Privacy policy
How ValueText collects, uses, shares, and protects personal data. Customer messages live in your own Salesforce org and are governed by the Data Processing Addendum, not this policy.
- Your messages, recipients, and conversation history (Customer Data) live in your own Salesforce organisation. ValueText processes that data as your processor under the Data Processing Addendum, not under this policy.
- We do not sell personal data. As a controller, we use service providers including Google, Salesforce, Calendly, Zoom, Fireflies.ai, Freshdesk, Stripe, 2Checkout, and AWS, each under contract; platform subprocessors (Twilio and Meta) are listed in the Data Processing Addendum.
- You can access, correct, delete, or port personal data we hold as a controller, and California residents have the rights described in Section 9.2.
This summary is for orientation only and does not replace the full policy below.
01Introduction
ValueText Private Limited ("ValueText", "we", "us", "our") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, interact with our marketing and sales activities, become a customer, or otherwise engage with us.
This Privacy Policy applies to personal data we process as a data controller. Where we process personal data on behalf of our customers as a data processor (for example, where customer employees use our platform to send messages to their end-recipients), that processing is governed by our Data Processing Addendum and the terms of the relevant customer agreement, not by this Privacy Policy.
If you have any questions about this Privacy Policy or how we handle your personal data, contact us at info@valuetext.io.
02Who we are
ValueText Private Limited is a private limited company registered in India. We provide a Salesforce-native messaging platform used by businesses worldwide for SMS, WhatsApp, voice, and related communications.
Registered office
Tower B, 8-4-300/1/A, Flat No. 103, Kalpataru Residency, Sanathnagar, Erragadda Sub Post Office, Erragadda, Hyderabad, Telangana 500018, India
Data protection contact
For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the EU General Data Protection Regulation ("GDPR"), ValueText is the data controller of personal data described in Section 4 of this Privacy Policy.
03The two distinct data relationships
It is important to understand that we engage with personal data in two distinct contexts, with different roles and different governing documents.
3.1 Personal data we control
When you visit our website, fill in a form, attend a sales call, subscribe to our communications, or become our customer, ValueText decides why and how your personal data is processed. We are the data controller. This Privacy Policy governs that processing.
3.2 Customer Data on the platform
When our customers use the ValueText platform to send messages to their own contacts, those messages and recipient details are Customer Data. ValueText does not control this data; our customers do. Where ValueText acts as a data processor in respect of Customer Data, our obligations are set out in our Data Processing Addendum, which forms part of each customer's agreement with us.
3.3 Our platform architecture and Customer Data
Customer Data is stored within each customer's own Salesforce organisation. ValueText operates under one of two architectural models depending on the deployment: a direct model where messages flow directly between Salesforce and the messaging provider without passing through ValueText infrastructure, and a pass-through model where messages transit ValueText infrastructure briefly for delivery processing and are deleted immediately thereafter. Neither model results in long-term storage of Customer Data on ValueText infrastructure. The specific model applicable to a customer's deployment is described in our Data Processing Addendum.
04Personal data we collect
This section describes personal data we collect and process as a data controller. Personal data on the platform (Customer Data) is addressed in Section 3.2 above.
4.1 Website visitors
When you visit valuetext.io, we collect:
- Technical data: IP address, browser type and version, device information, operating system, referring URL, pages visited, time spent on pages, and interaction events.
- Cookies and tracking data: as described in Section 11.
- Analytics data: behavioural and engagement data collected via Google Analytics 4 and Google Tag Manager.
- Advertising data: conversion and audience data collected via Google Ads conversion tracking for measuring the effectiveness of our advertising campaigns.
4.2 Marketing leads and prospects
When you interact with our marketing activities, including contacting us, requesting a demo, downloading content, or being identified as a prospect, we collect:
- Identification data: name, job title, company name.
- Contact data: business email address, business phone number, country, region.
- Professional data: seniority, department, industry, company size, role responsibilities.
- Engagement data: which content you viewed, emails you opened, links you clicked, demos you attended.
- Enrichment data: publicly available business contact information collected via Apollo, used to enrich our understanding of prospects and to identify companies that match our ideal customer profile.
4.3 Sales process
When you engage with our sales team, we collect:
- Meeting scheduling data: information you provide when booking a meeting via Calendly, including name, email, timezone, and meeting purpose.
- Call recordings and transcripts: audio recordings, transcripts, and AI-generated summaries of sales and demo calls conducted via Zoom and processed through Fireflies.ai. Recording is disclosed at the start of each call, and you may decline to be recorded.
- Sales notes and correspondence: notes captured by our sales team, emails exchanged with you, and any other communications.
4.4 Customers
When your organisation becomes a ValueText customer, we collect about you in your professional capacity:
- Account contact data: name, role, business email, business phone, billing address, signatory details.
- Billing and payment data: transaction records, invoice history, payment method metadata (we do not store full payment card details, see Section 4.6).
- Account usage data: account creation date, plan tier, seat count, login timestamps, configuration choices made by your administrators.
- Support and training data: any information you provide when contacting support, attending training, or interacting with our onboarding team.
4.5 Support requests
When you contact support, we collect:
- Identification and contact data: name, business email, company.
- Ticket content: the content of your support request, any attachments, screenshots, and any troubleshooting information you provide.
- Conversation history: records of past support interactions to provide continuity.
This data is processed through Freshdesk.
4.6 Payment processing
When you pay us, payment card data is collected and processed by our payment providers (Stripe and 2Checkout) under their own privacy policies. We do not store full payment card numbers or CVV codes. We receive only transaction metadata necessary for billing reconciliation, which is stored in our Salesforce billing records.
05Lawful basis for processing
Under UK GDPR and GDPR, we process personal data on the following lawful bases:
You have the right to object to processing based on legitimate interest. See Section 9.
06How we use personal data
We use the personal data described in Section 4 for the following purposes:
- Operating our website and providing the information and content you request from it.
- Marketing and lead generation: identifying potential customers, contacting prospects to introduce our services, sending newsletters and marketing communications (with consent where required), measuring marketing campaign effectiveness, and re-engaging prospects who have shown interest.
- Sales process management: scheduling meetings, conducting demos, capturing call notes and recordings to improve our sales team's effectiveness, and tracking opportunities through our CRM.
- Customer relationship management: onboarding new customers, providing the platform, handling billing and payments, providing support and training, and communicating service updates.
- Product improvement: understanding how customers use the platform to identify areas for improvement (we use aggregated and anonymised data wherever possible for this purpose).
- Security and fraud prevention: detecting unusual activity, protecting our systems, and protecting our customers.
- Legal compliance: meeting our regulatory obligations, responding to lawful requests from authorities, and defending legal claims.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
08International transfers
ValueText is headquartered in India. Personal data we collect from individuals in the United Kingdom, the European Economic Area, or other regions may be transferred to and processed in India and in other countries where our service providers operate (including the United States).
Where we transfer personal data from the UK or EEA to a country that has not received an adequacy decision from the relevant authority, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office, where applicable.
If you would like more information about our international transfer arrangements, contact us at info@valuetext.io.
09Your rights
Depending on where you live, you may have the following rights in relation to your personal data.
9.1 Rights under UK GDPR and GDPR
If you are in the UK or EEA, you have the following rights:
- Right of access: to obtain confirmation of whether we process your personal data and a copy of that data.
- Right to rectification: to correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten"): to request deletion of your personal data in certain circumstances.
- Right to restriction of processing: to limit how we use your data in certain circumstances.
- Right to data portability: to receive your personal data in a structured, machine-readable format.
- Right to object: to object to processing based on legitimate interest, and to object to direct marketing at any time.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: with a supervisory authority. In the UK, that is the Information Commissioner's Office. In the EU, you may complain to your local data protection authority.
To exercise any of these rights, contact us at info@valuetext.io. We will respond within 30 days. We may ask for verification of your identity before processing your request.
9.2 Rights under California law (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know: what personal data we have collected about you, the categories of sources, the purposes of collection, and the categories of third parties we share it with.
- Right to delete: your personal data, subject to certain exceptions.
- Right to correct: inaccurate personal data.
- Right to opt out of "sale" or "sharing" of personal data: we do not sell personal data and do not "share" it for cross-context behavioural advertising as those terms are defined under California law.
- Right to limit use of sensitive personal information: we do not use sensitive personal information for purposes beyond what is necessary to provide our services.
- Right to non-discrimination: you will not be discriminated against for exercising these rights.
To exercise these rights, contact us at info@valuetext.io. You may also designate an authorised agent to make a request on your behalf, subject to verification.
9.3 Other jurisdictions
If you reside in another jurisdiction with applicable data protection law, you may have similar rights. Contact us to discuss them.
10How long we keep personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymised. Standard retention periods are below. We may retain data longer where required by law or where reasonably needed to defend legal claims.
12Children's privacy
Our website and services are intended for business users and are not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have collected personal data from a child under 16, we will delete it.
If you believe we may have collected personal data from a child, contact us at info@valuetext.io.
13Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit using industry-standard protocols.
- Access controls limiting personal data access to authorised personnel.
- Regular review of our security practices.
- Vendor due diligence on the service providers listed in Section 7.
No method of transmission or storage is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, contact us immediately at info@valuetext.io.
ValueText is ISO 27001:2022 certified; see Security for the certificate details.
14Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. We will post the updated policy on this page with a revised "Last updated" date. For material changes, we will provide additional notice where reasonably practicable, such as by email to customers or a notice on our website.
We encourage you to review this Privacy Policy periodically.
15How to contact us
For questions, requests, or complaints about this Privacy Policy or our handling of personal data, contact us. Email: info@valuetext.io. Postal address: Tower B, 8-4-300/1/A, Flat No. 103, Kalpataru Residency, Sanathnagar, Erragadda Sub Post Office, Erragadda, Hyderabad, Telangana 500018, India.
If you are in the UK and we cannot resolve your concern, you may lodge a complaint with the Information Commissioner's Office.
If you are in the EEA, you may lodge a complaint with your local data protection authority.
If you are in California, you may contact the California Attorney General.