Privacy Policy

Last updated:

1. Introduction

Sendio ("we", "us", or "our") operates the Unified Communication Platform available at sendio.dev and its subdomains (api.sendio.dev, app.sendio.dev). This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our services.

Sendio provides a unified API structured into two modules under one brand: Messaging Module (send and receive messages across WhatsApp, Telegram, Discord, Instagram, and Messenger) and Social Module (publishing to Instagram, Facebook Pages, TikTok and LinkedIn + lead capture from Facebook Lead Ads and TikTok Lead Gen Custom API). The Social Module ships live in Phase B-F of the roadmap.

By using our services, you agree to the practices described in this policy. If you do not agree, please do not use the platform.

2. Information We Collect

Account data: When you register for Sendio, we collect your email address, name (optional), and authentication data. We use OTP (One-Time Password) verification — we do not store passwords.

Workspace data: Information about your workspaces, channel configurations, API keys (stored hashed), webhook URLs, and team preferences.

Message metadata (Messaging Module): We log metadata for messages processed through our API, including: message identifiers, channel used, recipient number or identifier, send and delivery timestamps, delivery statuses (sent, delivered, read, failed), and error codes where applicable. Sendio does NOT store message content. The message body is transmitted to the channel provider and immediately discarded from our systems.

Social Module data (Phase B onwards): When you publish content or capture leads via the Social Module, we collect: published post identifiers, social channel (Instagram, Facebook Pages, TikTok, LinkedIn), basic metrics (impressions, public engagement returned by the provider), timestamps and publication statuses. For Lead Capture (Facebook Lead Ads + TikTok Lead Gen Custom API + LinkedIn Lead Gen Forms in Phase F): the lead payload (name, email, phone, and form fields) is transmitted to your webhook; we persist only identifiers and metadata necessary for deduplication and delivery. Post content (caption, media) is stored only as long as needed to execute the publish call to the provider.

Usage data: We automatically collect information about how you interact with our API and dashboard, including: IP addresses, browser user agent, pages visited, API endpoints called, message volumes, and performance metrics.

Billing data: If you subscribe to a paid plan, our payment processor (Stripe) handles your payment information. Sendio only stores the last 4 digits of your card and the Stripe customer ID.

3. How We Use Your Information

Service operation: We use your data to process and route messages through your configured channels, maintain your account and workspaces, deliver webhooks to your endpoints, and provide technical support.

Billing and charges: We process usage data to calculate consumption, generate invoices, apply overage charges per your plan, and prevent fraud or abuse.

Security: We use access logs and usage patterns to detect suspicious activity, prevent unauthorized access, protect against attacks (DDoS, injection, etc.), and enforce per-plan rate limits.

Service improvement: We analyze aggregated and anonymized usage data to improve API reliability, optimize delivery performance, and develop new features.

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Data Retention

Messaging Module metadata retention periods depend on your plan:

Free: 7 days • Developer: 30 days • Starter: 90 days • Professional: 180 days • Scale: 365 days

Social Module: Published post metadata (identifiers, channel, timestamps, public metrics) and lead capture metadata (form identifiers, timestamps, deduplication hashes) follow the same per-tier retention windows as the Messaging Module — socialFree 7 days, socialStarter 90 days, socialPro 180 days, socialScale 365 days. Post content (caption, media) is discarded immediately after the publish call to the provider; lead payloads are removed from transit after successful delivery to your configured webhook.

Once the retention period expires, metadata is automatically deleted through a scheduled purge process (auto-purge). This deletion is permanent and irreversible.

Account data is retained for as long as your account is active. If you request account deletion, we will delete all your data within 30 days of the request, except data we are legally required to retain for legal or tax purposes.

Access and security logs are retained for 90 days regardless of plan.

5. Third-Party Services

Sendio integrates with the following service providers to operate messaging and social channels. Each provider processes data according to their own privacy policies:

Meta Platforms (WhatsApp, Instagram DMs, Messenger, Instagram Publishing, Facebook Pages, Facebook Lead Ads): Messages sent through WhatsApp Cloud API, Instagram Direct Messages and Facebook Messenger; posts published to Instagram and Facebook Pages; and leads captured via Facebook Lead Ads are processed by Meta. By connecting these channels, you accept Meta's Platform Terms and Data Policy.

Telegram: Messages are sent through Telegram's Bot API. Telegram processes these messages per their Terms of Service.

Discord: Messages are sent through Discord's API. Discord processes these messages per their Privacy Policy.

TikTok for Business (Phase C): Posts published via TikTok Content Posting API and leads captured via TikTok Lead Gen Custom API are processed by TikTok. By connecting TikTok Business Accounts, you accept the TikTok Business Terms and TikTok Privacy Policy.

LinkedIn (Phase F): Posts published via the LinkedIn Marketing Developer Platform and leads captured via LinkedIn Lead Gen Forms are processed by LinkedIn. By connecting your LinkedIn Page, you accept the LinkedIn Marketing Developer Platform Terms.

Additionally, we use: Stripe for payment processing, cloud infrastructure services for hosting and storage, and monitoring services for observability and alerting.

6. Data Security

We implement multiple layers of security to protect your information:

Encryption in transit: All communications with our API and dashboard use TLS 1.2+ (HTTPS). API keys are transmitted exclusively via authorization headers over encrypted connections.

Encryption at rest: Data stored in our databases is encrypted with AES-256.

Signed webhooks: Every webhook sent to your endpoints includes an HMAC-SHA256 signature that allows you to verify the authenticity of the request. This prevents webhook spoofing attacks.

Secure cookies: Dashboard sessions use httpOnly cookies with Secure and SameSite=Strict flags, preventing XSS and CSRF attacks.

Hashed API keys: API keys are stored hashed — never in plain text. You can only see the full key at the time of creation.

OTP authentication: We use one-time password (OTP) verification instead of passwords, reducing phishing and credential reuse risks.

Despite these measures, no system is 100% secure. If you discover a security vulnerability, please contact us immediately at security@sendio.dev.

7. Your Rights

In accordance with GDPR and applicable data protection regulations, you have the following rights:

Right of access: You may request a copy of all personal data we hold about you. We will provide this information in JSON format within 30 days of the request.

Right of rectification: You may correct inaccurate personal data through your dashboard or by contacting support.

Right of erasure: You may request complete deletion of your account and associated data. We will process your request within 30 days.

Right to data portability: You may export your data (workspace configurations, message logs, webhook configurations) in JSON format via our API or by requesting it from support.

Right to object: You may object to the processing of your data for specific purposes by contacting our team.

To exercise any of these rights, contact us at support@sendio.dev with the subject "Personal data request".

8. Children's Privacy

Sendio is not designed for or directed to persons under the age of 13. We do not knowingly collect personal information from children under 13.

If we discover that we have collected data from a child under 13, we will delete that information immediately. If you are a parent or guardian and believe your child has provided us with personal data, contact us at support@sendio.dev.

9. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements.

For material changes, we will notify you via email to the address associated with your account and/or through a prominent notice on the dashboard at least 30 days before the changes take effect.

Your continued use of Sendio after the effective date of the updated policy constitutes your acceptance of the changes.

10. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us:

General email: support@sendio.dev
Privacy inquiries: privacy@sendio.dev
Security vulnerabilities: security@sendio.dev

We respond to all privacy inquiries within 10 business days.

Privacy Policy — Sendio — Sendio