Privacy Policy
Last updated: 2026-08-17
This policy explains what information Zilan Inbox collects, how we use and store it, and what rights you have over your own data. Please read it in full.
1. Who we are
Zilan Inbox ("the Service", "we", "us") is an omnichannel customer conversation tool for businesses. Business customers connect their own social media and email accounts and use the Service to receive and reply to messages from their end customers in a single interface.
Operated by: 合肥紫蓝网络科技有限公司, 安徽省合肥市高新区兴园社区服务中心科学大道55号3幢2楼-安徽广电企服中心A2186号(一址多照登记).
For privacy matters, contact: support@zilaninbox.com
2. Two kinds of people, two different roles
Understanding this policy depends on distinguishing two groups:
- Business customers (our users) — the companies and their staff who register accounts, connect channels, and use the Service to handle messages. For this data, we are the data controller.
- End customers (our users' customers) — consumers who contact a business customer via Facebook, Instagram, X, WhatsApp or email. For this data, we are a data processor, acting on the business customer's instructions.
If you are an end customer and want to know how your messages are used, please contact the business you were talking to — they are the party that decides how that data is used. We will also assist with any related request.
3. What information we collect
3.1 Information business customers provide
| Category | Details | Purpose |
|---|---|---|
| Account information | Name, email address, hashed password | Authentication and account management |
| Company information | Company name, industry | Account ownership, issuing receipts |
| Team members | Member name, email, role | Access control and collaboration |
| Subscription and billing | Plan, subscription status, transaction records | Billing. We do not store full card numbers — payments are handled by a third-party payment provider |
3.2 Channel access credentials
When a business customer connects Facebook, Instagram, X, WhatsApp or an email account, we obtain and store an access token or email authentication details, used to send and receive messages on behalf of that business.
These credentials are stored in an access-restricted database and are used solely by this service. We use them only as far as necessary to send and receive messages and to maintain the connection. We do not use them to publish content, read friend or follower lists, or perform any action you have not authorised.
3.3 Conversation and message data ⚠️
This data is required for the core function of the Service. We store:
- Message content — the text sent by end customers and the replies sent by business customers
- Attachments — images, files and other content sent with messages
- End customer profile data — name, avatar, username and email address, as publicly available or authorised on the relevant platform
- Conversation metadata — timestamps, source channel, read status, conversation status
- Internal notes — notes recorded by the business customer's team (never visible to end customers)
We do not read, analyse or use conversation content for any purpose beyond operating the Service. Specifically: we do not use it to train AI models, we do not use it for advertising, and we do not sell it to anyone.
3.4 Information collected automatically
- IP address, browser type, operating system, access times
- Sign-in records and key action logs (for security auditing and troubleshooting)
- Cookies strictly necessary to keep you signed in (see section 8)
4. Third-party processors (important disclosure)
Your conversation data is not processed by any third-party software. Customer message content, attachments and contact information are stored only in our own application and database, and are handled directly by us.
Channel messages travel directly between the platform you connected (your email provider, X, and so on) and the Service, with no processor in between.
In addition, we use a cloud server provider to host the Service, a payment provider to process subscription fees, and an email provider to send notifications. These providers access data only as far as necessary to provide their service and are bound by contract.
We do not sell, rent, or share your data with any third party for marketing purposes.
5. Where data is stored, and how we protect it
Data is stored on servers located in Hong Kong SAR, China.
Our security measures include:
- Isolation between businesses — each company's data is isolated at the database level; no company can access another's conversations, customers or member information
- Encryption in transit — all data is transmitted over HTTPS/TLS
- Irreversible password storage — passwords are one-way hashed; we cannot see your original password
- Access control — each account can only reach data belonging to its own company; cross-company access is rejected at the query layer
We make reasonable efforts to protect your data, but no internet service can guarantee absolute security. If a data security incident occurs that may affect your rights, we will notify affected business customers promptly and report to regulators as required by applicable law.
6. How long we keep data
| Data type | Retention period |
|---|---|
| Conversations and messages | Kept while the account is active, up to 730 days |
| Account and company information | Kept while the account is active |
| Channel access credentials | Kept while the account is active; deleted immediately when the account is closed, or on written request |
| Billing records | Retained as required by tax and accounting law (typically at least 5 years) |
| Action and sign-in logs | 180 days |
| Backups | After a deletion request is processed, residual copies in backups are cleared within 35 days as backups rotate |
After account closure we delete your data within 30 days, except where retention is required by law (such as billing records).
7. Your rights
You have the following rights over your data:
- Access — find out what data we hold about you
- Correction — fix inaccurate information (most of it directly in your settings)
- Deletion — request deletion of your data; see our Data Deletion Policy
- Export — on written request, obtain a copy of your conversation and customer data in a common format
- Withdraw authorisation — stop receiving from any channel at any time, or revoke this service's access from the platform itself (e.g. X, Facebook)
- Complain — lodge a complaint with your local data protection authority
To exercise these rights, email support@zilaninbox.com. We respond within 30 days.
8. Cookies
We use strictly necessary cookies only:
- Authentication — keeping you signed in
- Security — preventing cross-site request forgery (CSRF)
- Preferences — remembering interface language and light/dark theme
We do not use advertising or cross-site tracking cookies.
9. Children's privacy
The Service is intended for business users and is not directed at children under 14. We do not knowingly collect personal information from children. If you believe we have, please contact us and we will delete it promptly.
10. Platform-specific notes
When you connect via Facebook, Instagram, X or WhatsApp, our use of data from those platforms is also governed by each platform's developer policies. We commit that we:
- access data only within the scope the business customer has explicitly authorised
- use platform data solely for the conversation management features of the Service
- do not resell platform data or use it for ad targeting
- delete the corresponding access credentials when a business customer closes their account
11. Changes to this policy
This policy may be updated as features change or regulations evolve. For material changes, we will notify business customers by email or in-product, and update the "last updated" date at the top of this page. We encourage you to review this page periodically.
12. Contact us
Privacy enquiries: support@zilaninbox.com
Everything else: support@zilaninbox.com