Sendiee processes personal data because messaging is intimate by definition. This document explains exactly what we collect, why, where it lives, who can touch it, and how to make us stop. It applies to every user of sendiee.com and our platform globally.
Overview
Codestormx (Sendiee) (“Sendiee”, “we”, “our”) provides an AI-powered messaging automation platform. This Privacy Policy describes how we collect, use, share and safeguard personal data when you visit sendiee.com or use our platform (the “Services”).
This policy is written for both (a) our direct customers (businesses using the Services) and (b) end users whose personal data we process on behalf of our customers as a data processor.
Data we collect
Customer account data
- Identifiers — name, work email, phone, billing address, GSTIN.
- Authentication — hashed passwords, OAuth tokens for Meta / Google.
- Billing — masked card data via Razorpay/Stripe; we never store full PAN.
Conversation data (processor)
- Messages exchanged on WhatsApp, Instagram or Messenger between our customer and their end users.
- Contact metadata — phone, name, profile photo, language, tags.
- Media attachments — images, voice notes, documents.
Usage data
- Device data, IP address, log timestamps, feature usage.
- Cookies — strictly necessary, analytics (PostHog), and consent-managed marketing.
How we use data
We process personal data only for the purposes set out below, and only on the legal bases described.
| Purpose | Legal basis | Retention |
|---|---|---|
| Providing the Services | Contract | Lifetime of account |
| Billing & invoicing | Legal obligation | 8 years |
| Product analytics | Legitimate interest | 24 months |
| Marketing emails | Consent | Until withdrawn |
| Fraud prevention | Legitimate interest | 5 years |
| AI model improvement | Consent (opt-in) | De-identified, indefinite |
International transfers
Sendiee is an India-incorporated entity with primary infrastructure in AWS Mumbai (ap-south-1). For redundancy and disaster recovery, encrypted backups are replicated to AWS Singapore (ap-southeast-1). For customers in the EU and UK we offer EU residency on Pro+ plans, served from AWS Frankfurt (eu-central-1).
All cross-border transfers are governed by Standard Contractual Clauses (SCCs) where required, and Data Processing Addenda are available to all customers.
Security
- Encryption at rest with AES-256; in transit with TLS 1.2+.
- Role-based access control with mandatory 2FA for all employees.
- SOC2 Type II report available under NDA (Type I attested 2025).
- Annual third-party penetration testing (last: Q4 2025, by Cobalt).
- 24/7 incident response team. Notification within 72h of confirmed breach.
Sendiee Teambox apps
Sendiee Teambox — our omni-channel shared inbox for support and sales teams — is available as native apps for iOS, Android, Windows and macOS, alongside the web app. The apps are a window into data already stored on the Sendiee platform: they display and send conversation data belonging to your Sendiee organization, and everything in this policy (collection, sharing, retention, your rights) applies to that data equally when accessed through an app.
The following applies to all four apps:
- You sign in with your Sendiee Teambox agent account; session credentials are stored only on your device.
- The apps contain no third-party analytics, advertising, or tracking SDKs. We do not track your location, contacts, browsing, or activity outside the app, and we never sell app data.
- All app traffic goes exclusively to Sendiee servers over HTTPS/TLS (plus the platform push and update services noted per platform below).
- Signing out ends the session and clears credentials from the device; conversation data remains on the Sendiee platform under your organization's retention settings.
The four sections below describe what is specific to each platform.
iOS app
- Credentials— sign-in tokens are stored in the iOS Keychain, Apple's hardware-backed secure storage.
- Biometric lock (optional) — you can require Face ID / Touch ID to open the app. Biometric matching is performed entirely on-device by iOS; biometric data never reaches Sendiee.
- Camera, microphone & photo library — used only with your permission, and only to capture or attach photos, videos and voice notes that you choose to send in a conversation. Nothing is accessed in the background.
- Push notifications (optional) — if you enable notifications, a device push token is registered with our servers along with the platform and app version, and messages are delivered via the Expo push service and Apple Push Notification service (APNs). A per-agent setting lets you hide message previews so conversation content is excluded from notification payloads.
- Deletion — signing out unregisters the push token and clears stored credentials; uninstalling the app removes all locally stored data.
The app is distributed through the Apple App Store; Apple's own privacy policy governs App Store telemetry (downloads, crashes reported to Apple).
Android app
- Credentials — sign-in tokens are stored in encrypted storage backed by the Android Keystore.
- Biometric lock (optional) — you can require fingerprint / face unlock to open the app. Biometric matching is performed entirely on-device by Android; biometric data never reaches Sendiee.
- Camera, microphone & photos — used only with your permission, and only to capture or attach photos, videos and voice notes that you choose to send in a conversation. Nothing is accessed in the background.
- Push notifications (optional) — if you enable notifications, a device push token is registered with our servers along with the platform and app version, and messages are delivered via the Expo push service and Google Firebase Cloud Messaging (FCM). A per-agent setting lets you hide message previews so conversation content is excluded from notification payloads.
- Deletion — signing out unregisters the push token and clears stored credentials; uninstalling the app removes all locally stored data.
The app is distributed through Google Play; Google's own privacy policy governs Play Store telemetry, and our Play Data Safety declaration mirrors this section.
Windows app
- How it works — the Windows app is a desktop shell around the Teambox web app (teambox.sendiee.com). It collects no data beyond what the web app collects.
- Local storage— your session (cookies, tokens, cache) and app preferences are stored in the app's profile folder on your device, under your Windows user account.
- Notifications — new-message alerts use native Windows notifications, honoring your message-preview setting.
- Updates — the app periodically checks GitHub for new releases. This sends a standard web request (IP address, app version) to GitHub and includes no personal data or account information.
- Deletion— signing out clears your session. Uninstalling removes the app; any remaining profile data can be deleted from your user's AppData folder.
macOS app
- How it works — the macOS app is a desktop shell around the Teambox web app (teambox.sendiee.com). It collects no data beyond what the web app collects.
- Local storage— your session (cookies, tokens, cache) and app preferences are stored in the app's container in your user Library (Application Support) on your device.
- Notifications — new-message alerts use native macOS notifications, honoring your message-preview setting.
- Updates — the app periodically checks GitHub for new releases. This sends a standard web request (IP address, app version) to GitHub and includes no personal data or account information.
- Deletion — signing out clears your session. Uninstalling removes the app; any remaining profile data can be deleted from ~/Library/Application Support.
Your rights
Subject to applicable law (DPDPA 2023, GDPR, CCPA), you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing or withdraw consent.
You can exercise most of these rights directly from your account settings, or by emailing [email protected]. We respond within 30 days.
If you are an end user of one of our customers, please direct your request to that customer first; we will support them in fulfilling it.
Retention & deletion
When you delete your account, we delete personal data within 30 days, except where retention is required by law (tax records, audit logs). Encrypted backups are purged within 90 days.
End-user conversation data is retained per the data controller's (our customer's) instructions, configurable from 7 days to indefinite.
Children's data
The Services are not directed to children under 18. We do not knowingly collect data from minors. If you believe we have, please email [email protected] and we will delete it promptly.
Changes
We may update this policy. Material changes are notified at least 30 days before they take effect, by email and via an in-app banner. Historical versions are available at sendiee.com/legal/archive.
Contact us
Data Protection Officer
Email: [email protected]
Postal: Codestormx (Sendiee), Attn: DPO, 42 Brighton Rd, Barrie, ON L4M 6S4, Canada.
Email our DPO at [email protected] or write to Codestormx (Sendiee), Attn: Privacy, 1/106/C, Velangkattu Thottam, Tiruppur, Tamil Nadu 641665, India.