HOME / PRIVACY POLICY

Privacy Policy

Effective 1 September 2026

This policy describes what ValueRamp actually does today, including the parts that are manual, incomplete, or less reassuring than a buyer might hope. Every retention period and every sub-processor named below was checked against the running system rather than copied from a template. Where we have no mechanism for something, this policy says so instead of promising one.

Who is responsible for your data?

Arjun Sachdeva, trading as ValueRamp, in Gurugram, Haryana, India.

ValueRamp is not yet incorporated — it operates as a sole proprietor (not incorporated), so the controller is a named individual rather than a company. We state this plainly because a policy that implies a corporate entity where none exists is misleading about who you would actually be contracting with. This section will change when ValueRamp incorporates.

For most of the data ValueRamp handles, our customer is the controller and ValueRamp is the processor. When a customer connects their email, calendar, Slack or CRM, they decide what is ingested and why; we process it on their instructions. The people whose conversations are analysed are usually our customers’ customers, and they have no direct relationship with ValueRamp. Responsibility for telling those people sits with the customer, and the Data Processing Agreement sets that out.

Where is your data stored?

All data is stored in Supabase’s Singapore (ap-southeast-1) region. Regional data residency selection is not currently available.

That applies to every customer. There is no per-workspace choice of region, and selecting one is not something the product offers. If your procurement requires data to stay in a jurisdiction other than Singapore, ValueRamp cannot meet that today.

Backups are held separately, in Cloudflare R2 in the Asia-Pacific region. That is a different provider in a different place from the database, and it is stated separately rather than folded into “Singapore”.

Some of the sub-processors listed below operate outside Singapore and India, so using ValueRamp involves cross-border transfers of personal data. Our error-monitoring provider, Sentry, runs in a United States region.

What data does ValueRamp process?

Two different things, and it is worth separating them. The first is ordinary account data: the names, work email addresses and roles of the people on your team who use the product, plus the customer records, plans and tasks you create in it.

The second is Communication Intelligence, which ingests customer conversations and extracts structured signals from them. It is off by default and must be explicitly enabled per workspace and per channel by an administrator. When it is on, these are the sources and the exact scope:

SourceWhat is taken
EmailForwarded or BCC’d mail only, sent to a per-user address. Body, participants and subject. Attachments are dropped at the mail gateway and never reach our systems.
Meeting transcripts (Fathom)The full verbatim transcript, plus the AI summary and action items.
Calendar (Google)Attendees and event titles only. Event descriptions are never read or stored.
SlackSlack Connect (externally shared) channels only — message text and sender. Direct messages and group DMs are never ingested, under any setting.
HubSpotHistorical sales email, calls, meetings and notes, up to the deal close date.

Automated and bulk email — newsletters, no-reply addresses and list mail — is dropped before storage.

Two limits are worth stating because they cut the other way. Emails and meetings that match no known customer account are still stored: the body is stripped, but participant addresses, domains, the subject line and the source identifier are retained. And for meetings we store the full transcript, not a summary.

Is your data used to train AI models?

No. ValueRamp does not train models on customer data.

Message bodies, meeting transcripts and participant lists are sent to Anthropic for analysis and drafting. That is processing, not training, and it is why Anthropic is named in the table below rather than described as “a hosting provider”. No other AI provider receives any customer data.

How long is data kept?

DataRetention
Raw communication content30 days by default; configurable by the workspace between 7 and 90 days
— exception: sales email imported from HubSpot24 months from the deal close date
Structured analysis (the AI extraction)Indefinite
— identifiers inside that analysisReplaced with pseudonymous tokens after 365 days
Audit logIndefinite
Backups30 days. Data deleted from live systems ages out of backups within a further 30 days — a full purge at day 60

Two details in that table matter more than the numbers. The retention window is stamped when a message is written, so changing the setting is not retroactive — it applies to what arrives afterwards, not to what is already stored.

And structured analysis of communications — including the names and email addresses of participants — is retained indefinitely. Deleting the raw message does not delete the analysis derived from it.

What happens to identifiers over time?

After 365 days, participant names and email addresses inside structured analysis are replaced with stable pseudonymous tokens.

We call this pseudonymisation, and the precision is deliberate rather than pedantic. The salt used to generate those tokens is retained, so the mapping remains derivable and the data is still personal data. Describing it as irreversible would overstate what we do.

The analytical free text — objections, action items, risk detail, subject lines — is retained. Only the identifiers within it are replaced. One residual is worth naming: a third party mentioned inside a message body, who is not one of the recorded participants, is not pseudonymised.

What happens if you turn Communication Intelligence off?

Marking an account “do not analyze” stops AI analysis of its communications. Messages already received may remain in our ingestion records.

Turning it off is therefore not the same as removing what was already collected. If you need that removed, ask, and it is handled manually.

Who else receives your data?

Every sub-processor, including the ones that are easy to forget because they are not product features:

Sub-processorPurposeData received
SupabasePrimary database (Singapore)All application data
RailwayBackend hostingAll backend data in transit and in memory; application logs
VercelFrontend hostingRendered pages, session cookies, request logs
CloudflareInbound email routing; document and backup storage (R2)Inbound email; uploaded documents; encrypted backups
ResendOutbound emailRecipient addresses and email bodies
AnthropicAI analysis and draftingMessage bodies, meeting transcripts, participant lists
HubSpotCRM import (read-only)Deals, companies, contacts, engagement history
SlackCommunication ingestChannel and user information, message text
GoogleCalendar ingest; usage-data importCalendar attendees and event titles; spreadsheet contents
FathomMeeting transcriptsFull verbatim meeting transcripts
SentryServer-side error monitoringException messages, stack traces, a sample of request traces
FrankfurterCurrency reference ratesCurrency codes only — no personal data

Sentry is listed because it is a sub-processor even though it is not a feature, and vendors like it are commonly left off lists like this for exactly that reason. It monitors errors on our servers only. There is no session replay, and ValueRamp runs no product analytics — no Google Analytics, Segment, PostHog, Mixpanel or Hotjar.

How is data protected?

Third-party integration credentials are encrypted by ValueRamp using AES-256-GCM. All other data is protected by our database provider’s encryption at rest and by access controls. We state it that way because claiming we encrypt every message body ourselves would not be true.

Data in transit uses TLS. Backups are encrypted and have been restored and verified. Row-level security is enabled on every table as a deny-all backstop, with database privileges as an independent lock — though the per-workspace separation that actually does the work is enforced by the backend, which the security page describes in full.

What are your rights, and how do you exercise them?

Requests to access, correct, or delete personal data are handled manually. Contact privacy@valuerampai.com. We will respond as promptly as we are able.

There is deliberately no number in that sentence. ValueRamp has no automated export, no self-service erasure and no request-tracking system, so a fixed-deadline commitment would be a promise with no mechanism behind it. When those exist, this policy will say so and give a figure.

Two further specifics, stated because they are the kind of thing usually left vague. Deleting an account is a soft delete — the data is archived rather than removed. And the nearest thing to an objection mechanism is the per-account “do not analyze” flag, which is set by the customer’s administrator rather than by the individual, and which stops analysis without stopping storage.

Consent

Workspace administrators must explicitly enable Communication Intelligence. An optional consent acknowledgement is available in settings.

Because ValueRamp is the processor here, the obligation to establish a lawful basis for ingesting a conversation — and to tell the people in it — sits with the customer who enables the feature, not with ValueRamp. The Data Processing Agreement states that allocation directly.

Cookies and the public website

The pages on this website set no analytics or advertising cookies and run no tracking scripts. The product at valuerampai.com/login sets cookies that are strictly necessary to keep you signed in and to remember your display theme. The theme preference is stored in your browser only.

Changes to this policy

When this policy changes materially, the effective date at the top changes with it. If you are a customer, we will tell you rather than relying on you noticing.

Contact

Privacy questions and data-subject requests: privacy@valuerampai.com. Anything else about the product: get in touch.