Skip to main content
Ridhzo — Leads Move Faster

Privacy Policy

At Ridhzo, we believe privacy is foundational to building a high-velocity sales CRM. This policy transparently outlines how we collect, process, isolate, and safeguard your data.

Last updated: September 20, 2026
Effective: September 20, 2026
v2.1

1. Overview & Scope

This Privacy Policy governs the access to and usage of the Ridhzo CRM platform, including our marketing website (ridhzo.com), the Ridhzo Mobile Progressive Web Application (PWA), cloud workspace instances, webhooks, and REST APIs (collectively referred to as the "Service" or "Platform").

Ridhzo ("we", "us", or "our") provides high-velocity mobile lead management, automated lead ingestion, pipeline tracking, and instant WhatsApp follow-up tooling for sales professionals, real estate brokers, marketing agencies, financial advisors, and independent business owners.

Core Commitment: We never sell, rent, monetize, or cross-train machine learning models on your lead data. Your leads belong exclusively to your tenant workspace.

2. Data Controller vs. Data Processor

Under international data protection frameworks, our role depends on the category of data being processed:

Ridhzo as Data Controller

We act as the Data Controller for your workspace administrative data: subscriber account registration, team member email addresses, billing invoices, and website usage telemetry.

Ridhzo as Data Processor

For the end-customer leads you capture (prospect names, phone numbers, notes, ad attributes), you (the subscriber) are the Data Controller, and Ridhzo acts strictly as a Data Processor under your operational instructions.

3. Information We Collect

We collect information in three distinct categories:

A. Workspace Account & Billing Data

  • Name, professional email address, and mobile phone number for authentication.
  • Workspace business name, industry vertical, and team seat allocations.
  • Payment transaction tokens, billing address, and tax identification (GSTIN / VAT numbers). We do not store full credit card numbers; transactions are handled by PCI-DSS Level 1 certified gateways.

B. Ingested Lead Data

Data captured automatically from your connected lead acquisition sources or uploaded manually:

  • Full name, phone number (standardized into E.164 format), and email address.
  • Ad campaign metadata: Form ID, Page ID, Ad Set ID, Platform Source (Meta, Google, Webhook, Form).
  • Custom fields defined by you (e.g., budget range, property type, location, consultation notes).
  • Pipeline progression timestamps, status transitions, and response latency SLA timers.

C. Technical & Device Data

  • Browser user agent, IP address, operating system, and screen resolution.
  • Web Push notification subscription endpoint tokens for vibrating instant alerts.
  • Local device IndexedDB / Cache storage tokens used for offline outbox synchronization.

4. Meta, Google & WhatsApp Integrations

Ridhzo integrates deeply with advertising networks and messaging channels. Each integration complies with the respective platform provider policies:

Meta (Facebook & Instagram) Lead Ads

When you connect Meta Lead Ads via OAuth or incoming webhooks, we verify incoming SHA-256 HMAC payload signatures. We extract the ad form responses and route them directly to your isolated workspace. We do not utilize Facebook lead data for ad retargeting or third-party profiling.

Google Ads Lead Form Extensions

We process webhook payloads authenticated via Google Ads Webhook Keys. Lead records are stored solely in your tenant account to facilitate your sales team's follow-up.

WhatsApp Messaging (`wa.me` & Watxio API)

When reps tap "Contact on WhatsApp", Ridhzo initiates a secure client-side deep link (wa.me/<number>?text=<encoded_template>) or transmits through official WhatsApp Cloud APIs. You are responsible for ensuring consent from prospects prior to outbound messaging in compliance with WhatsApp Business Messaging guidelines and applicable anti-spam laws.

5. How We Use Your Information

We process data exclusively for legitimate operational purposes:

  • Ingesting and routing leads within sub-minute SLAs to your designated sales reps.
  • Dispatching push notifications to your mobile phone when a new inquiry arrives.
  • Synchronizing pipeline deal progression and flagging inactive prospects with "Going Cold" alerts.
  • Processing recurring subscription invoices and verifying authorized seat counts.
  • Providing responsive technical customer support and troubleshooting webhook failures.
  • Maintaining system integrity, preventing brute-force authentication attacks, and enforcing rate limits.

6. Data Isolation & Cryptographic Security

We employ defense-in-depth architectural safeguards to protect your business information from unauthorized access, data leaks, or cross-tenant exposure:

  • Tenant-Isolated Postgres: All SQL read and write operations are strictly partitioned by tenant identifier. No workspace can ever inspect, query, or mutate records belonging to another tenant.
  • AES-256 Encryption at Rest: Database volumes, webhook payload logs, and integration tokens are encrypted using industry-standard AES-256 GCM encryption.
  • TLS 1.3 in Transit: All HTTP traffic, mobile PWA API calls, and webhooks are transmitted exclusively over modern TLS 1.3 cryptographic protocols with HSTS enforcement.
  • Offline Outbox Tamper-Resistance: Leads modified on mobile while offline are stored in encrypted browser IndexedDB partitions and dispatched sequentially with conflict-resolution locks upon network reconnection.

7. Data Sharing & Third-Party Sub-Processors

We do not sell personal data to data brokers. We engage a limited set of vetted cloud infrastructure sub-processors who adhere to stringent security obligations:

Sub-ProcessorPurposeSecurity Safeguards
AWS / Neon CloudEncrypted Cloud Hosting & Serverless PostgresSOC 2 Type II, ISO 27001, AES-256
Razorpay / StripeSubscription Billing & Payment GatewayPCI-DSS Level 1 Compliant
CloudflareDDoS Protection, CDN & WAF DefenseEdge encryption, TLS 1.3, SOC 2
Web Push Services (Google FCM / Apple APNs)Cryptographic Mobile Push NotificationsVAPID payload encryption

8. Data Retention & Permanent Deletion

We retain workspace data for as long as your subscription is active. Upon cancellation or non-renewal of your account:

  • Grace Period: Your data remains accessible in read-only mode for 30 days to permit CSV export of your pipeline and contacts.
  • Purge SLA: After 30 days of cancellation or upon verified written request to [email protected], all leads, notes, custom fields, and webhook audit trails are permanently wiped from production databases.
  • Encrypted Backups: Point-in-time database snapshots are rotated out and overwritten within an automated 30-day lifecycle window.

9. Your Rights & Choices

Regardless of your jurisdiction, we respect global data privacy principles including India's Digital Personal Data Protection Act (DPDP Act 2023), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA):

  • Right to Access & Portability: You can export all leads, pipeline statuses, and notes in standard CSV/JSON format at any time directly from workspace settings.
  • Right to Rectification: You can modify or update any prospect or user record instantly.
  • Right to Erasure ("Right to be Forgotten"): You can delete individual leads or request full tenant workspace eradication.
  • Right to Restrict or Object to Processing: You may disconnect ad accounts or disable push alert subscriptions with a single click.

10. Grievance Officer & Regulatory Inquiries

In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the designated Grievance Officer for Ridhzo is:

Grievance & Data Protection Officer

Ridhzo Technologies Pvt. Ltd.

Email: [email protected] (Attn: Data Grievance)

Phone: +91 98201 44520

Hours: Monday – Saturday, 9:00 AM – 8:00 PM IST

Grievances are formally acknowledged within 24 hours and addressed within 15 business days.

Questions or Inquiries?

Our compliance and data protection team responds to all inquiries within 24 hours.