Legal · Privacy

Privacy Policy

Last updated September 10, 2026. This policy describes what data boxli collects, how we use it, and your rights as either a boxli operator or a recipient of a boxli send.

Working draft
This privacy policy is in draft, currently under review by outside counsel. The substance below reflects our actual data handling today; the legal language will be finalized before formal publication. Questions: privacy@sendaboxli.com.

1. Who this applies to

boxli has two categories of users: operators (the B2B revenue teams who run campaigns through the platform) and recipients (the individuals who receive a physical boxli send). Different parts of this policy apply to each.

2. Data we collect from operators

  • Account data: name, email, organization, role, billing contact information.
  • Campaign data: contact lists, target accounts, video content, message templates.
  • Integration tokens: OAuth credentials for HubSpot, Salesforce, Slack — encrypted at rest with per-org keys.
  • Usage data: dashboard activity, feature usage, error logs.

3. Data we collect from recipients

  • Identity data: name, role, company, mailing address — supplied by the operator from their CRM.
  • Engagement signals: lid open events, video play sessions, NFC tap events, QR scans, time-on-page on the personalized landing page.
  • Geo data: coarse latitude/longitude and resolved place_id from device telemetry, used for pass-around detection.
  • Device data: user-agent and OS for video play sessions.

4. How we use it

Operator data: to provide the platform, bill subscriptions, support customers, and communicate about service changes.

Recipient data: to deliver the physical send, render the personalized landing page, generate engagement signals for the originating operator's CRM, and — in aggregate, anonymized — to improve our default trigger thresholds and signal scoring formula.

5. Recipient rights

Recipients can opt out of all future boxli sends from any operator by emailing optout@sendaboxli.com. We honor the request within five business days. Opt-out is enforced centrally and applies across all operators using the platform.

6. Sharing

We share recipient engagement data with the originating operator only. We do not sell recipient data, do not share it across operators, and do not provide it to third parties except as required to deliver the service (FedEx for fulfillment, Stripe for payment processing, Resend for transactional email).

7. Retention

Engagement events are retained for the duration of the originating operator's subscription plus 90 days. After that, recipient-identifying fields are anonymized; aggregate event counts are retained indefinitely for product analytics.

8. Security

Data is encrypted in transit (TLS 1.3) and at rest. Per-org row- level security in our Postgres database isolates each operator's data. SOC 2 Type II is planned for 2026; full security posture at /security.

9. Google user data (Gmail)

Operators can connect a Google account in Settings → Integrations so that campaign workflow emails send from their own Gmail mailbox. When you do, boxli asks Google for two things: permission to send email on your behalf (thegmail.send scope) and your email address (to label the connection). We request no other Gmail permission — boxli cannot read, search, modify, or delete anything in your mailbox, and the permission we request does not allow it.

What we do with it: when a workflow you built reaches a Send Email step, boxli composes the message from the subject and body you wrote in that step and sends it through Gmail from your account to the recipient of that box. Nothing is sent that you did not author and place in a workflow.

What we store: an OAuth refresh token, encrypted at rest with AES-256-GCM using a key that exists only on our servers; the address of the connected mailbox; and which team member connected it, when. Short-lived access tokens are held in memory only. We do not store copies of sent messages beyond the workflow template already in your campaign, and no boxli employee reads your mail.

Deleting it: click Disconnect on the Gmail card and the token is deleted immediately; you can also revoke boxli at any time from your Google Account permissions page, after which the connection is removed the next time boxli checks it. If Gmail is unavailable and you have opted in, workflow emails fall back to boxli's own sender with replies directed to you; otherwise the step is handed to your team as a task.

boxli's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the Send Email feature described above; it is never used for advertising, never sold, never shared with third parties other than the recipient you are emailing and the Google service itself, and never read by humans except with your explicit consent for support, for security, or where required by law.

Separately, boxli's own staff account connects Google Sheets to read the telemetry spreadsheets that our in-box devices report into. That connection uses a boxli-owned Google account, never an operator's.

10. Contact

For privacy questions, data access requests, or to exercise any right under this policy: privacy@sendaboxli.com.