InboundraInboundra ← Back to Inboundra

Privacy Policy

Effective Date: April 12, 2026 | Last Updated: August 25, 2026

1. Who We Are

Inboundra LLC ("Inboundra", "we," "us," "our") is a domestic for-profit Limited Liability Company organized under the laws of the Commonwealth of Puerto Rico and registered with the Puerto Rico Department of State Registry of Corporations under number 573241. Our principal office is 11 Valle de las guavas, Aguada, PR 00602, Puerto Rico, and our website is inboundra.io. Full corporate identity is published on our Legal Information page.

We provide automated text messaging services (SMS, WhatsApp, and Messenger) on behalf of our business clients to qualify leads and schedule appointments, and we provide digital marketing, social media management and custom business automation services to those clients. This policy covers both consumers who interact with our AI assistants and our business clients.

2. Information We Collect

When you interact with our AI assistant (for example, 'Sofía') via text message, we may collect:

Business client account and billing information. If you are a business client of Inboundra (not a consumer texting one of our AI assistants), we additionally collect and retain account and billing information: your name and business name, contact email, the services contracted, and records of invoices and payments (amounts, dates, payment status). Card and bank details are collected and processed directly by our payment processor, Stripe — we never see or store your full card or bank account numbers. Billing records are retained for as long as required for accounting, tax, and audit obligations, which may extend beyond the deletion windows described in Section 6.

2b. Lead Forms Hosted by Inboundra

Inboundra hosts lead-capture pages on its own domain on behalf of a business client, such as inboundra.io/get-quote.html for Power Solar Isabela. When you submit one of those forms we collect the name and phone number you provide, and optionally the email, town and message. That information is transmitted immediately to the business client named on the page, which becomes the controller of that data and holds it under its own retention rules; Inboundra transmits and logs it on that client's behalf under a written agreement. We do not use it for our own marketing and we do not sell it. We also record, at the moment you submit, a consent record: the date and time, your IP address, your browser identifier, the exact text of the disclosure that was on your screen, and your answer to the separate optional checkbox for offers and promotions. That record exists so the business client can prove the messaging consent you gave; it is kept for 5 years, as described in Section 6. Leaving the offers checkbox unchecked blocks marketing campaigns to your number and does not affect the messages that coordinate your own appointment. Requests about that data may be sent to inboundrahq@inboundra.com and we will route them to the business client.

3. How We Use Your Information

We use your information to:

4. Data Ownership

Your data is owned by the business you contacted (our client). Inboundra acts as a data processor for that data, on behalf of our clients. For the measurement of our own website described in Section 11, Inboundra is the controller: that data is ours, it is separate from any client's data, and it is stored on separate infrastructure with separate credentials. We maintain your data in custody solely for the purpose of providing our services.

5. Data Sharing

We share your information with:

We do not sell your personal information to third parties.

6. Data Retention and Deletion

We retain your personal data only as long as necessary to provide our services and comply with legal obligations.

Rolling retention for active customers. For individuals actively engaging with our AI assistant, we retain:

End of service agreement. When our service agreement with a business client terminates:

Legal holds. If we receive a valid legal request or regulatory inquiry, retention windows may be paused solely for the specific data subject to that request, for as long as legally required.

Proof of consent after a deletion. If you ask us to delete your data, we do, with two exceptions we tell you in advance. First, from the messaging-consent record we keep only the core that proves that number authorized the messages (the number, the date, a cryptographic digest of the text that was on your screen, and your answer to the offers checkbox); we erase your name, your email, your town, your IP address and your browser identifier from that record. Second, we keep your phone number by itself on our suppression lists: the record of the deletion request, and, if you left the offers checkbox unchecked or replied STOP, the list that blocks marketing to that number. We keep the first because it is the only thing that would let us defend a claim about those same messages. We keep the second because it is the only way to be sure a later upload does not message you again. Neither is used to contact you.

7. Your Rights Over Your Data

Puerto Rico has no single comprehensive data privacy statute. We nonetheless grant every person the following rights over the data we hold, as a binding commitment of Inboundra LLC:

How to exercise these rights. You may make any of these requests directly through the same WhatsApp or SMS number you have been messaging — our AI assistant automatically recognizes data-rights requests and records them with a timestamp and a response deadline. For a request you want to be certain reaches a person, write to inboundrahq@inboundra.com. Any of the following phrases (in Spanish or English) will trigger a data-rights request, and our list is illustrative rather than exhaustive:

Marketing opt-out. Separately from the rights above, you can stop receiving any marketing messages from our AI assistant at any time by replying STOP, PARE, CANCELAR, BAJA, ALTO, SACAME, DETENTE, or BASTA (or similar phrases in Spanish or English such as "no me escribas", "déjame en paz", "unsubscribe", "leave me alone"). Marketing opt-outs take effect immediately.

Response time. We answer data-rights requests within 10 business days from receipt. That deadline is our own commitment, not a period imposed by statute. Requests received through our automated system are recorded with a timestamp and a deadline in an append-only audit trail. No screen displays them today and no alert is sent to a person, so email is the only channel with a guaranteed human read. We say this plainly because the previous wording of this paragraph promised a human handler that our system does not currently notify.

You can also contact us directly at inboundrahq@inboundra.com for any request or complaint regarding your data.

8. Automated Messaging and Consent

Our AI assistant sends automated text messages. By submitting your phone number through our client's lead capture forms, you consent to receive automated messages. You may opt out at any time by replying PARE, STOP, CANCELAR, BAJA, ALTO, SACAME, DETENTE, or BASTA to any message.

9. AI Disclosure

Our assistant is an artificial intelligence system, not a human. The assistant (whose name varies by business client — for example, 'Sofía') identifies itself as an AI in every first interaction and will disclose its AI nature if asked directly.

9b. Do Not Track and Global Privacy Control

Some browsers send a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal. There is no industry consensus on how these should be honored, and this site does not currently respond to them. We state that plainly rather than imply otherwise. Your control over measurement on this site is the cookie banner and the Cookie preferences link in the footer of every page: nothing beyond strictly necessary storage runs until you allow it there, and withdrawing takes the same single click as granting. Our full cookie disclosure is in the Cookie Policy.

9c. Third Parties That Collect Through This Site

Site fonts are served by Google Fonts, so Google receives your IP address when a page loads, before any consent decision. It is not a cookie or a tracker and we do not use it to measure you, but it happens and we prefer to say so. Hosting is provided by Vercel Inc., which processes technical request logs on our behalf; the project's Speed Insights and Web Analytics products are not loaded by any page of this site. If you allow the analytics or marketing categories, the third parties named in the Cookie Policy may set their own cookies under their own policies. As of the date of this policy, no third-party measurement tag is configured.

10. Security

We use industry-standard security measures to protect your data, including encrypted database storage, role-based access controls, and regular security audits.

10b. Security Breach Notification

Puerto Rico's Act 111-2005, the Ley de Información al Ciudadano sobre la Seguridad de los Bancos de Información, together with DACO Regulation 7376, governs what happens if a database holding personal information of Puerto Rico residents is breached. The statute is triggered by specific data types: a person's name combined with a social security number, a driver's license or other government ID, a financial account number, a username and password, HIPAA-covered medical information, tax information, or employment evaluations.

The lead information this site collects (name, phone, email, town, message) does not by itself fall within those categories. However, Inboundra does hold credentials for the staff accounts of its business clients, which is one of the listed categories, so the statute applies to us. Our commitment, which mirrors the statute:

This policy itself is published under Puerto Rico's Act 39-2012 (Ley de Notificación de Política de Privacidad) and DACO Regulation 8568, which require a business operating in or from Puerto Rico to publish a clear, concise, conspicuous and unambiguous privacy policy and to link to it from its website. The footer link on every page is that link.

11. This Website: Cookies and Measurement

inboundra.io uses cookies and measurement technologies, under prior consent. When you first arrive, a notice asks you to choose. Until you choose, only strictly necessary storage is used, and no analytics or advertising tag is loaded at all. Declining is one click, exactly like accepting, and you can withdraw or change your choice at any time from the "Cookie preferences" link in the footer.

Attribution data. When you arrive from an ad, an email or a link, we record how you got here: UTM parameters, the referring website, and platform click identifiers (such as fbclid or gclid) present in the URL. This tells us which of our own campaigns works. It is not used to identify you as a person.

Retention. Once our own database is connected, raw site events are kept for a limited window (180 days by default) and then deleted automatically. Until it is connected, site events are not stored at all: only the event type and the page are written to our hosting provider’s technical logs, with no identifiers. Aggregated counts contain no individual records.

Your control. Declining analytics stops collection entirely. You may also request deletion of everything associated with your browser identifier by writing to inboundrahq@inboundra.com; see Section 7 for your rights and our response deadline.

Server access logs are kept by our hosting provider for operational and security purposes only.

12. Social Media Management Services

When a business client contracts our digital marketing and social media management service, we are granted working permissions on assets that remain owned by that client — typically a Facebook Page, an Instagram account and a Meta advertising account. In that role:

Data held inside Meta's platforms is also subject to Meta's own Privacy Policy, over which Inboundra LLC has no control.

13. Contact Us

Inboundra LLC
11 Valle de las guavas, Aguada, PR 00602, Puerto Rico
Phone / WhatsApp: +1 (939) 438-2346
Email: inboundrahq@inboundra.com

14. Changes to This Policy

We may update this policy from time to time. The "Last Updated" date at the top reflects the most recent revision, and that date is what marks when the current version takes effect. Changes are published on this same page and at this same address; if some time has passed since your last visit, we recommend checking it before sending us any data.