Privacy Policy

Last updated: July 29, 2026

1. Introduction

Sales Stratix ("we", "us", "our") provides a multi-channel marketing and customer relationship management platform for small and medium businesses in India. This Privacy Policy explains what personal data we collect, how we use it, and the choices you have. This policy applies to the Sales Stratix web application, our backend services, and any related communications.

We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India. Where our customers operate outside India, we apply equivalent protections drawing from the EU General Data Protection Regulation (GDPR).

2. Who we serve and what we are

Sales Stratix is a business-to-business platform. Our customers are registered retail and consumer-facing businesses of any category — for example apparel and boutiques, jewellery, footwear, electronics, furniture and home, supermarkets and grocery, pharmacy, automotive, and service businesses — that use Sales Stratix to manage their own end-customer relationships, sales teams and marketing campaigns. We are a data processor for the business data our customers upload (their customer records, transactions, employee and performance records, campaign performance, etc.) and a data controller for the limited data we collect about the business owner directly (their login email, profile, billing).

3. Information we collect

From the business owner (you, our customer)

  • Account data: name, email address, phone number, business name, business address.
  • Billing data: payment method details (card last 4 digits, UPI handle), invoice history. Payment processing is handled by Razorpay; full card numbers are never stored on our servers.
  • Usage data: pages visited inside the Sales Stratix dashboard, features used, API calls made, timestamps of activity. Used to improve the product and provide support.
  • Communications: emails, support tickets, and chat messages between you and our support team.

From your end-customers (the people you market to)

When you upload your customer records, lead lists, or transaction history to Sales Stratix, we receive that data on your behalf. This may include: names, phone numbers, email addresses, transaction amounts, purchase history, custom fields you define, and message engagement data (delivered, read, clicked, replied). You are the data controller for this information; we process it strictly under your instructions.

About your employees (your sales team)

Sales Stratix includes team, performance and incentive features, so when you add staff to your workspace we process data about them on your behalf. This may include: name, email address, phone number, employee ID, designation, role and team assignment, login activity, and work performance records — sales and lead activity attributed to them, customer interactions logged, targets, achievement against those targets, incentive and performance-pay calculations, customer feedback ratings, and (where you use it) attrition records.

You are the data controller for your employees' data and are responsible for informing them that you use Sales Stratix to manage performance and incentives, and for having a lawful basis to do so. We process it strictly under your instructions and do not use it for any purpose of our own.

From integrated third-party platforms

  • Meta WhatsApp Business Platform: when you connect WhatsApp via our Embedded Signup, Meta returns a WhatsApp Business Account ID and phone number ID. We store these to route messages and approvals correctly.
  • Email providers (Resend, SendGrid, Postmark, Mailgun, AWS SES): API keys you bring to connect your email sending. We store these encrypted and never display them in plaintext.
  • AiSensy (legacy): for customers who connect WhatsApp via AiSensy instead of Meta direct, their AiSensy API key is stored encrypted.
  • Google Firebase Cloud Messaging (push notifications): if you or your team enable notifications in our mobile app, your device registers a push token with Google. We store that token to send you app notifications (for example a new lead assigned to you, or a task reminder). The token identifies a device, not a person, and you can turn notifications off at any time from your device or app settings — doing so stops all push delivery.
  • ERP, accounting and billing software (Tally, Zoho Books, QuickBooks, Xero, Vyapar, or a custom REST endpoint): if you connect one, we import the sales and customer records it holds — typically invoice/transaction amounts, dates, line items, customer name and contact details, and the sales representative recorded against each sale. This data is processed exactly like records you upload manually. Connection credentials and API keys are stored encrypted; disconnecting the integration stops all further syncing.

4. How we use your information

  • To provide the Sales Stratix service — letting you generate templates with AI, send campaigns, manage customers and leads, manage your sales team, and view analytics, targets and incentive calculations.
  • To process payments and issue invoices, via Razorpay.
  • To send service emails (account verification, billing receipts, password resets, security alerts). These are not marketing emails; you cannot opt out of them while you have an active account.
  • To improve the product through aggregated usage analytics.
  • To provide customer support when you contact us.
  • To comply with legal obligations (tax records, lawful requests from authorities).

5. Third parties we share data with

We share data only with the providers necessary to operate the service. Each is bound by a written data processing agreement.

  • Supabase — database, authentication, file storage. Hosted in AWS Mumbai region (ap-south-1) for Indian data residency.
  • AI model providers — Anthropic (Claude), OpenAI, Google (Gemini) and xAI (Grok) — AI generation of message content, campaign drafts, images and analytics summaries. Your campaign goals and brand context are sent to whichever provider serves that feature; results are returned and stored in your workspace. We use these providers under their business/API terms, which do not permit training on customer data submitted through the API. We do not send your end-customer contact lists to these providers — only the campaign brief and brand context needed to generate content.
  • Meta (Facebook) WhatsApp Business Platform — for WhatsApp message delivery and template approvals.
  • Resend / SendGrid / Postmark / Mailgun / AWS SES — email delivery (whichever you choose to connect).
  • MSG91 — for India DLT-compliant SMS delivery (when you connect SMS).
  • Razorpay — payment processing for Sales Stratix subscription fees.
  • AiSensy — for customers using AiSensy as their WhatsApp BSP (legacy path).

We do not sell personal data. We do not share data with advertisers. We do not use end-customer data uploaded by our business customers for any purpose other than executing the service those businesses request.

6. WhatsApp data — special considerations

When you connect WhatsApp to Sales Stratix via Meta's Embedded Signup, we obtain a long-lived access token that lets us call Meta's Cloud API on your behalf. This token is stored encrypted in our database and used only to: (a) submit message templates you create to Meta for review, (b) send messages you have composed to recipients you have selected, and (c) receive delivery, read, and inbound-message webhooks from Meta.

We comply with Meta's WhatsApp Business Solution Provider terms. Inbound messages received via WhatsApp are processed solely to update delivery status and to honour STOP / opt-out requests from recipients. We do not read inbound message content for any other purpose.

Disconnecting WhatsApp in Sales Stratix immediately revokes the stored token; we no longer use it after that point. If you delete your Sales Stratix workspace, the token is also deleted.

7. Cookies and local storage

We use only what the Service needs to function. We do not use advertising cookies, and we do not allow third-party advertising or cross-site tracking networks on our application.

  • Authentication and session. When you sign in, your browser stores a session token (via cookies and/or browser local storage, managed by Supabase Auth). This is what keeps you signed in between pages. Clearing it signs you out. The Service cannot work without it.
  • Preferences. We store small items locally in your browser to remember your choices — for example saved Ask AI queries and interface preferences. These stay on your device and are not personal data we collect centrally.
  • Mobile app storage. Our mobile app caches static files (scripts, styles, images) on your device so it loads quickly and works on a poor connection. It does not cache authenticated data responses on the device.
  • Security. We process IP address and browser user-agent for security purposes — rate limiting and abuse prevention.
  • Record of agreement. When you create an account we record that you accepted these documents, which version you were shown, and the date, IP address and browser you accepted from. This is kept as proof that the contract was formed, not for security or marketing, and is retained for as long as it may be needed to evidence the agreement — including after account closure.

You can clear or block cookies and local storage in your browser settings. Blocking the authentication session will prevent you from signing in. We do not currently respond to browser “Do Not Track” signals, as there is no consistent standard for them.

8. Data retention

  • Account data: retained for the duration of your subscription plus 90 days after termination, then deleted.
  • Record of your agreement to these Terms and this Policy (version, date, IP, browser): retained beyond account deletion, for as long as a claim relating to the agreement could still be brought. This is a deliberate exception to the deletion rules above — it is the evidence that the contract existed, and deleting it would defeat its purpose.
  • Billing records: retained for 7 years to comply with Indian tax law.
  • End-customer data you upload: retained for as long as your workspace exists; deleted immediately when you delete the workspace or remove specific records.
  • Employee and performance data: retained for as long as your workspace exists. Deactivating an employee retains their historical performance and incentive records for your own payroll and audit purposes; deleting the workspace deletes them.
  • Campaign history and message logs: retained for 18 months, then automatically purged.
  • Backups: retained for 30 days for disaster recovery; encrypted at rest.

9. Your rights

You have the following rights regarding your personal data:

  • Access: request a copy of personal data we hold about you.
  • Correction: ask us to correct inaccurate data.
  • Erasure: ask us to delete your data, subject to legal retention requirements.
  • Portability: receive your data in a machine-readable format. Parts of the Service offer a direct CSV download; for anything not yet available as a self-serve download, email us and we will provide it (normally CSV) within 30 days, at no charge.
  • Withdrawal of consent: withdraw consent at any time for processing that relies on consent.
  • Complaint: file a complaint with the Data Protection Board of India if you believe we have mishandled your data.

To exercise any of these rights, email customersupport@salesstratix.com. We respond within 30 days.

10. Security

We use industry-standard security practices. In particular:

  • Encryption in transit. The entire application is served over HTTPS/TLS. We do not serve any page or API endpoint over plain HTTP.
  • Encryption at rest. Sensitive credentials — such as the API keys and access tokens you supply to connect WhatsApp, email, SMS or ERP systems — are encrypted before they are stored, and are never displayed back to you in plaintext.
  • Password security. We never store your password. Authentication is handled by Supabase Auth, which stores only a salted one-way hash. Neither we nor our staff can read or recover your password; a forgotten password can only be reset, not retrieved.
  • Email-verified sign-in and password reset. Account access is tied to a verified email address. Password resets and sign-in links are sent to that address as single-use, time-limited links.
  • Tenant isolation. We run on Supabase (PostgreSQL) with row-level security on every multi-tenant table, so one customer's data cannot be reached by another customer.
  • Role-based access. Inside your workspace, what each person can see and do is governed by their assigned role (owner, admin, manager, member, cashier). Internally we apply least-privilege access for our own staff.
  • Session and device security. Sessions are token-based and expire; you can sign out of a session at any time. Our mobile app does not cache authenticated API responses on the device, so signing in as a different user on a shared phone cannot surface the previous user's data.

No system is perfectly secure. In the unlikely event of a data breach affecting your personal data, we will notify you and the Data Protection Board of India within 72 hours of becoming aware of it.

11. International transfers

We primarily store and process data within India (Supabase Mumbai region). Some of our third-party providers (Anthropic, OpenAI, Google, xAI, Meta, Resend) are based outside India. When data is transferred to those providers, we rely on appropriate safeguards including the provider's standard contractual clauses and their own equivalent data protection commitments.

12. Children's privacy

Sales Stratix is not intended for use by children under 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify active customers by email at least 30 days before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.

14. Contact us and grievance redressal

For any privacy question, data access request, correction, erasure request, or complaint, contact our Grievance Officer:

Grievance Officer — Sales Stratix Private Limited
Email: customersupport@salesstratix.com
Postal: at the registered office address below, marked for the attention of the Grievance Officer.

How we handle complaints. We acknowledge every grievance within 72 hours of receipt and resolve it within 30 days. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.

If you are an employee of one of our business customers and your question concerns how your employer uses your performance or incentive data, please raise it with your employer first — they are the data controller for that information. We will support them in responding, and you may still contact us if they do not.

Sales Stratix is operated by Sales Stratix Private Limited, a company incorporated on 25 July 2026 under the Companies Act, 2013 with the Ministry of Corporate Affairs (India).

Corporate Identity Number (CIN): U63990KL2026PTC105017
Registered office: 29/107 Classic Hundai, Dottappankulam, Sulthan Bathery, Wayanad — 673592, Kerala, India