This Privacy Policy describes how VartAI ("VartAI", "we", "us") collects, uses, discloses, and safeguards personal information when you visit our website, book a demo, or use our services (the "Services"). By using the Services you agree to this Policy. Questions? Email hello@vartai.ai.
Who we are
VartAI provides a conversational AI platform that helps businesses respond to inbound leads by SMS and voice. We act as a data controller for information collected through this website and as a data processor / service provider for personal information our customers submit to the platform to nurture their own leads.
Information we collect
- Contact data you submit — name, business email, phone, company, message.
- Account & billing data from customers — company details, billing address (payments processed by Stripe; we don't store card numbers).
- Usage & device data — IP address, user agent, pages viewed, referrer, timestamps.
- Cookies & similar tech — see the Cookies section and our cookie banner.
- Customer-provided lead data processed on our customers' behalf (name, phone number, email, message content, call transcripts, consent records).
How we use information
- Provide, operate, and secure the Services.
- Respond to inquiries, deliver demos, and manage the sales relationship.
- Measure and improve the site and Services (with consent where required).
- Comply with legal, tax, and regulatory obligations.
- Detect and prevent fraud, abuse, and security incidents.
Legal bases (EEA/UK): contract, legitimate interests (running and improving the Services), consent (marketing cookies and electronic marketing where required), and legal obligation.
Consent-based outreach (CASL, TCPA, GDPR/PECR)
VartAI operates a strict consent-based outreach model. We only nurture leads on a customer's behalf where the customer represents that it has obtained a valid legal basis to contact the individual — express written consent under the U.S. Telephone Consumer Protection Act (TCPA) and FCC rules for autodialed / prerecorded / SMS communications, express consent under Canada's Anti-Spam Legislation (CASL) for commercial electronic messages, and a lawful basis under the EU/UK GDPR and PECR for electronic marketing.
U.S. customers: we prefer consent-based reach-out and require proof of lead generation — including the source, timestamp, IP address, and the specific opt-in language shown to the consumer — before we will nurture that lead on your behalf. This is a contractual condition of using the Services and is intended to satisfy TCPA "prior express written consent" record-keeping obligations. We honor STOP / UNSUBSCRIBE / opt-out signals in real time across SMS and voice, maintain internal Do-Not-Contact lists, and suppress reconsent attempts.
International transfers
Personal information is primarily processed in Canada (Toronto) with limited sub-processing in the United States and EU. Where we transfer personal data from the EEA/UK, we rely on Standard Contractual Clauses and the UK Addendum, and we apply supplementary technical and organizational measures.
Retention
We retain personal information for as long as needed to provide the Services, meet legal, accounting, and tax obligations, and resolve disputes. Consent and opt-out records are retained for at least six (6) years to demonstrate compliance with CASL, TCPA, and equivalent regimes. See our Security page for storage and encryption practices.
Your rights
Depending on where you live, you may have the right to:
- Access, correct, delete, or export your personal information.
- Object to or restrict certain processing, and withdraw consent at any time.
- Opt out of targeted advertising, "sale," or "sharing" (CPRA / U.S. state laws).
- Lodge a complaint with your local supervisory authority (e.g. OPC in Canada, ICO in the UK, your EU DPA).
To exercise these rights, email hello@vartai.ai. For lead data held on behalf of a VartAI customer, please contact that customer directly; we will support their response.
Security
We implement administrative, technical, and physical safeguards designed to protect personal information — TLS in transit, encryption at rest, hardened authentication, and least-privilege access. No system is 100% secure; we notify affected parties and regulators of qualifying incidents within the timelines required by law (including the 72-hour GDPR window). See Security for details.
Google user data & Google API Services (Limited Use)
When you sign in to the VartAI application at app.vartai.ai with Google, or connect your Google Calendar to VartAI (including through our scheduling integration with Cal.com), Google shares certain information with us based on the OAuth scopes you approve on Google's consent screen.
What we access from your Google Account
- Basic profile & email (
openid,email,profile) — your name, email address, Google account ID, and profile picture, used solely to create and authenticate your VartAI account. - Google Calendar (
https://www.googleapis.com/auth/calendarand/orcalendar.events, via Cal.com) — read your availability and create, update, or cancel calendar events on your behalf so that VartAI and Cal.com can book meetings that your AI agent has scheduled with a lead.
How we use Google user data
- Authenticate your login to the VartAI application.
- Check free/busy availability and place, reschedule, or cancel events on the calendar you connect.
- Sync booked meetings between VartAI, Cal.com, and your Google Calendar.
Limited Use disclosure. VartAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- Use Google user data to serve advertising, including retargeting or personalized ads.
- Sell Google user data or transfer it for creditworthiness, lending, or similar purposes.
- Allow humans to read Google user data, except (a) with your explicit consent for specific messages, (b) as necessary for security (e.g. investigating abuse), (c) to comply with applicable law, or (d) for aggregated, anonymized internal operations, and in each case only in compliance with the Limited Use policy.
- Use Google user data to train, fine-tune, or develop generalized/non-personalized AI or machine-learning models.
Sub-processors that touch Google data. Cal.com (calendar scheduling) processes the Google Calendar events you book through VartAI. Our hosting and telephony sub-processors do not receive Google Calendar content.
Retention. We retain OAuth refresh tokens for as long as your Google connection is active, and event metadata only as long as needed to operate scheduling and reporting. You can revoke VartAI's access at any time from Google Account → Security → Third-party access, or by disconnecting the integration inside app.vartai.ai. Revocation stops future access; we will delete stored tokens promptly and delete associated event metadata on request to hello@vartai.ai.
Children
The Services are not directed to children under 16 and we do not knowingly collect their personal information.
Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where required, notified to you.
Contact
VartAI — Privacy Team
Email: hello@vartai.ai
Questions? Email hello@vartai.ai