Privacy Policy
Last updated: 6 October 2026
Cowazo (“Cowazo”, “we”, “us”) is a CRM and business operations platform run by Caasaa AI Innovations Pvt Ltd, a company registered in India. This policy explains what personal data we collect when you use our website www.cowazo.com, the Cowazo app at app.cowazo.com (including workspace addresses on cowazo.com and our customers’ own domains), and our mobile app, and how we use and protect it.
1. Who is responsible for your data
For your Cowazo account, your sign-in and billing, we are the data fiduciary (controller).
For the records a business keeps in its Cowazo workspace — its leads, customers, contacts, calls, messages, invoices and files — that business decides what is stored and why. We process that data on the business’s behalf and only to provide the service to it. If you are a lead or customer of a business that uses Cowazo, please contact that business first about your data; we will help them answer you.
2. What we collect
You give us
- Account details: name, email address, mobile number, password (stored only as a one-way hash), profile photo, and your two-step sign-in setting.
- Workspace details: business name, address, GSTIN or tax numbers, logo, branding and settings.
- Business records you or your team add: leads, contacts, organisations, notes, tasks, meetings, proposals, projects, invoices, payments, tickets, expenses, files and messages.
- Billing details: the plan you choose and invoices we issue. Card, UPI and bank details are entered on our payment provider’s page (PayU, Razorpay or Stripe) and are never stored by us.
- Support requests you send us.
Collected when you use Cowazo
- Sign-in and security data: IP address, browser and device type, sign-in times and the devices that are signed in.
- Activity in the workspace: an audit log of changes (who did what, and when), so a business can see its history.
- Push notification tokens for devices where you turn notifications on.
- Cookies: one essential sign-in cookie, and short-lived cookies used while you connect another service. We do not use advertising or tracking cookies in the app.
From services you connect
When you or your admin connect another service in Cowazo — such as Google Calendar, Google Sheets, a mailbox, WhatsApp Business, a telephony provider (Exotel, Twilio, Plivo), Zoom or a payment gateway — we receive the data that is needed for that connection to work, as described when you connect it. Keys and tokens for these services are stored encrypted.
3. Google user data
Cowazo can connect to your Google account if you choose to. We ask only for the access each feature needs:
| Feature | Access we ask for | What we do with it |
|---|---|---|
| Continue with Google (sign-in) | Your name and email address | Sign you in to your Cowazo account. |
| My calendar (Google Calendar) | View and edit events on your calendars; see when you are busy | Add the calls and meetings you plan in Cowazo to your calendar and keep them up to date; if you choose “Both ways”, log on the matching lead a meeting you add in Google whose guests include that lead’s email, and follow moves and cancellations of those meetings; warn you when you plan something at a time you are already busy. |
| Google Sheets | Edit spreadsheets you choose | Keep a copy of your leads or invoices in the sheet you name. |
| Google Meet | Through the Google Calendar connection | Add a Meet link to online meetings you plan. |
- Events on your calendar that do not include a lead’s email address are never copied into Cowazo. For busy times we only read the start and end times, never what the event is.
- We do not sell Google user data, use it for advertising, or let anyone read it except to provide these features, for security, to comply with law, or with your consent.
- We do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models.
- You can disconnect at any time in Cowazo (Settings → My calendar, or Settings → Integrations), which also revokes our access, or from your Google Account at myaccount.google.com/permissions.
Cowazo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use data
- To provide Cowazo: run your workspace, sync the services you connect, send the emails, messages and reminders you ask for, and show reports.
- To run the AI features you use, such as call analysis, drafting replies and the assistant (see section 6).
- To keep accounts secure: two-step sign-in, detecting misuse, and audit logs.
- To bill for subscriptions and keep the tax and accounting records the law requires.
- To answer support requests and send service notices (for example about your trial, payments or changes to these terms).
- To improve Cowazo using aggregated information about how features are used — not the contents of your records.
We do not sell personal data, and we do not use a business’s workspace records for our own marketing.
5. Who we share data with
We use trusted service providers who process data for us under contract and only for these purposes:
- Hosting and storage: our servers and backups are in India.
- Payments: PayU, Razorpay or Stripe, for subscription and invoice payments.
- Email delivery: the email service that sends our system emails, or the mail server a workspace connects.
- AI processing: Anthropic, to run the AI features (see section 6).
- Services you connect yourself (section 2), which receive what the connection needs.
We may also disclose data when the law requires it, to protect people’s safety or our rights, or as part of a merger or sale of our business (with the same protections continuing).
6. AI features
When you use an AI feature, the text needed for that task (for example a call transcript, a lead’s history or the message you are drafting) is sent to our AI provider, Anthropic, to produce the result. It is used only to answer that request and is not used by us or by Anthropic to train AI models.
7. Where data is stored and how long we keep it
- Workspaces on our India service are stored on servers in India. If a business chooses another region, its workspace data is stored there.
- We keep workspace data while the workspace is active. If a subscription ends, the business can export its data; we delete or anonymise the workspace data within 90 days after closure, unless the law requires us to keep part of it longer (for example invoices and tax records).
- Sign-in and security logs are kept for up to 12 months.
- Backups are overwritten on a rolling basis.
8. How we protect data
Data travels over encrypted connections (HTTPS). Passwords are hashed, and keys and tokens for connected services are encrypted. Each business’s data is kept separate from other businesses’ by database row-level security, and within a business, people only see the records their role allows. Staff access is limited and needs two-step sign-in. No system is completely secure; if a breach affects your personal data we will tell you and the authorities as the law requires.
9. Your rights
Under India’s Digital Personal Data Protection Act, 2023 and other applicable laws you can ask to access, correct, update or erase your personal data, withdraw consent, and nominate someone to act for you. You can change most of your details yourself in Cowazo (Settings → My profile). For anything else, write to us at the address below; we reply within 30 days. For records a business keeps about you, we will pass your request to that business.
10. Children
Cowazo is a business service and is not meant for anyone under 18. We do not knowingly collect children’s data.
11. Changes to this policy
If we make important changes, we will update the date above and tell account owners by email or in the app before the change takes effect.
12. Contact and grievance officer
Caasaa AI Innovations Pvt Ltd, Noida, Uttar Pradesh, India
Email: support@cowazo.com
Questions, requests and complaints about personal data go to our Grievance Officer at the same email address, with “Privacy” in the subject. We acknowledge complaints within 48 hours and resolve them within 30 days. If you are not satisfied, you can approach the Data Protection Board of India.