Privacy Policy
This Privacy Policy explains how Crosvia ("Crosvia", "we", "us", "our") collects, uses, shares, and protects information in connection with the Crosvia customer-relationship-management platform, websites, and related services (together, the "Service"). By using the Service you agree to the practices described here.
1. Our role: controller and processor
Crosvia is a multi-tenant platform that businesses ("Customers") use to capture and manage their own leads and customer relationships. Where Crosvia processes lead, contact, and conversation data on behalf of a Customer, the Customer is the data controller and Crosvia acts as a data processor under that Customer's instructions and their own privacy policy. Where Crosvia collects information directly for its own purposes — for example, registering a Customer account or operating the Service — Crosvia acts as the controller.
2. Information we collect
- Account information. Name, work email, password (stored hashed), workspace/brand name, and role of the people who use Crosvia on behalf of a Customer.
- Lead and contact data. Information our Customers capture about their prospects and customers — such as name, phone number, email, enquiry details, notes, documents, and pipeline status — submitted to Crosvia by the Customer or collected through connected sources the Customer authorizes.
- Integration data. When a Customer connects a third-party account (such as Meta or WhatsApp), we receive only the data needed to provide the requested feature — for example lead-form submissions, message content, conversion events, and the identifiers and access tokens for the Customer's own connected assets.
- Usage and technical data. Log data, device and browser information, IP address, and product activity used to operate, secure, and improve the Service.
3. Meta and WhatsApp data
Crosvia integrates with Meta technologies, including the WhatsApp Business Platform, the Meta Lead Ads / Lead Retrieval features, and the Meta Conversions API. When a Customer connects their own Meta business assets:
- We retrieve lead-form submissions from the Customer's connected Pages/ad accounts and deliver them into that Customer's workspace.
- We send and receive WhatsApp messages through the Customer's own WhatsApp Business number and store those conversations against the relevant lead.
- We send server-side conversion events to the Customer's own pixel/dataset via the Conversions API so the Customer's campaigns can be measured and optimized.
We use Meta and WhatsApp data only to provide these features to the Customer who connected the assets. We do not sell this data, do not use it for advertising of our own, and handle it in accordance with the Meta Platform Terms, the WhatsApp Business Messaging Policy, and applicable Meta Developer Policies. Access tokens for connected assets are stored encrypted and are isolated per Customer workspace.
4. How we use information
- To provide, maintain, secure, and improve the Service.
- To deliver the features a Customer enables, including lead capture, follow-ups, messaging, analytics, and conversion reporting.
- To authenticate users, prevent abuse, and enforce our Terms.
- To communicate with Customer account users about the Service.
- To comply with legal obligations.
5. How we share information
We do not sell personal information. We share information only as follows:
- With the Customer who owns the relevant workspace and the users they authorize.
- With service providers (subprocessors) who host and operate the Service on our behalf — for example our cloud infrastructure and database providers — under contractual confidentiality and security obligations.
- With the third-party platforms a Customer connects (such as Meta/WhatsApp), to deliver the requested integration.
- For legal reasons, where required by law or to protect rights, safety, and the integrity of the Service.
- In a business transfer, subject to continued protection of the information.
6. Data retention
We retain Customer and lead data for as long as the Customer's account is active or as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce agreements. Customers can delete data within the Service, and may request deletion as described below.
7. Security
We protect information with administrative, technical, and organizational measures, including encryption in transit and at rest, role-based access controls, per-workspace tenant isolation, and encrypted storage of third-party credentials. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any incident.
8. Data location
The Service is hosted on cloud infrastructure located in India. Where information is processed in other locations by our subprocessors or connected platforms, we take steps to ensure appropriate safeguards apply.
9. Your rights and choices
Depending on your location and your relationship with Crosvia, you may have rights to access, correct, export, restrict, or delete personal information. If you are an end user (a lead) whose data sits in a Customer's workspace, please contact that Customer (the controller) directly; we will support them in fulfilling your request. You can also contact us at [email protected] and we will route your request appropriately.
10. Data deletion
You can request deletion of your data at any time. See our Data Deletion instructions for how to do this, or email [email protected].
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children. If you believe a child's information has been provided to us, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the "Last updated" date. Material changes will be communicated through the Service or by email where appropriate.
13. Contact us
Questions about this policy or our data practices? Email [email protected].