Legal

Privacy Policy

Last updated: July 2026

Vani CRM (“Vani”, “we”, “us”, or “our”) is a WhatsApp, Telegram and Email marketing platform operated for businesses in India. This Privacy Policy explains what data we collect when you use Vani CRM (the “Service”), how we use it, who we share it with, and the rights you have over it. By creating an account or using the Service, you agree to the practices described here.

1. Information we collect

We collect the following categories of data:

  • Account information — your name, email address, phone number, and business details, collected when you sign up or complete onboarding.
  • Contact and lead data — names, phone numbers, email addresses, and any other fields you upload or capture through the Service (for example via CSV import, manual entry, or web forms) for the purpose of running campaigns.
  • Campaign and message data — the templates, message content, and media you send through WhatsApp, Telegram, or Email, along with delivery, open, click, and reply metadata returned by the relevant channel.
  • WhatsApp Business API data— message status callbacks, inbound replies, and conversation metadata received from Meta’s WhatsApp Business Platform on your behalf, when you connect a WhatsApp Business number.
  • Usage and analytics data — logs, device and browser information, IP address, and in-app activity used to operate and improve the Service.
  • Payment data — billing details and transaction records processed by our payment partner. We do not store your card, UPI, or bank credentials.

2. How we use your data

We use the data described above to:

  • Send WhatsApp, Telegram, and Email campaigns on your instructions, and deliver replies to your inbox.
  • Provide campaign analytics — delivery, open, click-through, and engagement reporting.
  • Operate account, credit, and billing functionality, including invoicing and top-ups.
  • Maintain the security, integrity, and performance of the Service, and prevent abuse or spam.
  • Communicate with you about your account, service updates, and support requests.
  • Comply with legal obligations under Indian law and the requirements of our upstream providers, including Meta.

We do not sell your data, or your contacts’ data, to third parties, and we do not use your contact lists or message content to train third-party or general-purpose AI models.

3. Third-party service providers

We rely on the following sub-processors to operate Vani CRM. Each processes data strictly to provide their respective service to us, under their own privacy and security terms:

  • Meta Platforms, Inc. (WhatsApp Business Platform)— delivers WhatsApp template messages and receives delivery status and inbound replies on your connected number, subject to Meta’s Business Messaging Policy and Privacy Policy.
  • Supabase — hosts our primary database, storing account, contact, and campaign records securely.
  • Clerk — manages authentication, sign-in, and session security for your account.
  • Razorpay — processes credit purchases and payments; card, UPI, and bank details are handled directly by Razorpay under PCI-DSS standards and are never stored on our servers.

We may also use Telegram’s Bot API for Telegram broadcasts and reputable email delivery providers for transactional and campaign email, each governed by their own terms.

4. Data retention and deletion

We retain account, contact, and campaign data for as long as your account is active, and for a reasonable period afterwards to comply with legal, accounting, or dispute-resolution requirements (typically up to 90 days after account closure, unless a longer period is required by law). You may request deletion of your account and associated data at any time by writing to us at raghavmanishprakash@gmail.com. We will process verified deletion requests within 30 days, except where retention is required by law or for legitimate billing and fraud-prevention purposes.

5. Data security

We use industry-standard safeguards — encryption in transit, access controls, and secure hosting with our infrastructure providers — to protect data against unauthorised access, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Your rights

As an Indian business or individual using the Service, you have rights under the Information Technology Act, 2000 (including the Sensitive Personal Data or Information Rules, 2011) and the Digital Personal Data Protection Act, 2023. Subject to these laws, you may:

  • Access the personal data we hold about your account and contacts.
  • Correct inaccurate or incomplete data.
  • Request erasure of your account and associated data, subject to Section 4 above.
  • Withdraw consent for optional communications at any time.
  • Lodge a grievance with our designated contact, and escalate to the relevant authority if unresolved.

As the business using Vani CRM, you remain the data controller for the contacts and leads you upload, and you are responsible for obtaining any consent required from those individuals before messaging them through the Service.

7. Children’s privacy

Vani CRM is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors.

8. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will update the “Last updated” date above and, for material changes, notify you by email or in-app notice.

9. Contact us

For privacy requests, questions, or grievances, write to our Grievance Officer at raghavmanishprakash@gmail.com. We aim to respond within 7 business days.