Legal

Privacy Policy

Last updated: 2 August 2026

1. Overview

VritantAI ("we", "our", "us") is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights. It applies to visitors to vritantai.com and to customers who use the VritantAI platform.

2. Data We Collect

We collect: (a) Account data: name, email address, company name, store URL; (b) Billing data: processed by Paddle as Merchant of Record; we do not store payment card numbers; (c) Product catalog data: product titles, descriptions, prices, and availability you sync from your store; (d) Usage data: API calls, page views, feature interactions, error logs; (e) Communication data: support tickets, emails, and in-app messages; (f) Agent conversation data: messages exchanged in your storefront widget or WhatsApp channel.

3. How We Use Your Data

We use your data to: (a) Provide and improve the Service, including running GEO audits, citation benchmarks, hallucination sweeps, and powering the shopping agent; (b) Process billing and send invoices; (c) Send product updates, security notices, and support responses; (d) Detect and prevent fraud or abuse; (e) Comply with legal obligations. We do not use your catalog data or conversation data to train AI models. We do not sell your data.

4. Third-Party Services

We use the subprocessors below to deliver the platform. Each entry names what the provider does for us and the categories of data it handles, grouped by the role it plays.

AI inference

  • DeepSeek: Primary LLM inference for the shopping agent's routing, response, and verification steps where the tenant's region permits it. Tenants in a restricted region are served by the other inference vendors in this category instead, so a residency requirement is met by routing rather than by exception.Data: Query text and relevant catalog context sent per-request; no persistent identifiers.
  • Anthropic: LLM inference for the shopping agent and GEO hallucination sweeps.Data: Query text and relevant catalog context sent per-request; no persistent identifiers.
  • OpenAI: Fallback LLM inference and embedding generation for catalog retrieval.Data: Query text, catalog context, and product content sent for embedding; no persistent identifiers.
  • Google (Gemini): Fallback LLM inference and GEO citation benchmarking.Data: Query text and relevant catalog context sent per-request; no persistent identifiers.
  • Cohere: Cross-encoder re-ranking of catalog search results, so the products shown to a shopper are ordered by relevance to the question actually asked.Data: Query text and the text of candidate catalog documents sent per-request; no persistent identifiers.

Infrastructure

  • Supabase: PostgreSQL database hosting with row-level security enforced per tenant.Data: All persisted platform data: account, catalog, conversation, and billing records.
  • Redis: Managed Redis hosting for the background job queue and for short-lived caching of rate limits and session state.Data: Queue payloads and cache entries; short-lived, not a system of record.

Payments

  • Paddle: Merchant of Record for subscription billing and invoicing.Data: Billing contact details and subscription state; payment card data is held by Paddle, never by VritantAI.
  • Razorpay: Payment link generation and reconciliation for native-checkout orders.Data: Order amount, currency, and payment status; card data is held by Razorpay, never by VritantAI.

Messaging

  • Meta (WhatsApp Business Platform): Sending and receiving WhatsApp messages on a tenant's behalf via the Embedded Signup OAuth flow.Data: WhatsApp Business Account ID, phone number ID, and an encrypted access token; message content in transit.

Observability

  • Sentry: Error monitoring across the API, workers, and dashboard.Data: Stack traces and request metadata; scrubbed of known-sensitive fields before capture.
  • PostHog: Product analytics for the widget and dashboard.Data: Anonymised usage events; not used for advertising or cross-site tracking.

The same vendor list, with the same data categories, is published on our Trust Center.

Each provider is bound by data processing agreements appropriate to their role. We do not share your data with advertising networks.

5. WhatsApp and Meta Data

When you connect WhatsApp Business to VritantAI using Meta Embedded Signup, we access the following data via OAuth: your WhatsApp Business Account ID, phone number ID, and a long-lived access token. The access token is encrypted at rest using AES-256-GCM before storage. The plaintext token is never persisted. We use this data solely to send and receive messages on your behalf via the WhatsApp Business API. We do not access your personal Facebook profile, ad accounts, or any Meta data beyond what is required to operate the WhatsApp channel. You can revoke access at any time by clicking Disconnect in Settings → Integrations → WhatsApp, or by removing VritantAI from your WhatsApp Business Account in Meta Business Manager. Upon disconnection, your access token is deleted from our systems. If you request deletion of your data, we will also notify Meta as required under Meta Platform Terms.

6. Multi-Tenant Data Isolation

All customer data is isolated using PostgreSQL Row-Level Security (RLS) scoped to each tenant's unique ID. No query issued by VritantAI's application layer can return data across tenant boundaries. Tenant IDs are never exposed to other tenants. Staff access to production data requires MFA and is logged.

7. Data Retention

We retain account data for the duration of your subscription plus 90 days, after which it is deleted. Conversation logs are retained for 12 months by default; you can configure a shorter retention window in your account settings. Audit history is retained for 24 months. Hallucination event logs are retained for 12 months.

8. Your Rights

Depending on your jurisdiction, you may have the right to: access your personal data; correct inaccurate data; delete your account and associated data; export your data in a machine-readable format; restrict or object to certain processing; lodge a complaint with a supervisory authority. To exercise any of these rights, email business@vritantai.com. We will respond within 30 days.

9. Cookies

We use strictly necessary cookies for session management and authentication. We use analytics cookies (PostHog) to understand how the product is used, these are anonymised and do not track you across other websites. We do not use advertising or tracking cookies. You can opt out of analytics cookies in your account settings.

10. Security

We employ commercially reasonable security measures including: encryption of data at rest and in transit; API key storage using one-way hashing (plaintext shown only once at creation); HMAC verification of all inbound webhooks; MFA for staff access to production systems; quarterly security reviews. No system is perfectly secure; please contact business@vritantai.com immediately if you discover a vulnerability.

11. International Data Transfers

VritantAI is headquartered in Bengaluru, India. Your data may be processed in data centres operated by our third-party providers in the United States, European Union, and other regions. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to ensure adequate protection for international data transfers.

12. Children's Privacy

The Service is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact business@vritantai.com and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

14. Contact

For privacy enquiries: business@vritantai.com. For data deletion requests: business@vritantai.com with subject "Data Deletion Request". Postal address: VritantAI, Bengaluru, Karnataka, India.