Legal

Privacy Policy

Last updated: 2026-04-20

1. Who we are

Fairshift is operated by Voltuse Technologies. Registered office: Hyderabad, India. Contact for privacy requests: privacy@fairshift.co.

2. What we collect

We collect three categories of data:

  • Account data: your name, email, company, tenant ID, role.
  • Content data: conversations your AI handles, knowledge documents you upload, lead records you import, files and images.
  • Usage data: timestamps, IPs, browser and device info, and aggregated performance metrics we use to improve the product.

3. How we use it

To run the service: route messages to the right persona, render the dashboard, send transactional email, and bill your account. We do not sell personal data, and we do not use your content to train general-purpose models.

4. Who we share it with

We share data only with sub-processors strictly required to deliver the product. Every sub-processor is listed on our Trust Center. A signed Data Processing Addendum (DPA) is available on request at privacy@fairshift.co.

5. Where we store it

Primary databases are hosted on Supabase (AWS regions). Media lives in Supabase Storage. Transactional email is sent via Resend. Payment records are held by Stripe (USD) and Razorpay (INR). We mirror retention and deletion policies of each sub-processor.

6. Retention

  • Account and billing records: 7 years after termination (as required by tax law).
  • Conversations and messages: 18 months after last activity, or earlier on request.
  • Audit log (activity_log): 24 months; used for debugging, security, and compliance.
  • Deleted accounts: purged within 30 days of deletion request.

7. Your rights

You have the right to:

  • Access the personal data we hold on you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Receive a machine-readable export of your data (portability).
  • Object to processing (GDPR Art. 21).

To exercise any of these rights, email privacy@fairshift.co. We respond within 30 days.

8. Security

All secrets (SMTP passwords, API keys) are encrypted at rest with AES-256-GCM. Transport is TLS 1.2+. Row-Level Security scopes every query by tenant. Only the service role can bypass RLS, and service-role access is limited to server-side code.

9. Cookies

We use strictly-necessary cookies for authentication (session token) and to persist your dashboard preferences. We do not use tracking or advertising cookies.

10. Changes to this policy

We will announce material changes by email to account owners at least 30 days before they take effect. Your continued use of Fairshift after that period means you accept the updated policy.

11. Contact

Privacy questions: privacy@fairshift.co.
Everything else: hello@fairshift.co.