Draft v1 — 6 October 2026 — pending founder approval
Privacy policy
Last updated
Who we are
Sambandh (sambandh.ai) is operated by Anurag M, an individual based in India (“we”, “us”). Contact us about privacy at privacy@sambandh.ai. Our grievance officer is Anurag M, at the same address.
Our two roles
- Your account data (who you are, how you sign in, your plan, how you use the service): we decide how it’s used, so we are the controller.
- Your CRM content (the contacts, notes, interactions, deals and follow-ups you store): you decide what goes in, and we process it on your behalf to provide the service. For this data we are your processor (a “service provider” under US state laws and a “data processor” under India’s DPDP Act).
What we collect
- Account data: your email address, name if you give it, timezone, sign-in records and settings.
- CRM content: whatever you or your assistant save: names, companies, titles, email addresses, phone numbers, tags, notes, interactions, deals and follow-ups.
- Usage data: counts and timestamps, such as when your assistant first connected, how many records you’ve created and on which days you used Sambandh, plus which assistant made a change. We use counts, not the content of your records.
- Sign-up source: the referring site and campaign tags (UTM) of your first visit.
- Logs: IP address, the page or endpoint, the response status, the time and the client. Logs never contain CRM content, tool inputs or request bodies.
- Billing data: Dodo Payments, our merchant of record, collects your payment details. We receive your plan, subscription status, amounts and dates. Your card number never reaches us.
- Support and waitlist: emails you send us, and your email address if you join the waitlist.
Please don’t store health information, payment card numbers, government ID numbers, passwords or other credentials in Sambandh. Our acceptable use policy forbids it, and notes containing card or ID numbers are refused.
How we use it, and our legal bases
- To provide Sambandh: store and return your CRM, sign you in, run billing and send service emails (contract).
- To keep it secure and stop abuse: rate limits, logs and fraud checks (legitimate interests).
- To understand and improve the product, using counts rather than the content of your records (legitimate interests).
- To send the waitlist or launch email you asked for (consent; unsubscribe anytime).
- To keep tax and accounting records and meet legal requests (legal obligation).
Your AI assistant
Sambandh works through Claude, a service by Anthropic that you choose and sign in to yourself. When you ask Claude to read or update your CRM, the information it reads becomes part of that conversation. Anthropic handles it under your agreement and settings with them; Anthropic is not our sub-processor.
- On consumer plans (Free, Pro and Max), Claude may use conversations to improve its models unless you turn this off in Claude under Settings › Privacy. Claude’s business plans don’t train on your data by default.
- Claude’s memory features may also keep details it has seen.
- Deleting a record in Sambandh doesn’t delete it from past chats or from Claude’s memory.
We never sell your data or use it to train AI models. Sambandh runs no AI models of its own.
Who we share it with
- Sub-processors that host and run the service, listed with their purpose and location on our sub-processors page.
- Dodo Payments, our online reseller and merchant of record, which processes payments as an independent controller under its own privacy policy.
- Your assistant, when you ask it to read or change your CRM (above).
- Authorities, only when the law requires it. Where allowed, we tell you first.
We don’t sell personal data, and we don’t share it for cross-site advertising.
Our access to your CRM
We don’t look at your CRM content except to fix a problem you report, with your permission, or when the law requires it.
Where your data is stored
Your data is stored in the United States (AWS us-east-1, through Supabase), and the service runs on Vercel in the same region. Sambandh is operated from India: our operator may access systems from India for support and maintenance. Where data protection law requires it, transfers rely on the European Commission’s Standard Contractual Clauses and the UK Addendum.
How long we keep it
| Data | Kept | Then |
|---|---|---|
| CRM content (contacts, interactions, deals, follow-ups) | While your account is open: during free setup, a trial, a paid plan, or read-only after a plan ends | After 12 months with no sign-in and no use from your assistant, we email you 30 and 7 days before, with an export link, then delete it |
| Account you delete | Deleted from the live database at once | Rolls off backups within 7 days |
| A single record you delete | Restorable for 30 days, then purged | Backups as above |
| Sign-in tokens for assistants | Access tokens 1 hour; refresh tokens 90 days | Revoked or expired token records purged after 7 days |
| Security and access logs (no CRM content, no request bodies) | 180 days | Deleted |
| Billing records | 8 years, for tax law | Your email is removed when you delete your account |
| Waitlist emails | Until you unsubscribe, or 12 months after launch if you don’t open an account | Deleted |
| Support email | 3 years | Deleted |
| Sign-up source (referrer and campaign tags) | With your account | Deleted with your account |
Security
Data is encrypted in transit and at rest, every query is limited to your own workspace, and sign-in tokens are stored only as keyed hashes. Details are on our security page.
Your rights
Depending on where you live, you can:
- EU and UK (GDPR): access, correct, delete, restrict or object to processing of your data, take a copy in a portable format, withdraw consent, and complain to your data protection authority.
- US states with privacy laws: know what we hold, get a copy, correct it, delete it, and opt out of sale or sharing (we do neither). We won’t treat you differently for using these rights.
- India (DPDP Act): get a summary of your data, correct and erase it, nominate someone to act for you, and use our grievance process.
You can do most of this yourself: export, edit and delete records, or delete your account from the dashboard. For anything else, email privacy@sambandh.ai. We reply within 30 days and may need to confirm it’s you.
If you are in someone’s CRM
Our users decide what they store about their contacts. If someone’s Sambandh CRM contains your information, contact that person: they control it. If you can’t, write to privacy@sambandh.ai and we’ll pass your request to the account holder, where we can identify them.
Cookies and analytics
We use only essential cookies, such as the one that keeps you signed in to the dashboard. Our site analytics are cookieless and count page views, referrers and campaign tags. We use no advertising pixels.
Do Not Track
We don’t track you across other sites, so Do Not Track and Global Privacy Control signals don’t change anything: everyone gets the no-tracking behaviour.
Children
Sambandh is for people aged 18 and over. We don’t knowingly collect data from children.
If something goes wrong
If we confirm a breach affecting your data, we’ll notify you without undue delay and within 72 hours, with what we know and what you may need to tell your contacts.
Changes to this policy
We’ll email you at least 14 days before a material change takes effect. The date at the top shows when this policy last changed.
Contact
Privacy questions and requests: privacy@sambandh.ai. Grievance officer: Anurag M, privacy@sambandh.ai. General support: support@sambandh.ai.