Privacy Policy

Effective Date: August 1, 2026  |  Last Updated: August 1, 2026

1. Introduction

Welcome to Vedra Technologies Pvt. Ltd. (“Company”, “we”, “our”, or “us”). We operate the VedraFlow Marketing Automation Platform and related services (collectively, the “Services”) available at vedratechnologies.com.

We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services, including when you connect your Meta (Facebook) advertising account to our platform.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Name, email address, phone number, company name, job title.
  • Billing Information: Payment details processed via PCI-DSS compliant processors (we do not store raw card numbers).
  • Business Details: Tax ID/GST identification, business category, billing address.
  • Communications: Support requests, feedback, and customer communications.

2.2 Information Collected Automatically

  • Usage & Device Data: IP address, browser type, OS, device identifiers, session metrics.
  • Cookies & Tokens: Authentication tokens, session state cookies, analytics identifiers.

2.3 Meta Platforms (Facebook) API Data

When you connect your Meta Business or Ad Account to VedraFlow via OAuth, we access the following scoped advertising parameters strictly required to deliver our automation services:

  • Ad Account Information: Account ID, name, currency, timezone, status.
  • Campaign & Ad Set Parameters: Objectives, budgets, targeting parameters, placement settings, status.
  • Ad Creatives: Image/video hashes, headlines, ad copy, CTA links, target destinations.
  • Performance Metrics: Impressions, clicks, reach, spend, conversion counts.
  • Facebook Page Association: Page ID and Page name (used exclusively to represent your business on created ad objects).

Notice: We do NOT access your personal Facebook profile, friends list, private messages, personal feed, or any non-advertising data.

3. How We Use Your Information

We process collected data to operate, maintain, optimize, and secure our Services:

  • To execute ad creation, ad set configuration, and campaign scheduling on your behalf.
  • To aggregate campaign analytics and display real-time metrics on your dashboard.
  • To process subscription payments and send transactional invoices/receipts.
  • To enforce security, prevent fraudulent activity, and comply with statutory legal requirements.

Data obtained via Meta Marketing API is NEVER sold, rented, transferred to data brokers, or used for target profiling outside your explicit account instructions.

4. Meta (Facebook) Platform Compliance

Our integration complies strictly with the Meta Platform Terms and Meta Business Tools Terms.

  • Minimal Scope Access: We request only advertising management permissions (e.g., ads_management, ads_read, pages_read_engagement).
  • Token Protection: OAuth access tokens are encrypted using AES-256 at rest and never exposed in client logs or raw storage.
  • Access Revocation: You can revoke VedraFlow's access at any time through your Facebook Business Integration Settings.
  • Data Deletion Request: Revoking access triggers our automated token cleanup and purges active session credentials.

5. International Regulatory Compliance

5.1 European Union (GDPR)

Users in the EU/EEA enjoy rights under GDPR, including the right to access, rectify, erase (“Right to be Forgotten”), restrict processing, data portability, and object to processing. Legal bases include Contractual Necessity, Legitimate Interest, and Consent.

5.2 California (CCPA / CPRA)

California residents have the right to request disclosure of collected personal information, request deletion, and opt-out of sales. Vedra Technologies Pvt. Ltd. does not sell personal information.

5.3 India (DPDP Act 2023)

In compliance with the Digital Personal Data Protection Act 2023, Indian data principal rights—including access, correction, erasure, and grievance redressal within statutory timeframes—are fully supported.

6. Data Security & Storage

We implement enterprise-grade security protocols:

  • TLS 1.2 / TLS 1.3 encryption for all data in transit.
  • AES-256 database level encryption for sensitive tokens at rest.
  • Role-Based Access Control (RBAC) and strict environment isolation.
  • Continuous vulnerability scanning and automated threat mitigation.

7. Data Retention & Deletion

We retain account data for the duration of your active subscription plus 3 years for tax and regulatory audit purposes. Advertising logs are retained for 90 days. You may submit a formal Data Deletion Request at any time by contacting our privacy team.

8. Contact Us & Grievance Officer

If you have any questions, concerns, or data rights requests regarding this Privacy Policy or Meta platform integration, please contact:

Vedra Technologies Pvt. Ltd. — Legal & Compliance Office

Email: contact@vedratechnologies.com

Website: https://www.vedratechnologies.com