Privacy Policy
Last updated: August 7, 2026
Gozogo ("we", "our", "us") provides a conversational interface over Zoho One
via WhatsApp. This policy explains what data we access, how we use it, and your rights.
1. What We Access
When you connect your Zoho account, we request read-only access to:
- Zoho Books: invoices, payments, bills, estimates, expenses
- Zoho CRM: deals, leads, accounts, contacts, activities
We do not modify, create, or delete any records in your Zoho account. All access
is read-only.
2. What We Store
- Conversation history: Your questions and our answers, for audit
and quality improvement. Stored in our database with tenant isolation (row-level security).
- Account information: Your name, email, phone number, and Zoho
organisation ID for authentication and routing.
- Zoho credentials: OAuth refresh tokens are encrypted at rest
(Fernet encryption) and stored in our database. We never store your Zoho password.
- Billing information: Subscription status and Razorpay subscription IDs.
Payment card details are handled entirely by Razorpay and never touch our servers.
3. What We Do NOT Store
- Your business data (invoices, payments, customer records). We query Zoho in
real-time and do not maintain a copy of your data.
- Payment card numbers, CVVs, or banking details.
- Voice recordings. Voice messages are transcribed and immediately discarded.
4. How We Use Your Data
- To answer your business questions via WhatsApp
- To send proactive reports (daily digests, alerts, weekly summaries) if your
subscription includes them
- To generate collection reminders when you request them
- To improve our metric catalogue and question understanding
5. Third-Party Services
- Zoho: Your data source. Governed by Zoho's privacy policy.
- Meta (WhatsApp): Message delivery. Governed by Meta's privacy policy.
- Anthropic (Claude): AI question understanding. Your question text
is sent to Claude for metric selection. No business data is sent to Claude.
- OpenAI (Whisper): Voice transcription only, if you send voice notes.
- Razorpay: Payment processing. Governed by Razorpay's privacy policy.
6. Data Security
- All communication is encrypted in transit (TLS/HTTPS)
- Zoho credentials are encrypted at rest (Fernet symmetric encryption)
- Database access is isolated per tenant via PostgreSQL Row-Level Security
- JWT authentication with time-limited tokens
7. Data Retention
Conversation history is retained for 12 months from creation. You can request
deletion of your data at any time by contacting us.
8. Your Rights
- Access: Request a copy of your stored data
- Deletion: Request deletion of your account and all associated data
- Revocation: Disconnect your Zoho account at any time via Zoho's
Connected Apps settings
- Portability: Request your conversation history in machine-readable format
9. Contact
For privacy concerns or data requests, contact us at
privacy@gozogo.com.
10. Changes
We may update this policy. Material changes will be communicated via WhatsApp
to active users.