This policy explains what information SyBox collects, how we use and protect it, and the choices and rights you have — including how we handle data processed through the WhatsApp Business Platform.
Who we are & our role
SyBox is a business-messaging platform that lets teams manage WhatsApp, Facebook Messenger, Instagram Direct, SMS, email, and internal conversations from a single shared inbox. In this policy, "SyBox", "we", and "us" refer to SMART SOUQ SARL AU, a company registered in Morocco (RC Marrakech N° 154779, RC Fès N° 87323, ICE 003587569000031), with its registered office at 359 Bureau N°5, Étage 2, Lot Massar, Marrakech, and a branch at 27 Rue Brahim Roudani, VN, Étage 5, Bureau 17, Fès.
Our role depends on the data:
- As a controller — for the accounts of the businesses that subscribe to SyBox and the team members who sign in (registration details and how they use the product).
- As a processor — for the conversation content and contacts our customers send and receive through their own connected channels. We process that data on their instructions; each customer is the controller of the messages in their workspace.
Information we collect
We collect only what is needed to run the service, keep it secure, and meet our legal obligations.
Account & profile
A display name, email address, phone number, a securely hashed password, an optional avatar, language preference, and role or permission settings.
Business messaging data
To operate a connected channel we receive and store the messages, media, delivery status, timestamps, and contact identifiers (such as phone numbers and profile names) that flow through it — including via the WhatsApp Business Platform. This data belongs to the customer's workspace and is processed on their behalf.
Connected-account & integration data
If a customer connects an integration, we access only the data that feature needs, and only with the customer's explicit authorization, which can be revoked at any time. How we handle Google data — importing Google Contacts and signing in with Google — is described in the Google APIs & sign-in section below.
Technical & usage data
Limited technical data to operate securely: IP address and the approximate country derived from it, browser and device type, session and sign-in records, security events (such as failed logins), and diagnostic logs.
We use your IP address and the country inferred from it to give you a better experience — for example choosing an appropriate default language — to apply the rules applicable in your region, and to help keep the service secure. We use it only for an approximate country, not to pinpoint your precise location.
| Category | Why we process it | Typical retention |
| Account & profile | Provide access, authenticate users, apply permissions | While the account is active |
| Messages & contacts | Deliver the shared-inbox service to the customer | Controlled by the customer; deleted on request or account closure |
| Integration data | Run the feature the customer enabled | Until disconnected or deleted |
| Technical & security logs | Protect the service, detect abuse, debug | Short window, then deleted or aggregated |
How we use information
- Provide, maintain, and improve the SyBox service and its features.
- Authenticate users, enforce permissions, and keep workspaces separate and secure.
- Send and receive messages on the channels a customer has connected.
- Deliver operational communications, such as verification codes and account notices.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with applicable law and the terms of the platforms we connect to.
We do not sell personal information, and we do not use the content of our customers' messages or their contacts for advertising or to train unrelated models.
AI features
Some SyBox features use artificial intelligence to make a conversation easier to handle: turning a voice note into text, translating a message into the reader's language, reading a support screenshot, and gauging how a customer feels.
- The models are ours and run on our own servers. Content processed by these features is not sent to a third-party AI provider, is not used to train anyone else's models, and is not shared for that purpose.
- They are optional, and off until switched on. Each AI feature is a separate setting a workspace administrator enables, and it can be switched off again at any time from the workspace settings - after which the feature stops processing anything.
WhatsApp Business Platform & Meta
SyBox integrates with the WhatsApp Business Platform provided by Meta so customers can message their own contacts. When a customer connects a WhatsApp Business number:
- We receive inbound messages through a secure webhook and send outbound messages through Meta's Cloud API, using credentials authorized by the customer.
- We store and route the data by WhatsApp Business Account and phone-number identifiers so it appears in the correct workspace.
- We handle this data in accordance with Meta's Platform terms, the WhatsApp Business Messaging Policy, and applicable law, solely to provide the service to the customer.
Meta's own handling of that data is governed by its terms and privacy policy at whatsapp.com/legal/business-policy.
Facebook Pages & Instagram Messaging
SyBox also integrates with Meta's Messenger Platform and the Instagram Messaging API so customers can handle their Facebook Page and Instagram Direct conversations in the same shared inbox. When a customer connects a Facebook Page or an Instagram professional account:
- We receive inbound Messenger and Instagram Direct messages through secure webhooks and send replies through Meta's Graph API, using credentials the customer authorized.
- To display conversations properly in the team inbox, we request Business Asset User Profile Access. This lets us retrieve the name and profile picture of the person who messaged the Page or Instagram account, so agents can identify the customer they are talking to. This profile data is shown only inside that customer's own workspace and is never used for any other purpose.
- We keep this profile data only as long as needed to display the conversation, and we handle it in accordance with Meta's Platform Terms and applicable law.
Meta's own handling of that data is governed by its terms and privacy policy at facebook.com/privacy/policy.
Google APIs & sign-in
Some optional features connect to Google: importing contacts from Google Contacts, and signing in with a Google account. A customer enables these explicitly and can disconnect them at any time.
- We request only the narrowest Google scopes each feature needs, and only after the customer authorizes it.
- Limited Use. SyBox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Contacts data solely to import contacts into the customer's workspace, never for advertising, and we never sell it or transfer it to anyone else.
- Google sign-in is used only to authenticate the user; we receive a basic profile (name and email) to identify the account, and nothing more.
Legal bases
Where the GDPR or similar laws apply, we rely on: contract (to provide the service), legitimate interests (to secure and improve the platform, balanced against your rights), consent (for optional integrations you enable, which you may withdraw), and legal obligation. For data we process on a customer's behalf, that customer is responsible for having a valid legal basis for the messages they send and receive.
Cookies
We use a small number of first-party cookies and local browser storage that are strictly necessary to run the app — for example to keep you signed in, remember your language (the langCode cookie), and remember your interface theme.
On our public marketing website only (smartsybox.com) — and never inside SyBox workspaces, the inbox, or the app, where your data and your customers' data are handled — we use Google Analytics (a Google service) to understand how visitors find and use the site. It sets its own cookies (such as _ga) and collects usage data such as pages viewed and an approximate location derived from your IP address. For visitors in Europe, we ask for your consent through a cookie banner before any Google Analytics cookie is set, and we remember your choice; elsewhere it loads without a banner. You can opt out at any time through your browser settings or Google's opt-out browser add-on. We do not use advertising cookies, and we run no analytics or cross-site tracking inside the workspaces. Clearing cookies in your browser will sign you out.
How we share information
- Platform & messaging providers — Meta (for WhatsApp, Facebook Messenger, and Instagram) and the SMS or email providers a customer configures, to deliver messages on the customer's connected channels.
- Infrastructure providers — vetted hosting vendors that store and process data on our instructions under confidentiality and data-protection commitments.
- Integrations you enable — such as Google, only to the extent needed for a feature you turned on.
- Legal & safety — where required by law or to protect the rights and safety of SyBox, our customers, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not sell or rent personal information to third parties.
International transfers
SyBox and our providers may process data in countries other than where you are located. When we transfer personal data across borders, we use appropriate safeguards — such as standard contractual clauses or an equivalent lawful mechanism — to protect it.
Data retention
We keep personal data only as long as needed for the purposes in this policy. Account data is retained while the account is active. Conversation and contact data stays under the customer's control and is deleted when the customer deletes it or closes the workspace, subject to short backup and legal-retention periods. Security and diagnostic logs are kept for a limited window and then deleted or aggregated.
How we protect information
We apply technical and organizational measures appropriate to the risk, including encryption in transit, hashed passwords, per-workspace data isolation, signed-request verification for platform webhooks, access controls and permission scopes, session revocation, and monitoring for suspicious activity. No method is completely secure, but we work continuously to protect your data and respond quickly to incidents.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. You may also lodge a complaint with a data-protection authority. To exercise these rights, contact us at privacy@smartsouq.app. We respond within the timeframe required by law. To delete your data, see our Data Deletion instructions.
End users of our customers
If you are an individual who messages a business that uses SyBox, that business is the controller of your conversation and we process it on their behalf. Please direct requests to access or delete your data to the business you were communicating with; we will support them in fulfilling your request.
Children's privacy
SyBox is a business tool and is not directed to children. We do not knowingly collect personal data from children under the age required by local law. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes
We may update this policy to reflect changes to the service or the law. When we make material changes, we update the "Last updated" date above and, where appropriate, notify you. Continued use of SyBox after an update means you accept the revised policy.