Privacy Policy

Last updated: September 14, 2026

At Vinkora ("Vinkora," "we," "us") we protect the personal data of the people who visit our website, contract our services, and use our CRM. This Policy explains what data we process, for what purposes, with whom we share it, how long we retain it, and how you can exercise your rights. It applies to vinkora.net, to the crm.vinkora.net platform (the "CRM"), and to our client-acquisition services.

1. Data Controller

Vinkora is a brand operated by VINKORA MARKETING, C.A. For any matter related to your personal data, you may write to us at info@vinkora.net.

We act in two distinct capacities:

2. Data We Process

2.1. When You Visit vinkora.net

2.2. When You Use the CRM

2.3. Integrations You Connect

When you connect third-party services (Google, Meta, telephony providers, your email inbox, or external storage for backups), we process the credentials and data necessary for that integration to function. Credentials are stored encrypted and are never displayed in the browser.

3. How We Use Data

We do not sell personal data or transfer it to third parties for advertising.

4. Artificial Intelligence

The CRM includes artificial intelligence features that each organization decides whether to enable: responding to conversations, scoring and classifying leads, summarizing chats and calls, suggesting replies, completing fields, and analyzing metrics.

5. Data from Google APIs (Limited Use)

Vinkora's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Vinkora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect your Google account, we request only the following permissions and use them solely for the features you enable:

Google PermissionHow We Use It
Google Search Console (read-only)To read your website's performance on Google (clicks, impressions, queries, and pages) and display it in the CRM's analytics.
Google Analytics (read-only)To read your property's reports (sessions, traffic sources, and conversions) to display them in the analytics and attribute your leads.
Google AdsTo read your campaign metrics (spend, clicks, and conversions) to calculate cost per lead and return. We do not create or modify campaigns.
Google Calendar (events)To create, update, and cancel on your calendar the events for appointments scheduled in the CRM, including their Google Meet link and the invitation to attendees.
Google Drive (only files created by Vinkora)To store backup copies. We do not access the rest of your Drive.
Your Google account email addressTo identify which account you connected.

6. Meta Data (WhatsApp, Messenger, Instagram, and Ads)

7. Calls, Video Calls, and Recordings

If the organization enables it, phone calls and video calls made from the CRM may be recorded and transcribed in order to follow up on each case, accurately record what was agreed, and maintain service quality. Recordings are kept in the contact's record and are viewable only by that organization's authorized personnel. The organization is responsible for informing its contacts and obtaining their consent where required by the laws of its country.

8. Electronic Signature and Identity Verification

Each signature generates an evidence file to demonstrate who signed, when, and that the document was not altered. Identity documents are stored encrypted. Biometric verification is performed by Didit and occurs only if the signer accepts it during the process; biometric data is sensitive data and is processed with the corresponding protection. From the verification, we retain the result and the necessary evidence. The sender of the contract is the controller of that data.

9. With Whom We Share Data

We work with providers that process data on our behalf, under their data protection terms and solely to provide the service:

ProviderPurpose
SupabaseCRM database, authentication, and files
RenderCRM hosting
BanahostingHosting of the vinkora.net website
ResendPlatform emails (account confirmation, notifications, and password recovery)
Web3FormsDelivery of website form submissions to our email
VercelExecution of the free SEO audit
GoogleCalendar, Meet, Search Console, Analytics, Ads, Drive, and Sheets, and website analytics
MetaWhatsApp, Messenger, Instagram, and ad metrics
DigitalOceanServer for WhatsApp connections via QR code
Anthropic, OpenAI, and GoogleArtificial intelligence features
DeepgramAudio transcription
LiveKit and CloudflareVideo calls, their recording, and call connectivity
Twilio and InfobipTelephony, when the organization connects its own account
DiditBiometric identity verification
PayPalPayment processing

We may also disclose data to authorities when required by law or a valid order. Several providers host data outside your country, mainly in the United States. In those cases, the transfer is carried out under the contractual safeguards offered by those providers.

10. How Long We Retain Data

11. How to Request Deletion of Your Data

We confirm deletion within a maximum of 30 days, except for data that we are required by law to retain.

12. Your Rights

You may request access to your data, its rectification or update, its erasure, restriction of processing, object to processing, request portability, and withdraw your consent at any time. Write to us at info@vinkora.net; we may ask you for information to verify your identity. We respond within the time limits set by applicable law, generally between 10 and 20 business days. If you are not satisfied with the response, you may contact the data protection authority in your country.

13. Security

We apply technical and organizational measures to protect data: encryption in transit (HTTPS), AES-256 encryption of credentials and identity documents, isolation of each organization's data in the database, role-based access control, two-step verification, daily backups, and activity logs. No system is infallible. If a security incident affecting your data occurs, we will notify you without undue delay and in accordance with the law.

14. Minors

Our services are intended for businesses and professionals. They are not directed to individuals under 18 years of age, and we do not knowingly collect their data.

15. Cookies

We use cookies to make the website work and, if you accept, to measure its use. You may change your choice at any time. See the details in our Cookie Policy.

16. Changes to This Policy

We may update this Policy. We will post the current version on this page with its update date and, if the change is material, we will notify our clients by email or within the CRM.

17. Contact

Questions about your privacy? Write to us at info@vinkora.net.