Privacy Policy

Last updated: November 4, 2024

1. Data Controller

VapiWrap is operated by Threesixtyvue ("Company," "we," "us," or "our"). Threesixtyvue is the data controller responsible for your personal information collected through the VapiWrap platform (the "Service").

Data Controller: Threesixtyvue

Product Name: VapiWrap

Privacy Contact: privacy@vapiwrap.com

2. Introduction

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

3. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when using our Service, including:

  • Account registration information (name, email address, business name, website URL)
  • Payment and billing information processed through our third-party payment processor (Stripe)
  • Customer data you upload or create within the Service
  • Communications you send to us (support requests, feedback, inquiries)
  • White-label customization data (logos, color preferences, domain settings)

2.2 Automatically Collected Information

When you access our Service, we automatically collect certain information, including:

  • Usage data (pages visited, features used, time spent, interaction data)
  • Device information (IP address, browser type, operating system, device identifiers)
  • Log data (access times, error logs, referral URLs)
  • Cookies and similar tracking technologies (see Section 7)

2.3 Third-Party Service Data

When you connect third-party services (such as Vapi, Stripe, or other integrations), we may collect:

  • API credentials and access tokens
  • Data synced from connected services
  • Usage metrics from integrated platforms

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, maintain, and improve our Service
  • To process payments and manage subscriptions
  • To communicate with you about your account, updates, and support
  • To monitor usage patterns and optimize performance
  • To detect, prevent, and address technical issues or fraudulent activity
  • To enforce our Terms of Service and protect our legal rights
  • To comply with legal obligations and regulatory requirements
  • To send marketing communications (with your consent, where required)
  • To develop new features and analyze Service performance

4. Data Sharing and Disclosure

4.1 Third-Party Service Providers

We share your information with trusted third-party service providers who assist us in operating our Service:

  • Supabase: Database and authentication services
  • Stripe: Payment processing and billing
  • Vapi: Voice AI integration and usage tracking
  • Vercel: Application hosting and infrastructure
  • Email service providers: Transactional and marketing emails

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice on our Service before your information is transferred.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, government agencies).

4.4 Protection of Rights

We may disclose your information when we believe it is necessary to:

  • Enforce our Terms of Service
  • Protect our rights, property, or safety
  • Investigate fraud or security issues
  • Protect the rights, property, or safety of our users or others

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication mechanisms and password hashing
  • Regular security audits and vulnerability assessments
  • Access controls and role-based permissions
  • Monitoring for unauthorized access or suspicious activity

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You acknowledge and accept this inherent risk when using the Service.

6. Data Retention

We retain your information for as long as necessary to:

  • Provide you with the Service and maintain your account
  • Comply with legal obligations (e.g., tax, accounting, regulatory requirements)
  • Resolve disputes and enforce our agreements
  • Support business operations and legitimate interests

When you delete your account or request data deletion, we will remove or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, financial records).

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. Types of cookies we use:

  • Essential cookies: Required for the Service to function (authentication, session management)
  • Analytics cookies: Help us understand usage patterns and improve the Service
  • Preference cookies: Remember your settings and customizations

You can control cookie settings through your browser. Note that disabling cookies may limit your ability to use certain features of the Service.

8. Your Data Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data in a machine-readable format
  • Objection: Object to processing of your information for certain purposes
  • Restriction: Request restriction of processing under certain circumstances
  • Withdraw consent: Withdraw consent where processing is based on consent

To exercise these rights, please contact us at privacy@vapiwrap.com. We will respond to your request within 30 days.

9. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately so we can delete it.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to the transfer of your information to the United States and other countries where we or our service providers operate.

We take appropriate safeguards to ensure your information receives adequate protection in accordance with this Privacy Policy and applicable laws.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last updated" date
  • Sending you an email notification (for significant changes)
  • Displaying a prominent notice within the Service

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@vapiwrap.com

Website: https://vapiwrap.com

Address: VapiWrap, [Your Business Address]

13. Specific Regional Disclosures

13.1 California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information (subject to certain exceptions)
  • Right to opt-out of the sale of personal information (we do not sell your information)
  • Right to non-discrimination for exercising your CCPA rights

13.2 European Union Residents (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including those described in Section 8. Our legal basis for processing your information includes:

  • Contract performance: Processing necessary to provide the Service
  • Legitimate interests: Improving our Service, fraud prevention, security
  • Legal obligation: Compliance with applicable laws
  • Consent: Where you have provided explicit consent