Privacy Policy
Last updated: 5 September 2026
This Privacy Policy explains how Vesma(“Vesma”, “we”, “us”) collects, uses, discloses, and safeguards personal data. Vesma is an AI sales assistant that helps businesses (our “Customers”) respond to, qualify, and follow up with their leads over messaging channels such as WhatsApp.
Vesma is operated as a sole proprietorship based in India. We act as a data processor on behalf of our Customers for the lead/end-customer data they process through Vesma, and as a data controllerfor our Customers’ own account data.
1. Who this policy covers
- Customers — businesses and their team members who hold a Vesma account.
- Leads / end-customers — individuals who message a Customer’s connected WhatsApp number or submit an enquiry, whose messages Vesma helps the Customer handle.
- Visitors — people who browse our website.
2. Data we collect
From Customers
- Account details: name, work email, password (hashed), business name, role, and workspace settings.
- Business content: knowledge-base documents you upload (e.g. brochures, price lists, FAQs) used to ground AI replies.
- Billing details processed by our payment provider (we do not store full card numbers).
From leads / end-customers (via WhatsApp & web forms)
- WhatsApp profile name and phone number.
- Message content and conversation history exchanged with the Customer’s number.
- Information you choose to share in conversation (e.g. budget, location, requirements) used to qualify and route the enquiry.
Automatically
- Usage and device data (e.g. log data, IP address, browser type) and cookies needed to operate and secure the service.
- On our public marketing pages only, the Meta Pixel, which tells Meta that a browser visited vesma.app so we can measure our advertising and show ads to people who have visited. It does not run inside the Vesma application, and it does not run on Customer microsites, so visitors to a Customer’s site are never collected by it.
3. How we use data
- To generate and send timely replies, qualify and score leads, schedule appointments, and send follow-ups on behalf of the Customer.
- To retrieve relevant answers from the Customer’s uploaded knowledge base (using text embeddings).
- To provide the dashboard, CRM, analytics, and notifications.
- To operate, secure, debug, and improve the service, and to comply with legal obligations.
4. WhatsApp Business Platform
Vesma integrates with the WhatsApp Business Platformprovided by Meta. When a lead messages a Customer’s connected number, Meta delivers that message to Vesma so the Customer can respond. Our use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, and our processing of WhatsApp data is also governed by the WhatsApp Business Messaging Policy. We do not use WhatsApp message content for advertising and do not sell it.
5. Google integrations & Google user data
5.1 Google Calendar
Customers may optionally connect a Google Calendar account so that appointments booked in Vesma appear on the calendar their team already uses. This integration is off by default and is never required to use Vesma.
When connected, Vesma requests only the following Google OAuth scopes:
| Scope | Why we request it |
|---|---|
.../auth/calendar.events | To create an event when an appointment is booked, move it when the appointment is rescheduled, and remove it when the appointment is cancelled. |
.../auth/calendar.events.freebusy | To check whether the Customer is already busy at a proposed time, so the AI does not double-book them. |
Vesma only creates and manages the appointment events it books on the Customer’s behalf. It does not read the contents of other calendar events; availability is checked as busy/free time only. Google access and refresh tokens are stored encrypted at rest and are used solely to perform the actions above. A Customer can disconnect at any time from Settings, which revokes Vesma’s access and deletes the stored tokens.
Limited Use.Vesma’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide the integration or as required by law, and we do not use it to train generalised AI models. Calendar data is not sent to our AI provider.
5.2 Google Ads
Customers may optionally connect a Google Ads account so that the Search campaigns they plan in Vesma can be created in their own Google Ads account instead of being copied across by hand. This integration is off by default and is never required to use Vesma.
When connected, Vesma requests only the following Google OAuth scopes:
| Scope | Why we request it |
|---|---|
.../auth/adwords | To list the Google Ads accounts the Customer can advertise from; to create the campaign, ad group, keywords and ads the Customer planned in Vesma, in the account they choose, in a paused state; and to read the performance of those campaigns so results can be shown next to the leads they produced. Google offers Google Ads access as this single scope. |
.../auth/datamanager | To report back to the Customer’s own Google Ads account that a click on their ad became a qualified enquiry, so Google can find more people like that buyer. The report carries the click identifier Google issued, the time, and the enquiry’s stated budget as a value. It never carries the person’s name, phone number or messages. |
Vesma never activates a campaign or changes a budget: everything it creates starts paused and the Customer switches it on in Google Ads. It does not modify campaigns the Customer created themselves and does not access billing. Google Ads tokens are stored encrypted at rest, are used solely for the actions above, and are deleted when the Customer disconnects from Marketing › Connections. Google Ads data is not sent to our AI provider. The Limited Use commitments above apply equally to Google Ads data.
6. AI processing & sub-processors
To deliver the service we share the minimum necessary data with the following sub-processors, under appropriate confidentiality and data-protection terms:
| Sub-processor | Purpose |
|---|---|
| Meta Platforms (WhatsApp Business Platform) | Sending/receiving WhatsApp messages |
| OpenAI | Generating AI replies and text embeddings from message/knowledge content |
| Razorpay | Subscription billing & payments (Customers only) |
| Resend | Transactional email (e.g. notifications) |
| Cloud hosting & object storage | Running the application, database, and document storage |
Message and document content sent to our AI provider is used only to produce responses for the Customer and is not used by us to train models.
7. Sharing & disclosure
We do not sell personal data. We disclose data only: to the relevant Customer (who controls their leads’ data); to the sub-processors above; where required by law or to protect rights and safety; and in connection with a business transfer, subject to this policy.
8. Data retention
We retain personal data for as long as a Customer’s account is active or as needed to provide the service, then delete or anonymise it within a reasonable period, unless a longer period is required by law. Customers can delete leads, conversations, and documents from the dashboard; see Data Deletion.
9. Security
We use industry-standard measures including encryption in transit (HTTPS), hashed passwords, encryption of stored third-party access tokens, access controls, and signature verification of inbound webhooks. No method of transmission or storage is fully secure, but we work to protect your data and review our practices regularly.
10. Your rights
Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023), you may request access to, correction of, or deletion of your personal data, and may withdraw consent. Leads should contact the business they messaged (the Customer) as the primary controller; you may also contact us and we will assist or route the request. To exercise rights, email [email protected].
11. Children
Vesma is a business tool not directed to children and is not intended for use by anyone under 18.
12. International transfers
Some sub-processors may process data outside India. Where that occurs, we take steps to ensure an appropriate level of protection for the data.
13. Changes
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.
14. Contact & grievances
For privacy questions or to raise a grievance under applicable Indian data-protection law, contact our Grievance Officer at [email protected]. We aim to acknowledge grievances within a reasonable period.