Privacy Policy
Vitaro ("Vitaro," "we," "us") provides CRM software for small sales teams. This policy explains what information we collect through the Vitaro app (vitaroapp.com), why we collect it, who we share it with, and how you can get it deleted. We wrote this to actually describe what the product does, not as a generic template — if something here changes, we'll update this page and the date above.
1. Information we collect
Account information. When you sign up, we collect your email address, name, company name (optional), and a password (handled by Firebase Authentication — we never see or store your raw password).
Pipeline data you enter. Deals, accounts, contacts, notes, activity logs, follow-up tasks, and any custom fields you create. This is the core data the product runs on, and it's owned by you and your team, not us.
Team data. Your team name, invite code, and the roster of who's on your team.
Billing information. Payment is processed entirely by Stripe. We store your subscription status and a Stripe customer reference, never your card number.
Google account data (only if you connect it). Connecting Gmail/Calendar is optional. If you connect it, we request the following Google permissions, and only those:
- Read your Gmail messages (
gmail.readonly) — to auto-log a contact's emails as deal activity - Send email on your behalf (
gmail.send) — only when you click "Send" inside Vitaro, never automatically - Read your Calendar (
calendar.readonly) and create events (calendar.events) — to auto-log meetings and let you schedule from a deal - Your basic Google account email, to confirm which account is connected
You can disconnect Google access at any time from Account settings, which revokes these permissions immediately.
Push notification tokens, only if you opt in to browser notifications.
API keys, only if you generate one to connect Zapier or your own integration.
2. How we use this information
- To run the core product — your pipeline board, accounts, reports, and Health Score
- To send transactional email (password resets, notifications you've opted into, deal emails you send)
- To process payment and manage your subscription
- To generate AI content when you explicitly click a "Generate" button (see Section 4)
- To fix bugs and improve the product
We do not sell your data, and we do not use your pipeline data to train any AI model.
3. Who we share data with
We use a small number of vetted service providers (subprocessors) to run Vitaro. Each only receives the data it needs to do its specific job:
| Provider | What they handle |
|---|---|
| Google Cloud / Firebase | Hosting, database, authentication, backend functions — the infrastructure Vitaro runs on |
| Stripe | Payment processing and subscription billing |
| Resend | Delivering transactional email (deal emails you send, notifications) |
| Anthropic | Powers the optional AI features (deal briefs, summaries, drafts) — see Section 4 |
| Google APIs | Gmail/Calendar sync — only if you connect your Google account |
Zapier and your own integrations. If you generate an API key and set up Zaps or your own integration, data flows to whatever you've configured on your end. That's outside our control once it leaves Vitaro — it's governed by your agreement with Zapier or whatever tool you connected, not this policy.
We do not share your data with advertisers or data brokers, and we don't run any analytics or ad-tracking scripts on this site — there's nothing here to disclose on that front because we don't use any.
4. AI features specifically
Vitaro's AI features (Deal Brief, Account Summary, Task Suggestion, Email Draft) are entirely opt-in — nothing runs automatically. When you click "Generate," the specific deal or account data relevant to that request (activity notes, deal stage, value, timeline) is sent to Anthropic's Claude API to produce the response. That data is used only to generate your result; per Anthropic's own policies, API data isn't used to train their models. We keep a monthly usage cap per team to prevent runaway costs, unrelated to your personal data.
5. Data retention and deletion
If you cancel your subscription, your data isn't deleted — access is simply locked until you resubscribe, so you don't lose your pipeline by pausing payment. You can export your deals to CSV at any time, canceled or not.
We don't yet have a fully self-serve "delete my account" button. If you want your data permanently deleted, email vitarosoftware@gmail.com and we'll delete it and confirm once it's done.
6. How we protect your data
Team data is isolated at the database level using Firestore security rules, not just hidden in the interface — a rep's account can only ever query their own deals, and one team's data is not reachable by another team's account under any normal use of the app. All traffic to Vitaro is encrypted in transit (HTTPS).
7. Cookies
We use Firebase Authentication's session storage to keep you logged in. We don't use third-party advertising cookies or tracking pixels.
8. Children's privacy
Vitaro is a business tool, not directed at children. We don't knowingly collect information from anyone under 16.
9. International data transfers
Vitaro runs on Google Cloud/Firebase infrastructure, which may process and store data in the United States and other countries where Google operates data centers.
10. Your rights
You can access, correct, or export your data at any time from inside the app. To request full deletion of your account and data, or to ask us anything about what we hold, email vitarosoftware@gmail.com.
11. Changes to this policy
If this policy changes in a way that matters, we'll update the date at the top of this page. Continuing to use Vitaro after a change means you accept the update.