Privacy Policy
Last updated: July 2, 2026
Vemra, LLC ("Vemra," "we," "us," or "our") operates the website vemra.ai and provides AI-powered marketing automation services including website generation, blog content creation, social video production, AI chatbot, AI phone receptionist, and lead management (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, password, and business name when you create an account.
- Business Profile: Business description, services, location, industry, phone number, and branding preferences used to generate your website and content.
- Payment Information: Credit card or payment details processed securely through Stripe. We do not store full card numbers on our servers.
- Communications: Emails, support tickets, and chat messages you send to us.
- Phone Numbers: Business phone numbers provided for AI receptionist provisioning and SMS notifications.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, clicks, time spent, and interactions within the Service.
- Device Information: Browser type, operating system, device type, screen resolution, and IP address.
- Cookies: We use essential cookies for authentication and session management, analytics cookies (Google Analytics, Microsoft Clarity) for service improvement, and preference cookies to remember your settings.
- Log Data: Server logs including access times, referring URLs, and error reports.
1.3 Information from Third Parties
- OAuth Providers: If you sign in with Google, we receive your name, email, and profile picture.
- AI Phone Calls: Call recordings, transcriptions, and metadata from Retell AI when your AI receptionist handles calls.
- Lead Data: Information submitted by visitors to your generated website (name, email, phone, message).
1A. Website Analytics & Business-Visitor Identification
Our own websites (including vemra.ai) run a first-party, cookieless analytics pixel we call the vBIG Beacon. It helps us understand which businesses engage with Vemra and improve our marketing. Here is exactly what it does and how we limit it:
- Cookieless local storage.Instead of cookies, the pixel stores a random visitor identifier and basic visit data (a visit counter and your first/last landing page) in your browser's localStorage. This is used to recognize return visits to our site. It contains no name or contact info and can be cleared any time by clearing your browser storage.
- Marketing attribution.We read campaign parameters (UTM tags) and advertising click identifiers (e.g. Google's
gclid, Meta'sfbclid, and equivalents) from the URL to attribute visits to the ad or campaign that referred you. - Form-based identity. When you submit a form on our site containing an email address or phone number, the pixel may transmit that value so we can associate your visit with your inquiry. The email/phone is hashed on our server and the raw value is discarded from the analytics record. This identity feature is suppressed entirely when your browser signals Global Privacy Control (GPC) or Do Not Track (see Section 9A).
- IP-to-company (firmographic) lookup. For B2B analytics, we may resolve the network address (IP address) of a request to the organization or company that operates it (for example, company name, website domain, and network/ASN), using providers such as IPinfo and ipapi.co. We do not store your raw IP address as part of this feature. Only the resolved company-level result is retained. Addresses that resolve to consumer ISPs, mobile carriers, or hosting providers are discarded.
- Third-party visitor identification (RB2B). We may use RB2B, a U.S. business-visitor identification service, to identify the company (and, for some U.S. business visitors, the professional contact) associated with a website visit, so our team can follow up on business interest. RB2B operates its own technology on our site subject to its own privacy practices (see rb2b.com). This feature is used for business (not consumer) contexts and is suppressed under GPC/Do Not Track. You can opt out of this and all identification via Your Privacy Choices.
These identification features apply to our own Vemra websites. Websites we generate and host for our customers run only the cookieless analytics and lead-capture described above unless the customer states otherwise in their own privacy policy.
2. How We Use Your Information
- Generate and host your AI-powered website, blog content, and social videos.
- Provision and operate your AI phone receptionist and chatbot.
- Capture, store, and deliver leads from your website to your dashboard.
- Send lead notifications via email and SMS (with your consent).
- Process payments and manage your subscription.
- Provide customer support and respond to inquiries.
- Analyze usage patterns to improve and develop new features.
- Detect, prevent, and address technical issues and security threats.
- Comply with legal obligations.
3. AI-Generated Content
Vemra uses artificial intelligence (powered by Anthropic Claude, OpenAI, and other providers) to generate websites, blog posts, social videos, and carousels based on your business profile. Your business information is sent to these AI providers solely for the purpose of content generation. We do not use your business information to train AI models. Generated content is stored on our servers and belongs to you per our Terms of Service.
4. AI Phone Receptionist & Call Recording
If you enable the AI phone receptionist feature, calls to your business number are answered by Retell AI. All calls are recorded and transcribed for quality assurance, lead capture, and compliance purposes. Call recordings are stored securely and accessible only to you through your dashboard. Callers are informed that the call may be recorded. You are responsible for compliance with local call recording laws in your jurisdiction.
5. SMS & Text Messaging
With your explicit consent, we send SMS messages including lead notifications, website demo links, and follow-up messages. See our SMS Terms for complete details on consent, frequency, and opt-out procedures. We do not sell, rent, or share your phone number with third parties for marketing purposes.
6. Data Sharing & Disclosure
We do not sell your personal information. We share data only with:
- Service Providers: Vercel (hosting), Stripe (payments), Retell AI (phone), Anthropic/OpenAI (content generation), Twilio (SMS), HeyGen/ElevenLabs (video), Google Analytics, Microsoft Clarity.
- Analytics & Visitor Identification: IPinfo and ipapi.co (IP-to-company firmographic lookup) and RB2B (U.S. business-visitor identification), as described in Section 1A. These operate on our own websites for B2B analytics; raw IP addresses are not retained by the IP-to-company feature.
- Legal Requirements: When required by law, subpoena, or government request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- With Your Consent: Any other disclosure you specifically authorize.
7. Data Retention
- Account Data: Retained while your account is active and for 30 days after deletion.
- Generated Content: Retained while your account is active. Exported content remains yours after account closure.
- Call Recordings: Retained for 90 days, then automatically deleted unless you download them.
- Lead Data: Retained while your account is active.
- Usage Analytics: Aggregated data retained indefinitely; personal identifiers removed after 26 months.
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest for sensitive data, secure password hashing (bcrypt), role-based access controls, regular security audits, and DDoS protection via Vercel/Cloudflare. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update or correct inaccurate data.
- Deletion: Request deletion of your personal data (subject to legal obligations).
- Portability: Receive your data in a structured, machine-readable format.
- Opt-Out: Unsubscribe from marketing emails and SMS at any time.
- Restrict Processing: Request that we limit how we use your data.
To exercise these rights, contact us at privacy@vemra.ai or use Your Privacy Choices.
9A. Global Privacy Control & Do Not Track
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of the sale/sharing of personal information and of cross-context behavioral tracking. We also honor the legacy Do Not Track (DNT) signal. When your browser sends either signal, our analytics pixel automatically disables its identity and visitor-identification features. It will not fire form-based identity, will not transmit raw email or phone, and third-party identification is suppressed. Only cookieless, non-identifying analytics continue. No action or account is required. The signal is respected automatically.
10. California Privacy Rights (CCPA/CPRA)
California residents have the right to know what personal information we collect and how we use it, to request access to and deletion or correction of that information, and to opt out of the "sale" or "sharing" of personal information (including sharing for cross-context behavioral advertising). We do not sell personal information for money. Some of the analytics and business-visitor identification described in Section 1A may constitute "sharing" under California law.
You may exercise these rights, including the right to opt out, by using Your Privacy Choices or emailing privacy@vemra.ai. As described in Section 9A, we also honor the Global Privacy Control (GPC) browser signal as a valid opt-out. We will not discriminate against you for exercising any of these rights.
11. Children's Privacy
Vemra is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
12. International Users
Vemra is operated from the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US. By using the Service, you consent to this transfer.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Continued use of the Service after changes constitutes acceptance.
14. Contact Us
If you have questions about this Privacy Policy, contact us at: