HOME / PRIVACY POLICY
Privacy Policy
Effective 1 September 2026
This policy describes what ValueRamp actually does today, including the parts that are manual, incomplete, or less reassuring than a buyer might hope. Every retention period and every sub-processor named below was checked against the running system rather than copied from a template. Where we have no mechanism for something, this policy says so instead of promising one.
Who is responsible for your data?
Arjun Sachdeva, trading as ValueRamp, in Gurugram, Haryana, India.
ValueRamp is not yet incorporated — it operates as a sole proprietor (not incorporated), so the controller is a named individual rather than a company. We state this plainly because a policy that implies a corporate entity where none exists is misleading about who you would actually be contracting with. This section will change when ValueRamp incorporates.
For most of the data ValueRamp handles, our customer is the controller and ValueRamp is the processor. When a customer connects their email, calendar, Slack or CRM, they decide what is ingested and why; we process it on their instructions. The people whose conversations are analysed are usually our customers’ customers, and they have no direct relationship with ValueRamp. Responsibility for telling those people sits with the customer, and the Data Processing Agreement sets that out.
Where is your data stored?
All data is stored in Supabase’s Singapore (ap-southeast-1) region. Regional data residency selection is not currently available.
That applies to every customer. There is no per-workspace choice of region, and selecting one is not something the product offers. If your procurement requires data to stay in a jurisdiction other than Singapore, ValueRamp cannot meet that today.
Backups are held separately, in Cloudflare R2 in the Asia-Pacific region. That is a different provider in a different place from the database, and it is stated separately rather than folded into “Singapore”.
Some of the sub-processors listed below operate outside Singapore and India, so using ValueRamp involves cross-border transfers of personal data. Our error-monitoring provider, Sentry, runs in a United States region.
What data does ValueRamp process?
Two different things, and it is worth separating them. The first is ordinary account data: the names, work email addresses and roles of the people on your team who use the product, plus the customer records, plans and tasks you create in it.
The second is Communication Intelligence, which ingests customer conversations and extracts structured signals from them. It is off by default and must be explicitly enabled per workspace and per channel by an administrator. When it is on, these are the sources and the exact scope:
| Source | What is taken |
|---|---|
| Forwarded or BCC’d mail only, sent to a per-user address. Body, participants and subject. Attachments are dropped at the mail gateway and never reach our systems. | |
| Meeting transcripts (Fathom) | The full verbatim transcript, plus the AI summary and action items. |
| Calendar (Google) | Attendees and event titles only. Event descriptions are never read or stored. |
| Slack | Slack Connect (externally shared) channels only — message text and sender. Direct messages and group DMs are never ingested, under any setting. |
| HubSpot | Historical sales email, calls, meetings and notes, up to the deal close date. |
Automated and bulk email — newsletters, no-reply addresses and list mail — is dropped before storage.
Two limits are worth stating because they cut the other way. Emails and meetings that match no known customer account are still stored: the body is stripped, but participant addresses, domains, the subject line and the source identifier are retained. And for meetings we store the full transcript, not a summary.
Is your data used to train AI models?
No. ValueRamp does not train models on customer data.
Message bodies, meeting transcripts and participant lists are sent to Anthropic for analysis and drafting. That is processing, not training, and it is why Anthropic is named in the table below rather than described as “a hosting provider”. No other AI provider receives any customer data.
How long is data kept?
| Data | Retention |
|---|---|
| Raw communication content | 30 days by default; configurable by the workspace between 7 and 90 days |
| — exception: sales email imported from HubSpot | 24 months from the deal close date |
| Structured analysis (the AI extraction) | Indefinite |
| — identifiers inside that analysis | Replaced with pseudonymous tokens after 365 days |
| Audit log | Indefinite |
| Backups | 30 days. Data deleted from live systems ages out of backups within a further 30 days — a full purge at day 60 |
Two details in that table matter more than the numbers. The retention window is stamped when a message is written, so changing the setting is not retroactive — it applies to what arrives afterwards, not to what is already stored.
And structured analysis of communications — including the names and email addresses of participants — is retained indefinitely. Deleting the raw message does not delete the analysis derived from it.
What happens to identifiers over time?
After 365 days, participant names and email addresses inside structured analysis are replaced with stable pseudonymous tokens.
We call this pseudonymisation, and the precision is deliberate rather than pedantic. The salt used to generate those tokens is retained, so the mapping remains derivable and the data is still personal data. Describing it as irreversible would overstate what we do.
The analytical free text — objections, action items, risk detail, subject lines — is retained. Only the identifiers within it are replaced. One residual is worth naming: a third party mentioned inside a message body, who is not one of the recorded participants, is not pseudonymised.
What happens if you turn Communication Intelligence off?
Marking an account “do not analyze” stops AI analysis of its communications. Messages already received may remain in our ingestion records.
Turning it off is therefore not the same as removing what was already collected. If you need that removed, ask, and it is handled manually.
Who else receives your data?
Every sub-processor, including the ones that are easy to forget because they are not product features:
| Sub-processor | Purpose | Data received |
|---|---|---|
| Supabase | Primary database (Singapore) | All application data |
| Railway | Backend hosting | All backend data in transit and in memory; application logs |
| Vercel | Frontend hosting | Rendered pages, session cookies, request logs |
| Cloudflare | Inbound email routing; document and backup storage (R2) | Inbound email; uploaded documents; encrypted backups |
| Resend | Outbound email | Recipient addresses and email bodies |
| Anthropic | AI analysis and drafting | Message bodies, meeting transcripts, participant lists |
| HubSpot | CRM import (read-only) | Deals, companies, contacts, engagement history |
| Slack | Communication ingest | Channel and user information, message text |
| Calendar ingest; usage-data import | Calendar attendees and event titles; spreadsheet contents | |
| Fathom | Meeting transcripts | Full verbatim meeting transcripts |
| Sentry | Server-side error monitoring | Exception messages, stack traces, a sample of request traces |
| Frankfurter | Currency reference rates | Currency codes only — no personal data |
Sentry is listed because it is a sub-processor even though it is not a feature, and vendors like it are commonly left off lists like this for exactly that reason. It monitors errors on our servers only. There is no session replay, and ValueRamp runs no product analytics — no Google Analytics, Segment, PostHog, Mixpanel or Hotjar.
How is data protected?
Third-party integration credentials are encrypted by ValueRamp using AES-256-GCM. All other data is protected by our database provider’s encryption at rest and by access controls. We state it that way because claiming we encrypt every message body ourselves would not be true.
Data in transit uses TLS. Backups are encrypted and have been restored and verified. Row-level security is enabled on every table as a deny-all backstop, with database privileges as an independent lock — though the per-workspace separation that actually does the work is enforced by the backend, which the security page describes in full.
What are your rights, and how do you exercise them?
Requests to access, correct, or delete personal data are handled manually. Contact privacy@valuerampai.com. We will respond as promptly as we are able.
There is deliberately no number in that sentence. ValueRamp has no automated export, no self-service erasure and no request-tracking system, so a fixed-deadline commitment would be a promise with no mechanism behind it. When those exist, this policy will say so and give a figure.
Two further specifics, stated because they are the kind of thing usually left vague. Deleting an account is a soft delete — the data is archived rather than removed. And the nearest thing to an objection mechanism is the per-account “do not analyze” flag, which is set by the customer’s administrator rather than by the individual, and which stops analysis without stopping storage.
Consent
Workspace administrators must explicitly enable Communication Intelligence. An optional consent acknowledgement is available in settings.
Because ValueRamp is the processor here, the obligation to establish a lawful basis for ingesting a conversation — and to tell the people in it — sits with the customer who enables the feature, not with ValueRamp. The Data Processing Agreement states that allocation directly.
Cookies and the public website
The pages on this website set no analytics or advertising cookies and run no tracking scripts. The product at valuerampai.com/login sets cookies that are strictly necessary to keep you signed in and to remember your display theme. The theme preference is stored in your browser only.
Changes to this policy
When this policy changes materially, the effective date at the top changes with it. If you are a customer, we will tell you rather than relying on you noticing.
Contact
Privacy questions and data-subject requests: privacy@valuerampai.com. Anything else about the product: get in touch.