Privacy
Last updated 6 September 2026
This describes what we actually do, not what we might do. Where it names a limit — that we never send a customer's name to a model, that we never write an email recipient into the shared registry — that limit is enforced in the software and not merely intended.
Two relationships, and they are not the same
Invologs stands in two different positions to personal data, and almost every question about privacy depends on which one is meant.
You, dealing with us. When you visit this website, book a demo, subscribe, sign up, or run a workspace you pay for, we decide what is collected and why. That is the part this policy governs directly.
Your customers, inside your workspace. The names, addresses, telephone numbers and order histories you record in Invologs are yours. You decide what goes in, what it is used for and how long it stays. We hold and process it on your instructions so the software can work, and we do not use it for anything of our own. If one of your customers wants to know what is held about them, or wants it deleted, the answer has to come from you — we will help you produce it, and we will not act on their instruction over yours.
What we collect from you
When you use this website
- Book a demo — your name, business name, email address, and optionally a telephone number, your trade, roughly how many products you carry, what you use today, and anything you type in the notes.
- Newsletter — your email address, and the fact that you confirmed it by clicking the link we sent. It is a separate opt-in and never a side effect of anything else.
- Find your workspace — the address or workspace name you type, and a short-lived record that the question was asked, which is what lets us rate-limit it. Those records are pruned.
- Signing up — your business name, the workspace name you choose, your name, your email address and your telephone number, plus the plan you picked. A six-digit code is emailed to the address and nothing is created until it comes back.
Cookies and measurement on this website
This site uses Google Analytics, which sets cookies in your browser and tells us how many people reach which page and what they do next. What we look at is counts — how many visitors, to which pages — and we neither ask for nor record anything that identifies you as a person: no name, no email address, no account. We use it to understand whether the site explains the product, and for nothing else. It is not used for advertising, we run no advertising tags, and nothing here is sold or passed to anybody for marketing.
Google receives the data that measurement produces — the pages you viewed, roughly where you were and what kind of device you used — and processes it under its own terms. If you would rather not be counted, your browser's own controls and the extensions built for it will stop it, and the site works exactly the same without it.
Your workspace is not measured at all. Measurement stops at this website. Once you sign in to Invologs there is no analytics tag, no measurement id and no request to any analytics provider — not a screen you opened, not a button you pressed, not an anonymised version of either. There is nothing to opt out of, because nothing is collected.
That is the same boundary the AI layer keeps, for the same reason: your workspace holds somebody else's business data, held on your instruction, and a third party who is not a processor of yours has no business receiving any of it — including which screens you look at.
The site also stores a short list of workspaces you have looked up, kept on your own device so the finder can offer them again — a server-side list of which workspaces a browser had visited would be a customer list, so there is not one. Fonts are served from our own domain rather than a font CDN, which is a choice made so that loading a page does not disclose your address to a third party.
When you have a workspace
- Account — the organization, its display name, the plan it is on, when a trial ends, and the settings that make integrations work. Credentials among those settings are stored encrypted and are never returned in readable form by any interface.
- Users — the name, email address and role of everybody you give access to, and when they last signed in. Passwords are stored as hashes; we never see one and never send one. A new administrator is created with no password at all and chooses their own through a one-time link that expires.
- Billing — what you were charged, how much of it was tax, the invoice number, the gateway's reference, and the billing name, address and tax registration you give us for the receipt. We never receive or store your card details — the payment happens on the gateway's own page.
- Usage we count — how many orders, products, users, locations and outgoing emails your plan has used, so the plan can be enforced and so you can be warned before a limit rather than at it. Our record of email usage counts messages and their purpose and never records who they were sent to: the allowance needs to know how many, not to whom, and copying your contacts into a registry shared across tenants would put them where your workspace boundary does not reach.
- An audit trail of administrative actions — who did what, when. The value of a secret is never recorded; that it was set, by whom, and when is exactly enough.
- Technical — server logs stamped with the organization and a request id. Your browser holds your session tokens and the workspace name you last signed in with, in its own storage, so you are not asked to type them again.
Data inside a workspace
This is the part that belongs to you, and it is worth being specific about what the software will hold if you use all of it: customer names, email addresses, telephone numbers, delivery and billing addresses, tax registrations, credit limits and payment terms, notes you write about a customer, their order and return history, payments, WhatsApp conversations where you use that channel, and any documents you upload.
Each workspace is a separate schema in the database, and which one a request is for is decided before it runs. That separation is structural rather than a filter somebody remembered to add: a query in one workspace cannot reach another's rows by being written carelessly.
Some of what you record is a consent flag — whether a customer agreed to marketing email or messages. The software records the flag and honours it; obtaining the consent is yours. If you send marketing through Invologs, you are the one who has to be able to show it was asked for.
Why we hold it
- To provide the software you have asked for, which is the whole of what workspace data is used for.
- To take payment for it, and to issue a receipt that says what was charged and how much of it was tax.
- To reach you: the code that confirms your address, the link that sets your password, a reminder before a renewal, and a note when something in your workspace needs attention.
- To enforce the plan you are on, which needs counts and nothing else.
- To keep the service working and secure — logs, rate limits, and the audit trail.
- To answer you when you write to us.
We do not sell anything to anybody, and we do not advertise. What you type into the demo form is used to prepare and run your demo. It is not added to a mailing list and it is not passed on.
Who else sees it
Only the services below, only for the part of the job each one does, and only when you use the feature that involves them. Several are switched on per workspace with your own account credentials, which means the data goes to a provider you already have a relationship with rather than to ours.
| Who | What they get | When |
|---|---|---|
| Razorpay | For your subscription: the amount, the plan code and your organization name — no personal data. For a payment link you send your own customer: the amount and, if you supply them, that customer's name, telephone number and email address so the gateway can present the payment to them. | Paying us, and taking money from your customers on your own gateway account. |
| Meta (WhatsApp Business) | The conversation itself — messages, and the telephone number at the other end of them. | Only if you connect WhatsApp, with your own Meta credentials. Meta bills you directly for messaging. |
| ImageKit | Product images you upload, and nothing else. | Only if image upload is configured, with your workspace's own key. |
| Your email provider | The messages you send from Invologs — invoices, quotations, price lists — and their recipients. | Whenever mail goes out. Each workspace sends from its own mailbox. |
| Anthropic | References and figures, never identities — see the next section. The single exception is a document you upload for the agent to read, which is sent as it is. | Only if the AI layer is enabled for your workspace and only for work you or a monitor asked for. |
| Google Analytics | How many people reach which page of this website and what they do next, with the cookies that measurement needs. This website only. Nothing from inside a workspace and nothing about how the application is used — no customer, no order, no figure, no organization name, no screen. | Visiting invologs.com. Never while you are using Invologs. |
| Cloudflare | Requests to this website, and the bot check on the demo form. | Serving invologs.com. It does not host workspace data. |
| Our hosting and database provider | Everything, as the infrastructure it runs on. | Always. |
We will also disclose data where the law requires it. If we are ever compelled to hand over data belonging to a workspace, we will tell you unless we are forbidden from doing so.
The AI layer, and what it is never told
Invologs includes an agent that watches your data and explains what it finds. It is worth reading this section even if you skip the rest, because the rule it describes is unusual and it is enforced rather than promised.
No customer identity ever reaches the model. The agent reasons about references and figures — customer:28, order:412 — and is never told who that is. A name is put back only at the two edges entitled to know it: the database query, which is bound to your workspace, and the screen, which shows it to a person who is already signed in to that workspace.
There are four overlapping layers behind that, and they are all in the code:
- The agent's tools do not select identifying columns at all. A field that is never loaded cannot leak.
- Everything bound for the model passes through one gate. Keys carrying identity are removed, and anything that looks like a name, an email address, a telephone number or an address is removed unless it has been explicitly declared safe. Deny by default, and every removal is recorded.
- A question you type is rewritten before it is stored, because a typed name is the one input no tool stands in front of. A name matching two of your customers is not resolved to either.
- The agent has no search tool, and the module that can turn a name into a record is deliberately unreachable from it.
Your catalogue is not personal data — product names and SKUs are your commercial data, and an agent that cannot name a product writes answers nobody can read, so they are shown by default. You can switch that off. Personal data is never shown whatever that setting says.
Documents you upload are the exception, and it is deliberate. If you give the agent an invoice, a delivery note or a purchase order to read, the file is sent to the AI provider as it is, because a scrubber run over an image corrupts the image rather than protecting anybody. So: a document you upload may be processed by a third-party AI provider, and by uploading it you confirm you have the right to supply it for that purpose. Do not upload a document if you do not. Uploaded files are stored in your own workspace's database rather than in separate file storage, so deleting the record deletes the file.
The agent reads and recommends; it never acts. Nothing it proposes is carried out until a person decides. If the AI layer is not enabled for your workspace, no model is called at all and nothing leaves for one.
How it is kept
- One schema per workspace, selected before a request runs, so isolation is structural rather than a discipline.
- Credentials are encrypted in the database, with a key held by the deployment and never stored beside them.
- Passwords are hashed and never emailed. A new administrator sets their own through a one-time link that expires; the flow exists so that no password ever travels by email.
- Sessions expire, and a refused session ends rather than being renewed indefinitely.
- Verification before creation. Signing up proves the email address with a code before any workspace exists. The code is stored hashed, expires, and dies after a small number of wrong guesses.
- The workspace finder answers identically whether or not an address is registered, so it cannot be used as a list of who our customers are.
No system is perfect. If you believe you have found a weakness, please write to support@invologs.com before disclosing it publicly, and we will work with you.
How long we keep it
- Workspace data — for as long as your workspace exists. Deleting is not uniform inside the product and it is worth knowing which is which: a customer you delete is marked deleted and stays recoverable; products and users are deactivated rather than removed, so their history survives and nothing of yours is destroyed to get back under a plan limit; most other records, when you delete them, are deleted.
- A suspended workspace — if you stop paying, your workspace is suspended, not deleted. Your data stays exactly as it is and comes back when you pay.
- A deactivated workspace — personal data deleted after six months. When a workspace is deactivated, whether you asked us to close it or we closed it after a long-unpaid period, we keep it for six months and then delete the personal data in it: your customers' names, contact details and addresses, the accounts of everybody who had access to the workspace, the conversations, and any documents uploaded to it. Permanently, and not recoverable afterwards.
The six months is deliberate rather than arbitrary — it is long enough for a business that comes back to find its own history intact, and long enough to ask us for an export after somebody has already closed the account. Ask us to delete it sooner and we will.
What survives is our own billing record — what we charged you and the tax invoices we issued you, which tax law requires us to keep for longer. Those are our records rather than your workspace's, and they contain nothing from inside it. - A user you deactivate inside a workspace is a different thing and is not on that clock. Their record stays while the workspace does, because your own history refers to it — an order records who raised it — and it goes when the workspace's data goes, or sooner if you delete it.
- Signups that were never completed — pruned. What they hold is a name, an address and a telephone number for an account that may never exist.
- Workspace-finder requests — kept only long enough to rate-limit, then pruned.
- Billing records and tax invoices — kept for as long as tax law requires them, which is longer than the rest.
- Newsletter — until you unsubscribe, which every send offers.
Your rights
You can ask us what we hold about you, ask for a copy of it, ask for it to be corrected, ask for it to be deleted, and object to a particular use. Write to support@invologs.com and we will answer.
If your question is about data inside somebody's workspace— you bought something from a shop that uses Invologs, and you want to know what they hold — ask the shop. They control that record and we act on their instructions. Tell us and we will point you to them, but we will not change or delete their data on a third party's request.
Where it goes
The service and its database are operated from infrastructure we run. Several of the providers listed above operate outside India, so using those features means data reaching them where they run. If that matters for a particular feature, most of them are optional and switched on per workspace, and you can simply not switch them on.
Children
Invologs is business software and is not intended for anybody under 18. We do not knowingly collect data from children. If you believe a child's data has reached us, write to us and we will remove it.
Changes
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your data, we will tell the account's administrators by email rather than relying on you re-reading the page.
Contact
Privacy: support@invologs.com. Anything else: support@invologs.com. By post: Yubiera Technologies LLP, Ernakulam, Kerala 683101, India.
Yubiera Technologies LLP · Ernakulam, Kerala 683101, India