Legal

Privacy Policy

Effective September 5, 2026 · Terms of Service

What we collect, what we do with it, and who else touches it. In plain English first, because a policy nobody reads protects nobody.

In plain English

  • We never sell personal data, and we run no advertising or analytics trackers on optyflo.com.
  • You own the contacts, messages and content in your workspace. We process them only to run your campaigns, flows and events.
  • For your contacts' data we act as a processor on your instructions; for your own account data we are the data fiduciary / controller.
  • Our servers are in India. Shared email delivery runs through Amazon SES in the EU (Stockholm) unless you connect your own SMTP or Gmail.
  • Connected-service credentials and WhatsApp session keys are encrypted at rest. Passwords are stored only as one-way hashes.
  • You can export your data from the app at any time and ask us to delete it by email. Privacy requests are acknowledged within one business day.

The summary is for convenience; the full text below is what governs.

1. Who we are and what this covers

Optyflo ("Optyflo", "we", "us") is a workflow automation platform that also performs the sending: email from your own verified domain, WhatsApp through Meta's Cloud API, automated voice calls, Zoom webinar automation, forms and lead magnets, a CRM with a unified inbox, and an AI builder. Optyflo was formerly marketed as SalesProClub; both names refer to the same service and operator.

This policy covers optyflo.com and its subdomains, the Optyflo web application and API, the open-tracking pixel and tracked links inside emails our customers send, the optional website script a customer may embed for attribution, and every message we transmit on a customer's behalf.

Two roles apply, and they decide what you can ask of us:

  • Account holders — our customers and their team members. For the data you give us to open and run an account, Optyflo is the data fiduciary under India's Digital Personal Data Protection Act, 2023 and the controller under the GDPR where it applies.
  • Contacts — the subscribers, leads, webinar registrants, quiz players and website visitors of our customers. For this data Optyflo is a data processor acting on the customer's documented instructions. The customer decides why and how it is used. If you are a contact, your first point of contact is the business that messaged you; we will help them respond.

2. Information we collect

Data you give us directly:

  • Account data — name, work email, company name, password (stored only as a salted hash), and the email address and basic profile returned by Google if you sign in with Google.
  • Workspace content — contacts (email, phone number, tags, custom fields, notes, deals), templates, campaign copy, automation flows, webinar and quiz definitions, forms and lead magnets, uploaded files and voice recordings, knowledge-base documents you ask the AI builder to answer from, and your unsubscribe / compliance footer settings.
  • Billing data — your plan, any individually purchased modules, and the ledger of metered usage. Paid plans are provisioned by our team rather than through a self-serve checkout, and we do not store card or bank details.
  • Integration credentials — the API keys, OAuth tokens and phone-number identifiers for services you connect: Amazon SES or your own SMTP server, Gmail, Google Sheets, Meta WhatsApp Cloud API, an Indian WhatsApp business service provider such as AiSensy, Obligr voice, Zoom and Razorpay. Section 6 covers how they are protected.
  • Support and marketing — messages you send to hello@optyflo.com, demo-booking and contact-form submissions, and your email address if you join the newsletter from the site footer.

Data we collect automatically:

  • Usage and security logs — sign-in events, IP address, browser and device type, pages and actions in the app, API calls, and an activity log of changes in a workspace. Administrative actions on a customer account are separately audited.
  • Sending and delivery events — sends, deliveries, bounces, complaints, opens, clicks, replies and unsubscribes for the messages you send, returned to us by Amazon SES, Meta, your provider or your own mail server.
  • Presence — a lightweight heartbeat while you have the app open, used for the team-presence indicator and to expire stale sessions.

Data we process on behalf of customers:

  • Contacts and their engagement history — uploaded by CSV, captured by forms and lead magnets, synced from Zoom registrations, or created by inbound email and WhatsApp replies. Optyflo computes an engagement score per contact (hot / warm / cold / dormant) from that history so customers can segment; the score drives no decision with legal effect on the contact.
  • Webinar registrations, live attendance and no-show labels received from Zoom; quiz answers submitted on public quiz pages; and payment events (amount, status, payer identifiers) received from a customer's own Razorpay account to trigger their flows.
  • Voice-call outcomes — answered, busy, no answer, duration and keypress — written back to the contact for calls a customer places through Obligr.
  • Website visits and conversions recorded by the optional attribution script, where a customer has enabled it (section 5).

3. How we use it

  • To provide the service — authenticate you, store your workspace, schedule and deliver messages, run flows, host public forms and quiz pages, and show you analytics.
  • To keep senders healthy — run the automatic warm-up ramp, throttle sends, monitor bounce and complaint rates, suppress addresses that have unsubscribed or hard-bounced, and pause an account whose complaint rate crosses 0.3% or bounce rate crosses 3%, because one bad sender damages deliverability for everyone.
  • To power AI features you invoke — the AI flow builder, campaign and subject-line drafting, WhatsApp template drafting and knowledge-base answers. See section 7.
  • To bill you — record metered usage and produce statements.
  • To secure and improve the product — detect abuse, debug failures, measure which features are used, and prioritise fixes. We use aggregate usage data; we do not build profiles of your contacts for our own purposes.
  • To communicate with you — transactional email about your account (security alerts, delivery problems, sending paused) always; product news only if you opted in, and every such email carries an unsubscribe link.

We do not sell personal data, rent lists, or use customer contact data to market to those contacts ourselves.

5. Cookies, pixels and the attribution script

On optyflo.com and in the app we set only cookies needed to run the service: a session cookie after you sign in, a CSRF token, and short-lived preference cookies. We load no third-party analytics or advertising trackers on our own site and use no cross-site tracking cookies.

Emails sent through Optyflo may include a one-pixel open-tracking image and rewritten tracked links, where the sending customer has those features on. They record the time of an open or click, the message and recipient, and the IP address and user-agent of the request. Every marketing email carries a one-click List-Unsubscribe header and a visible unsubscribe link.

A customer may embed an optional attribution script on their own website to connect sign-ups and revenue back to campaigns. It is designed to be first-party only:

  • It sets one cookie on the customer's own domain (a random visitor id) and uses no third-party cookies.
  • It does no fingerprinting and makes requests to no one but Optyflo.
  • It honours the Global Privacy Control signal and the browser's Do-Not-Track setting: when either is on, the script does nothing at all.
  • Visitor IP addresses are stored only as a salted one-way hash.

Customers who use the attribution script, or who enable conversion uploads to an advertising platform, are responsible for disclosing it in their own privacy notice and obtaining any consent their jurisdiction requires.

6. Security and where data lives

Our application and database servers are hosted in India. Outbound email through our shared infrastructure is relayed by Amazon Simple Email Service in the AWS Europe (Stockholm) region; if you connect your own SMTP server or Gmail, mail leaves from that provider instead. Uploaded files are stored on our servers or, where configured, in Amazon S3.

  • All traffic to and from Optyflo is encrypted in transit with TLS.
  • Passwords are stored as salted one-way hashes and are never recoverable.
  • Integration credentials, OAuth tokens and WhatsApp session keys are encrypted at rest with AES-256-GCM before they reach the database.
  • Public unauthenticated endpoints (form submissions, inbound webhooks, the attribution script) are rate-limited, and inbound webhooks from Zoom, Amazon SES and Meta are signature-verified. Outbound webhooks we send are signed with HMAC-SHA256.
  • Access to production is limited to the people who operate the service, and administrative actions on customer accounts are written to an audit log that survives account deletion.
  • We take rolling backups of the production database and keep them for a short window so that a failed release or corruption can be reversed.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you — and the Data Protection Board of India or another regulator where required — without undue delay.

7. AI features

The AI builder and its related features run on OpenAI: drafting a flow onto the canvas from a description, analysing an existing flow, writing campaign emails and subject-line options, drafting Meta-compliant WhatsApp templates, generating an email theme, and answering questions from a knowledge base you upload.

  • We send OpenAI only the text needed for the request you made — the brief, the flow description, or the relevant excerpts of your knowledge base. We do not send your contact list.
  • OpenAI processes this under its API terms, which do not permit it to train on API inputs and outputs.
  • AI output is a draft. A generated flow stays a reviewable draft until you explicitly promote it, and you are responsible for reviewing anything generated before it is sent.
  • AI generation is capped per workspace per day and per month; the ceilings depend on your plan and are visible in your account.

8. Who we share data with (subprocessors)

We share personal data only with the providers below, only as needed to run the feature you use, and under contracts that restrict what they may do with it. Several of these are services you connect with your own account; your relationship with that provider is then governed by its terms as well.

  • Amazon Web Services — email delivery (SES) and, where configured, file storage (S3).
  • Meta Platforms — the WhatsApp Business Platform (Cloud API) via embedded signup, using your own WhatsApp Business number, and the Conversions API if you enable ad attribution. Optyflo is a Meta Tech Provider; Meta bills your business directly for WhatsApp conversations and we do not meter them unless we have agreed otherwise in writing.
  • Indian WhatsApp business service providers (for example AiSensy) — template messaging when you connect such an account.
  • Obligr — automated outbound voice calls to Indian numbers when you connect an Obligr account.
  • Zoom — meeting creation and binding, registrant sync, attendance and live-session events for your webinars.
  • Google — sign-in with Google, sending from your Gmail mailbox (send scope only), reading and writing the Google Sheets you choose, and Google Ads conversion uploads if you enable them. See the Google note below.
  • Razorpay — receiving payment.captured, payment.failed and order.paid events from your own Razorpay account to trigger flows and attribute revenue. We never see card details.
  • TikTok — Events API conversion uploads, if you enable them.
  • OpenAI — the AI features in section 7.
  • Our hosting, DNS and email-domain providers, and the accounting providers we use to invoice you.

Google API Services: Optyflo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail access only to send the messages you compose or schedule, Sheets access only to read and write spreadsheets you choose, and Drive read access only to list files you pick. We never read your inbox and never transfer Google user data to third parties except as needed to provide those features.

Ad-conversion uploads to Meta, Google and TikTok transmit hashed identifiers (for example a SHA-256 of a lowercased email) plus event details; the platform matches them against its own users. These uploads are off unless you turn them on and connect the ad account.

We may also disclose data when the law requires it, to enforce our Terms, to protect the rights or safety of Optyflo, our customers or the public, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.

9. International transfers

Your data is stored in India. Email relayed through our shared Amazon SES account passes through the EU (Stockholm). The providers in section 8 may process data in the United States or other countries where they operate. Where the GDPR applies we rely on the providers' Standard Contractual Clauses or an adequacy decision; where the DPDP Act applies we transfer only to countries not restricted by the Central Government.

10. Retention

  • Account and workspace data — kept while your account is active.
  • After you close your account or ask us to delete it — the workspace and the data in it are removed from live systems within 30 days, and from backups when those backups age out shortly after.
  • Suppression records — email addresses and numbers that have unsubscribed, bounced or complained are kept so the opt-out keeps being honoured even after the surrounding contact record is deleted.
  • Invoices, usage ledgers and admin audit logs — kept for as long as Indian tax and company law require, in a form that no longer links to a deleted workspace where possible.
  • Attribution visitor records and conversion events — retained per the customer's own settings; the first-party visitor cookie expires after 400 days.
  • Security and access logs — rotated on a rolling basis and kept no longer than needed to investigate incidents.

Free accounts that stay inactive for a prolonged period may be deleted after we email a warning to the address on file.

11. Your rights

Wherever you are, you can ask us to access, correct, export, restrict or delete the personal data we hold about you, to object to processing based on legitimate interests, and to withdraw consent you previously gave. Under the DPDP Act you may also nominate someone to exercise these rights for you. Under the GDPR you may complain to your supervisory authority; under the CCPA you may opt out of "sale" or "sharing" — we do neither — and you will not be discriminated against for exercising a right.

  • Account holders — most of this is self-service. Update your profile in Settings, take a full CSV of your contacts, replies and deals out of Settings without asking anyone, revoke any connected integration from Account → Connections, and delete an API token from Developer settings. To close the account or for anything else, email hello@optyflo.com from the address on the account.
  • Contacts of our customers — reply STOP or use the unsubscribe link in any message, or contact the business that messaged you. If you cannot reach them, write to hello@optyflo.com with the business name and we will forward the request and confirm what was done.

We acknowledge privacy requests within one business day and resolve them within 30 days, or tell you why we need longer. We may ask you to verify your identity first.

Grievance Officer: for the purposes of the DPDP Act and the Information Technology Act, 2000, our Grievance Officer can be reached at hello@optyflo.com. Grievances are acknowledged within one business day and addressed within 30 days.

12. Children

Optyflo is a business tool. You must be at least 18 to hold an account, and customers may not knowingly use the service to collect or message data about children under 18 without the verifiable parental consent their law requires. If you believe a child's data has reached us, email hello@optyflo.com and we will delete it.

13. Changes to this policy

When we add an integration, a subprocessor or a new kind of processing, we update this page and the effective date. For material changes we also email account holders at least 14 days before they take effect. Continued use after that date means you accept the updated policy.

14. Contact

Privacy requests, data-processing agreements (DPA), subprocessor questions and everything else: hello@optyflo.com. Privacy questions are answered within one business day.