Privacy Policy
Last Updated: September 12, 2026
01Overview
This Privacy Policy explains how Vesso LLC collects, uses, discloses, and protects information when you use our websites, applications, AI features, meeting tools, analytics, integrations, and related services. Vesso is a business-to-business platform, and many features are used by companies, teams, and workspace administrators.
If you use Vesso through an organization, that organization may control the workspace and determine how your information and Customer Data are processed within Vesso.
02Information We Collect
We collect information in the following categories:
- Account and profile information: name, email address, company, role, login details, preferences, timezone, plan, and billing-related identifiers.
- Workspace and CRM data: accounts, contacts, opportunities, tasks, projects, notes, files, folders, ownership, team assignments, territories, pipeline data, forms, templates, campaigns, cadences, and collaboration activity.
- Meeting data: calendar events, meeting metadata, attendees, meeting links, recordings, audio, transcripts, speaker labels, notes, summaries, action items, decisions, scorecards, sentiment, topics, and related CRM context.
- AI and chat data: prompts, messages, page context, generated outputs, recommendations, feedback, demo chat messages, site chatbot conversations, and usage signals.
- Integration data: information from services you connect, such as Google Calendar, Microsoft Outlook, imported CSV or spreadsheet data, API or webhook metadata, and other connected business systems.
- Advertising account data: when a workspace connects an ad platform such as LinkedIn Ads or Meta Ads, the ad accounts, campaign groups or ad sets, campaigns, budgets, schedules, status, daily performance metrics, and aggregated audience reporting for those accounts, as described in Section 6.
- Prospecting and enrichment data: company, contact, firmographic, role, domain, and business signal information from customer imports, public sources, third-party providers, and enrichment workflows.
- Usage, device, and analytics data: IP address, browser, device, pages viewed, referrer, URLs, campaign (UTM) parameters, paid-click identifiers appended to ad links (such as LinkedIn's li_fat_id, Meta's fbclid, Google's gclid, and Microsoft's msclkid), events, scroll depth, session identifiers, localStorage identifiers, approximate location, timestamps, and interaction data.
- Communications: support requests, contact forms, waitlist submissions, marketing preferences, emails, and other messages you send to us.
03How We Use Information
We use information to:
- Provide, operate, secure, debug, and improve Vesso.
- Create and manage accounts, workspaces, permissions, subscriptions, billing, support, and communications.
- Process CRM records, meetings, transcripts, files, analytics, cadences, campaigns, tasks, and collaboration workflows.
- Generate AI outputs such as summaries, recommendations, prep briefs, follow-up drafts, cadence drafts, scoring, and chatbot responses.
- Operate integrations, imports, exports, APIs, webhooks, calendar sync, tracking scripts, and related connected workflows.
- Provide advertising campaign planning, performance reporting, budget pacing alerts, and campaign management for ad accounts a workspace connects, and measure the performance of Vesso's own advertising.
- Send transactional messages, activity digests, service notices, product updates, and marketing communications where permitted.
- Monitor usage, prevent abuse, enforce terms, protect security, comply with law, and respond to legal requests.
04AI Processing
Vesso's AI features may process Customer Data, page context, CRM data, meeting content, prompts, chat messages, and other information you provide or authorize to generate outputs. We may use third-party AI infrastructure or model providers to deliver these features. Those providers process information on our behalf according to our agreements with them.
Unless we state otherwise in a separate agreement or product setting, Vesso does not sell Customer Data and does not permit third-party AI providers to use Customer Data to train their general-purpose models. We may use logs, feedback, and aggregated or de-identified information to evaluate, secure, and improve Vesso and its AI features.
Information received from LinkedIn's or Meta's APIs is excluded from that improvement use: we do not use it to train, fine-tune, or improve any AI or machine-learning model. Vee may summarize a workspace's own connected campaign data (such as spend, pacing, and results) for the members of that workspace, and may propose ad targeting from the workspace's own go-to-market profile; our AI providers process that data only to generate the requested output under written agreements that prohibit training on it.
05Meeting Recording, Transcription, and Conversation Intelligence
When you use meeting features, Vesso may process meeting audio, recordings, transcripts, speaker labels, calendar details, attendees, CRM associations, notes, summaries, action items, sentiment, scorecards, and follow-up drafts. This information may include personal information about meeting participants who are not Vesso users.
Workspace users are responsible for providing required notices and obtaining required consents before recording, transcribing, analyzing, or sharing meetings. Recordings, transcripts, notes, and shared links may be available to workspace members or external recipients depending on permissions and sharing settings.
06Calendar, Email, and Third-Party Integrations
If you connect Google Calendar, a Gmail or Google Workspace mailbox, Microsoft Outlook, a Microsoft 365 mailbox, an advertising platform such as LinkedIn Ads or Meta Ads, or another integration, Vesso accesses and stores only the information needed to provide the connected workflow, such as event titles, descriptions, attendees, dates and times, meeting links, calendar identifiers, recurrence details, email messages, ad campaign and performance data, OAuth tokens, and related metadata. You can disconnect integrations at any time through Vesso settings or the third-party provider's account settings.
Google user data
When you sign in with Google or connect a Google integration, Vesso accesses only the Google user data you authorize on Google's consent screen:
- Basic profile information (name, email address) to identify your account and label the connected integration.
- Google Calendar (read-only): event titles, descriptions, attendees, dates and times, meeting links, and recurrence details, used to show your events in the Vesso calendar and to power AI meeting prep and the notetaker's auto-join.
- Gmail: message headers, recipients, subjects, and bodies, used to log email conversations with your CRM contacts onto their timelines and to pause outreach cadences when a prospect replies; the ability to send email that you compose in Vesso from your own address; and, where your workspace administrator designates a shared support mailbox, to create and update support tickets from inbound messages to that mailbox and to send ticket replies from that shared address.
How we use it. Vesso uses Google user data solely to provide and improve the user-facing features described above at your request. We do not use Google user data for advertising, do not sell it, and do not use it to develop or train generalized AI or machine-learning models.
How we store it. OAuth tokens are encrypted at rest, and Google user data is stored on access-controlled cloud infrastructure. From a connected Gmail mailbox used for CRM logging, Vesso stores message content only where the message matches a contact or account in your CRM workspace; the content of unmatched messages is discarded, although the counterparty's email address and display name may be retained as a suggested contact where your workspace enables contact discovery. If your workspace administrator designates a mailbox as the workspace's shared support inbox, inbound messages to that mailbox are stored and converted into support tickets in your workspace whether or not the sender matches a CRM record, so that your team can respond to them in Vesso.
How we share it. Google user data is shared only with the service providers that host and operate Vesso on our behalf, with members of your workspace according to its permissions and sharing settings, at your direction, or as required by law. Human access is limited to narrow cases such as your explicit permission, security investigation, abuse prevention, or legal compliance.
How to delete it. You can disconnect Google integrations in Vesso settings or revoke Vesso's access from your Google account permissions. Disconnecting deletes the stored OAuth credentials and stops all further access. Email and calendar records already logged to your CRM remain part of your workspace's Customer Data and can be deleted in the product or by contacting privacy@vesso.ai.
Vesso's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft user data
When you sign in with Microsoft or connect a Microsoft integration, Vesso accesses only the Microsoft account data you authorize on Microsoft's consent screen, via the Microsoft identity platform and Microsoft Graph:
- Basic profile information (name, email address) to identify your account and label the connected integration.
- Outlook Calendar (read-only): event titles, descriptions, attendees, dates and times, meeting links, and recurrence details, used to show your events in the Vesso calendar and to power AI meeting prep and the notetaker's auto-join.
- Microsoft 365 mail: message headers, recipients, subjects, and bodies, used to log email conversations with your CRM contacts onto their timelines and to pause outreach cadences when a prospect replies; the ability to send email that you compose in Vesso from your own address; and, where your workspace administrator designates a shared support mailbox, to create and update support tickets from inbound messages to that mailbox and to send ticket replies from that shared address.
The same commitments described above for Google user data apply equally to Microsoft user data: we use it solely to provide the user-facing features you request; we do not use it for advertising, sell it, or use it to develop or train generalized AI or machine-learning models; OAuth tokens are encrypted at rest; message content is retained only as described above for connected mailboxes and designated support inboxes; sharing is limited to our service providers, your workspace's permissions, your direction, or legal requirements; and human access is limited to the same narrow cases. Vesso's use of information received from Microsoft APIs adheres to the Microsoft APIs Terms of Use.
You can disconnect Microsoft integrations in Vesso settings or revoke Vesso's access from your Microsoft account (personal accounts or work and school accounts). Disconnecting deletes the stored OAuth credentials and stops all further access.
LinkedIn advertising data
When a workspace member connects a LinkedIn Ads account, Vesso accesses only the advertising data authorized on LinkedIn's consent screen:
- Ad accounts: the identifiers, names, and currency of the ad accounts the connecting member manages, used to label the connection and scope reporting.
- Campaign data: campaign groups, campaigns, objectives, formats, budgets, schedules, and status.
- Performance reporting: daily metrics such as impressions, reach, clicks, spend, engagements, video views, leads, and conversions.
- Aggregated audience reporting: impressions and clicks broken down by company, job title, seniority, industry, and company size, exactly as LinkedIn reports them. These are aggregate counts; Vesso does not receive the identity, profile, or activity of any individual LinkedIn member through this integration.
Vesso requests read access to campaigns and reporting and, so that you can pause a campaign or change its budget or end date from Vesso, permission to manage campaigns. Vesso does not create ads, edit creative, or change targeting on your behalf.
How we use it. Vesso uses LinkedIn advertising data solely to provide campaign planning, performance reporting, pacing alerts, and campaign management to the members of the workspace that connected the account, and to show, within campaign performance reporting, which of the workspace's own CRM accounts appear in LinkedIn's aggregated company-level engagement reporting for that workspace's campaigns. That reporting is displayed only as a report on the ad account's performance: we do not write it to contact or company records, use it in lead or account scoring, segmentation, or outreach, use it to enrich or create records, build audiences or profiles from it, use it for our own advertising, or use it to train or improve AI or machine-learning models. We keep LinkedIn advertising data separate from prospecting and enrichment data.
How we store it. OAuth tokens are encrypted at rest. Campaign, performance, and audience reporting data is stored on access-controlled cloud infrastructure and retained for no longer than twelve months from the date it is retrieved from LinkedIn. Organization names resolved from LinkedIn's company-level reporting are retained for no longer than 30 days. Both periods are subject to any shorter period required by LinkedIn's Data Storage Requirements.
How we share it. LinkedIn advertising data is visible to members of the connecting workspace according to its permissions, and is otherwise shared only with the service providers that host and operate Vesso on our behalf, at your direction, or as required by law. We do not sell it or transfer it to third parties. We combine LinkedIn advertising data across workspaces only in aggregated, de-identified form, only to report on campaign performance to our customers, and only with the connecting workspace's agreement. Human access is limited to the same narrow cases described above for Google user data.
How to delete it. You can disconnect LinkedIn in Vesso settings or revoke Vesso's access from your LinkedIn permitted services settings. Disconnecting deletes the stored OAuth credentials and stops all further access, and stored campaign, performance, and audience reporting data for that account is deleted within 10 days of disconnection, of deletion of the workspace, or of a request to privacy@vesso.ai. Campaigns you planned manually in Vesso are Customer Data and are not affected. Vesso's use of information received from LinkedIn APIs adheres to the LinkedIn API Terms of Use and the LinkedIn Marketing API Program terms. Sharing of conversion events from vesso.ai with LinkedIn is described in Section 7.
Meta advertising data
When a workspace member connects a Meta Ads account (Facebook and Instagram advertising), Vesso accesses only the advertising data authorized on Meta's consent screen:
- Ad accounts: the identifiers, names, currency, and Business portfolio names of the ad accounts the connecting member can advertise on, used to label the connection and scope reporting.
- Campaign data: campaigns, ad sets, objectives, optimization goals, budgets, bid strategy, schedules, status, delivery issues, and, where a workspace asks Vesso to create a campaign, the targeting it chose.
- Performance reporting: daily metrics such as impressions, reach, clicks, link clicks, spend, engagements, video views, leads, conversions, and conversion value.
- Aggregated audience reporting: impressions and clicks broken down by age band, gender, country, region, placement, and device, exactly as Meta reports them. These are aggregate counts; Vesso does not receive the identity, profile, or activity of any individual Facebook or Instagram user through this integration.
- Targeting reference data: the interests, behaviors, industries, employers, job titles, locations, Pixels, and existing Custom Audiences available to the ad account, retrieved when you build a campaign in Vesso and not stored beyond the campaign you create.
Vesso requests read access to campaigns and reporting and, so that you can pause a campaign, change its budget or end date, or launch a campaign you planned in Vesso, permission to manage ads. Campaigns created through Vesso are created paused; Vesso does not create ad creative or edit your existing ads.
Custom Audiences from your CRM. If you explicitly ask Vesso to build a Meta Custom Audience from your CRM contacts, Vesso hashes the selected contacts' email addresses with SHA-256 and uploads only the hashes to your ad account as a customer-list audience; Meta matches them to accounts on its side and discards the rest under Meta's Custom Audience Terms. Contacts on your workspace's unsubscribe list are excluded, the action is recorded in your workspace audit log, and no other CRM fields are sent. Vesso never does this automatically.
How we use it. Vesso uses Meta advertising data solely to provide campaign planning, performance reporting, pacing alerts, and campaign management to the members of the workspace that connected the account. We do not write it to contact or company records, use it in lead or account scoring, segmentation, or outreach, use it to enrich or create records, build audiences or profiles from it, use it for our own advertising, or use it to train or improve AI or machine-learning models. We keep Meta advertising data separate from prospecting and enrichment data.
How we store it. OAuth tokens are encrypted at rest. Campaign, performance, and audience reporting data is stored on access-controlled cloud infrastructure and retained for no longer than twelve months from the date it is retrieved from Meta, subject to any shorter period required by Meta's Platform Terms.
How we share it. Meta advertising data is visible to members of the connecting workspace according to its permissions, and is otherwise shared only with the service providers that host and operate Vesso on our behalf, at your direction, or as required by law. We do not sell it or transfer it to third parties, and we do not combine it across workspaces.
How to delete it. You can disconnect Meta in Vesso settings or remove Vesso from your Business integrations on Facebook. Disconnecting deletes the stored OAuth credentials and stops all further access, and stored campaign, performance, and audience reporting data for that account is deleted immediately on disconnection, on deletion of the workspace, or within 10 days of a request to privacy@vesso.ai. Removing Vesso on Facebook notifies us through Meta's deauthorize callback and triggers the same deletion automatically. You can also ask Meta to send us a Data Deletion Request from the same Facebook settings page: Vesso deletes everything it holds from Facebook about your account and gives you a confirmation code with a status page you can check at any time. To request deletion without a Facebook account, email privacy@vesso.ai. Custom Audiences you created live in your Meta ad account and are deleted there. Campaigns you planned manually in Vesso are Customer Data and are not affected. Vesso's use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies. Sharing of conversion events from vesso.ai with Meta is described in Section 7.
09Payments and Billing
Payment information is processed by our payment providers, such as Stripe. Vesso may receive billing contact details, plan information, transaction status, invoices, subscription identifiers, and limited payment metadata. We do not store full payment card numbers on our own systems.
10Data Retention and Deletion
We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes. Retention periods may vary based on workspace settings, plan type, feature, legal requirements, backup schedules, and whether the data is Customer Data, account data, analytics data, billing records, or support communications.
Some categories have fixed limits. Data received from connected third-party services is retained no longer than the provider's terms allow: LinkedIn and Meta advertising data is retained for no more than twelve months from retrieval and deleted on disconnection or within 10 days of a deletion request, as described in Section 6, and stored OAuth credentials for any integration are deleted immediately when you disconnect it. Web analytics paid-click identifiers expire from the visitor's browser after 90 days.
When information is deleted, it may take additional time to remove it from backups and logs. We may retain limited information where required by law, necessary for security, or needed to prevent abuse.
11Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and managed cloud services with encryption at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12Your Choices and Privacy Rights
Depending on your location and relationship to Vesso, you may have rights to access, correct, delete, export, or object to certain processing of your personal information. You may also be able to manage profile settings, integration connections, notification preferences, marketing emails, cookie settings, and workspace permissions in the product.
If your information is controlled by a Vesso customer workspace, we may direct your request to that customer or process it according to their instructions. To exercise privacy rights, contact us at privacy@vesso.ai.
13Marketing Communications
If you sign up for updates, request a demo, join a waitlist, subscribe to emails, or otherwise provide contact information, we may send marketing and sales communications where permitted. You can unsubscribe from marketing emails using the link in those emails. We may still send transactional, security, billing, and service-related messages.
14International Data Transfers
Vesso is based in the United States, and information may be processed in the United States and other countries where we or our service providers operate. Those countries may have data protection laws different from where you live. Where required, we use appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses.
15Children's Privacy
Vesso is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Vesso, contact us so we can take appropriate steps.
16Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice, such as by posting the updated policy, updating the date above, emailing account contacts, or notifying users in the Service.
17Contact Us
Questions? Contact us at privacy@vesso.ai.
Vesso LLC
2525 Arapahoe Ave
Ste E4 #1074
Boulder, CO 80302