Skip to main content
Last Updated: February 8, 2025 At Moonbase Inc. (“Moonbase,” “we,” “us,” or “our”), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and otherwise process your personal data when you use our unified customer platform (collectively, the “Services”), visit our websites (the “Sites”), or otherwise interact with us.

1. Introduction

1.1 Purpose of this Privacy Policy

This Policy describes the types of personal data we collect, how we use and process it, with whom we share it, and your rights and choices. It applies to personal data we collect when you:
  • Visit, access, or use our Sites that link to or reference this Privacy Policy
  • Use or interact with our Services
  • Communicate with us (e.g., via email, phone, or events)
  • Provide information in connection with a prospective or existing business relationship
  • Otherwise engage with us in person or online

1.2 Controller vs. Processor

  • Controller: For personal data covered by this Privacy Policy, Moonbase Inc. is the “controller,” meaning we decide how and why the personal data is processed for our own business purposes.
  • Processor: In some situations, we process personal data strictly on behalf of our customers, who act as “controllers.” If you are an end user of one of our customers, please consult their privacy policies.
Data Processing Agreements (DPAs)
When we act as a processor on behalf of our customers, our Data Processing Agreement (DPA) governs our handling of personal data. To review or enter into our DPA, please contact legal@moonbase.ai.

2. Definitions / Key Terms

  • Personal Data / Personal Information: Any information relating to an identified or identifiable individual.
  • Sensitive Personal Data: Certain categories of personal data given heightened legal protection (e.g., health or biometric data).
  • Processing: Any operation on personal data, including collection, use, storage, disclosure, or disposal.
  • Services: Moonbase’s CRM, email marketing automation, and customer support platform, including related software/tools.
  • Sites: Moonbase’s public-facing websites and landing pages.
  • User / You / Your: Any individual who visits our Sites, registers for or uses our Services, or otherwise interacts with us.

3. Who We Are and How to Contact Us

For personal data processed under this Privacy Policy, Moonbase Inc. is the responsible entity. If you have questions or concerns, please contact us: Moonbase Inc.
548 Market St
PMB 58465
San Francisco, California 94104 USA
Email: legal@moonbase.ai
If you have a specific data protection inquiry, mention “Data Protection Inquiry” in the subject line. Our Data Protection Officer (if required) can also be reached via this email.

4. Scope

This Privacy Policy applies only to Moonbase’s collection and processing of personal data for our own business purposes. It does not apply to data handling by third parties we do not control. If you integrate our Services with third-party apps or services, their privacy practices are governed by their own policies.

5. Information We Collect

We collect various categories of personal data, either directly from you, automatically (e.g., via cookies), or from third parties.

5.1 Personal Data You Provide Directly

  • Account Registration Data: Name, email address, phone number, password, employer, job title, etc.
  • Billing & Payment Data: Credit card details, billing address, transaction history (processed via secure third-party payment processors).
  • Marketing & Communications Data: Preferences for marketing communications, form submissions, event registrations.
  • Support & Inquiry Data: Records of support tickets, user feedback, surveys, etc.
  • Content You Upload: Data included in CRM entries, marketing assets, or customer support tickets.
  • Sensitive Data: We do not intentionally collect or process sensitive personal data. If you choose to upload such data, you must ensure it is lawfully collected and shared.

5.2 Personal Data Collected Automatically

  • Device Data: IP address, browser type, operating system, mobile device IDs, hardware settings.
  • Usage Data: Pages viewed, time spent, links clicked, access dates/times, diagnostic data.
  • Location Data: Approximate geolocation inferred from IP address (or more precise location if you enable it).

5.3 Personal Data from Third Parties

  • Third-Party Integrations: If you connect external services (e.g., email platforms), we may receive relevant data.
  • Marketing & Analytics Providers: We may receive contact info, demographics, or interest data.
  • Public Sources: Publicly available information like social media profiles or open databases.

Where GDPR or similar laws apply, we rely on one or more of the following legal bases:
  1. Performance of a Contract: Providing the Services as agreed in our Terms.
  2. Legitimate Interests: Enhancing or securing our Services, unless overridden by your interests or rights.
  3. Consent: In specific scenarios (e.g., sending direct marketing where required by law). You may withdraw consent at any time.
  4. Legal Obligations: Complying with laws, regulations, or legal processes.

7. How We Use Your Personal Data

We use personal data for:
  1. Provision of Services: Account setup, CRM functions, marketing automation, customer support, and transaction processing.
  2. Customer Support: Responding to inquiries, troubleshooting, providing updates.
  3. Marketing & Promotions: Sending newsletters, offers, or event invitations, in accordance with preferences and laws (e.g., CAN-SPAM).
  4. Analytics & Service Improvement: Aggregating usage data to improve performance and user experience.
  5. Security & Fraud Prevention: Detecting or investigating unauthorized or suspicious activities.
  6. Compliance: Meeting legal obligations, responding to lawful requests, enforcing our Terms.
  7. Business Operations: Audits, mergers, acquisitions, or other corporate transactions.

8. Cookies and Similar Technologies

We and our partners use cookies, web beacons, and similar technologies to collect information about your activities on our Sites and within the Services.
  • Strictly Necessary Cookies: Essential for operation (e.g., session cookies).
  • Functional Cookies: Store user preferences or enhance site performance.
  • Analytics Cookies: Collect usage data (e.g., via Google Analytics).
  • Advertising/Targeting Cookies: Track browsing habits to serve relevant ads.
You can usually manage or disable cookies in your browser or device settings, though some features may be limited. Do Not Track / Global Privacy Control
At this time, our Sites may not respond to DNT or GPC signals in a uniform way. We continue to evaluate industry standards and legal requirements.

Our Sites and Services may contain links to or integrate with third-party websites and apps. We are not responsible for the privacy practices of these third parties, and this Policy does not apply to them. Review their policies before providing personal data.

10. How We Share and Disclose Personal Data

We do not sell your personal data. We may disclose it in the following cases:
  1. Service Providers: Vendors who assist with hosting, payments, analytics, or support, under contractual obligations.
  2. Business Partners: When you opt into integrations or explicitly request sharing.
  3. Corporate Transactions: In case of mergers, acquisitions, financing, or sale of assets.
  4. Legal Compliance & Protection: If required by law or necessary to protect rights, property, or safety.
  5. Consent: In other ways if we have your explicit consent.

11. International Data Transfers

Moonbase is headquartered in the United States. Your personal data may be transferred to countries other than your own (including the U.S.). We implement safeguards like Standard Contractual Clauses (SCCs) to protect data in accordance with this Policy and applicable law.

12. Data Retention

We retain personal data only as long as needed for the purposes in this Policy, or as required by law. For example:
  • Account Data: Kept for the duration of your account plus a reasonable period afterward.
  • Billing & Payment Data: Retained per financial and tax regulations.
When no longer needed, we securely delete or anonymize the data.

13. Additional Disclosures for Specific Jurisdictions

13.1 California Residents (CCPA/CPRA)

If you are a California resident, you may have certain rights under the CCPA/CPRA, including:
  • Right to Know: Request that we disclose the specific personal data we collect, use, disclose, and share about you (we do not sell your personal data).
  • Right to Delete: Request deletion of your personal data, subject to legal exceptions.
  • Right to Correct: Request correction of any inaccurate personal data we hold about you.
  • Right to Opt Out of Sale or Sharing: Opt out of any “sale” or “sharing” of your personal data (again, we do not sell personal data).
  • Right Not to Be Discriminated Against: We will not discriminate against you for exercising any CCPA/CPRA rights.
To exercise these rights, please contact us. We will verify your request by asking for information sufficient to confirm your identity. You may also designate an authorized agent to exercise these rights on your behalf.

13.2 Residents of Other U.S. States

Residents of states such as Virginia, Colorado, Connecticut, and Utah may have similar rights. We will honor valid requests in accordance with the applicable state law. If you have questions or wish to exercise your rights, please contact us.

13.3 EEA/UK Residents (GDPR)

If you reside in the European Economic Area (EEA) or the United Kingdom (UK), you have the following rights under the GDPR or equivalent UK laws:
  • Right of Access: Request a copy of your personal data that we hold.
  • Right to Rectification: Correct inaccuracies or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to certain conditions.
  • Right to Restrict Processing: Ask us to restrict the processing of your data in specific circumstances.
  • Right to Data Portability: Obtain a machine-readable copy of your personal data to transfer to another provider.
  • Right to Object: Object to processing of your data, especially for direct marketing purposes.
  • Right to Withdraw Consent: If processing is based on your consent, you may withdraw it at any time.
You also have the right to lodge a complaint with your local data protection authority if you believe we have not complied with our obligations. To exercise your rights, please contact us.

14. Your Rights and Choices

All users may:
  • Opt Out of Marketing: Unsubscribe from marketing emails by clicking the “unsubscribe” link or contacting us.
  • Access/Correct/Delete Data: Request access, correction, or deletion of personal data where legally permissible.
  • Object or Restrict: Ask us to stop or limit certain processing.
Where we act as a processor on behalf of our customers, direct these requests to the relevant controller (our customer).

15. Children’s Privacy

Our Sites and Services are not intended for individuals under 18, and we do not knowingly collect personal data from them. If we learn we have unintentionally collected data from someone under the relevant age, we will delete it promptly. If you believe we have collected data from a minor, contact us.

16. Data Security and Breach Notification

We take measures (e.g., encryption, access controls, audits) to protect personal data. However, no security measures are completely foolproof. If we become aware of a data breach affecting your personal data, we will notify you (and any regulatory authority) as required by law.

17. Internal Policies on Data Handling

  • Limited Access: We grant employee access on a need-to-know basis.
  • Training: Employees receive training on security, privacy, and data handling.
  • Audits: We conduct periodic reviews to ensure compliance and identify improvements.
  • Vendor Management: Service providers must adhere to data protection standards.

18. Google Integrations

18.1 Overview

We offers optional integrations with certain Google products, including Gmail and Google Calendar (“Google Integrations”), to enhance your experience with our Service. By choosing to enable these integrations, you will grant us access to specific data from your Google account.

18.2 Data We Access and How We Use It

When you connect your Google account (e.g., Gmail or Google Calendar), we access and process the following categories of data (“Google User Data”) in order to provide or improve user-facing features within our Services:
  • Gmail Data: This may include your email messages, subject lines, recipients, timestamps, attachments, and other metadata required for our shared inbox features. Specifically:
    • Reading and Sending Emails: With your permission, we will be able to read, modify, create, and send emails from your connected Gmail account to provide a unified inbox experience.
    • Storage and Display: We may store copies of your email content (including subject lines, message bodies, attachments, and metadata) on our servers in order to display them within the Services, log conversations, and enable notifications for you and any authorized team members.
    • Email Content: Your email messages may contain sensitive or confidential information. By integrating Gmail, you acknowledge that such data may be visible to other authorized users in your Moonbase workspace (e.g., team members sharing the same inbox).
  • Google Calendar Data: When you connect your Google Calendar, we may access:
    • Calendar Events and Metadata: This includes event titles, start/end times, attendees, and other relevant details in order to show upcoming meetings and automatically log activities.
    • Modifying and Creating Events: If you allow it, Moonbase can create or modify events on your calendar.
We use Google User Data solely for purposes that are clearly communicated to you within our user interface, such as displaying relevant emails, sending emails, logging conversations, logging calendar events, and improving your workflow within our Services. We do not use Google User Data to develop, train, or improve any generalized AI or machine learning models.

18.3 Compliance with Google API Policies

Moonbase’s use and transfer of information received from Google APIs (including Gmail and Google Calendar data) will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
  • No Unauthorized Use: We will not use Google User Data for advertising, marketing, or any purposes outside the scope of the user-facing features you explicitly enable.
  • No Unauthorized Sharing: We will not sell or transfer Google User Data to third parties, except:
    1. Service Providers assisting in providing or improving our Services (under binding confidentiality and data protection terms);
    2. Security Purposes (e.g., investigating abuse, or where needed to protect rights, property, or safety);
    3. Legal Compliance (e.g., responding to valid legal process or law enforcement requests); or
    4. Corporate Transactions (e.g., mergers, acquisitions, or sales of assets) after obtaining explicit prior consent from you if required.
  • No Human Reading: Moonbase personnel will not read your Google User Data unless:
    1. We obtain your separate affirmative consent to do so (e.g., you explicitly request support that requires review of specific messages or calendar entries);
    2. It is necessary for security purposes (e.g., investigating a bug or abuse);
    3. It is necessary to comply with applicable law or legal processes; or
    4. The data (including derivations) is aggregated and anonymized and used for our internal operations in compliance with all applicable privacy laws.

18.4 Your Choices and Revocation of Access

Enabling a Google Integration is entirely optional. If you choose not to connect your Gmail or Google Calendar, you can still use most features of our Services (though some functionalities will be limited). You can revoke Moonbase’s access to your Google account at any time by: Once revoked, Moonbase will no longer have the ability to read or write data to your Gmail or Google Calendar, though previously synchronized data may remain in our systems in accordance with our data retention practices and as required for record-keeping or legal compliance.

18.5 No Endorsement or Control Over Google

Moonbase is not affiliated with Google and does not control Google’s privacy or security practices. Your use of the Google Integrations is subject to Google’s own terms and privacy policies, in addition to this Privacy Policy.

19. Updates to This Privacy Policy

We may update this Privacy Policy periodically. The “Last Updated” date reflects the most recent changes. For significant changes, we may provide additional notice (e.g., by email or a site banner). We encourage you to review this Policy regularly.

20. Contact Us

For any questions or comments about this Privacy Policy, or to exercise your rights, contact us: Moonbase Inc.
548 Market St
PMB 58465
San Francisco, California 94104 USA
Email: legal@moonbase.ai
Include “Privacy Inquiry” or “Data Subject Request” in the subject line, as appropriate. We will respond as soon as reasonably practicable and as required by law.