Privacy

Last reviewed: 2026-09-05

Our role

Meterbox Inc. is a data processor under your Data Processing Agreement (DPA). You are the data controller for your end-customers. We process personal data only on your documented instructions (Art. 28(3)(a) GDPR): billing the customers you tell us to bill, metering the usage you tell us to meter, sending the transactional emails you configure.

Cookies & analytics

We use strictly necessary cookies only: bp_sid for the authenticated session and bp_csrf for cross-site request forgery protection. Both are set after you log in.

On the marketing site only (no user logged in), we forward a small set of anonymized product-analytics events, such as page views and conversions like signing up or submitting the contact form, to Mixpanel from our own servers. Your browser never loads Mixpanel's script or contacts Mixpanel directly, and no third-party cookie is set. The only local state is a randomly generated, session-scoped id kept in your browser's sessionStorage, cleared when you close the tab rather than a persistent cookie, plus a short allowlist of page path and campaign parameters. We never send your name, email, or other account data to Mixpanel. If you log in or sign up, that session is linked to a separate id generated for your account, never your real email or user id, so we can measure signup and conversion funnels.

Data categories we process

  • Tenant team: name, email, hashed password, MFA factors, login audit
  • End-customer records: name, email, plan, status, optional phone
  • Usage events: customer id, model id, token / call counts, cost estimates
  • Financial records: ledger entries, credit grants, invoices, payment status
  • Audit trail: who-did-what on every privileged mutation

Lawful basis: contract necessity (Art. 6(1)(b)) for billing operations and legitimate interest (Art. 6(1)(f)) for the audit trail required to defend against fraud + meet SOC 2 / ISO 27001 control requirements.

Data subject requests

Articles 15 (export) and 17 (erasure) are served from the same admin API your team already uses:

  • GET /v1/customers/{id}/dsar/export: JSON bundle of everything we hold on the subject
  • POST /v1/customers/{id}/dsar/erase: anonymizes PII (name → [erased], email cleared), stamps erased_at, blocks further metering. Financial records are retained under the legal-obligation exception (Art. 17(3)(b))

CCPA "Right to Know" + "Right to Delete" map onto the same two endpoints: same underlying flow, different statutory framing.

Subprocessors

See the public list at /subprocessors. Material changes are notified at least 30 days in advance per Art. 28(2) GDPR.

Data residency

Each tenant runs on a single-tenant data plane pod pinned to one region. Cloud and Managed tier customers pick the region at provisioning. Self-Managed deployments inherit your cluster's region. See docs and the Deployment tiers section on the home page.

Contact

DPA, privacy, or compliance questions: contact@meterbox.ai. Security disclosures: see /security.