Privacy Policy
Quick Navigation
1. Two Different Roles — Please Read This First
Converso handles two distinct categories of personal data, and our responsibilities differ for each. Understanding which one applies to you determines who you should contact about your data.
1.1 Account Data
If you sign up for Converso as a business owner, manager or staff member, we decide how your account information is handled. For that data we act as the Data Fiduciary (equivalent to a "controller"), and this Policy governs it directly. Your rights under Section 7 are exercised against us.
1.2 Lead & Customer Data
Converso is a tool that businesses use to store information about their own customers and enquiries ("Leads"). The business that subscribes to Converso decides what Lead information to collect, why, and for how long. That business is the Data Fiduciary for the Lead data; Converso is only a Data Processor acting on its instructions.
2. Personal Data We Collect
2.1 Account and Identity Data (We are the Fiduciary)
| Data Category | Why We Hold It |
|---|---|
| Email address | Account identity, sign-in one-time passcodes, service notifications |
| Mobile number | Optional sign-in, phone verification |
| Name | Display within your team, attribution of activity |
| Business details | Business name, time zone, working-hour settings for reminder scheduling |
| Role & permissions | Owner, manager, or staff access control within your business |
| Auth & sessions | Authentication tokens and session records to keep you signed in & allow session revocation |
| Push tokens | Device push tokens and notification preferences for mobile push alerts |
2.2 Lead Data (We are a Processor)
Businesses using Converso may store the following about their enquiries: name, phone number, email address, service interest, location, lead source and source detail, stage and quality rating, deal value, follow-up schedule, notes and activity history, uploaded attachments, and — where the business has connected WhatsApp — conversation history, message content and media.
We also record consent metadata on each Lead: consent status, the time consent was given or withdrawn, the notice text shown at the time, and the IP address from which the enquiry was submitted. This exists so the business can demonstrate lawful collection under the DPDP Act.
2.3 WhatsApp Data
- We receive and store messages that customers send to a connected WhatsApp Business number, including text, images, documents, audio, video, stickers, shared locations and contact cards.
- We store customer WhatsApp phone numbers and public WhatsApp profile names.
- We store delivery receipts (sent, delivered, read, failed) for messages sent by the business.
- Media files are fetched from Meta and cached in our storage when a user first opens them (because Meta deletes media from its servers after approximately 30 days).
- WhatsApp access credentials are stored encrypted at rest using AES-256-GCM.
- WhatsApp messaging is subject to Meta's own privacy terms as the underlying platform operator.
2.4 Technical and Operational Data
- Error & Diagnostic reports: captured when something fails so we can diagnose faults.
- Server logs: recording API requests, IP addresses, and timestamps for security and abuse prevention.
- Billing records: subscription status, plan, invoices, and payment reference identifiers. We do not store card numbers, CVVs, UPI PINs or bank credentials. Payments are handled entirely by Razorpay (Section 5).
2.5 What We Do NOT Do
3. How We Use Personal Data
We process personal data for the following specific operational purposes:
- Create and operate your account and authenticate you.
- Provide core CRM functionality — capturing, assigning, tracking and reporting on leads.
- Send operational notifications: follow-up reminders, missed follow-up alerts, daily summaries and team invitations.
- Deliver and receive WhatsApp messages on behalf of a connected business.
- Import leads from connected sources you authorise, such as Meta Lead Ads, website forms and Google Sheets.
- Process subscription payments and maintain billing records.
- Maintain security, detect abuse, and diagnose faults.
- Comply with legal obligations and enforce our terms.
4. Notifications and Communications
We send service emails and push notifications that are necessary to operate the Service — sign-in codes, follow-up reminders, alerts and billing notices. These cannot be fully disabled while your account is active, though push notifications can be turned off on each device and reminder timing can be configured.
Reminder and alert emails respect configured quiet hours and are not sent overnight.
If we ever send product or marketing email, it will carry an unsubscribe link and opting out will not affect your use of the Service.
5. Sub-processors and Third Parties
We rely on the following providers. Each processes data only to deliver its specific function, and we remain accountable for account data throughout.
| Provider | Function | Data Involved |
|---|---|---|
| Supabase | Managed PostgreSQL database and file storage | All application data and uploaded attachments |
| Amazon Web Services | Application hosting (Lambda, API Gateway), secrets management — region ap-south-1, Mumbai | All application data in transit and at rest |
| Meta Platforms | WhatsApp Cloud API; Meta Lead Ads import | WhatsApp messages and media; lead form submissions |
| Firebase Cloud Messaging for push; Google Sheets API for optional lead sync | Device tokens, notification content; synced lead rows | |
| Razorpay | Payment processing and subscription billing | Billing contact details and payment data (card details go directly to Razorpay) |
| Sentry | Error monitoring | Diagnostic context in failing requests |
| AWS SES | Transactional email delivery | Recipient email address and message content |
Our primary infrastructure is located in India (AWS ap-south-1, Mumbai). Some providers listed above operate globally and may process data outside India. Where that happens we rely on contractual safeguards, and transfers are made only to countries not restricted by the Government of India under Section 16 of the DPDP Act.
We may also disclose personal data where legally required — to comply with a valid legal order, enforce our terms, or protect rights and safety. In a business merger or asset sale, data may be transferred with prior notice.
6. Retention and Deletion
6.1 Lead Data
Each business configures its own retention period, which defaults to 365 days. Businesses may erase individual Leads at any time. When a Lead is erased on request, we retain a non-identifying proof-of-erasure record — a hashed reference, the business ID, timestamp and reason — so the business can demonstrate DPDP Act compliance. This record contains no personal data.
6.2 Account Deletion
You may request deletion of your account from within the application or via our web portal. When you submit a request:
- Deletion is scheduled 30 days in the future, not performed immediately.
- During those 30 days nothing is destroyed, and signing in again cancels the request.
- Businesses you solely own are deactivated during the window so scheduled emails stop.
- After 30 days a background process permanently deletes your profile, solely-owned businesses, and all associated leads, conversations, messages, attachments, memberships and invitations. This cascade is irreversible.
Settings -> Profile -> Delete Account) or visit our dedicated web page.6.3 Other Retention
- Sign-in OTPs and refresh tokens expire automatically.
- Billing and transaction records are retained as required by Indian tax law, typically eight years.
- Server diagnostic logs are retained for a limited operational period and then purged.
7. Your Rights Under the DPDP Act
Under the Digital Personal Data Protection Act, 2023, as a Data Principal whose account data we hold as Data Fiduciary, you have the right to:
Converso also provides subscribing businesses with tools to export data and execute erasure requests from their own customers. We respond to verified requests within prescribed DPDP Act timelines.
8. Security Safeguards
We enforce strict enterprise security controls to safeguard all personal data:
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the DPDP Act and its rules.
9. Children's Data
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data of any individual under 18 years of age. Businesses using Converso must not enter data about children without verifiable parental consent as required by Section 9 of the DPDP Act. If we learn that we hold a child's data without such consent, we will delete it immediately.
10. Obligations for Subscribing Businesses
If you use Converso to store data about other people, you are the Data Fiduciary for that data. You are responsible for:
- Giving your customers a clear notice and obtaining valid consent before entering their details.
- Publishing your own privacy policy (Converso provides a settings field to record your policy URL).
- Designating a contact for privacy queries (Converso provides fields for DPO name and contact email).
- Responding to access, correction and erasure requests from your customers.
- Using WhatsApp messaging only with recipients who have opted in, adhering to Meta's WhatsApp Business Messaging Policy.
- Setting a lead retention period appropriate to your specific business purpose.
11. Changes to This Policy
We may update this Policy as the Service changes or legal regulations evolve. The "Last updated" date at the top of this document will be updated accordingly. For material changes, we will provide advance notice through the Service or by email before changes take effect. Continued use after the effective date constitutes acceptance of the revised Privacy Policy.
12. Contact and Grievance Redressal
For any privacy questions, rights requests, or complaints regarding personal data processing:
⏱️ We aim to acknowledge every grievance within 72 hours and resolve it within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.