On this page
VGraple CRM handles the names, phone numbers and conversations of your customers. This page states what protects them, in the order that matters, and links to the feature documentation and the legal documents for the detail.
What is encrypted
Personal fields on contacts and leads are encrypted at rest with a field-level key that is kept outside the database and escrowed separately from the servers. Searching by name or phone uses hashed shadow columns, so lookups never require decrypting the table. Backups are encrypted with a second key. All traffic between browsers, the Android app, Meta and the platform runs over TLS.
Who can do what
Three roles ship on every plan: Owner, Admin and Agent, with a permission matrix documented on the security and roles feature page. Sensitive settings (API keys, Meta app secrets, payment credentials) are visible to Owners only. Two-factor authentication with an authenticator app is available to every user and can be required. Sessions expire after 24 hours idle and rotate their tokens.
What is recorded
An audit log records who did what and when: sign-ins, role changes, settings changes, template submissions, broadcasts, exports and deletions. It is on every plan, including Free, under Insights, Audit Log. Outbound webhooks are signed with an HMAC secret so the receiving system can verify they came from your workspace.
How Meta access is handled
VGraple CRM is a Meta Tech Provider. Your WhatsApp Business Account stays yours; the platform holds a system-user token scoped to messaging and management for your assets, and the connection can be revoked from Meta Business Manager at any time. Inbound webhooks from Meta are verified with the app secret before anything is processed.
Backups and recovery
Encrypted backups run continuously with 14-day retention and point-in-time recovery. Restore drills are part of the operating routine, and the system console surfaces backup health as a first-class signal.
Legal
The data processing agreement sets out roles, sub-processors and retention. The privacy policy covers the website and the app. Security disclosures go to [email protected] with "Security" in the subject and are acknowledged within one working day.