Privacy Policy
Last updated: September 14, 2026
At Vinkora ("Vinkora," "we," "us") we protect the personal data of the people who visit our website, contract our services, and use our CRM. This Policy explains what data we process, for what purposes, with whom we share it, how long we retain it, and how you can exercise your rights. It applies to vinkora.net, to the crm.vinkora.net platform (the "CRM"), and to our client-acquisition services.
1. Data Controller
Vinkora is a brand operated by VINKORA MARKETING, C.A. For any matter related to your personal data, you may write to us at info@vinkora.net.
We act in two distinct capacities:
- As controller of the data of people who visit the website, write to us, or request information, and of our clients' account and billing data.
- As processor of the data that our clients upload to or receive in the CRM (their contacts, leads, conversations, recordings, and contracts). In that case, the client is the controller: the client decides the purposes for which that data is used, must inform its contacts, and must have a legal basis for processing it. We process that data solely to provide the service to the client and in accordance with its instructions.
2. Data We Process
2.1. When You Visit vinkora.net
- Contact and demo forms: name, email address, phone number, business name, and any information you choose to provide (plan of interest, team size, or budget).
- Free SEO audit: the web address you want analyzed and the email address to which we send the report.
- WhatsApp and social media: if you write to us, your number or username, your profile name, and the messages you send us.
- Browsing: IP address, device and browser type, pages visited, and, depending on your choice in the cookie notice, analytics data.
2.2. When You Use the CRM
- Account data: name, email address, phone number, organization, role, password (stored in encrypted form), two-step verification, preferences, and devices registered to receive notifications.
- Billing data: plan, number of users, payment history, and receipts you upload. PayPal payments are processed by PayPal; we do not store full card numbers.
- Your contacts' data (as processor): name, phone number, email address, company, tags, funnel stage, notes, tasks, quotes, payments, attachments, and conversations via WhatsApp, Messenger, Instagram, Telegram, or email.
- Calls and video calls: audio recordings, transcripts, summaries, and call data (date, duration, numbers, and the agent who handled the call).
- Electronic signature: documents, signer data, verification codes, and signature evidence (IP address, date and time, document hash, and timestamp). If the sender of the contract requires it, also a photo of the identity document and a biometric verification (liveness check and facial comparison).
- Technical logs: access events, IP address, browser, and security events.
2.3. Integrations You Connect
When you connect third-party services (Google, Meta, telephony providers, your email inbox, or external storage for backups), we process the credentials and data necessary for that integration to function. Credentials are stored encrypted and are never displayed in the browser.
3. How We Use Data
- To provide the CRM and its features, and to give you support (performance of the contract).
- To respond to your requests for information or a demo and to send you the audit you requested (your request and consent).
- To manage your subscription, payments, and billing (contract and legal obligations).
- To protect the platform and prevent fraud or abuse (legitimate interest).
- To measure and improve the website with aggregated analytics (your consent, which you may withdraw in the cookie notice).
- To send you Vinkora marketing information only if you provided your data for that purpose. You may unsubscribe at any time.
- To comply with legal obligations.
We do not sell personal data or transfer it to third parties for advertising.
4. Artificial Intelligence
The CRM includes artificial intelligence features that each organization decides whether to enable: responding to conversations, scoring and classifying leads, summarizing chats and calls, suggesting replies, completing fields, and analyzing metrics.
- To generate each response, the necessary data is sent to the AI provider configured by the organization (Anthropic, OpenAI, or Google), using that organization's key.
- Call transcription is performed by Deepgram, and reading of the identity document during a signature is performed by Anthropic.
- Vinkora does not use your data or your contacts' data to train AI models. Each provider processes the data in accordance with its service terms.
- AI classifications help the organization's team prioritize its work; the team can review and change them. Vinkora does not make decisions that produce legal effects concerning individuals based solely on automated processing.
5. Data from Google APIs (Limited Use)
Vinkora's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Vinkora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect your Google account, we request only the following permissions and use them solely for the features you enable:
| Google Permission | How We Use It |
|---|---|
| Google Search Console (read-only) | To read your website's performance on Google (clicks, impressions, queries, and pages) and display it in the CRM's analytics. |
| Google Analytics (read-only) | To read your property's reports (sessions, traffic sources, and conversions) to display them in the analytics and attribute your leads. |
| Google Ads | To read your campaign metrics (spend, clicks, and conversions) to calculate cost per lead and return. We do not create or modify campaigns. |
| Google Calendar (events) | To create, update, and cancel on your calendar the events for appointments scheduled in the CRM, including their Google Meet link and the invitation to attendees. |
| Google Drive (only files created by Vinkora) | To store backup copies. We do not access the rest of your Drive. |
| Your Google account email address | To identify which account you connected. |
- Use: we display that information only to members of your organization, within the CRM's features.
- Storage: we store access tokens encrypted; metrics are retrieved when you open them, and we retain only the reports you generate.
- Sharing: we do not sell Google data or use it for advertising or to train AI models. It is processed only by the providers that operate the service and, if you request an AI analysis, by your organization's AI provider.
- Human access: no one at Vinkora reads your Google data, except with your permission to provide you support, for security purposes, or as required by law.
- Revocation: you can disconnect Google from the CRM or revoke access in your Google account. Upon disconnection, we delete the stored tokens.
6. Meta Data (WhatsApp, Messenger, Instagram, and Ads)
- Messaging: when an organization connects WhatsApp Business, Messenger, or Instagram, we receive messages, files, profile name or username, account identifier, and delivery statuses. If the conversation starts from an ad, we also receive that ad's identifier, in order to know which campaign brought in the lead.
- Ads: if you connect your Meta ad account, we read your campaigns and their metrics to display them in the analytics. We do not create or modify ads.
- We use this data solely to operate the organization's conversation inbox, AI assistant, and analytics. Tokens are stored encrypted.
- You can disconnect Meta from the CRM, remove the integration in Facebook (Settings → Business Integrations) or in Instagram (Settings → Apps and Websites), and request deletion of your data as explained in Section 11.
7. Calls, Video Calls, and Recordings
If the organization enables it, phone calls and video calls made from the CRM may be recorded and transcribed in order to follow up on each case, accurately record what was agreed, and maintain service quality. Recordings are kept in the contact's record and are viewable only by that organization's authorized personnel. The organization is responsible for informing its contacts and obtaining their consent where required by the laws of its country.
8. Electronic Signature and Identity Verification
Each signature generates an evidence file to demonstrate who signed, when, and that the document was not altered. Identity documents are stored encrypted. Biometric verification is performed by Didit and occurs only if the signer accepts it during the process; biometric data is sensitive data and is processed with the corresponding protection. From the verification, we retain the result and the necessary evidence. The sender of the contract is the controller of that data.
9. With Whom We Share Data
We work with providers that process data on our behalf, under their data protection terms and solely to provide the service:
| Provider | Purpose |
|---|---|
| Supabase | CRM database, authentication, and files |
| Render | CRM hosting |
| Banahosting | Hosting of the vinkora.net website |
| Resend | Platform emails (account confirmation, notifications, and password recovery) |
| Web3Forms | Delivery of website form submissions to our email |
| Vercel | Execution of the free SEO audit |
| Calendar, Meet, Search Console, Analytics, Ads, Drive, and Sheets, and website analytics | |
| Meta | WhatsApp, Messenger, Instagram, and ad metrics |
| DigitalOcean | Server for WhatsApp connections via QR code |
| Anthropic, OpenAI, and Google | Artificial intelligence features |
| Deepgram | Audio transcription |
| LiveKit and Cloudflare | Video calls, their recording, and call connectivity |
| Twilio and Infobip | Telephony, when the organization connects its own account |
| Didit | Biometric identity verification |
| PayPal | Payment processing |
We may also disclose data to authorities when required by law or a valid order. Several providers host data outside your country, mainly in the United States. In those cases, the transfer is carried out under the contractual safeguards offered by those providers.
10. How Long We Retain Data
- Account and CRM data: for as long as your subscription is active. If the subscription remains suspended for 6 months without being reactivated, we archive a protected backup copy and delete the account from the platform. You may ask us to delete that copy as well.
- Automatic backups: deleted on a rolling basis according to the configured retention period (15 days by default).
- Requests made on the website: for as long as they are useful to assist you and for the business relationship, or until you request their deletion.
- Billing: for the periods required by tax and accounting laws.
11. How to Request Deletion of Your Data
- If you are a CRM client: you can disconnect your integrations from Apps and export your contacts and leads. To delete your organization and all of its data, write to us at info@vinkora.net from the account email address with the subject line "Delete my account."
- If you contacted us via WhatsApp, Messenger, or Instagram, or submitted your data on the website: write to us at info@vinkora.net with the subject line "Delete my data" and include your number, username, or email address.
- If you are a contact of a business that uses Vinkora: request deletion from that business, which is the controller of your data. If it does not respond, write to us and we will help you route the request.
We confirm deletion within a maximum of 30 days, except for data that we are required by law to retain.
12. Your Rights
You may request access to your data, its rectification or update, its erasure, restriction of processing, object to processing, request portability, and withdraw your consent at any time. Write to us at info@vinkora.net; we may ask you for information to verify your identity. We respond within the time limits set by applicable law, generally between 10 and 20 business days. If you are not satisfied with the response, you may contact the data protection authority in your country.
13. Security
We apply technical and organizational measures to protect data: encryption in transit (HTTPS), AES-256 encryption of credentials and identity documents, isolation of each organization's data in the database, role-based access control, two-step verification, daily backups, and activity logs. No system is infallible. If a security incident affecting your data occurs, we will notify you without undue delay and in accordance with the law.
14. Minors
Our services are intended for businesses and professionals. They are not directed to individuals under 18 years of age, and we do not knowingly collect their data.
15. Cookies
We use cookies to make the website work and, if you accept, to measure its use. You may change your choice at any time. See the details in our Cookie Policy.
16. Changes to This Policy
We may update this Policy. We will post the current version on this page with its update date and, if the change is material, we will notify our clients by email or within the CRM.
17. Contact
Questions about your privacy? Write to us at info@vinkora.net.