At "Wabox" ("we," "us," or "our"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
Please read this Privacy Policy carefully. By accessing or using "Wabox", you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
1. Information We Collect
1.1. Information You Provide to Us
We collect information that you voluntarily provide when using our services:
- Account Information: Name, email address, phone number, company name, job title, and password
- Profile Information: Business-related information, preferences, and settings
- Communication Data: Messages, feedback, and support requests you send to us
- Payment Information: Billing details processed through secure third-party payment processors (we do not store complete credit card information)
1.2. Information Collected Automatically
When you use "Wabox", we automatically collect certain information:
- Device Information: IP address, browser type and version, device type, operating system, and unique device identifiers
- Usage Data: Pages visited, features used, time spent on pages, click patterns, and navigation paths
- Log Data: Server logs including access times, error messages, and system activity
- Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to enhance user experience and analyze usage patterns
1.3. Information from Third-Party Services
- Google Calendar API: When you connect your Google Calendar, we access calendar events, scheduling data, and related metadata solely to provide scheduling features
- Meta Platform Services: When you connect Facebook, Instagram, or other Meta services, we may receive your profile information, email address, and other data you authorize (see Section 4 for detailed information)
- OAuth Providers: If you sign in using third-party authentication, we receive basic profile information as permitted by those services
2. How We Use Your Information
We use the collected information for the following purposes:
2.1. Service Provision and Improvement
- To create and manage your account
- To provide, operate, and maintain our services
- To process transactions and send transaction notifications
- To personalize your experience and deliver content relevant to your interests
- To analyze usage patterns and improve our platform's functionality
- To develop new features, products, and services
2.2. Communication
- To respond to your inquiries and provide customer support
- To send administrative information, updates, and security alerts
- To send marketing communications (with your consent, where required)
- To notify you about changes to our services or policies
2.3. Security and Legal Compliance
- To detect, prevent, and address technical issues and security threats
- To enforce our Terms of Service and protect our rights
- To comply with legal obligations and respond to lawful requests
2.4. User Consent for Profile Building
We will obtain your explicit consent before using any data, including data from third-party platforms like Meta, to build, augment, or enhance your user profile beyond the purposes explicitly stated at the time of collection. You have the right to withdraw this consent at any time through your account settings.
4. Meta Platform Data: Facebook, Instagram, and WhatsApp Integration
4.1. What Meta Platform Data We Collect
When you choose to connect your Meta platform accounts to "Wabox", we may collect:
- Profile Information: Your name, profile picture, email address, and public profile data
- Authentication Data: User ID and access tokens necessary for maintaining your connection
- Permissions You Grant: Any additional data you explicitly authorize through Meta's permission dialogs
4.2. How We Use Meta Platform Data
We use Meta Platform Data solely for the following purposes:
- Authentication: To verify your identity and enable single sign-on functionality
- Account Creation: To create and populate your "Wabox" profile
- Communication: To contact you regarding your account (if you provide email through Meta)
- Service Features: To provide features that you specifically request and authorize
4.3. What We DO NOT Do with Meta Platform Data
In compliance with Meta Platform Terms and Developer Policies, we commit to the following restrictions:
- No Unauthorized Profile Building: We do not use Meta Platform Data to build or augment user profiles without your explicit consent
- No Third-Party Sharing: We do not sell, rent, or share Meta Platform Data with third parties except as explicitly permitted under Meta's terms or with your express direction
- No Advertising Data Misuse: We do not use any data from Meta advertising (including Facebook Pixel data) to build user profiles, for retargeting outside of Meta platforms, or for any purpose other than measuring ad campaign performance in aggregate
- No Data Combination: We do not combine Meta Platform Data with other data sources to identify individuals without your consent
- No Independent Use: We do not use Meta Platform Data for any purpose beyond what you authorized when connecting your account
4.4. Data Storage and Security for Meta Platform Data
- Secure Storage: Meta Platform Data is stored with appropriate technical, physical, and organizational security measures
- Limited Retention: We retain Meta Platform Data only as long as necessary to provide our services or as required by law
- Access Controls: Only authorized personnel can access Meta Platform Data, and only for legitimate business purposes
- Encryption: Meta Platform Data is encrypted both in transit and at rest
4.5. Your Rights Regarding Meta Platform Data
- Revoke Access: You can revoke "Wabox"'s access to your Meta accounts at any time through your Meta account settings or privacy settings on Facebook or Instagram
- Data Deletion: When you revoke access or close your account, we will delete your Meta Platform Data within 90 days unless retention is required by law
- Access Your Data: You can request a copy of the Meta Platform Data we hold about you by contacting us at rozi@inodreamstudio.com
- Direct Requests to Meta: For privacy rights requests related to data originally from Meta platforms, you may also contact Meta directly through their Privacy Policy
4.6. Meta Platform Terms Compliance
Our use of Meta Platform Data complies with:
- Meta Platform Terms
- Meta Developer Policies
- Meta Data Terms
- All applicable data protection laws and regulations
We regularly review our practices to ensure ongoing compliance with Meta's terms and will update this policy to reflect any changes in our use of Meta Platform Data.
5. Google Calendar API Usage and Data Handling
Our application integrates with Google Calendar API to provide scheduling and calendar management features. Here's how we handle your Google Calendar data:
- Limited Access: We only request access to calendar data necessary for our scheduling features
- No Storage: We do not store your Google Calendar data on our servers. All calendar information is accessed in real-time through the Google Calendar API
- No Sharing: We do not share, sell, or transfer your Google Calendar data to third parties
- Temporary Processing: Calendar data is only processed temporarily in memory to display scheduling information and is not persisted
- Revocable Access: You may revoke our access to your Google Calendar at any time through your Google Account settings (myaccount.google.com/permissions)
- Google API Compliance: Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
6. Data Security
We implement appropriate technical, physical, and organizational security measures to protect your personal information, including:
- Encryption of data in transit using SSL/TLS protocols
- Encryption of sensitive data at rest
- Regular security assessments and vulnerability testing
- Access controls and authentication mechanisms
- Employee training on data protection practices
- Regular backups and disaster recovery procedures
- Enhanced security measures for data from third-party platforms (Meta, Google)
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6.1. Security Incident Notification
In the event of a data breach or security incident that affects your personal information, we will:
- Notify affected users within 72 hours of becoming aware of the incident
- Notify relevant platform providers (Meta, Google) if their data is involved
- Notify applicable regulatory authorities as required by law
- Take immediate steps to mitigate the breach and prevent future incidents
- Provide information about the nature of the breach and steps you can take to protect yourself
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Active Accounts: We retain your account information for as long as your account remains active
- Closed Accounts: After account closure, we may retain certain information for up to 90 days for backup and recovery purposes
- Meta Platform Data: Data from Meta platforms is deleted within 90 days of account closure or access revocation, unless retention is required by law
- Google Calendar Data: Not stored; accessed in real-time only
- Legal Obligations: Some data may be retained longer to comply with legal, accounting, or regulatory requirements
- Aggregated Data: We may retain anonymized or aggregated data indefinitely for analytical purposes
8. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
8.1. Access and Portability
- Request access to the personal information we hold about you
- Request a copy of your data in a structured, machine-readable format
- For data from Meta platforms, you may also request data directly from Meta
8.2. Correction and Update
- Correct inaccurate or incomplete personal information
- Update your account information through your account settings
8.3. Deletion
- Request deletion of your personal information, subject to legal obligations
- Close your account through the account settings or by contacting us
- Revoke access to third-party platform data (Meta, Google) through respective platform settings
8.4. Restriction and Objection
- Request restriction of processing of your personal information
- Object to processing of your data for certain purposes
- Withdraw consent for profile building or data use at any time
8.5. Marketing Communications
- Opt-out of marketing emails by clicking the "unsubscribe" link
- Manage communication preferences in your account settings
To exercise any of these rights, please contact us at rozi@inodreamstudio.com. We will respond to your request within 30 days.
10. Third-Party Links and Services
Our platform may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
11. Children's Privacy
"Wabox" is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will take steps to delete such information.
We comply with the Children's Online Privacy Protection Act (COPPA) where applicable and do not knowingly process data from children under 13 in jurisdictions where COPPA applies.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
For data transfers involving Meta Platform Data, we comply with applicable data transfer mechanisms and Meta's requirements for international data transfers.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or updates to platform provider terms (such as Meta Platform Terms). We will notify you of any material changes by:
- Posting the updated policy on this page with a new "Last updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice on our platform
- Updating the privacy policy URL in our App Dashboard (for platform integrations)
Your continued use of "Wabox" after such changes constitutes your acceptance of the updated Privacy Policy. We maintain all versions of our privacy policies and will provide them to platform providers upon request.
14. Platform Provider Compliance and Audits
We cooperate with third-party platform providers (including Meta and Google) to ensure compliance with their terms:
- We make this Privacy Policy accessible to platform provider crawlers on a non-geo-blocked URL
- We maintain records of our data processing activities and user consents
- We respond to compliance review requests from platform providers
- We may be required to certify our compliance with platform terms annually
- We retain proof of user consent and legal requirements for data sharing
15. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Indonesia. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Indonesia.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For questions specifically about Meta Platform Data, you may also contact Meta directly through their support channels or review their Privacy Policy.
Acknowledgment:By using "Wabox", you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. This includes our practices related to Meta Platform Data, Google Calendar API data, and all other information collection and processing activities described herein.
Platform Compliance Statement: This Privacy Policy complies with Meta Platform Terms and Developer Policies (effective February 3, 2025), Google API Services User Data Policy, and applicable data protection regulations. We regularly review and update our practices to maintain compliance.
