Privacy Policy

This policy explains how Manaspurti Technologies Private Limited ("Manaspurti", "we", "us") handles personal data when operating MessageHop, including the public website, customer console, support services, and related platform functions.

1. Roles and scope

For account, website, security, billing, and support administration, Manaspurti generally determines why and how personal data is used. For recipient information and message content submitted by a customer, the customer generally determines the purpose and MessageHop processes that data to provide the contracted service. Customers remain responsible for lawful collection, notices, consent, messaging classification, and instructions.

2. Information we process

  • Account and identity information such as name, business email, authentication state, organization membership, and role.
  • Organization, brand, project, registered-app, provider, sender, template, and billing configuration.
  • Integration and security data such as credential metadata, permissions, timestamps, IP-derived security signals, audit events, and request identifiers. Raw show-once credentials are not retained in retrievable form.
  • Messaging operations data such as recipient identifiers, template references, variables, delivery evidence, provider references, price snapshots, and billing events.
  • Support information such as ticket text, authorized attachments, chat messages, and safe operational references.
  • Website and service diagnostics needed for availability, security, abuse prevention, and troubleshooting.

3. Why we use information

We use information to provide and secure accounts; register and authorize applications; accept, dispatch, trace, and reconcile messages; maintain billing and audit evidence; deliver support; prevent fraud and abuse; comply with legal obligations; communicate material service or policy changes; and improve reliability. We do not claim to sell personal data or use customer message content for advertising.

4. Legal grounds and consent

The applicable ground depends on the relationship and jurisdiction, including performance of a contract, compliance with law, legitimate security and operational needs where permitted, and consent where required. Customers must secure the permissions and consents required for their recipients and channels. Withdrawing consent does not invalidate processing already lawfully completed.

5. Sharing and service providers

Information may be shared with messaging providers, cloud and infrastructure vendors, authentication providers, support tooling, payment or accounting providers, professional advisers, and authorities where necessary and lawful. Providers receive only the information reasonably needed for their function and may operate under their own legal obligations. We may disclose information in a corporate reorganization subject to appropriate confidentiality and notice requirements.

6. International processing

Providers and infrastructure may process information in more than one country. Where cross-border safeguards or customer instructions are required, they are addressed through the applicable service arrangement and law. Channel routing and destination availability remain account-specific.

7. Retention

We retain each data class only for the period needed for service delivery, security, audit, reconciliation, dispute handling, and legal obligations. Credentials can be revoked; operational and financial evidence may need to remain immutable for a longer period. Deletion requests are evaluated against customer instructions, tenant ownership, security needs, and required legal retention.

8. Security

Controls include tenant isolation, server-side authorization, scoped credentials, managed provider secrets, TOTP-backed privileged sessions, immutable evidence, audit logging, restrictive hosting policies, and bounded support access. No system is risk-free. Report a suspected vulnerability to security@msghop.com without including live secrets or customer content.

9. Individual choices and requests

Depending on applicable law, an individual may request access, correction, erasure, restriction, withdrawal of consent, grievance handling, or information about processing. If MessageHop processes recipient data solely for a customer, contact that customer first; we will assist the customer where required. Requests may require identity and authority verification.

10. Children

MessageHop is a business service and is not directed to children. Customers must not use it to process children's data without the authorization, notices, consent, and safeguards required by applicable law.

11. Changes and contact

We may update this policy to reflect product, provider, or legal changes. Material revisions will carry a new effective date. Privacy questions and grievances can be sent to hello@msghop.com. Do not send credentials, OTPs, or full message bodies by email.

Important: This public policy describes the current general service. A signed customer agreement or data-processing addendum may provide more specific terms and takes precedence where it expressly says so.