Effective Date: 16 May 2026 Last Updated: 18 June 2026 Version: 3.1
1
Who We Are
Spamvora (“we,” “us,” “our,” or the “Company”) is an AI-powered lead intelligence and spam protection platform delivered as a Software-as-a-Service (SaaS) product. The Service is accessed through a WordPress plugin and a cloud-based scoring dashboard.
Spamvora is operated as a sole proprietorship registered in Bengaluru, India. We help businesses and marketing agencies filter spam form submissions, score lead quality in real time, and protect advertising budgets from bot-generated or fraudulent traffic.
Business Name: Spamvora
Business Type: Sole Proprietorship
Country: India (Bengaluru)
Website: spamvora.com
Privacy Contact: info@spamvora.com
For the purposes of the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the UK General Data Protection Regulation (UK GDPR), Spamvora is the Data Fiduciary / Data Controller with respect to personal data collected from our users and website visitors.
2
Applicable Laws and Regulatory Framework
This Privacy Policy is designed to comply with the following laws and regulations:
| Law / Regulation | Applies To |
|---|---|
| Digital Personal Data Protection Act, 2023 (DPDPA) | All Indian users and users whose data is processed in India |
| Information Technology Act, 2000 & IT (Amendment) Act, 2008 | All users — governs data protection, cybersecurity, and electronic commerce in India |
| IT (Reasonable Security Practices) Rules, 2011 | Governs collection and handling of sensitive personal data in India |
| RBI Master Directions on Payment Aggregators & Gateways | Governs payment data handling in partnership with Razorpay |
| Consumer Protection (E-Commerce) Rules, 2020 | Indian consumers purchasing services online |
| General Data Protection Regulation (GDPR) | Users in the EU and EEA |
| UK General Data Protection Regulation (UK GDPR) & Data Protection Act 2018 | Users in the United Kingdom — enforced by the Information Commissioner’s Office (ICO) |
| CAN-SPAM Act (USA) | Email communications to US-based users |
| CASL (Canada) | Email communications to Canadian users |
3
What Personal Data We Collect and Why
We collect only the minimum personal data necessary to provide, operate, and improve the Service. Below is a complete, transparent breakdown of every category of data we collect.
3.1 Account Registration Data
When you create a Spamvora account, we collect:
- Full name — to identify your account and personalize communications
- Email address — for account access, transactional notifications, and support
- Password — stored in strongly hashed (bcrypt) form only; never in plaintext
- Business or website name — to configure your Spamvora workspace
Legal basis (DPDPA 2023 / GDPR / UK GDPR): Consent and contract performance. You provide this data voluntarily to access the Service.
3.2 Payment and Billing Data
All payments for Spamvora subscriptions are processed by Razorpay Software Private Limited (“Razorpay”), an RBI-licensed Payment Aggregator. We do not directly collect, store, or process your full payment card details, bank account numbers, UPI IDs, or CVV/CVV2 codes.
Razorpay’s PCI-DSS certified infrastructure handles all payment card data. We receive only the following transaction metadata from Razorpay:
- Razorpay Payment ID and Order ID
- Subscription plan and billing cycle
- Transaction status (paid, failed, refunded)
- Invoice reference numbers
- Billing country and currency (INR)
- Payment method type (card, UPI, net banking, wallet — not the full details)
Legal basis: Contract performance and legal obligation (GST, tax record-keeping under Indian law).
3.3 Technical and Usage Data
When you interact with our website, dashboard, or API, we automatically collect:
- IP address (used for security and fraud detection; not sold or shared for marketing)
- Browser type and version
- Operating system and device type
- Referring URL and pages visited on our site
- Date, time, and duration of access
- Feature usage patterns within the dashboard
- API request logs (anonymized after 90 days)
Legal basis: Legitimate interests — service performance monitoring, security, and product improvement.
3.4 Spam Detection and Lead Scoring Data
When your WordPress plugin sends form submission data to our API for scoring, our systems process:
- Form field values submitted by your end users (e.g., name, email, phone, message text)
- Submitter IP address and approximate geolocation signals
- User-agent and browser fingerprint data
- Submission timing and behavioral signals
- Traffic reputation indicators
- Anti-bot and bot-behavior signals
This data is processed on your behalf as part of the spam scoring service. You are the Data Fiduciary / Data Controller for your end users’ data. Spamvora acts as your Data Processor / Consent Manager. See Section 10 for full details on this relationship.
Legal basis: Contract performance and legitimate interests.
3.5 Support and Communication Data
When you contact our support team, we collect:
- Your name and email address
- The content of your message or inquiry
- Attachments, screenshots, or error logs you share
Legal basis: Legitimate interests — customer support and service improvement.
3.6 Sensitive Personal Data
Under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, “sensitive personal data” includes passwords, financial information, health information, biometric data, and more. Spamvora:
- Stores passwords only in strongly hashed (bcrypt) form
- Does not collect biometric data, health information, or government identification numbers
- Does not store full financial data — this is handled exclusively by Razorpay under PCI-DSS compliance
- Obtains explicit consent before collecting any data that could be classified as sensitive
4
How We Use Your Personal Data
We use the data we collect for the following specific, lawful purposes only:
- Providing the Service — spam detection, lead scoring, dashboard access, API processing, plugin functionality
- Account management — account creation, authentication, and password resets
- Billing and subscriptions — processing payments through Razorpay, generating GST invoices, managing renewals
- Transactional email — account verification, payment receipts, renewal reminders, security alerts (sent via Resend)
- Customer support — responding to your inquiries, debugging technical issues
- Security and fraud prevention — detecting unauthorized access, preventing abuse, protecting system integrity
- Legal compliance — meeting obligations under DPDPA 2023, IT Act 2000, UK GDPR, GDPR, GST Act, and other applicable laws
- Service improvement — analyzing anonymized usage patterns to improve features and performance
- Marketing communications — only with your explicit, prior consent and only until you withdraw it
5
Email Communications and Anti-Spam Compliance
All emails sent by Spamvora are delivered exclusively through Resend (resend.com), a trusted transactional email platform based in the United States. Resend is SOC 2 Type II certified and GDPR/UK GDPR compliant. We maintain strict compliance with all applicable anti-spam laws globally.
5.1 Transactional Emails (Always Sent)
The following emails are sent as essential service communications and cannot be unsubscribed from while your account is active:
- Account registration confirmation and email verification
- Password reset requests
- Payment receipts and GST invoices (triggered by Razorpay transactions)
- Subscription renewal reminders (14 days and 3 days before annual renewal; 3 days before monthly renewal)
- Subscription cancellation confirmations
- Refund approval or denial notifications
- Critical security alerts (e.g., suspicious login, password changed)
- Plan upgrade or downgrade confirmations
- Service outage or maintenance notices
5.2 Marketing Emails (Opt-In Only)
We send marketing emails — product updates, new features, tips, and promotional offers — only to users who have given explicit, prior consent (opt-in). You may withdraw this consent at any time.
5.3 How to Unsubscribe
- Click the Unsubscribe link in the footer of any marketing email (one-click unsubscribe, RFC 8058 compliant)
- Email info@spamvora.com with subject “Unsubscribe”
All opt-out requests are processed within 10 business days in compliance with the CAN-SPAM Act. UK users’ requests are honored within 30 days per UK GDPR requirements. Indian users’ requests are honored within 5 business days per our DPDPA compliance commitment.
5.4 Our Anti-Spam Standards
✓ All email addresses come only from users who registered directly on our platform
✓ Every email clearly identifies Spamvora as the sender with an accurate subject line
✓ Every marketing email includes valid contact details and an unsubscribe mechanism
✓ We maintain and permanently honor email suppression lists
✓ We monitor bounce rates (<5%) and spam complaint rates (<0.1%) per Resend’s sending policy
✓ All outbound emails are authenticated with DKIM, SPF, and DMARC
✓ Compliant with CAN-SPAM (USA), CASL (Canada), GDPR (EU), UK GDPR (United Kingdom), and India IT Act / DPDPA 2023
6
Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and dashboard. Here is a full breakdown:
| Type | Purpose | Consent Required? |
|---|---|---|
| Essential | Session management, login authentication, security tokens (CSRF protection) | No — required for service |
| Functional | Remembering dashboard preferences and settings | Yes — optional |
| Analytics | Understanding how users navigate the site to improve it (anonymized data only) | Yes — optional |
| Security | Detecting bot traffic, fraudulent activity, and abusive behavior | No — required for security |
You can manage or disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from logging in or using the dashboard. We do not use cookies for cross-site advertising or third-party tracking.
7
How We Share Your Data — Sub-Processors
We do not sell, rent, or trade your personal data. We share data only with the following trusted sub-processors who process data strictly on our behalf, under contractual data protection obligations:
| Sub-Processor | Purpose | Data Shared |
|---|---|---|
| Razorpay Software Pvt. Ltd. India (RBI-licensed PA) |
Payment gateway processing, subscription billing, UPI/card/wallet transactions, GST invoice generation | Name, email, billing country, transaction amount (INR), payment method type |
| Resend, Inc. USA (SOC 2 Type II, GDPR/UK GDPR compliant) |
Transactional email delivery (receipts, account verification, security alerts, renewal reminders) | Email address, email subject and content |
| Amazon Web Services (EC2 / S3 / RDS) India region preferred |
Cloud infrastructure — app hosting, database storage, API processing | Account data, API request logs, spam scoring data |
We disclose personal data to third parties in these additional circumstances only:
- Legal requirement: When required by law, court order, or binding directive from an Indian regulatory authority, the UK Information Commissioner’s Office (ICO), or other competent law enforcement agency
- Safety: When necessary to prevent fraud, protect the rights, safety, or property of Spamvora, our users, or the public
- Business transfer: In connection with a merger, acquisition, or sale of assets — with prior notice to affected users (see Section 7.1)
- With your consent: In any other circumstance where you have given explicit, informed consent
7.1 Business Transfer Notice
If Spamvora undergoes a merger, acquisition, or transfer of substantially all assets, your personal data may be transferred as part of that transaction. We will notify all registered users by email via Resend at least 30 days in advance and provide the option to delete your account before the transfer is completed.
8
Data Storage, Localization, and International Transfers
8.1 Data Storage Location
Our primary infrastructure is hosted on Amazon Web Services (AWS). We prioritize the Asia Pacific (Mumbai) — ap-south-1 AWS region for storing Indian user data, in alignment with the spirit of the DPDPA 2023 and RBI guidelines on data localization.
Transactional emails are delivered via Resend, Inc., whose infrastructure is based in the United States. This transfer is governed by Resend’s Data Processing Agreement and Standard Contractual Clauses (SCCs), ensuring an adequate level of protection for personal data transferred outside India, the EEA, and the UK.
8.2 Payment Data Localization (RBI Compliance)
All payment transaction data processed through Razorpay is stored within India in compliance with the RBI Master Direction on Storage of Payment System Data (2018). We do not store, transfer, or process any payment card data, UPI transaction data, or bank account information on servers outside India.
8.3 International Transfers for EU/EEA and UK Users (GDPR / UK GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data may be transferred to and processed in India and the United States (for Resend email delivery and AWS infrastructure). We ensure all such transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs) or UK Addendum to EU SCCs, as applicable under UK GDPR
- Resend’s Data Processing Agreement incorporating SCCs
- AWS’s Data Processing Addendum incorporating SCCs
- Contractual data protection obligations with all sub-processors
9
Data Retention Schedule
We retain your personal data only as long as necessary for the purposes described in this Policy and to meet our legal obligations under Indian law (GST, Companies Act, IT Act).
| Data Category | Retention Period |
|---|---|
| Account data (name, email, preferences) | Active account duration + 30 days after confirmed deletion request |
| Billing and GST invoice records | 8 years (mandatory under GST Act and Indian tax law) |
| Razorpay transaction metadata | 8 years (RBI and tax compliance) |
| Spam detection / lead scoring data | Up to 90 days, then permanently deleted or anonymized |
| Support correspondence | 3 years from last interaction |
| Server access and API logs | 90 days, then purged |
| Email suppression / unsubscribe list | Indefinitely (to permanently honor opt-out requests) |
| Aggregated / anonymized analytics data | Indefinitely (cannot identify individuals) |
10
Data Fiduciary and Data Processor Relationship
This section is important if you are a Spamvora customer whose website visitors have form data processed through our Service.
- You (the Spamvora customer) are the Data Fiduciary / Data Controller for your end users’ data
- Spamvora is the Data Processor — we process end-user data only to deliver spam scoring results to you
- We do not use your end users’ data for our own marketing, profiling, or commercial purposes
- We do not sell your end users’ data to any third party under any circumstances
- You are responsible for having an adequate privacy notice on your own website
- Enterprise customers requiring a Data Processing Agreement (DPA) — including under UK GDPR Article 28 — may request one by emailing info@spamvora.com
11
Security Measures
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction. These include:
- HTTPS / TLS encryption for all data in transit between your browser, the plugin, and our servers
- Bcrypt password hashing — passwords are never stored in plaintext
- Role-based access controls — data accessible only to authorized personnel with a documented need
- Firewall and DDoS protection on all server infrastructure
- Regular security monitoring and audit logging
- API key authentication for all plugin-to-server communications
- DKIM, SPF, and DMARC authentication on all outbound email sent via Resend
- PCI-DSS compliant payment processing via Razorpay — we never handle raw card data
No method of internet transmission is 100% secure. In the event of a data breach likely to result in risk to your rights, we will notify affected users as required under DPDPA 2023, GDPR, and UK GDPR — and notify the relevant supervisory authority (Data Protection Board of India, the ICO for UK users, or the appropriate EU supervisory authority) where required.
12
Your Rights Under Indian, UK, and International Law
We honor the following rights for all users regardless of location. To exercise any right, email info@spamvora.com with subject “Privacy Rights Request”. We will respond within 30 days and may ask you to verify your identity first.
| Right | What It Means | Available Under |
|---|---|---|
| Right to Access | Request a copy of personal data we hold about you | DPDPA 2023, GDPR, UK GDPR, IT Act |
| Right to Correction | Request correction of inaccurate or incomplete data | DPDPA 2023, GDPR, UK GDPR |
| Right to Erasure | Request deletion of your personal data | DPDPA 2023, GDPR, UK GDPR |
| Right to Withdraw Consent | Withdraw consent for any consent-based processing at any time | DPDPA 2023, GDPR, UK GDPR |
| Right to Data Portability | Receive your data in a structured, machine-readable format | GDPR, UK GDPR, DPDPA 2023 |
| Right to Object | Object to processing for marketing or based on legitimate interests | GDPR, UK GDPR, DPDPA 2023 |
| Right to Nominate | Nominate another person to exercise your rights in case of death or incapacity | DPDPA 2023 (India-specific) |
| Right to Grievance Redressal | Lodge a complaint with our Grievance Officer and escalate to the relevant supervisory authority | DPDPA 2023, GDPR, UK GDPR, CPA 2019 |
- EU/EEA users may lodge a complaint with their local Data Protection Supervisory Authority if unsatisfied with our response.
- UK users may lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint.
- Indian users may escalate to the Data Protection Board of India (once operational under DPDPA 2023).
13
WordPress Plugin Transparency
Spamvora provides a WordPress plugin that website owners may voluntarily install and activate on their own websites. In the interest of full transparency, we confirm that the plugin:
- Does not install automatically — requires manual installation and activation by the website owner
- Does not install hidden software of any kind on the host server or visitor devices
- Does not inject advertisements or modify unrelated site content
- Does not redirect visitors to third-party websites without the site owner’s consent
- Does not execute malicious code or download unauthorized files
- Does not impersonate browser warnings, OS alerts, or security notifications
- Does not modify system settings unrelated to its spam protection function
- Can be disabled or completely uninstalled at any time by the website owner with no residual data stored locally
- Communicates with Spamvora servers exclusively via encrypted HTTPS connections for spam detection and license validation purposes only
Plugin update information is served through:
https://spamvora.com/wp-json/pum/v1/update?slug=spam-vora
14
Children’s Privacy
The Spamvora Service is not directed to children. We do not knowingly collect personal data from:
- Children under 18 years of age (as defined under the DPDPA 2023, which requires verifiable parental consent for minors)
- Children under 13 years of age under COPPA (USA)
- Children under 16 years of age under GDPR and UK GDPR, where applicable
If we discover that we have inadvertently collected data from a child under the applicable age threshold, we will delete it immediately. If you believe a child has submitted data through our Service, contact us at info@spamvora.com immediately.
15
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or service offerings. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page
- Notify registered users by email via Resend at least 14 days before material changes take effect
- For non-material clarifications or minor corrections, post the update without separate notice
Your continued use of the Service after the effective date of any updated Policy constitutes acceptance of the revised terms. We encourage you to review this page periodically.
16
Grievance Officer and Contact Information
In compliance with the Consumer Protection (E-Commerce) Rules, 2020, the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer for privacy-related complaints.
Designated Grievance Officer
Organization: Spamvora
Email: info@spamvora.com
Contact Page: spamvora.com/contact-us
Jurisdiction: Bengaluru, India
Acknowledgment time: Within 48 hours of receiving your complaint
Resolution time: Within 30 days of receiving your complaint
If you are not satisfied with the resolution provided by our Grievance Officer, you may escalate your complaint to:
- The Data Protection Board of India (once established and operational under DPDPA 2023)
- The appropriate Consumer Dispute Redressal Commission under the Consumer Protection Act, 2019 (Indian users)
- The Information Commissioner’s Office (ICO) at ico.org.uk (UK users)
- Your local Data Protection Supervisory Authority (EU/EEA users)
Privacy & Data Requests
Email: info@spamvora.com
Subject: “Privacy Rights Request”
Response: Within 30 days
Razorpay — Payment Data
For queries about payment data specifically handled by Razorpay, contact them directly: