Privacy Policy

Effective date: 2026-08-25  ·  Last updated: 2026-08-25

This Privacy Policy describes how MsgHub, operator of the MsgHub platform ("MsgHub", "we"), processes personal information. It covers both the msghub.info marketing website and the MsgHub platform (app.msghub.info, APIs, dashboards).

1. Two kinds of personal data we handle

MsgHub distinguishes between:

  1. Account Data — information about the MsgHub customer (your name, business name, email, phone, billing details, IP, session logs, support correspondence). MsgHub is the data fiduciary / controller for Account Data.
  2. Customer Data — information about your end-recipients that you upload or that flows through the platform (contact names, phone numbers, email addresses, message content, conversation transcripts, opt-in records, etc.). You are the data fiduciary / controller; MsgHub is the data processor. Your own privacy policy, DPA, and consent practices apply to Customer Data. See §7 and the DPA on request.

2. What we collect (Account Data)

CategoryExamplesPurposeLegal basis
Identity & contact Name, business name, email, phone, country Account creation, support, billing, KYC Contract performance · legal obligation (KYC / DLT)
Authentication Password hash (Argon2id), MFA seed (AES-256-GCM encrypted), session tokens Secure sign-in, MFA, prevent abuse Contract · legitimate interest (security)
Billing Invoice records, GSTIN, bank-transfer remittance details. We do not collect or store card numbers — invoices are settled by bank transfer. Invoicing, tax compliance, fraud prevention Contract · legal obligation
Usage & telemetry API call counts, feature flags used, error logs with request IDs, IP addresses, user-agent Operate, troubleshoot, rate-limit, detect abuse Legitimate interest
Support & communications Email threads, chat transcripts with support Respond to tickets, improve the product Contract · legitimate interest
Website analytics None — no third-party ad trackers Understand aggregate site usage Legitimate interest / consent where applicable

3. What Customer Data flows through the platform

When you use MsgHub you send and receive end-recipient personal data such as: names, phone numbers, email addresses, WhatsApp IDs, Instagram handles, message content (text / media), opt-in and opt-out records, delivery status, agent-bot conversation transcripts. We store only what is necessary to deliver the Service and comply with regulatory record-keeping (e.g. DLT consent logs).

We do not sell Customer Data. We do not use it to train third-party AI models. We do not repurpose it for advertising.

4. How we use Account Data

5. AI processing

Where you use MsgHub's AI features (chatbot, co-pilot, agent, embeddings, intelligence dashboards), the following applies:

6. Sharing and sub-processors

We share personal data only with sub-processors necessary to deliver the Service. The current list is maintained at §6.1 below and is updated when we add or change a sub-processor; material changes are announced to account admins by email at least 30 days before taking effect.

6.1 Current sub-processors

ProviderPurposeData categoriesLocation
Contabo GmbHHosting (VPS, storage, networking)All platform data at rest and in transitGermany (EU)
Razorpay (not currently active)Payment processing — integration present but unused; invoicing is by bank transferNone at presentIndia
Meta (WhatsApp Business)WhatsApp message delivery when usedPhone number, message content, template metadataIreland / US (per Meta policy)
Telecom SMPP carriers (MSG91)SMS / DLT-registered SMS deliveryPhone number, message content, DLT template ID, sender IDIndia (DLT)
Email gateways (SMTP / SendGrid / Mailgun etc. — configured per tenant)Email deliveryRecipient email, subject, body, bounce/click eventsPer provider
Anthropic / OpenAI / Google / OpenRouterLLM inferencePrompt + generated text (no identifiers unless you include them)US / EU / Singapore (per provider)
Hostinger (SMTP)Platform transactional email (login, password reset, alerts)Email, user ID, message bodyGermany (EU)
None — self-hosted Prometheus + Loki + GrafanaApplication monitoring (if applicable — else "None, self-hosted Prometheus + Loki")Error stack traces, request IDsGermany (EU)

7. DPDP Act 2023 (India) and GDPR (EU/EEA) rights

Under the Digital Personal Data Protection Act, 2023 (India) and, where it applies, the GDPR, you have the right to:

Submit a request to [email protected]. We respond within 30 days (DPDP) and within one calendar month (GDPR), extendable by a further two months for complex requests with prior notice. We may ask you to verify your identity.

8. End-recipient rights (Customer Data)

If you are an end-recipient who received a message through MsgHub and want to exercise your rights: please contact the MsgHub customer who messaged you first — they are the data fiduciary for your data. You can always reply STOP on SMS / STOP on WhatsApp / click unsubscribe on email to opt out. If the customer does not respond or you cannot identify them, you may contact us at [email protected] and we will assist with identification or escalate to the customer.

9. Cookies and similar technologies

10. Security

Summary of technical measures (full detail at msghub.info/security):

We will notify affected parties of a personal-data breach without undue delay, and the Data Protection Board of India (DPDP Act), the relevant supervisory authority (GDPR) within mandated windows, and CERT-In within 6 hours where the 2022 Directions apply.

11. Children

MsgHub is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact [email protected] and we will delete the account and data.

12. Changes to this Policy

Material changes will be notified to account admins by email at least 30 days before taking effect and will be posted with a new "Last updated" date at the top.

13. Contact

[email protected]