Skip to main content
Last updated 5 October 2026

Privacy Policy

What we collect, why, who else handles it, and what you can ask us to do about it. Written to be read.

Short version: we collect the minimum we need to talk to you, run the service and invoice you. We are a processor for your customers' conversation data. We don't sell data. Meta sees messages because WhatsApp is Meta. Details are below, and anything not covered can go to hello@squarebox.cloud.

1. Who this policy applies to

This policy explains how Squarebox Cloud ("Squarebox", "we", "us") handles personal data. It applies to visitors to global.squarebox.cloud, to people who contact us or request a meeting, and to the businesses that use the Squarebox platform and the staff who log in to it.

Section 4 explains how we handle the conversation data of your own customers when they message a WhatsApp number you run through Squarebox. That data is yours, and our handling of it follows your instructions and our agreement with you.

We have written this in plain language on purpose. If you need a formal version for procurement or a security review, ask and we will provide it.

2. Our two roles: controller and processor

Data protection laws in the markets we serve, including the EU GDPR, UK GDPR, the UAE Personal Data Protection Law and US state privacy laws, distinguish between the business that decides why and how personal data is used (a controller, or data fiduciary or business in some laws) and a provider that processes it on that business's behalf (a processor or service provider).

For our own website visitors, enquiries, customer accounts and billing records, we are the controller.

For the conversations, contact lists and message content that flow through a WhatsApp number belonging to one of our customers, we are a processor acting for that customer. We process that data only to provide the service and only on their instructions. We do not sell it, use it to market to their customers, or use it to train general-purpose AI models.

3. Information we collect directly

We keep collection narrow. From visitors and prospective customers we collect what a person chooses to send us, plus basic technical information needed to run and secure the site.

  • Enquiry and meeting details: name, business name, work email, phone number, country, industry, expected message volume and anything written in the message field.
  • Account data for customers: names, email addresses and roles of team members you invite, and their activity within the platform.
  • Billing data: business name, billing address, tax or VAT number if provided, and payment records. Card and bank details are handled by our payment providers and are not stored on our servers.
  • Correspondence: emails, WhatsApp messages and meeting notes exchanged with our team.
  • Technical data: IP address, browser and device type, pages visited and referring URL, held in server logs for security, debugging and aggregate traffic measurement.

4. Information we process on behalf of customers

Running WhatsApp messaging on Squarebox means the platform handles data about the people who message you: their WhatsApp phone number, profile name, the content and timestamps of messages in both directions, media they send, delivery and read status, any tags, notes or fields your team adds, and anything the AI agent collects because you configured it to ask.

We process this data to deliver, route, queue, retry, store and report on messages, to run the flows you have configured, and to provide support when you ask. Staff access is limited to named personnel, granted only for support and reliability work, and logged.

You control retention, export and deletion of this data, as described in section 8.

5. How we use information

We use personal data for a short, specific list of purposes.

  • To reply to your enquiry, arrange a meeting and prepare a proposal.
  • To create, configure, secure and operate your account.
  • To provide onboarding and support, including Meta Business verification and template submission on your behalf.
  • To invoice you and meet our tax and accounting obligations.
  • To monitor reliability, investigate incidents and prevent abuse or fraud.
  • To send service communications about outages, changes, security and billing, which are not marketing.
  • To send occasional updates about Squarebox where the law allows it, always with a clear way to opt out.

6. Legal bases

Where GDPR or UK GDPR applies, we rely on: taking steps at your request before entering a contract (when you ask for a meeting or proposal); performing our contract with you; our legitimate interests in running and securing our business and in contacting businesses that may benefit from the service, balanced against your rights; compliance with legal obligations; and consent, where we ask for it.

Under other laws, such as the UAE PDPL, we rely on the equivalent grounds those laws provide. You can object to processing based on legitimate interests, and withdraw consent, at any time.

Where you are the controller, collecting valid opt-in from your own customers before messaging them is your responsibility. WhatsApp requires it and the platform is built around it, but the consent has to be collected by you.

7. Sub-processors

We do not sell personal data. We rely on a small set of providers, each under contract terms that restrict them to processing data only for the service they provide.

  • Meta Platforms, as operator of the WhatsApp Business Platform. Every message sent or received through Squarebox passes through Meta's infrastructure and is processed under Meta's own terms. This is inherent to using official WhatsApp.
  • Cloud hosting and managed database providers.
  • AI model providers, for generating agent replies. We send only what is needed to answer the message in question.
  • Payment and accounting providers.
  • Email and messaging infrastructure providers, for notifications.
  • Error monitoring and analytics providers.

8. International transfers and retention

We and our providers operate in several countries, so personal data may be processed outside the country where it was collected, including in India, the European Union and the United States. Where GDPR or UK GDPR applies, we use recognised safeguards such as the European Commission's Standard Contractual Clauses and the UK addendum. Where a customer needs data stored in a particular region, we agree that in writing.

We keep enquiry data for up to 24 months from last contact unless you ask us to delete it sooner. Account and conversation data is kept while your agreement is active, then for 30 days so you can export it, after which it is deleted from production systems, with backups expiring within a further 60 days. Invoices and accounting records are kept for as long as tax law requires.

Customers can set shorter retention periods, and we will act on a documented deletion instruction ahead of these defaults.

9. How we protect data

Data is encrypted in transit and at rest. Access within the platform is role-based and recorded in an audit log. Internal access by our staff requires multi-factor authentication and is limited to the people who need it.

We patch dependencies, monitor for anomalies and keep backups. We do not claim formal security certifications we have not obtained. We will complete security questionnaires and sign a data processing agreement on request.

If a personal data breach occurs, we will notify affected customers without undue delay and support them in meeting their own notification duties, and we will notify regulators where the law requires us to.

10. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent. California and some other US states give residents similar rights, and we do not sell or share personal information for cross-context behavioural advertising.

To exercise any of these, email us. We respond within 30 days. If we need to verify who you are, we will ask for the minimum necessary.

If your data is held by a business that uses Squarebox, rather than by us directly, we will point you to that business and help them act on your request.

You can complain to your local data protection authority, such as an EU supervisory authority, the UK Information Commissioner's Office or the UAE Data Office, though we would appreciate the chance to resolve it first.

11. Cookies and analytics

This site uses only the cookies and local storage it needs to work, plus aggregate analytics to understand which pages are useful. We do not run third-party advertising trackers or sell audience data.

You can block or clear cookies in your browser at any time and the site will still work.

12. Children

Squarebox is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16 through this site. Customers who message minors as part of their business are responsible for obtaining any consent the law requires from a parent or guardian.

13. Contact

Questions, requests and complaints about privacy go to hello@squarebox.cloud with "Privacy" in the subject line. We acknowledge within three working days and aim to resolve within 30 days.

14. Changes to this policy

When this policy changes we update the date at the top. For material changes, we email account holders at least 14 days before they take effect.

This policy sits alongside our terms of service. If you need a signed data processing agreement, a security questionnaire or a specific data residency arrangement, contact us.