Vesma
FeaturesPricingSolutionsResourcesIntegrationsContact
Log inStart free

Privacy Policy

Last updated: 5 September 2026

This Privacy Policy explains how Vesma(“Vesma”, “we”, “us”) collects, uses, discloses, and safeguards personal data. Vesma is an AI sales assistant that helps businesses (our “Customers”) respond to, qualify, and follow up with their leads over messaging channels such as WhatsApp.

Vesma is operated as a sole proprietorship based in India. We act as a data processor on behalf of our Customers for the lead/end-customer data they process through Vesma, and as a data controllerfor our Customers’ own account data.

1. Who this policy covers

  • Customers — businesses and their team members who hold a Vesma account.
  • Leads / end-customers — individuals who message a Customer’s connected WhatsApp number or submit an enquiry, whose messages Vesma helps the Customer handle.
  • Visitors — people who browse our website.

2. Data we collect

From Customers

  • Account details: name, work email, password (hashed), business name, role, and workspace settings.
  • Business content: knowledge-base documents you upload (e.g. brochures, price lists, FAQs) used to ground AI replies.
  • Billing details processed by our payment provider (we do not store full card numbers).

From leads / end-customers (via WhatsApp & web forms)

  • WhatsApp profile name and phone number.
  • Message content and conversation history exchanged with the Customer’s number.
  • Information you choose to share in conversation (e.g. budget, location, requirements) used to qualify and route the enquiry.

Automatically

  • Usage and device data (e.g. log data, IP address, browser type) and cookies needed to operate and secure the service.
  • On our public marketing pages only, the Meta Pixel, which tells Meta that a browser visited vesma.app so we can measure our advertising and show ads to people who have visited. It does not run inside the Vesma application, and it does not run on Customer microsites, so visitors to a Customer’s site are never collected by it.

3. How we use data

  • To generate and send timely replies, qualify and score leads, schedule appointments, and send follow-ups on behalf of the Customer.
  • To retrieve relevant answers from the Customer’s uploaded knowledge base (using text embeddings).
  • To provide the dashboard, CRM, analytics, and notifications.
  • To operate, secure, debug, and improve the service, and to comply with legal obligations.

4. WhatsApp Business Platform

Vesma integrates with the WhatsApp Business Platformprovided by Meta. When a lead messages a Customer’s connected number, Meta delivers that message to Vesma so the Customer can respond. Our use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, and our processing of WhatsApp data is also governed by the WhatsApp Business Messaging Policy. We do not use WhatsApp message content for advertising and do not sell it.

5. Google integrations & Google user data

5.1 Google Calendar

Customers may optionally connect a Google Calendar account so that appointments booked in Vesma appear on the calendar their team already uses. This integration is off by default and is never required to use Vesma.

When connected, Vesma requests only the following Google OAuth scopes:

ScopeWhy we request it
.../auth/calendar.eventsTo create an event when an appointment is booked, move it when the appointment is rescheduled, and remove it when the appointment is cancelled.
.../auth/calendar.events.freebusyTo check whether the Customer is already busy at a proposed time, so the AI does not double-book them.

Vesma only creates and manages the appointment events it books on the Customer’s behalf. It does not read the contents of other calendar events; availability is checked as busy/free time only. Google access and refresh tokens are stored encrypted at rest and are used solely to perform the actions above. A Customer can disconnect at any time from Settings, which revokes Vesma’s access and deletes the stored tokens.

Limited Use.Vesma’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide the integration or as required by law, and we do not use it to train generalised AI models. Calendar data is not sent to our AI provider.

5.2 Google Ads

Customers may optionally connect a Google Ads account so that the Search campaigns they plan in Vesma can be created in their own Google Ads account instead of being copied across by hand. This integration is off by default and is never required to use Vesma.

When connected, Vesma requests only the following Google OAuth scopes:

ScopeWhy we request it
.../auth/adwordsTo list the Google Ads accounts the Customer can advertise from; to create the campaign, ad group, keywords and ads the Customer planned in Vesma, in the account they choose, in a paused state; and to read the performance of those campaigns so results can be shown next to the leads they produced. Google offers Google Ads access as this single scope.
.../auth/datamanagerTo report back to the Customer’s own Google Ads account that a click on their ad became a qualified enquiry, so Google can find more people like that buyer. The report carries the click identifier Google issued, the time, and the enquiry’s stated budget as a value. It never carries the person’s name, phone number or messages.

Vesma never activates a campaign or changes a budget: everything it creates starts paused and the Customer switches it on in Google Ads. It does not modify campaigns the Customer created themselves and does not access billing. Google Ads tokens are stored encrypted at rest, are used solely for the actions above, and are deleted when the Customer disconnects from Marketing › Connections. Google Ads data is not sent to our AI provider. The Limited Use commitments above apply equally to Google Ads data.

6. AI processing & sub-processors

To deliver the service we share the minimum necessary data with the following sub-processors, under appropriate confidentiality and data-protection terms:

Sub-processorPurpose
Meta Platforms (WhatsApp Business Platform)Sending/receiving WhatsApp messages
OpenAIGenerating AI replies and text embeddings from message/knowledge content
RazorpaySubscription billing & payments (Customers only)
ResendTransactional email (e.g. notifications)
Cloud hosting & object storageRunning the application, database, and document storage

Message and document content sent to our AI provider is used only to produce responses for the Customer and is not used by us to train models.

7. Sharing & disclosure

We do not sell personal data. We disclose data only: to the relevant Customer (who controls their leads’ data); to the sub-processors above; where required by law or to protect rights and safety; and in connection with a business transfer, subject to this policy.

8. Data retention

We retain personal data for as long as a Customer’s account is active or as needed to provide the service, then delete or anonymise it within a reasonable period, unless a longer period is required by law. Customers can delete leads, conversations, and documents from the dashboard; see Data Deletion.

9. Security

We use industry-standard measures including encryption in transit (HTTPS), hashed passwords, encryption of stored third-party access tokens, access controls, and signature verification of inbound webhooks. No method of transmission or storage is fully secure, but we work to protect your data and review our practices regularly.

10. Your rights

Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023), you may request access to, correction of, or deletion of your personal data, and may withdraw consent. Leads should contact the business they messaged (the Customer) as the primary controller; you may also contact us and we will assist or route the request. To exercise rights, email [email protected].

11. Children

Vesma is a business tool not directed to children and is not intended for use by anyone under 18.

12. International transfers

Some sub-processors may process data outside India. Where that occurs, we take steps to ensure an appropriate level of protection for the data.

13. Changes

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.

14. Contact & grievances

For privacy questions or to raise a grievance under applicable Indian data-protection law, contact our Grievance Officer at [email protected]. We aim to acknowledge grievances within a reasonable period.

Vesma

The ad-to-appointment platform for real-estate marketing: qualifies every WhatsApp lead, books the visit, and tells Meta and Google which leads were real.

PRODUCT
HomeFeaturesPricingSolutionsIntegrationsResourcesCompare
COMPANY
ContactPartners & agencies
LEGAL
PrivacyTermsData deletionRERA compliance
© 2026 Vesma[email protected]