MBX Reach
🌐 English

Privacy Policy

Last updated: 2026-09-12 · MediaBoxEnt Digital Studio LLC

This policy explains what MediaBoxEnt Digital Studio LLC does with personal data in MBX Reach: the data of the customers who hold accounts, and the data of the subscribers those customers send to. The two are handled differently, and the first section explains why that matters to you.

It applies to mbxreach.com, to the MBX Reach panel and API, and to the hosted signup, confirmation, preference and unsubscribe pages that our customers' subscribers see.

1.Two Kinds of People, Two Roles

This policy covers two groups, and the difference decides who answers a request.

Customers are the people and organisations with an MBX Reach account. For their data MediaBoxEnt is the controller: we decide what we collect and why, and this policy is our notice to them.

The terms on which we process a customer's subscribers for them, including the Standard Contractual Clauses for transfers out of Europe, are in the Data Processing Agreement. It applies to every account automatically and needs no signature.

Subscribers are the people on a customer's list. For their data MediaBoxEnt is the processor: our customer decided to add them and decided what to send them, and we act on that customer's instructions. If you received an email sent through MBX Reach and want to be removed, corrected or erased, ask the sender whose name is on the message; the fastest route is the unsubscribe link in its footer. If you cannot reach them, write to privacy@mbxreach.com and we will pass the request to them and help them act on it.

2.What We Collect About Customers

To open and operate an account we hold:

  • your name, your email address and the name of your workspace;
  • a cryptographic hash of your password, never the password itself, and, if you turn the second factor on, an encrypted authenticator secret and the hashes of your recovery codes;
  • your sign-in sessions, each with the time, the IP address it started from and a fingerprint of the browser it belongs to, so that you can see and end them from your account page;
  • failed sign-in attempts by IP address and by email address, for the lock-out that protects you from password guessing;
  • an audit log of significant actions in your workspace, with the actor, the action, the time and the IP address;
  • your workspace settings: sender name, reply-to address, the postal address that anti-spam law requires in your footer, brand colour, logo, timezone;
  • the hashes and prefixes of any API keys you create, and when each was last used;
  • the messages you send us for support, and anything you attach to them.

We do not ask for a payment card in the panel, and none is stored in MBX Reach.

3.What We Process for Customers About Their Subscribers

A customer's workspace holds, about each of its contacts:

  • the email address, first and last name, and any custom fields and tags the customer chose to keep;
  • the standing of that person with that workspace: subscribed, awaiting confirmation, unsubscribed, bounced or reported as spam, with the time and, for an unsubscribe, any reason the person gave;
  • where the address came from: a signup form, an import, the API or a manual entry, and, for a signup form, the IP address and the time of the signup, which is what proves the person actually asked;
  • one row per recipient per campaign recording whether the message was sent, delivered, bounced or reported, and the time;
  • engagement events when the customer leaves tracking on: an open or a click, the time, the link clicked, the browser or mail client string sent by the device, and a one-way hash of the IP address. We do not store the IP address of an open or a click.

The body of a sent message is not stored per recipient; the campaign itself is stored once, in the customer's workspace.

4.Tracking in Emails

Open tracking works with an invisible image, and click tracking by routing a link through mbxreach.com before it continues to its destination. Both are switches on each campaign, and a customer can turn either or both off.

Links to unsubscribe, to the preference page and to the browser version of a message are never tracked.

Most mail clients now load images through their own servers, which makes an open count an estimate rather than a fact. Nothing in MBX Reach reads a subscriber's mailbox, follows them across other websites, or builds a profile of them for advertising.

A customer may add campaign tags for their own web analytics. Those tags travel in the link and are read by whatever analytics that customer runs on their own site, under that customer's own privacy notice, not ours.

5.Why We Process It, and On What Basis

Where the GDPR or a similar law applies, our bases are these:

  • to provide the service under our contract with the customer: the account, the workspace, sending, reports;
  • our legitimate interest in keeping the platform and its shared sending reputation safe: the human check on public forms, sign-in throttling, the audit log, the abuse controls described below;
  • our legitimate interest in operating and improving the service: aggregate figures on how much is sent and how it performs;
  • compliance with a legal obligation, such as keeping the unsubscribe and suppression records that anti-spam law requires;
  • for subscribers, the basis is the customer's, not ours. A customer must have a lawful basis, normally consent, for adding a person to a list and mailing them.

6.Abuse Signals Shared Across the Platform

One control needs to be stated plainly, because it crosses the wall between workspaces. When someone reports a message as spam or an address bounces permanently, that address is recorded in a suppression list so that it can never be mailed again from that workspace.

When a customer imports a file, we count how many of its addresses have reported some other MBX Reach customer as spam. Only the count reaches the customer, in the explanation of why an import was held; no address, no name and nothing about the other workspace is disclosed in either direction. It exists so that a list which has already annoyed people once does not get to do it again from a new account.

We also check, at import time, whether an address's domain can receive email at all, by asking public DNS. That check sees the domain, never the address.

7.Who We Share It With

We do not sell personal data, we do not rent lists, and we do not mail our customers' subscribers on our own behalf.

We use a small number of providers to run the service, each acting on our behalf under its own data processing terms:

  • Cloudflare, Inc. provides the infrastructure MBX Reach runs on: hosting and compute, the database, file storage, the queue, the human check on public forms, the access control on our operator console, and the delivery of the email itself. It processes IP addresses and request metadata as part of that;
  • when a customer uses the optional AI writing assistant, the text of that request is sent to a third-party model provider through MediaBoxEnt's own relay, for the single purpose of returning the draft. A current list of these providers is available at privacy@mbxreach.com;
  • other MediaBoxEnt companies and products, where a customer connects them, and only for what that connection does.

We also disclose data where we are legally required to, where it is necessary to protect the rights, safety or property of MediaBoxEnt, our customers or the public, and, if MediaBoxEnt is ever involved in a merger or sale, to the successor, which remains bound by this policy or a policy at least as protective.

8.International Transfers

MediaBoxEnt is based in the United States and its providers operate globally, so data is processed outside the country you live in, including in the United States. Where the law requires a transfer mechanism, our providers act under standard contractual clauses or an equivalent safeguard.

9.How Long We Keep It

The clocks that matter:

  • contacts, lists, campaigns and reports live for as long as the customer keeps them; deleting them in the panel deletes them here;
  • engagement events, the open and click rows, are deleted automatically 180 days after they happen. Campaign totals, which carry no personal data, are kept;
  • sign-in sessions end at their expiry and are then deleted; failed sign-in records are cleared daily; email links, such as confirmation and password reset, expire within hours and are cleared daily;
  • the audit log is kept for 90 days as a security record, or less if the workspace shortens it from the panel;
  • when a workspace is deleted, everything in it is removed from the live service immediately and disappears from our infrastructure's point-in-time backups within 30 days;
  • suppression records, the addresses that unsubscribed, bounced or reported spam, are kept indefinitely on purpose. They are the mechanism that stops a deleted-and-reimported list from mailing someone who said no.

10.Security

Everything travels over HTTPS. Passwords are stored as salted hashes, authenticator secrets are encrypted with a key that never leaves our infrastructure, session and API key values are stored only as hashes, and the operator console sits behind an identity check separate from the product's own sign-in.

Sign-in is throttled by address and by IP, public forms carry a human check, and every significant action is recorded in an audit log. No system is perfectly secure, and we do not claim otherwise; if a breach affects your data we will notify you and any regulator as the law requires.

11.Your Rights

Depending on where you live, you may have the right to know what personal data we hold about you, to get a copy of it, to correct it, to have it deleted, to restrict or object to some processing, and to complain to your data protection authority. Californian residents additionally have the rights to know, to delete, to correct, and to opt out of sale or sharing; we do not sell or share personal data as those terms are defined there.

Customers can exercise most of these rights directly in the panel and can write to privacy@mbxreach.com for the rest. We answer within 30 days.

Subscribers should go to the sender whose name is on the message: they hold the relationship and they decide. Where we receive such a request we pass it to that customer promptly and help them carry it out. We will not delete a suppression record on request, because deleting it would allow the sending to resume; that is the one entry we keep in your interest, not the sender's.

We do not use your data for automated decision-making that produces legal effects about you. The automatic controls in this service act on workspaces and lists, not on individual subscribers.

12.Cookies

The panel sets a session cookie when you sign in, a short-lived cookie between the password step and the authenticator step, and a cookie remembering whether you chose the light or the dark theme. The human check on public forms sets its own cookie to tell people from bots. That is all: no advertising cookies, no cross-site tracking, no analytics of our own on the pages that carry the product.

Hosted signup forms and unsubscribe pages, the pages your subscribers see, set no cookie of ours at all.

13.Children

MBX Reach is a business tool and is not directed at children. Do not open an account if you are under 18, and do not use MBX Reach to collect data from children where the law of their country requires parental consent that you have not obtained.

14.Changes to this Policy

We may update this policy. Minor changes, including replacing a provider with another of the same kind, take effect when the revised version is published, and the version date at the top tells you when that happened. For a material change we give notice as described in the Terms of Service.

15.Contact

MediaBoxEnt Digital Studio LLC · 479 State Rt 17 Ste 6#3008, Mahwah, NJ 07430. MediaBoxEnt Technologies. Website: mbxreach.com.

Privacy and data requests: privacy@mbxreach.com · Support: support@mbxreach.com · Report abuse: abuse@mbxreach.com.

Let's keep in touch

New products when there are any, and the occasional note about the ones we already make. One click to leave.

We handle it as described in our Privacy Policy.