Privacy Policy
Effective date: 31 July 2026 · Last updated: 31 July 2026
This policy explains how Nexshift.ai (the "Service"), operated by YNXT360 CORE LLP ("we", "us"), collects and handles personal data belonging to visitors of our website, customers of our platform, and end users those customers engage through the platform. It also sets out how we handle data from third-party services our customers choose to connect — including Google Workspace, Meta WhatsApp Business, LinkedIn, and Zoom.
1. Who this policy applies to
- Website visitors — people who browse nexshift.ai and its sub-domains.
- Customers — businesses that sign up for the Nexshift.ai platform to run AI voice, WhatsApp, SMS, and chat engagement.
- End users — individuals our customers reach through the platform (for example, borrowers receiving an EMI reminder, students being qualified for a course).
- Connected-account owners — customer employees who choose to connect a third-party account (Google, Meta, LinkedIn) to the platform to enable specific features.
2. Personal data we collect
2.1 Data you give us directly
- Account details: name, work email, phone number, employer, role.
- Billing details: business name, address, GSTIN or other tax identifiers, and payment metadata (payment card numbers are handled by the payment processor and never stored on our servers).
- Support correspondence: the messages you send our team and the attachments you include.
- Content you upload for a campaign: recipient lists, scripts, message templates, product data, and any documents you attach for the agent to reference.
2.2 Data we collect automatically
- Usage data: pages viewed, features used, timestamps, and workflow events.
- Device data: IP address, browser type, operating system, coarse location inferred from IP.
- Cookies and similar technologies (see section 9).
- Call and message telemetry: connection time, call duration, delivery status, dispositions, and transcripts for calls that were made through the platform with the parties' consent.
2.3 Data from third parties
- Meta WhatsApp Business Platform: WABA identifiers, phone-number status, template approval state, and delivery receipts.
- Google Workspace: profile identity, Gmail messages, Calendar events, and Google Drive file metadata — only for the specific scopes an authorised user has approved (see section 3).
- LinkedIn, Zoom, and similar: profile identity and the resources the user chose to connect.
- Telephony carriers: call records and disposition data returned by the carrier that placed the call on our behalf.
3. Google user data — dedicated disclosure
Why we ask for Google account access. Nexshift.ai only requests Google OAuth scopes when a customer's authorised user explicitly chooses to connect their Google account to unlock a specific feature — for example, scheduling meetings from a conversation, drafting a follow-up email, or reading a specific Google Sheet the user selects as a lead source. We do not ask for scopes proactively and we never request permissions broader than what the enabled feature requires.
3.1 What Google data we access
- Profile (
openid, email, profile): the connected account's email address, name, and Google user ID so we can attribute actions to the right account inside the platform.
- Google Calendar (
calendar.events and read scopes): reading availability windows and creating events on behalf of the connected user so the platform can schedule meetings that agents book.
- Gmail (
gmail.send, gmail.compose, and read scopes as required): drafting or sending follow-up messages from the connected user's mailbox, and reading inbound replies to route them back into the workflow the customer configured.
- Google Sheets (
https://www.googleapis.com/auth/spreadsheets): Nexshift.ai reads the header row of a spreadsheet the customer connects, and appends new rows to that same spreadsheet as campaign activity happens (leads captured, reminders sent, call outcomes, webinar attendance). Nexshift.ai does not read spreadsheets the customer has not connected.
- Google Drive (
https://www.googleapis.com/auth/drive.file): Nexshift.ai can see only the spreadsheet files the customer has explicitly selected or that Nexshift.ai has itself created for the customer. This scope gives Nexshift.ai no visibility into any other file in the customer's Drive.
3.2 What we do with Google data
- Provide the feature the user enabled — and nothing else.
- Cache short-lived tokens and the minimum metadata needed to keep the feature working (e.g. calendar IDs the user picked, spreadsheet IDs).
- Log access at a metadata level (which scope was called, when, for which user) for security auditing.
3.3 What we do not do with Google data
- We do not sell, rent, or trade Google user data to any third party.
- We do not transfer Google user data to a third party except as necessary to provide or improve user-facing features, comply with law, or as part of a merger, acquisition, or asset sale with continued equivalent protections.
- We do not use Google user data to serve advertisements.
- We do not allow humans to read Google user data except (a) with the connected user's explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with law, or (d) where the data is aggregated and used for internal operations, and only in accordance with applicable rules.
- We do not train generalised or standalone artificial-intelligence or machine-learning models on Google user data. Any model use is limited to the specific feature the user enabled inside their own account.
3.4 Limited Use compliance
Nexshift.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.5 Revoking Google access and deletion
You can revoke Nexshift.ai's access to your Google account at any time from within the platform (Settings → Connected Accounts → Disconnect) or from your Google account at myaccount.google.com/permissions. On revocation we will:
- Delete stored OAuth tokens for that account within 24 hours.
- Delete cached Google data (calendar IDs, spreadsheet references, cached profile) within 30 days.
- Retain only what is necessary to satisfy legal, audit, or dispute-resolution obligations, in de-identified form where feasible.
If you want your data actively deleted rather than expired, email privacy@nexshift.ai with the connected account and we will confirm deletion within 30 days.
4. How we use personal data
- Provide the platform: run campaigns you configure, place calls, deliver messages, and return outcomes to your dashboards and integrations.
- Operate and improve: diagnose bugs, monitor quality, and improve individual features. Model tuning done on customer data is restricted to that customer's own tenant unless explicit written permission is obtained.
- Communicate: send account, billing, security, and service-status messages.
- Meet legal obligations: retain call recordings, consent artifacts, and DND records for the periods required by RBI, TRAI, and other applicable regulators.
- Prevent abuse: detect fraud, spam, harassment, or violations of our Terms.
5. Sharing and transfers
We do not sell personal data. We share it only with:
- Sub-processors we rely on to run the platform — cloud infrastructure (Amazon Web Services India region), speech providers, messaging carriers, telephony providers, payment processors, and analytics tools. Each is bound by a data-processing agreement and processes data only on our documented instructions.
- Meta (WhatsApp Business Platform) when a customer uses WhatsApp features on the platform.
- Google when a customer uses Google OAuth-enabled features; the payload of every request is limited to the enabled feature.
- Your end users — the recipients you address through the platform receive the messages and calls you configure.
- Regulators and law enforcement when compelled by a valid legal process.
- A successor in the event of a merger, acquisition, or sale of assets, subject to continued equivalent protections.
6. Data residency and cross-border transfers
Customer data for Nexshift.ai's platform is primarily stored in AWS's Mumbai (ap-south-1) region. Some sub-processors (for example certain speech and analytics vendors) may process data in other regions. Where personal data of individuals in the European Economic Area or the United Kingdom is transferred outside those jurisdictions, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
7. Security
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- OAuth refresh tokens and API credentials encrypted with AES-256-GCM before database storage.
- Role-based access control on the internal admin surface, with sensitive operations gated to a small number of super-admins.
- Segregated tenants — one customer's data is never made available to another.
- Continuous logging of admin access and periodic security review of infrastructure.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the applicable regulator within the timelines required by law.
8. Retention
- Account data: retained for as long as the account is active. Deleted (or de-identified) within 90 days of account closure unless legal obligations require longer.
- Call recordings and transcripts: retained per customer configuration, up to a default of 12 months, then deleted.
- WhatsApp and SMS logs: retained per customer configuration; message metadata (delivery, disposition) retained for billing reconciliation.
- Google OAuth tokens: revoked within 24 hours of disconnect; cached Google data purged within 30 days.
- Financial records: retained for the period required by Indian tax law (currently 8 years).
9. Cookies and similar technologies
The nexshift.ai website uses a small number of strictly-necessary cookies for session state and product analytics. We also load Google Tag Manager and Microsoft Clarity for aggregated product analytics. We do not use retargeting cookies. You can control cookies through your browser and opt out of analytics by contacting privacy@nexshift.ai.
10. Your rights
Depending on where you live, you may have the right to access, correct, or delete your personal data, to object to or restrict certain processing, to withdraw consent, and to data portability. To exercise these rights, write to privacy@nexshift.ai. We respond within 30 days and will verify your identity before acting on the request.
If you are an end user of a customer of ours (for example you received a call placed through Nexshift.ai on behalf of a lender), please raise the request with that business first — they are the "data fiduciary" for your data under Indian law. We will assist them in responding.
11. Children
Nexshift.ai is a business platform and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have done so, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we do, we update the "Last updated" date at the top. Material changes are notified to account administrators by email. Your continued use of the Service after a change constitutes acceptance of the updated policy.
13. Contact