Who we are & our role
SyBox is a business-messaging platform that lets teams manage WhatsApp, SMS, email, and internal conversations from a single shared inbox. In this policy, "SyBox", "we", and "us" refer to SMART SOUQ SARL AU, a company registered in Morocco (RC Marrakech N° 154779, RC Fès N° 87323, ICE 003587569000031), with its registered office at 359 Bureau N°5, Étage 2, Lot Massar, Marrakech, and a branch at 27 Rue Brahim Roudani, VN, Étage 5, Bureau 17, Fès.
Our role depends on the data:
- As a controller — for the accounts of the businesses that subscribe to SyBox and the team members who sign in (registration details and how they use the product).
- As a processor — for the conversation content and contacts our customers send and receive through their own connected channels. We process that data on their instructions; each customer is the controller of the messages in their workspace.
Information we collect
We collect only what is needed to run the service, keep it secure, and meet our legal obligations.
Account & profile
A display name, email address, phone number, a securely hashed password, an optional avatar, language preference, and role or permission settings.
Business messaging data
To operate a connected channel we receive and store the messages, media, delivery status, timestamps, and contact identifiers (such as phone numbers and profile names) that flow through it — including via the WhatsApp Business Platform. This data belongs to the customer's workspace and is processed on their behalf.
Connected-account & integration data
If a customer connects an integration — for example importing contacts from Google Contacts or linking a Google account for sign-in — we access only the data needed for that feature, and only with the customer's explicit authorization, which can be revoked at any time. SyBox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we use Google Contacts data solely to import contacts into the customer's workspace, never for advertising, and we do not sell it or transfer it to anyone else.
Technical & usage data
Limited technical data to operate securely: IP address and the approximate country derived from it, browser and device type, session and sign-in records, security events (such as failed logins), and diagnostic logs.
We use your IP address and the country inferred from it to give you a better experience — for example choosing an appropriate default language — to apply the rules applicable in your region, and to help keep the service secure. We use it only for an approximate country, not to pinpoint your precise location.
| Category | Why we process it | Typical retention |
|---|---|---|
| Account & profile | Provide access, authenticate users, apply permissions | While the account is active |
| Messages & contacts | Deliver the shared-inbox service to the customer | Controlled by the customer; deleted on request or account closure |
| Integration data | Run the feature the customer enabled | Until disconnected or deleted |
| Technical & security logs | Protect the service, detect abuse, debug | Short window, then deleted or aggregated |
How we use information
- Provide, maintain, and improve the SyBox service and its features.
- Authenticate users, enforce permissions, and keep workspaces separate and secure.
- Send and receive messages on the channels a customer has connected.
- Deliver operational communications, such as verification codes and account notices.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with applicable law and the terms of the platforms we connect to.
We do not sell personal information, and we do not use the content of our customers' messages or their contacts for advertising or to train unrelated models.
WhatsApp Business Platform & Meta
SyBox integrates with the WhatsApp Business Platform provided by Meta so customers can message their own contacts. When a customer connects a WhatsApp Business number:
- We receive inbound messages through a secure webhook and send outbound messages through Meta's Cloud API, using credentials authorized by the customer.
- We store and route the data by WhatsApp Business Account and phone-number identifiers so it appears in the correct workspace.
- We handle this data in accordance with Meta's Platform terms, the WhatsApp Business Messaging Policy, and applicable law, solely to provide the service to the customer.
Meta's own handling of that data is governed by its terms and privacy policy at whatsapp.com/legal/business-policy.
Legal bases
Where the GDPR or similar laws apply, we rely on: contract (to provide the service), legitimate interests (to secure and improve the platform, balanced against your rights), consent (for optional integrations you enable, which you may withdraw), and legal obligation. For data we process on a customer's behalf, that customer is responsible for having a valid legal basis for the messages they send and receive.
International transfers
SyBox and our providers may process data in countries other than where you are located. When we transfer personal data across borders, we use appropriate safeguards — such as standard contractual clauses or an equivalent lawful mechanism — to protect it.
Data retention
We keep personal data only as long as needed for the purposes in this policy. Account data is retained while the account is active. Conversation and contact data stays under the customer's control and is deleted when the customer deletes it or closes the workspace, subject to short backup and legal-retention periods. Security and diagnostic logs are kept for a limited window and then deleted or aggregated.
How we protect information
We apply technical and organizational measures appropriate to the risk, including encryption in transit, hashed passwords, per-workspace data isolation, signed-request verification for platform webhooks, access controls and permission scopes, session revocation, and monitoring for suspicious activity. No method is completely secure, but we work continuously to protect your data and respond quickly to incidents.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. You may also lodge a complaint with a data-protection authority. To exercise these rights, contact us at privacy@smartsouq.app. We respond within the timeframe required by law. To delete your data, see our Data Deletion instructions.
End users of our customers
If you are an individual who messages a business that uses SyBox, that business is the controller of your conversation and we process it on their behalf. Please direct requests to access or delete your data to the business you were communicating with; we will support them in fulfilling your request.
Children's privacy
SyBox is a business tool and is not directed to children. We do not knowingly collect personal data from children under the age required by local law. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes
We may update this policy to reflect changes to the service or the law. When we make material changes, we update the "Last updated" date above and, where appropriate, notify you. Continued use of SyBox after an update means you accept the revised policy.
Contact us
For any question about this policy or your personal data, or to exercise your rights, reach us at:
See also: Terms of Service · Data Deletion