Legal
Privacy Policy
Last updated: 10 July 2026
Stellavix takes your privacy seriously. This policy explains what personal data we collect when you use SolarisCRM, why we collect it, how we use it, and what choices you have.
1. Data controller
The data controller for SolarisCRM is Stellavix, a sole proprietorship registered at 552, Dr. Ambedkar Street, Devsar, Bilimora, Gujarat – 396380, India (GST: 24GKHPR3921J1ZV).
For any privacy-related questions, contact us at rishi@stellavix.in.
2. What data we collect
We collect the minimum data needed to provide and improve the service:
- Account information: Your name, work email address, phone number (optional), and the name of your organisation.
- Usage data: Pages visited within the app, features used, actions taken (e.g., proposals created, deals updated), and session duration. This is used to improve the product and troubleshoot issues.
- Business data you upload: Leads, contacts, deals, proposals, notes, and any other content you create or import into the platform. This data is yours — we process it only to deliver the service.
- Payment information: When you subscribe, payment is processed by Stripe. We do not store your card number or full payment details on our servers. We receive a payment confirmation and a billing reference from Stripe.
- Communication: If you contact us by email or support chat, we keep a record of that correspondence.
3. How we use your data
- To create and manage your account
- To deliver the features of SolarisCRM to you and your team
- To process subscription payments and send invoices
- To send transactional emails (account setup, billing receipts, renewal reminders)
- To respond to support requests
- To analyse aggregate usage patterns and improve the product
- To comply with legal obligations
We do not use your data for advertising and we do not sell it to any third party.
4. Who we share data with
We work with a small number of trusted third-party services to operate SolarisCRM. Each of them processes your data only as necessary for their specific function:
- Stripe — payment processing. Stripe has its own privacy policy and is PCI DSS compliant.
- Firebase (Google) — user authentication and secure session management.
- Third-party AI services — AI-powered features such as draft generation and RFP responses. Content sent to AI features is processed by trusted enterprise AI providers under their data processing terms and is not used to train their models.
We do not share your data with any other third parties without your explicit consent, except where required by law.
5. WhatsApp Business Platform
SolarisCRM integrates with Meta's WhatsApp Business Platform so that customer-facing teams can send and receive WhatsApp messages tied to their CRM records. When your workspace connects a WhatsApp Business Account (WABA), the following applies.
Data we receive from Meta on your behalf:
- Access tokens issued by Meta's OAuth for your WABA (stored encrypted at rest).
- WABA metadata — business name, phone numbers, quality rating, verification status.
- Inbound WhatsApp messages sent to your WABA phone numbers — sender phone number, text or media content, timestamps, Meta message IDs.
- Delivery status callbacks — sent, delivered, read, failed.
- Pricing metadata Meta returns on each conversation, used for cost reporting.
Data we send to Meta on your behalf:
- Outbound WhatsApp messages your team sends via SolarisCRM (text, template, media, interactive).
- Webhook subscription requests + business profile edits you initiate.
Retention: WhatsApp messages are retained for 365 days by default. Workspace admins can shorten this per workspace in WhatsApp Admin settings, or purge on demand.
PII masking: Outbound message bodies pass through an automated PII masker that redacts email addresses, credit card numbers, US SSN patterns, and phone numbers before storage in our database. The raw text is still delivered to the recipient via Meta.
Opt-out: Recipients who reply STOP, UNSUBSCRIBE, CANCEL, END, or QUIT to any of your WABA numbers are automatically flagged as opted-out. SolarisCRM will block further outbound messages to opted-out contacts.
Erasure: Workspace admins can export or permanently erase any contact's complete WhatsApp history from SolarisCRM at any time. Disconnecting a WABA soft-deletes the account record; messages remain under the retention policy above unless explicitly erased.
Sharing: We do not share your WhatsApp data with third parties. Outgoing webhooks that you configure send message events to endpoints you own. We do not sell any data.
Data controller role: Meta acts as a joint processor for WhatsApp messages under its own Business Terms — see WhatsApp Business Policy and Meta Platform Terms. Stellavix is a data processor. Your workspace admin is the data controller for messages sent through your WABA.
6. Cookies
SolarisCRM uses a small number of strictly necessary cookies to keep you logged in and to maintain your session securely. We use httpOnly cookies for authentication — these cannot be read by browser scripts, which protects against cross-site scripting attacks.
We do not use advertising cookies or third-party tracking cookies.
7. Data retention
We keep your account data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for account recovery or export. After that, it is permanently deleted from our systems.
Billing records and invoices are kept for 7 years as required under Indian tax law.
8. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct any inaccurate information
- Delete your account and associated personal data
- Export your business data (leads, contacts, deals, proposals) at any time from your account settings
- Object to any processing you did not consent to
To exercise any of these rights, email us at rishi@stellavix.in. We will respond within 30 days.
9. Security
We use industry-standard measures to protect your data — encrypted connections (HTTPS/TLS), httpOnly authentication cookies, and access controls that limit who within our team can access production data.
No system is completely immune to security incidents. If a breach occurs that affects your data, we will notify you as soon as reasonably practicable.
10. Children
SolarisCRM is a business tool intended for use by adults in a professional context. We do not knowingly collect data from anyone under 18 years of age.
11. Changes to this policy
If we make material changes to this Privacy Policy, we will notify you by email or through an in-app notice before the changes take effect. The "last updated" date at the top of this page will always reflect when the policy was last revised.
12. Contact
For any privacy questions or data requests, contact: rishi@stellavix.in
Stellavix
552, Dr. Ambedkar Street, Devsar
Bilimora, Gujarat – 396380
India