Privacy Policy
Effective date: 2026-08-25 · Last updated: 2026-08-25
This Privacy Policy describes how MsgHub, operator of the MsgHub platform ("MsgHub", "we"), processes personal information. It covers both the msghub.info marketing website and the MsgHub platform (app.msghub.info, APIs, dashboards).
1. Two kinds of personal data we handle
MsgHub distinguishes between:
- Account Data — information about the MsgHub customer (your name, business name, email, phone, billing details, IP, session logs, support correspondence). MsgHub is the data fiduciary / controller for Account Data.
- Customer Data — information about your end-recipients that you upload or that flows through the platform (contact names, phone numbers, email addresses, message content, conversation transcripts, opt-in records, etc.). You are the data fiduciary / controller; MsgHub is the data processor. Your own privacy policy, DPA, and consent practices apply to Customer Data. See §7 and the DPA on request.
2. What we collect (Account Data)
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Identity & contact | Name, business name, email, phone, country | Account creation, support, billing, KYC | Contract performance · legal obligation (KYC / DLT) |
| Authentication | Password hash (Argon2id), MFA seed (AES-256-GCM encrypted), session tokens | Secure sign-in, MFA, prevent abuse | Contract · legitimate interest (security) |
| Billing | Invoice records, GSTIN, bank-transfer remittance details. We do not collect or store card numbers — invoices are settled by bank transfer. | Invoicing, tax compliance, fraud prevention | Contract · legal obligation |
| Usage & telemetry | API call counts, feature flags used, error logs with request IDs, IP addresses, user-agent | Operate, troubleshoot, rate-limit, detect abuse | Legitimate interest |
| Support & communications | Email threads, chat transcripts with support | Respond to tickets, improve the product | Contract · legitimate interest |
| Website analytics | None — no third-party ad trackers | Understand aggregate site usage | Legitimate interest / consent where applicable |
3. What Customer Data flows through the platform
When you use MsgHub you send and receive end-recipient personal data such as: names, phone numbers, email addresses, WhatsApp IDs, Instagram handles, message content (text / media), opt-in and opt-out records, delivery status, agent-bot conversation transcripts. We store only what is necessary to deliver the Service and comply with regulatory record-keeping (e.g. DLT consent logs).
We do not sell Customer Data. We do not use it to train third-party AI models. We do not repurpose it for advertising.
4. How we use Account Data
- To provide, operate, secure, and improve the Service.
- To process payments and comply with tax and KYC laws.
- To send service emails (account, billing, security, legal updates). These are transactional; you cannot opt out without ending your use of the Service.
- To send product updates and marketing — only after you opt in. You may unsubscribe at any time via the link in every marketing email.
- To investigate suspected fraud, abuse, or violation of our Terms.
- To comply with legal obligations and respond to lawful government requests.
5. AI processing
Where you use MsgHub's AI features (chatbot, co-pilot, agent, embeddings, intelligence dashboards), the following applies:
- Prompts and generated responses are sent to third-party LLM providers (Anthropic, OpenAI, Google, OpenRouter, and any providers you configure on your own key) over HTTPS.
- We pass a tenant-scoped request; we do not include other customers' data.
- Providers process requests under their enterprise / API terms; those terms typically include no-training-on-customer-inputs commitments. You are responsible for reviewing the provider terms of any key you bring.
- We run prompt-injection detection, PII redaction, and output validation — safeguards, not guarantees. Do not feed raw, non-essential PII into prompts.
6. Sharing and sub-processors
We share personal data only with sub-processors necessary to deliver the Service. The current list is maintained at §6.1 below and is updated when we add or change a sub-processor; material changes are announced to account admins by email at least 30 days before taking effect.
6.1 Current sub-processors
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Contabo GmbH | Hosting (VPS, storage, networking) | All platform data at rest and in transit | Germany (EU) |
| Razorpay (not currently active) | Payment processing — integration present but unused; invoicing is by bank transfer | None at present | India |
| Meta (WhatsApp Business) | WhatsApp message delivery when used | Phone number, message content, template metadata | Ireland / US (per Meta policy) |
| Telecom SMPP carriers (MSG91) | SMS / DLT-registered SMS delivery | Phone number, message content, DLT template ID, sender ID | India (DLT) |
| Email gateways (SMTP / SendGrid / Mailgun etc. — configured per tenant) | Email delivery | Recipient email, subject, body, bounce/click events | Per provider |
| Anthropic / OpenAI / Google / OpenRouter | LLM inference | Prompt + generated text (no identifiers unless you include them) | US / EU / Singapore (per provider) |
| Hostinger (SMTP) | Platform transactional email (login, password reset, alerts) | Email, user ID, message body | Germany (EU) |
| None — self-hosted Prometheus + Loki + Grafana | Application monitoring (if applicable — else "None, self-hosted Prometheus + Loki") | Error stack traces, request IDs | Germany (EU) |
7. DPDP Act 2023 (India) and GDPR (EU/EEA) rights
Under the Digital Personal Data Protection Act, 2023 (India) and, where it applies, the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase data where processing is no longer necessary or lawful.
- Withdraw consent where processing relies on consent (withdrawal does not affect prior processing).
- Portability of data you provided, in a machine-readable format.
- Nominate another person to exercise your rights in the event of your death or incapacity (DPDP-specific).
- Grievance redressal — raise concerns with us first; if unresolved, approach the Data Protection Board of India.
Submit a request to [email protected]. We respond within 30 days (DPDP) and within one calendar month (GDPR), extendable by a further two months for complex requests with prior notice. We may ask you to verify your identity.
8. End-recipient rights (Customer Data)
If you are an end-recipient who received a message through MsgHub and want to exercise your rights: please contact the MsgHub customer who messaged you first — they are the data fiduciary for your data. You can always reply STOP on SMS / STOP on WhatsApp / click unsubscribe on email to opt out. If the customer does not respond or you cannot identify them, you may contact us at [email protected] and we will assist with identification or escalate to the customer.
9. Cookies and similar technologies
- Strictly necessary: session cookies (MsgHub platform), CSRF tokens. Cannot be disabled without breaking the site.
- Analytics: None. We do not use Google Analytics, Facebook Pixel, or advertising networks.
- Marketing: none. We do not track you across sites.
10. Security
Summary of technical measures (full detail at msghub.info/security):
- Multi-tenant Row-Level Security enforced at the database layer.
- AES-256-GCM for stored API keys, agent memory, MFA secrets, webhook secrets.
- Argon2id password hashing.
- HMAC-signed webhooks, replay-guarded with Redis SETNX.
- Five-layer SSRF guard on outbound URLs.
- AI prompt-injection detection, PII output validation.
- Append-only audit log, tenant-isolated.
- TLS 1.2+ for all external traffic.
- Regular backup drills and incident runbook; last drill date published at msghub.info/security.
We will notify affected parties of a personal-data breach without undue delay, and the Data Protection Board of India (DPDP Act), the relevant supervisory authority (GDPR) within mandated windows, and CERT-In within 6 hours where the 2022 Directions apply.
11. Children
MsgHub is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact [email protected] and we will delete the account and data.
12. Changes to this Policy
Material changes will be notified to account admins by email at least 30 days before taking effect and will be posted with a new "Last updated" date at the top.