Home/Security

Trust

Security and data protection

How VGraple CRM protects customer data: PII encrypted at rest, two-factor authentication, roles, an audit log on every plan, signed webhooks, encrypted backups and a DPA.

By Chirag Darji · Updated 26 Aug 2026 · 2 min read

On this page
  1. What is encrypted
  2. Who can do what
  3. What is recorded
  4. How Meta access is handled
  5. Backups and recovery
  6. Legal

VGraple CRM handles the names, phone numbers and conversations of your customers. This page states what protects them, in the order that matters, and links to the feature documentation and the legal documents for the detail.

What is encrypted

Personal fields on contacts and leads are encrypted at rest with a field-level key that is kept outside the database and escrowed separately from the servers. Searching by name or phone uses hashed shadow columns, so lookups never require decrypting the table. Backups are encrypted with a second key. All traffic between browsers, the Android app, Meta and the platform runs over TLS.

Who can do what

Three roles ship on every plan: Owner, Admin and Agent, with a permission matrix documented on the security and roles feature page. Sensitive settings (API keys, Meta app secrets, payment credentials) are visible to Owners only. Two-factor authentication with an authenticator app is available to every user and can be required. Sessions expire after 24 hours idle and rotate their tokens.

What is recorded

An audit log records who did what and when: sign-ins, role changes, settings changes, template submissions, broadcasts, exports and deletions. It is on every plan, including Free, under Insights, Audit Log. Outbound webhooks are signed with an HMAC secret so the receiving system can verify they came from your workspace.

How Meta access is handled

VGraple CRM is a Meta Tech Provider. Your WhatsApp Business Account stays yours; the platform holds a system-user token scoped to messaging and management for your assets, and the connection can be revoked from Meta Business Manager at any time. Inbound webhooks from Meta are verified with the app secret before anything is processed.

Backups and recovery

Encrypted backups run continuously with 14-day retention and point-in-time recovery. Restore drills are part of the operating routine, and the system console surfaces backup health as a first-class signal.

The data processing agreement sets out roles, sub-processors and retention. The privacy policy covers the website and the app. Security disclosures go to [email protected] with "Security" in the subject and are acknowledged within one working day.

Frequently asked questions

Is customer data encrypted?
Yes. Names, phone numbers and other personal fields are encrypted at rest with a field-level key. Search works through separate hashed shadow columns, so the plaintext never needs to leave the database in the clear for lookups. Transport is TLS everywhere.
Who can see API keys and secrets in my workspace?
Only the Owner role can view sensitive settings such as API keys, app secrets and payment credentials. Admins can manage the workspace without seeing them; Agents never can.
Do you have an audit log?
Yes, on every plan including Free. Every significant action (logins, settings changes, template submissions, broadcasts, exports, deletions) is recorded with the actor, the resource and the time, and is readable under Insights, Audit Log.
Where is the data hosted?
On managed cloud infrastructure with encrypted, off-site backups retained for 14 days and point-in-time recovery. Write to [email protected] for the current sub-processor list and hosting details for a data processing agreement.
Can I delete my data?
Yes. Contacts, conversations and the whole organisation can be deleted from the app; deletion requests by email are honoured too. A data deletion status page is provided for Meta platform requirements.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.