Privacy Policy
Last updated 21 July 2026 · Vametrix (“we”, “us”) operates the Vametrix Autonomous GTM Cloud at vametrix.com.
1. Who we are
Vametrix provides AI sales and marketing software to business customers in India. Our customers (“Clients”) use Vametrix to communicate with their own leads and buyers. For data about those buyers, the Client is the data controller and Vametrix acts as the data processor.
2. What we collect
- Client account data — name, work email, company, role, and authentication credentials (passwords are hashed by our authentication provider; we never see them).
- End-buyer conversation data — WhatsApp phone number, display name, message content, and metadata, received via the Meta WhatsApp Business Platform when a buyer messages a Client's number.
- Business records — leads, deal stages, notes and amounts entered by the Client.
- Advertising metrics — aggregate campaign spend, impressions, clicks and lead counts from connected ad accounts. We do not receive ad-platform user profiles.
- Operational logs — request timestamps, error records and usage metering needed to run and bill the service.
3. How we use it
Solely to deliver the service: routing and answering messages on the Client's behalf, maintaining their CRM records, reporting performance, providing support, securing the platform, and billing. We do not sell personal data, and we do not use end-buyer conversation content to train third-party models.
4. Sub-processors
We rely on: Meta Platforms (WhatsApp Business Platform message delivery), Supabase (database and authentication, hosted in Mumbai, India), Vercel (application hosting), OpenRouter (language-model inference for generating replies), and Razorpay (payments). Each processes data only as needed to provide their part of the service.
5. Where data lives & how it is isolated
Data is stored in India (Mumbai region). Every record is tagged to a single Client organisation and every query is filtered by that organisation, with database row-level security policies as an additional control. Third-party credentials supplied by Clients are encrypted at rest (AES-256-GCM).
6. Retention and deletion
We retain Client data for as long as the account is active. A Client may request export or deletion of their organisation's data at any time by emailing us; we complete verified deletion requests within 30 days, after which data is removed from production systems. End-buyers may ask a Client to delete their records, or contact us directly.
7. Your rights
You may request access to, correction of, or deletion of your personal data, and may withdraw consent to marketing messages at any time. End-buyers can stop all automated messages instantly by replying STOP on WhatsApp — this is honoured permanently and automatically.
8. Security
Encryption in transit (TLS) and at rest, tenant isolation, signed webhooks, least-privilege access, and audit logging. No security is absolute; we notify affected Clients promptly of any breach that affects their data.
9. Children
Vametrix is a business tool and is not directed at anyone under 18.
10. Changes
We will post any change on this page and update the date above. Material changes are communicated to Clients by email.
11. Contact
Questions, access requests or deletion requests: operations.vamshi@gmail.com.