Legal

Privacy Policy

Last updated January 1, 2026

1. Introduction

Socavi ("Socavi", "we", "us", or "our") is operated by company. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social automation and lead generation platform, and the rights you have under applicable law, including India's Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, company name, and phone number.

2.2 Google Sign-In Data

If you choose to sign in with Google, we receive your name and email address from your Google account for authentication purposes only. This data is used solely to create and manage your Socavi account.

2.3 Google Calendar Data

Connecting Google Calendar is optional, and nothing below happens unless you connect it. It is separate from Google Sign-In: signing in with Google does not give Socavi any access to your calendar.

When you connect it, we request two Google Calendar permissions and no others:

  • See when you are free or busy. We read only the start and end times of blocks marked busy on your primary calendar, so the assistant can offer times you are actually available. This permission does not let us see event titles, descriptions, locations, attendees, or any other detail of your existing meetings, and we do not receive them.
  • Create and manage events. We create the meetings your leads book through the assistant, each with a Google Meet link, and invite the lead to that event.

For meetings booked through Socavi we store the event identifier, its start and end time, its Meet link, and the name and email address the lead gave us, so the booking appears against that lead in your inbox and CRM. We do not store the contents of your existing calendar, and we never read, sell, or share your calendar data for advertising, model training, or any purpose other than providing the booking feature you asked for.

Your Google authorization is encrypted before it is stored and is never sent to your browser. You can revoke it at any time by disconnecting Google Calendar in Socavi under Integrations, or from your Google Account permissions page at myaccount.google.com/permissions. Revoking stops all further access immediately; meetings already created remain on your calendar and are yours to keep or delete.

We do not access your Google Drive, Gmail, contacts, photos, or YouTube data.

2.4 Social Conversation Data

When you connect Instagram, Facebook, or WhatsApp accounts, Socavi processes comments and direct messages to provide AI replies, qualification, and meeting booking. Conversation transcripts are stored securely for analytics, model quality, and audit purposes and are retained according to your plan settings.

2.5 Usage Data

We collect information about how you use our services, including API calls, dashboard interactions, and feature usage.

3. How We Use Your Information

  • To provide and maintain our social automation and lead-generation services
  • To process and complete transactions
  • To improve our platform and develop new features
  • To communicate with you about updates and support
  • To comply with applicable legal obligations and connected platform policies
  • To detect and prevent fraud or abuse

4. Data Retention

We retain your data only for as long as necessary to provide the service. Account and lead data is retained while your account is active and deleted within 30 days of account closure. Conversation transcripts are retained for up to 12 months unless your plan specifies a shorter period or you request earlier deletion. Some records may be retained longer only where required by law (for example, tax or accounting records), and only for the period the law requires. You can request deletion of your data at any time through our Data Deletion Instructions.

5. Data Security

We implement industry-standard security measures including:

  • Platform access tokens are AES-128 encrypted (encrypt-then-MAC) by our application before they reach the database, using a key held only on our servers. A copy of the database alone does not yield a usable credential.
  • Message content is encrypted at rest in the database under a separate key
  • Storage-level encryption applied by our infrastructure providers
  • TLS 1.2 or higher for all data in transit
  • Row-level security isolating every customer's data at the database layer
  • Access tokens and channel credentials are never returned to the browser
  • HIBP-checked passwords and OAuth-based platform connections

6. Data Sharing

We do not sell your personal information. We share data only with the subprocessors below, each strictly to operate the service:

  • Supabase — database, authentication, and file storage (United States)
  • Render — application and API hosting (United States)
  • Groq — AI inference for agent replies, captions, and lead scoring (United States)
  • Stripe — subscription billing and payment processing (United States)
  • Google Workspace — transactional and notification email (United States)
  • Sentry — error monitoring, where enabled (United States)

We also share data with the social platforms you connect, as required to deliver the messages you have authorized; with the CRM destination you configure; and with legal authorities where required by law.

7. Your Rights

Under applicable data protection laws, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for data processing

8. Third-Party Platform Data (Meta and others)

When you connect a social or messaging account such as Instagram or Facebook, Socavi accesses platform data only through the official APIs and only with the permissions you grant during the connection flow. For Meta platforms this is limited to the connected account profile, messages and comments directed at your connected account, and the platform-scoped identifiers needed to maintain a conversation.

We only process messages and comments that an end user initiates toward your connected account. We do not send unsolicited messages, we do not use this data for advertising, and we do not sell it. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including their limited use requirements.

You can revoke Socavi's access at any time in your platform settings under Apps and Websites. For full detail on how we handle platform data, see our Data Policy. To delete your data, see our Data Deletion Instructions.

9. Subprocessors

We use a limited set of trusted infrastructure providers to operate the service. Each processes data only as needed to provide their function:

  • Supabase - database and authentication hosting
  • Google Workspace - transactional and notification email delivery
  • Stripe - payment processing (for paid plans and payment links)
  • Our AI model provider - generating AI agent replies
  • Our application hosting provider - serving the web application

We do not sell your data and we do not share it with any party other than those listed here, the destinations you explicitly connect (such as your CRM), and where required by law.

10. International Data Transfers

Some of our subprocessors store and process data on servers located outside India. Where data is transferred across borders, we take steps to ensure it is protected by appropriate safeguards consistent with applicable law, including India's DPDP Act and, where relevant, the GDPR. By using the service, you understand that your data may be processed in these locations.

11. Children

Socavi is a business tool intended for use by businesses and professionals aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. Under the DPDP Act, processing the data of a child requires verifiable parental consent; if we learn that we have collected such data without that consent, we will delete it. If you believe a child's data has been provided to us, contact our Grievance Officer below.

12. Grievance Officer (India - DPDP Act)

In accordance with India's Digital Personal Data Protection Act, 2023, you may contact our Grievance Officer with any concern or complaint about how your personal data is handled. We will acknowledge and respond within the timelines required by law.

You can reach our Grievance Officer at hello@socavi.co.
We aim to acknowledge and respond to all grievances within 30 days.

13. Contact Us

For any privacy-related questions or to exercise your rights, contact our Data Protection Officer:

General privacy questions: hello@socavi.co
General support: hello@socavi.co