Skip to main content

Privacy Policy

Last updated: 29 July 2026

1. What we collect

Account data (such as email and name), usage and diagnostic data, and the data a workspace uploads or receives (such as leads, messages, media, campaign metadata, and provider events). When an owner connects an external provider, we also process the selected external identity, assets, granted permissions, and encrypted credentials needed to operate that connection. We do not sell customer data.

2. How we use it

To provide and secure the Service, route data to the correct tenant and venue, perform actions an authorized user requests, process payments, provide support, and improve product quality. We use aggregated or de-identified data for product analytics where appropriate.

3. Your rights (GDPR)

Available product data can be viewed, corrected, or exported using the relevant product tools. For access, correction, portability, or deletion requests that are not self-serve, follow our data-request instructions.

4. Data location and sub-processors

Primary application data is stored in the configured Supabase EU region. Vercel processes application requests according to the deployment configuration. Stripe may process subscriptions, Resend may deliver email, and a configured SMS gateway may deliver messages. The current subprocessor list describes these operational services. Providers connected by a venue also process data under that venue's provider account and the provider's own terms.

5. Security

We use transport encryption, provider-managed encryption at rest, application-level encryption for reusable provider credentials, role checks, tenant-scoped application logic, and database row-level security. No security control eliminates all risk.

6. Cookies

We use essential cookies to keep users signed in. Operational monitoring and product analytics may process technical request and usage data as described in this policy and any applicable consent controls.

7. Connected providers and data sharing

NamasteSuite sends data to a connected provider only for capabilities selected by an authorized workspace user. Depending on the feature, this may include content and media, hashed audience identifiers, conversion events, messages, leads, or reporting queries. The workspace is responsible for an appropriate lawful basis, notices, consent, and provider-policy compliance.

8. Retention, disconnection, and deletion

Disconnecting clears reusable provider credentials and requests provider-side revocation where supported. Non-sensitive audit, consent, billing, security, and delivery records may be retained for legitimate operational or legal purposes. Account and data requests are handled as described in our request guide.

9. Contact

Questions about privacy can be sent to privacy@namastesuite.com.