Privacy Policy
Last updated: 3 August 2026
1. What this policy covers
Trootlabs ("we", "us") provides a business automation platform — a dashboard, AI agents, and communication tools — used by businesses ("tenants", "you") across India. This policy explains what data we collect, why, and how it's handled — both about you as a tenant, and about your customers whose data flows through the platform on your behalf.
2. Data we collect
Account data: your name, business name, email, phone number, and login credentials, collected at signup.
Tenant business data: customer records, conversations, appointments, deals, invoices, and knowledge base documents you or your AI agents create while using the platform. This data belongs to you — we process it on your behalf, we don't use it to train models or sell it.
Channel credentials: WhatsApp Business, voice, calendar, and payment gateway credentials you connect under Settings → Channels, used solely to operate the integrations you configure.
Usage data: AI token consumption, feature usage, and error logs, used for billing accuracy and platform reliability.
3. How AI processing works
Messages sent to your AI agents (WhatsApp, voice, web chat) are processed by third-party AI model providers (currently Anthropic) to generate replies. We hold the AI provider account centrally — your customers' messages are not used by us or the AI provider to train models, per the provider's standard API terms.
4. Data storage & security
Data is stored on Supabase (managed Postgres, hosted in a region selected for proximity to Indian users) with row-level isolation between tenants — one business can never access another's data through the platform. Application hosting is on Vercel.
5. Data sharing
We don't sell tenant or customer data. Data is shared only with the sub-processors required to run the service you've configured — e.g. the AI model provider, your connected WhatsApp/voice/calendar/payment providers, and infrastructure providers (Supabase, Vercel).
6. Your rights
You can request export or deletion of your tenant's data at any time from Settings, or by contacting us directly. Deleting your account removes your business data within a reasonable retention window required for billing and legal compliance.
7. Contact
Questions about this policy: reach us via the contact details on our homepage.
This page is placeholder policy text drafted for development purposes. Replace it with content reviewed by qualified legal counsel before processing real customer data or payments.
