposes, and the categories of third parties we disclosed it to;
  • delete personal information we collected from you, subject to legal exceptions;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the past 12 months;
  • limit the use of sensitive personal information. We use sensitive information (such as account login credentials) only to provide the service, which the law permits;
  • not be discriminated against for exercising any of these rights.

To make a request, email hello@imsgs.co [or call toll-free number TBD]. We will verify your identity by matching information you provide against what we hold, and respond within 45 days (extendable by another 45 days where the law allows, with notice). You may use an authorized agent, who must provide signed permission from you.

If your information reached us as lead data, we are the customer's service provider. We will forward your request to the customer and assist them, and we will act on it as they direct.

Categories of personal information collected in the past 12 months

CategoryExamplesSource
IdentifiersName, email, phone number, IP address, account IDsYou; our customers (for leads); your device
Commercial informationSubscriptions, lines purchased, billing historyYou
Professional informationCompany, role, titleYou; our customers (for leads)
Internet activityLog data, in-app activity, audit eventsYour device and use of the service
CommunicationsMessage content and metadata, support emailsCustomers, leads, you
InferencesReply classification, inferred time zone, iMessage reachabilityGenerated by the service

Residents of other U.S. states with comparable privacy laws can exercise the same rights by contacting us using the details above.

08United States only

imsgs is offered only to businesses in the United States, for messaging U.S. phone numbers. Our systems and those of our sub-processors store and process data in the United States. Our service is not designed for, and we do not knowingly collect information from, people outside the U.S., and the platform rejects non-U.S. phone numbers.

The service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

09Security

We protect personal information with administrative, technical and physical safeguards, including:

  • encryption in transit (TLS) and at rest, with integration credentials encrypted at the field level;
  • role-based access inside each organization, with optional restricted workspaces;
  • two-factor authentication, which an organization owner can require for all users;
  • least-privilege access for our staff, logged and reviewed;
  • audit trails of sensitive actions such as exports, deletions and integration changes.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify affected customers and individuals as required by law and, for lead data, support our customers in meeting their own notification duties.

10Changes to this policy

We may update this policy as the product and the law change. We will post the new version here with a new “Last updated” date and, for material changes, notify account owners by email at least [30 days] before they take effect.

11Contact us

Questions, requests or complaints about privacy:

[Company legal name]
Attn: Privacy
[Street address, City, State ZIP]
hello@imsgs.co