Skip to content
Vestrum

Privacy Policy

Vestrum LLC · Last updated September 20, 2026

This Privacy Policy explains how Vestrum LLC, a Wyoming limited liability company (“Vestrum,” “we,” “us”), collects, uses, discloses, and protects personal information in connection with vestrumllc.com and Vestrum CRM (the “Service”). This Policy applies globally; Sections 11–14 contain disclosures specific to the European Economic Area/Switzerland, Canada, Australia, and California, respectively. The Service is not currently offered in the United Kingdom; see Section 9. If you connect Gmail or Google Calendar, the Google API Services section below also applies.

1. Information We Collect

  • Account and business information, such as name, business name, email, billing information, and KYC/verification information.
  • Customer Data submitted by customers, including contact records, messages, call metadata, recordings, notes, and other CRM information.
  • Usage and technical information, such as IP address, device/browser information, logs, authentication events, and feature usage.
  • Communications with Vestrum, including support requests.
  • Information processed through communications providers and integrations Customer connects, including a linked Gmail inbox, Google Calendar, or Microsoft mailbox, as described in Section 3 for Google APIs.

2. How We Use Information

  • Provide, maintain, secure, troubleshoot, and improve Vestrum CRM.
  • Authenticate users and prevent fraud, abuse, spam, and security incidents.
  • Provision and operate telecommunications, SMS, and email-connection functionality.
  • Verify Customer identity and assess risk (KYC) before provisioning communications features, including for Customers located outside the United States.
  • Process billing and manage subscriptions.
  • Respond to support and legal requests.
  • Comply with law and enforce our agreements.

3. Google API Services (Gmail and Calendar)

This Section applies when Customer or a Customer user chooses to connect a Google account to Vestrum CRM. Connecting Gmail or Google Calendar is optional; Vestrum does not require Google Sign-In to create an account. Vestrum's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Gmail (connected inbox). Vestrum requests https://www.googleapis.com/auth/gmail.readonly (to read INBOX mail, including message bodies, and to maintain a Gmail push watch for new INBOX messages), https://www.googleapis.com/auth/gmail.send (to send email the user composes from that mailbox, as the user's own Gmail address), and https://www.googleapis.com/auth/userinfo.email (to identify the connected account). Data accessed may include the mailbox email address; INBOX message metadata (sender, recipients, subject, timestamps, message and thread identifiers); message body content needed to display conversations in the CRM inbox; and OAuth access and refresh tokens. Vestrum does not change Gmail labels, read/unread state, archive, trash, or drafts, and does not request gmail.modify, Google Drive, Contacts API, Gmail settings, or the mail.google.com IMAP/SMTP scope.

Google Calendar (appointment sync). Vestrum requests https://www.googleapis.com/auth/calendar.events (to read and write events on calendars the user already has, so Vestrum appointments stay in sync) and https://www.googleapis.com/auth/userinfo.email (to identify the connected account). Data accessed may include the calendar email address and event titles, times, attendees, and identifiers.

How Google user data is used. Vestrum uses Google user data only to provide or improve user-facing features that are prominent in Vestrum CRM: displaying the connected Gmail INBOX, sending mail the user composes from that mailbox, receiving Gmail push notifications for new INBOX mail, and creating, updating, and reading Google Calendar events that correspond to Vestrum appointments. Vestrum does not sell Google user data; does not use it to serve advertisements (including personalized or retargeting ads); does not use it to train generalized AI or machine-learning models; and does not transfer it to third parties except as Limited Use allows (to provide those features, for security, to comply with law, or as part of a merger, acquisition, or sale of assets after obtaining any required user consent).

Storage, sharing, and human access. OAuth tokens and synced Gmail or Calendar content are stored with Customer's Vestrum workspace on infrastructure located in the United States (currently including Cloudflare for hosting, network, and security). Synced email content is Customer Data associated with Customer's account. Vestrum personnel are not allowed to read Gmail or Google Calendar user data unless the user has given affirmative agreement to access specific messages or events (for example, to diagnose a support issue the user asked Vestrum to look at); it is necessary for security purposes (investigating abuse, fraud, or a bug); the data is aggregated and anonymized for internal operations; or it is necessary to comply with applicable law.

Disconnecting and deletion. A Gmail mailbox or Google Calendar may be disconnected in the product at any time. Disconnecting Gmail deletes the mailbox connection and the inbox threads stored for that mailbox. Disconnecting Google Calendar deletes the calendar connection and stored tokens; existing Vestrum appointment records are not cancelled solely because a calendar was unlinked. Access may also be revoked in the user's Google Account at https://myaccount.google.com/permissions. To request deletion of Google user data Vestrum holds, disconnect the integration and/or email owners@vestrumllc.com. After account termination, Customer Data (including synced inbox content) is deleted or anonymized within one (1) month in the ordinary course, subject to Section 6.

4. Customer Data and Roles

For Customer Data that a business customer uploads or generates through Vestrum CRM, Vestrum generally processes the data on the customer's instructions as a service provider, processor, or equivalent role under applicable law. The customer remains responsible for determining the lawful basis for its collection and use and for responding to data-subject or consumer requests where applicable. The Data Processing Addendum (“DPA”) governs this processing in more detail.

5. Service Providers and Subprocessors

Vestrum uses service providers including Cloudflare (infrastructure/security) and Telnyx LLC (telecommunications connectivity), and Stripe (payment processing). A current subprocessor list is maintained in the Subprocessor List. Vestrum does not currently use WhatsApp/Meta or a separate transcription/AI-model provider; the Subprocessor List will be updated before any such provider is introduced.

6. Retention

Vestrum's standard post-termination retention targets are one (1) month for Customer Data and three (3) months for call recordings, subject to legal, security, backup, dispute, and accounting requirements, after which data is deleted or anonymized in the ordinary course.

7. Security

Vestrum uses reasonable safeguards, including encryption in transit and at rest and multi-factor authentication where supported, as further described in the Security Overview. No system can be guaranteed completely secure.

8. Regulated and Sensitive Data

Vestrum does not want, and Customer must not submit, protected health information, full payment card numbers, or other regulated sensitive data through the Service except as permitted by a separate written agreement (see Terms of Service Section 4). Vestrum does not currently offer HIPAA Business Associate Agreements or PCI DSS attestations.

9. International Processing and Geographic Scope

Vestrum is a U.S. company and its primary infrastructure is located in the United States. Vestrum and its service providers may process personal information in the United States regardless of where Customer or an end user (such as a contact in Customer's CRM) is located. Where Vestrum processes personal information originating from the EEA or Switzerland, Vestrum relies on the transfer mechanisms described in Section 10.

The Service is not currently offered to businesses located in the United Kingdom, and Customer must not use the Service to contact, or process personal information of, individuals located in the United Kingdom, consistent with Terms of Service Section 2.

10. Cookies

Vestrum uses cookies and similar technologies as described in the Cookie Policy, including a consent mechanism for non-essential cookies where required by applicable law (see Cookie Policy Section 4).

11. EEA / Switzerland — GDPR Disclosures

For individuals in the European Economic Area or Switzerland, Vestrum acts as a data controller with respect to account/billing information it collects directly, and generally as a data processor with respect to Customer Data processed on a business customer's instructions.

  • Legal bases for Vestrum's own processing as controller include performance of a contract (providing the Service), legitimate interests (security, fraud prevention, product improvement), compliance with legal obligations, and consent (for non-essential cookies and optional marketing).
  • International transfers of personal data from the EEA/Switzerland to the United States are made under the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, or Module 4: Processor to Controller, as applicable) and, where applicable, the Swiss Federal Data Protection and Information Commissioner's requirements. Copies are available on request to owners@vestrumllc.com.
  • Data subjects in the EEA have the right to access, rectify, erase, restrict, or port their personal data, to object to processing based on legitimate interests, to withdraw consent at any time, and to lodge a complaint with their local supervisory authority.
  • Where an individual's data is Customer Data controlled by one of Vestrum's business customers, Vestrum will direct the request to the relevant customer and provide reasonable assistance to that customer under the DPA.

12. Canada — CASL and PIPEDA

Vestrum processes personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable. Vestrum does not itself send commercial electronic messages to Canadian recipients on Customer's behalf; Customer, as the sender, is solely responsible for complying with Canada's Anti-Spam Legislation (CASL), including obtaining express or implied consent, providing sender identification, and including a functioning unsubscribe mechanism in every commercial electronic message sent using the Service.

13. Australia — Spam Act and Privacy Act

Customer is solely responsible for complying with Australia's Spam Act 2003, Do Not Call Register Act 2006, and Australian Privacy Principles for any communications sent to or personal information collected from individuals in Australia using the Service.

14. California — CCPA/CPRA Disclosures

This Section applies to California residents and supplements the rest of this Policy.

  • Categories of personal information Vestrum may collect about California residents (in the twelve months preceding the effective date of this Policy) include: identifiers (name, email, IP address); commercial information (billing and subscription history); internet/network activity (usage logs); and, where a resident is a contact within a business customer's CRM, the categories of Customer Data that customer has chosen to store (which may include identifiers, commercial information, and communications content/metadata).
  • Vestrum does not sell personal information and has not sold personal information in the preceding twelve months. Vestrum does not share personal information for cross-context behavioral advertising.
  • Where Vestrum processes personal information on behalf of a business customer as a service provider, Vestrum will not retain, use, or disclose that personal information for any purpose other than performing the services specified in the applicable agreement, will not combine it with personal information from other sources except as permitted by the CCPA, and certifies that it understands and will comply with these restrictions.
  • California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights. Requests may be submitted to owners@vestrumllc.com and will be verified before being processed. Where the request concerns Customer Data controlled by a Vestrum business customer, Vestrum will direct the requester to that customer.

15. Children

The Service is intended for business users and is not directed to children. Vestrum does not knowingly collect personal information from children under 16.

16. Changes

Vestrum may update this Policy from time to time and will provide notice where required, including at least fifteen (15) days' notice before a material change takes effect where reasonably practicable.

17. Contact

Questions or requests regarding this Policy may be directed to Ahmed Tarek Ali, Co-Founder/Manager of Vestrum LLC, a Wyoming limited liability company, at owners@vestrumllc.com.