Vetra logo Vetra ← Back to site

Privacy Policy

Last updated: August 25, 2026  ·  Effective immediately for data collected from this date forward. Data collected before this date is governed by the retention periods in effect at the time of collection.

If anything here does not match your experience of the product, tell us at legal@usevetra.com and we will correct it.

Vetra, LLC (“Vetra,” “we,” “us,” or “our”) operates the Vetra OS software platform and the website located at usevetra.com. Vetra serves local businesses across multiple industries — including bars, auto repair shops, cafés, restaurants, and liquor stores. This Privacy Policy explains what information we collect, how we use it, and your choices and rights regarding that information.

By using our website or services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our services.


1. Who This Policy Covers

This policy covers two categories of individuals:


2. Information We Collect

A. From Business Owners (Subscribers)

B. From End Users (Customers)

When a customer interacts with a Vetra-powered feature on a subscribing business’s behalf, the following information may be collected depending on the business type and features enabled:

C. Automatically Collected Data


3. How We Use Your Information

For Business Owners

For End Users (Customers)


4. SMS Communications and TCPA Compliance

Vetra operates under the requirements of the Telephone Consumer Protection Act (TCPA) and applicable FCC regulations. Please read this section carefully.

SMS to Business Owners

Business owners who subscribe to Vetra services consent to receive automated SMS notifications — the “SMS handoff” messages — containing lead details from widget interactions. These messages are operational in nature (not marketing) and are a core feature of the subscribed service. Messages are delivered via Telnyx, Inc., our telecommunications carrier, using a toll-free number registered to Vetra. Message frequency varies based on widget traffic. Standard message and data rates may apply.

Consent to receive SMS from Vetra is not required to browse our public website, but is required for full use of SMS-dependent lead handoff features. Business owners may opt out by replying STOP, and may request assistance by replying HELP or contacting legal@usevetra.com. Participating carriers are not liable for delayed or undelivered messages.

SMS Involving End Users (Customers)

The Vetra widget collects a phone number from the end user as part of the inquiry flow. By providing their phone number within the widget, the end user acknowledges that:

Business owners who use the Vetra platform are solely responsible for ensuring their own customer follow-up communications (calls, texts, emails) are compliant with the TCPA, including obtaining proper written consent before sending marketing or promotional text messages to end users.

Consent is not transferable: A customer’s consent to receive SMS from a subscribing business does not constitute consent to receive SMS from Vetra or any other party. Vetra does not use end-user phone numbers or contact information for its own marketing.

Automated Workflow Timing

Retention workflow timing may be calculated using interaction dates, service history fields, and workflow logic configured by the subscribing business. Vetra provides workflow tooling and infrastructure support, but the subscribing business controls campaign rules, eligibility, and message approvals.

Opt-Out

Business owners receiving operational SMS notifications may reply STOP to unsubscribe or contact us at legal@usevetra.com. Unsubscribing from SMS may affect platform functionality.


5. AI Processing

Vetra uses third-party AI services to read text, answer calls and chats, and pull structured details out of what people write, say and photograph. We do not build or train AI models of our own. The providers we use are named individually at usevetra.com/sub-processors.

What we can commit to:

What we cannot honestly promise, and previously did. An earlier version of this policy said end-user data was “never” used by any provider to train their foundational models. We have removed that, because it was broader than we can enforce. Much of our AI work is routed through a gateway to third-party model providers, and that gateway states in its own terms that it makes no warranty about a downstream provider’s training, retention or security practices. Those providers operate under their own terms, which they can change. Where we know a provider’s default terms permit training on submitted content, we say so on the sub-processor page rather than implying otherwise here.

If you would rather your information were not processed by AI at all, contact legal@usevetra.com. For most features AI processing is the feature, so in practice this may mean the business you are dealing with should use a different channel with you — but tell us and we will tell you honestly what is and is not possible.


6. Payment Processing (Stripe)

All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you complete checkout, you are interacting directly with Stripe’s secure infrastructure. Vetra does not receive, store, or have access to your full payment card number, bank account number, or CVV. Stripe’s privacy policy is available at stripe.com/privacy.

For ACH payments, Stripe processes your bank account information under its own privacy and security standards, including Nacha Operating Rules compliance.


7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share information in the following limited circumstances:

Mobile privacy commitment: Mobile phone numbers, SMS consent records, and SMS opt-in data are not shared with third parties or affiliates for their own marketing or promotional use.


7A. International Data Transfers

Vetra is based in Tennessee and most of our providers are in the United States. Some are not, and some personal information is therefore transferred outside the United States. We state this plainly because the specific transfers matter more than a general statement does:

Countries outside the United States have different data protection laws, and in some cases local authorities may be able to access data held there. If you would prefer that your information not be processed by a provider outside the United States, contact legal@usevetra.com; where the request concerns a recorded call, tell us the business you called and roughly when, so we can find the record.

The country of each provider is listed on the sub-processor page.


8. Data Retention & Deletion Policy

Our retention approach, stated plainly: operational records — interaction history, call transcripts, customer profiles, transaction details — are retained for the duration of the subscribing business's relationship with Vetra, because history is what makes the service useful: recognising a returning customer, answering a card dispute, and showing a business its own patterns all depend on it. We do not apply short deletion timers to this data. What balances that: we honor deletion requests (Section 9), a small number of categories carry fixed automated windows stated below, and payment card numbers are never retained at all.

Periods marked Automated below are carried out by a job that runs daily without anyone asking for it. Periods marked On request are carried out when a deletion request is made or during a manual review — the software to automate them may exist, but it is not switched on, and we would rather say so than imply an automation that is not running. Everything else is governed by a legal retention obligation or by the provider’s own configuration.

Retention Schedule by Data Category

Deletion Rights and Procedures

Subscribers and end users may submit a formal data request (deletion, access, correction, or opt-out) using our data request form or by emailing legal@usevetra.com. We will acknowledge your request within 5 business days and respond within 30 days unless legal, tax, or regulatory retention obligations require longer holding (e.g., 7-year IRS contractor records, 4-year TCPA SMS logs). When a request is partially fulfilled, the requester is notified which data was deleted and which remains under regulatory hold, with the basis for retention.

Deletion is performed across all primary stores (database, file storage, application caches) and propagated to downstream third-party processors (Stripe, Resend, Customer.io, Telnyx) as their APIs permit. Fulfilment is currently carried out manually by a person for each request; we intend to automate it as request volume grows, and this page will say so when that happens.

Policy Review and Enforcement

This retention policy is reviewed at least annually. Automated windows are enforced by a daily retention job in our infrastructure; other periods are enforced manually or by vendor configuration. Material changes to this policy will be communicated to subscribers via email and reflected in the “Last updated” date at the top of this Privacy Policy.


9. Your Rights

All Users

California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To submit a request, use our data request form or email legal@usevetra.com. We will respond within 45 days.


10. Children’s Privacy

Our services are intended for use by local businesses and adult consumers. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly.


11. Security

We implement technical and organizational safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS/TLS), access controls, and secure payment processing via Stripe. Card number detection runs on every bar slip photograph immediately after capture; any image found to contain a full card number is deleted and the card number is never written to our database. No method of transmission over the internet is 100% secure, however, and we cannot guarantee absolute security.


12. Cookies and Tracking Technologies

Our website uses browser cookies and local storage to support core site functionality (such as remembering widget session state) and to measure how our marketing pages are used.

We do use third-party analytics. Our public marketing pages load Google Analytics 4, and one page additionally loads Microsoft Clarity, which records a replay of the visit. Both set their own identifiers and both are third-party services, so we will not tell you our site is free of third-party tracking — it is not. What we do not do is run advertising cookies, build advertising audiences, or sell or share cookie-derived data with anyone for marketing purposes.

You can block these with standard browser privacy settings or an extension, and nothing on the site stops working if you do. Google and Microsoft describe their own handling at Google and Microsoft.

A specific disclosure about Microsoft Clarity, which Microsoft requires us to make: Microsoft collects personal data from visitors to the page where Clarity runs, and acts as an independent controller of that data rather than as our service provider. Microsoft may use it for its own purposes, including improving Microsoft products and providing Microsoft Advertising. We do not receive advertising data back and we do not use Clarity to build profiles. See the Microsoft Privacy Statement.

Do Not Track: Our website does not alter its behavior in response to browser Do Not Track (DNT) signals, as no universal standard for DNT compliance currently exists.


13. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.


14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will notify active subscribers via email. Continued use of the service after any changes constitutes your acceptance of the updated policy.


15. Contact Us

For privacy-related inquiries, requests, or complaints: