Privacy Policy
Xtromate CRM at xtromate.com · Effective 5 October 2026
Xtromate CRM is operated by Xtromate Technology (registered name XTROMATE), a proprietorship based in Jodhpur, Rajasthan, India ("Xtromate", "we", "us"). This policy explains what information we handle, why, and what choices you have. Questions: xtromateofficial@gmail.com.
1. Our role: processor and controller
- Our customers ("Clients") are businesses that connect their own WhatsApp Business Account, Facebook Page, Instagram account, Google Business Profile and ad account to Xtromate CRM.
- For the personal data of a Client's own customers, leads and contacts ("End Users"), the Client is the data controller (the "data fiduciary" under India's Digital Personal Data Protection Act, 2023 and its Rules) and Xtromate is the data processor (service provider). We process that data only on the Client's instructions and to provide the service.
- For Client account data (name, business details, login email, billing details, usage logs), Xtromate is the controller.
- If you are an End User and want to exercise rights over your data, please contact the business that messaged you first. We will help them respond.
2. Information we access and store
| Category | Examples |
|---|---|
| Client account data | Name, business name, email, phone, GST details, billing records, team members, login and usage logs. |
| WhatsApp data | Messages, media, delivery status, phone numbers and profile names of the Client's customers, templates, and the Client's WhatsApp Business Account and phone number settings. |
| Facebook Page and Instagram data | Page and account details, posts and comments, direct messages sent to the connected account, lead form submissions. |
| Ad account data | Campaigns, ad sets, ads, spend and performance insights, and the ctwa_clid (click-to-WhatsApp ad referral id) and ad referral details that link a chat to the ad that started it. |
| Google Business Profile data | Business listing details, reviews and messages, where the Client connects it. |
| Lead and CRM data | Contact details, tags, notes, qualification answers, conversation summaries, lead scores, follow-up schedules, outreach lists uploaded by the Client. |
| Access tokens | Authorisation tokens issued by Meta and other platforms when the Client connects an account. They are stored encrypted. |
| Technical data | IP address, device and browser type, error and security logs, cookies needed for sign-in. |
We only request the permissions needed for the features the Client turns on. We do not access personal Facebook or Instagram profiles beyond what Facebook Login for Business grants for connecting the Client's business assets.
3. How we use information
- Provide the service: send and receive WhatsApp messages, manage the inbox and CRM, qualify leads, schedule follow-ups, publish and manage social content, run and report on Meta ads, and run outreach the Client has set up.
- Operate, secure and improve the platform, prevent abuse and fraud, and meet legal obligations.
- Bill Clients, provide support, and send service notices.
- We do not sell personal data, and we do not use Client or End User data for advertising of our own or for third-party advertising.
4. AI processing
- Xtromate CRM uses AI models to draft replies, qualify leads, summarise chats and classify intent. To do this, message text and relevant context are sent to third-party AI model providers acting as our sub-processors.
- Where our agreements with those providers allow, Client and End User data is not used to train their models. We choose provider terms and settings with this in mind and do not use Client data to train our own models.
- AI replies may be wrong. Clients are responsible for reviewing their AI settings and may switch to human-only mode at any time. Clients must disclose AI use to End Users where required by law or platform rules.
5. Sub-processors and sharing
We share data only with service providers needed to run the product, under written terms that require confidentiality and security. Categories:
- Cloud hosting and storage providers, with data hosted in India.
- AI model providers (to generate replies, summaries and classifications).
- Email and message-sending vendors (service emails, notifications).
- Payment gateway: Razorpay (subscription payments; we do not store full card details).
- Platforms the Client connects: Meta (WhatsApp, Facebook, Instagram, Ads) and Google. Data flows to and from them under the Client's own accounts and their terms.
A current list of named sub-processors is available on request at xtromateofficial@gmail.com. We may also disclose data if required by law or to protect rights and safety, and in a business transfer, with notice.
6. Retention and deletion
- Access tokens: deleted immediately when the Client disconnects an account or closes the workspace.
- Messages, leads, contacts and connected-account content: kept while the Client's subscription is active. After termination or a verified deletion request, deleted within 30 days. Backups are overwritten within a further 30 days.
- Billing and tax records: kept for 8 years as required by Indian tax and accounting law.
- Security and audit logs: kept for up to 12 months.
- Clients may set shorter retention for chats inside the product where available.
See our Data Deletion Instructions for how to request deletion.
7. Security
- Encryption in transit (HTTPS/TLS) and encryption of access tokens and secrets at rest.
- Per-Client data separation, role-based access and least-privilege access for our staff.
- Logging and monitoring, regular backups, and prompt patching.
- If a personal data breach affecting Client data occurs, we will notify the Client without undue delay so they can meet their own obligations, and notify authorities where we are required to.
No system is perfectly secure, but we work to protect your data with reasonable safeguards.
8. Rights under the DPDP Act
Individuals in India have rights to access information about their personal data, correct and erase it, withdraw consent, nominate another person to exercise rights, and have grievances addressed. For End User data, please contact the Client (the data fiduciary) first; we will assist them. For Client account data, write to us.
Grievance contact: Grievance Officer, Xtromate Technology, Jodhpur, Rajasthan, India. Email: xtromateofficial@gmail.com. We aim to acknowledge within 7 days and resolve within 30 days. You may also approach the Data Protection Board of India once it is operational.
9. Client responsibilities
- Clients must have a lawful basis and valid consent or opt-in from every person they message or upload, and must honour opt-outs promptly.
- Clients must give their End Users their own privacy notice that covers their use of Xtromate CRM and AI.
- Clients must follow the WhatsApp Business Messaging Policy, WhatsApp Business Terms, and Meta Platform Terms and Developer Policies.
10. Children
The service is for businesses. It is not directed to anyone under 18, and Clients must not knowingly collect children's data through it.
11. International transfers
Primary hosting is in India. Some providers (such as AI model providers or Meta) may process data outside India. We use providers with appropriate safeguards and only transfer where permitted by law.
12. Cookies
We use essential cookies for sign-in and security. We do not use advertising cookies on the dashboard.
13. Changes
We may update this policy. For material changes we will notify Clients by email or in the product before they take effect. The effective date is shown at the top.
14. Contact
Xtromate Technology (XTROMATE), Jodhpur, Rajasthan, India · xtromateofficial@gmail.com · xtromate.com