Trust & data protection

We move messages that carry your customers' personal data. Here is exactly how we protect it — and what we don't claim.

Handling phone numbers and customer records is a responsibility before it is a service. We collect as little as possible, encrypt what we carry, keep every sender accountable, and never sell your data or your customers'. This page states our practices plainly, without security theatre.

Last updated: 20 July 2026

01How we think about it

Most security pages list badges. We would rather list behaviours you can hold us to. Three principles guide how we build and operate:

  • Collect less. Data we never hold cannot be leaked. We do not ask for information we have no operational need for.
  • Encrypt in transit, always. Every connection to our website and APIs is served over TLS. There is no unencrypted path.
  • Say only what is true. We do not claim certifications we do not hold. See section 08.

02What we collect — and what we don't

On this website, we collect only what you choose to send us through the enquiry form: your name, email address, optional phone number, the service you're interested in, and your message.

  • Analytics only with consent. No advertising cookies and no cross-site profiling. We use Google Analytics only if you accept the cookie banner — decline and nothing loads. You can change your mind any time via "Cookie preferences".
  • No accounts. You can browse and enquire without creating one.
  • No profiling or automated decision-making. Your enquiry is read by a person.

Full detail is in our Privacy Policy.

03Encryption and transport

All traffic to vamanasandesh.com and to our messaging APIs is encrypted with TLS. Our website and API endpoints sit behind Cloudflare, which terminates TLS and absorbs volumetric and application-layer attacks before they reach our origin.

API integrations authenticate over HTTPS only. We do not accept credentials or message payloads over unencrypted connections.

04Sending responsibly

A messaging platform is only as trustworthy as the traffic it carries. These are the rules we apply to ours.

  • Consent is the sender's obligation, and we hold you to it. We expect senders to hold valid consent for every recipient, and we will not knowingly carry traffic that doesn't.
  • Accountable sender identities. Sender IDs and message templates are approved before traffic flows, so every message traces back to a named, responsible owner.
  • Tier-1 operator connectivity. Direct operator routes mean fewer intermediaries handling your traffic.
  • No purchased lists. We will not send to data you cannot show a lawful basis for.

05Your rights under the DPDP Act

India's Digital Personal Data Protection Act, 2023 gives you rights over your personal data, and we honour them regardless of where you contact us from. You may request access to your data, ask us to correct it, ask us to delete it, or withdraw a consent you previously gave.

To exercise any of these, email connect@vsandesh.in or use the contact form. We do not charge for these requests.

06Retention and deletion

We keep enquiry details only as long as needed to respond to you and to maintain reasonable business records, after which we delete or anonymise them. You can ask us to delete your data at any point, and we will act on it.

07Third parties we rely on

We keep our supplier list deliberately short, because every additional processor is additional exposure.

  • Cloudflare — hosts, delivers and secures this website, and provides DDoS protection.
  • Google Fonts — serves the site's typefaces. Google may see your IP address as part of that; no cookies are set.
  • Google Analytics — loaded only if you consent, to measure how the site is used. It sets analytics cookies and processes usage data on our behalf; decline or withdraw any time via "Cookie preferences".
  • Telecom operators — carry SMS and WhatsApp traffic over registered, licensed routes.

We do not share your information with any of these for marketing purposes, and we do not sell, rent or trade personal data to anyone.

08What we do not claim

Plenty of vendors imply certifications they have never been audited against. We would rather be straight with you, so that everything else on this page carries weight:

  • We are not currently ISO 27001 or SOC 2 certified. If we pursue certification, we will say so here with the certificate.
  • We do not describe ourselves as "bank-grade" or "military-grade". Those phrases mean nothing specific.
  • We do not promise that any system is unbreachable. No honest provider can.

If a security claim matters to your procurement process, ask us directly and we will answer precisely — including when the answer is "we don't do that yet."

09Reporting a vulnerability

If you believe you have found a security issue in our website, APIs or browser extensions, we want to hear about it before anyone else does.

Email connect@vsandesh.in with the subject line SECURITY, describing what you found and how to reproduce it. We aim to acknowledge reports within two business days. Please give us a reasonable window to fix the issue before disclosing it publicly. We will not pursue legal action against researchers who report in good faith and avoid privacy violations or service disruption.

10Contact

For any security or data-protection question, reach us via WhatsApp +91 63050 64680, our contact form, or by email at connect@vsandesh.in.

Vamana Sandesh · Guntur, Andhra Pradesh, India.