Legal · Updated 2026-08-16
Privacy Policy
This policy covers Veera at veeranow.com — the web application, the outbound calling, WhatsApp and email channels, and the public business directory. It applies both to customers who use Veera and to recipientsVeera contacts on a customer’s behalf.
Who is responsible for your data
Veera operates from Ahmedabad, Gujarat, India. Where a customer uses Veera to contact other people, that customer is the controller of the contact data they upload, and Veera acts as a processor on their instructions. For account, billing and usage data, Veera is the controller.
What we collect
From customers
- Account identity from Google or Apple sign-in — name, email, profile photo.
- Organisation and client workspace records, team membership and role.
- Contacts you upload or import, and any notes, tags or custom fields on them.
- Message, call and campaign records created when you use the outreach channels.
- Billing records — subscription, invoices, payment status. Card details never reach Veera; Razorpay handles them.
- Product analytics — which pages you visit and which features you use. This runs only if you accept analytics; see Analytics and advertising below.
From people Veera contacts
- The phone number, email address or WhatsApp number the customer supplied, and, on WhatsApp, the recipient’s WhatsApp profile name.
- Call transcripts, and the message content and any media (such as images or documents) exchanged during the conversation.
- Delivery, read, reply and opt-out status.
Veera does not buy contact lists and does not sell personal data to anyone.
How outbound contact is controlled
Three protections are enforced in code on every send path, not left to the customer’s discretion:
- Quiet hours.Calls and messages are blocked outside permitted local hours for the recipient’s jurisdiction.
- Suppression. Once someone opts out, unsubscribes, or is added to a do-not-contact list, every channel refuses to contact them again.
- Unsubscribe. Outbound email carries a working unsubscribe path, including the List-Unsubscribe header.
AI-placed calls identify themselves as AI-assisted at the start of the call, and disclose that the call is being transcribed.
Who else processes your data
Veera uses the following sub-processors. Each receives only what its function requires.
| Sub-processor | What it is used for |
|---|---|
| Google Firebase / Google Cloud | Authentication, Firestore database, Cloud Functions, hosting, push messaging |
| Meta (WhatsApp Business Platform) | Sending and receiving WhatsApp messages on your behalf |
| Twilio | Placing and receiving phone calls, caller-ID verification, and carrying call audio |
| Deepgram | Converting call speech to text — the default transcription provider |
| Sarvam AI | Converting call speech to text for Indic-language calls |
| Cartesia | Generating the AI voice heard on calls, and transcription when configured as the speech-to-text provider |
| ElevenLabs | Generating the AI voice heard on calls, and running the conversational voice agent |
| OpenAI | Generating the AI agent’s side of a live call — receives the running call transcript |
| Railway | Hosting the call-orchestration service — recipient call audio, live transcripts and contact numbers pass through it |
| Amazon SES / Smartlead | Sending outbound email on your behalf |
| Anthropic | AI drafting, classification and summarisation of your content |
| Razorpay | Payment collection and mandates for subscriptions |
| Google Analytics 4 | Product analytics. Loads only after you accept analytics cookies; Google advertising signals are denied unconditionally |
| Meta (Pixel — website advertising measurement) | Measuring visits to our public pages — the marketing site and the business directory — and building advertising audiences. Loads only after you accept advertising cookies, and never inside your account; Veera and Meta are joint controllers for this collection (GDPR Art. 26) |
WhatsApp and Meta
Veera sends and receives WhatsApp messages through Meta’s WhatsApp Business Platform (the Cloud API). When a message is sent to or received from someone on WhatsApp, Meta processes that person’s phone number, WhatsApp profile name, the message content and any media, and the delivery and read status, acting as a processor on the customer’s and Veera’s behalf. Meta’s own systems retain message content for up to 30 days for delivery, and phone-number identifiers for up to 30 days after the last status update, and then delete them. That is separate from any record Veera keeps in the customer’s workspace.
Recipients are contacted on WhatsApp only where the customer has a lawful basis to do so, including the recipient’s opt-in where it is required. Under our Terms of Use the customer is responsible for obtaining that consent, and every send path enforces quiet hours and honours opt-outs and the do-not-contact list. Meta’s own handling of WhatsApp data is governed by the WhatsApp Business Terms and the WhatsApp Privacy Policy.
Where data is stored and how it is protected
- Records are stored in Google Cloud Firestore, encrypted at rest.
- Every record is path-scoped to one organisation and client. Access is checked on the server against a verified identity claim on every request — never against a value supplied by the browser.
- All traffic uses HTTPS/TLS. Inbound webhooks are signature-verified.
- API keys and provider credentials live in Google Secret Manager, never in the database or in client code.
How long data is kept
Account and workspace data is kept while the account is active. You can delete individual contacts, conversations and call records at any time from the application, and deleting your organisation removes its data.
Veera does not publish a fixed retention window for every record type yet. Rather than state a duration that is not in force, this section will be updated with specific periods when they are set. If you need a defined retention period now, contact us and we will confirm it for your account in writing.
Your rights
Depending on where you live — for example under the EU/UK GDPR, the California CCPA/CPRA, or India’s Digital Personal Data Protection Act — you may have the right to access your data, correct it, delete it, restrict or object to processing, obtain a portable copy, and withdraw consent. To exercise any of these, email privacy@veeranow.com.
If Veera contacted you and you are not a customer: you can ask for your data to be erased at the same address, and you do not need an account to do it. Tell us the phone number or email address that was contacted. Erasure removes the contact record, its message and call history, and its transcripts.
Where a customer uploaded your data, we will also notify that customer of your request, as they are the controller of it.
Analytics and advertising
Veera asks before any analytics or advertising technology loads. Until you make a choice, no third-party script is requested at all — not Google’s, not Meta’s — and no cookie or identifier is set. This is prior blocking, not a banner that appears after the tracking has already started.
Analytics. If you accept analytics, Veera loads Google Analytics 4 to understand which pages and features get used. Google advertising signals are denied unconditionally — no ad storage, no ad user data, no ad personalisation — whatever else you accept.
Advertising. If you accept advertising, Veera loads the Meta Pixel from Meta Platforms Ireland Limited on public marketing pages, so we can measure and target our ads on Facebook and Instagram. For that collection Veera and Meta are joint controllers under Article 26 GDPR: we are responsible for the collection and for giving you this notice, Meta is responsible for what it does with the data afterwards, and Meta undertakes to answer access and erasure requests about pixel data within 7 days — you can raise those with either of us. Automatic advanced matching is switched off: Veera sends no email address, phone number or name to Meta. The pixel runs on our public pages — the marketing site and the business directory — and never inside your account: no page you reach after signing in loads it, so your workspace, your contacts and your conversations are never disclosed to Meta.
Because the Meta Pixel discloses your visit to Meta, accepting advertising is a “sale” or “sharing” of personal information as California defines those terms. If you refuse advertising, or if your browser sends a Global Privacy Control signal, no such sharing happens. Veera honours Global Privacy Control — it is our Do Not Sell or Share My Personal Information mechanism, and it keeps advertising off without your having to ask again. Do Not Track is honoured the same way.
Changing your mind. Withdrawing is as easy as accepting:
Withdrawing removes the advertising and analytics cookies from your browser and reloads the page, so the technology actually stops rather than merely going quiet.
What we keep. Your choice is stored in a first-party cookie for 180 days, recording which purposes you accepted, which version of this notice you saw, and the language it was shown in. Refusals are kept for the same period, precisely so you are not asked again on every visit. The record is deliberately anonymous — it does not identify you. You can also use an ad/analytics blocker, or email us at privacy@veeranow.com and we will confirm suppression for your account.
Children
Veera is for business use and is not directed at anyone under 18.
Changes
Material changes will be reflected here with a new date at the top of the page, and customers will be notified in the application before the change takes effect.
Contact
Privacy requests: privacy@veeranow.com. Everything else: hello@veeranow.com.
Governed by the laws of India. See also our Terms of Use.