Privacy Policy
Last updated: August 25, 2026 · Effective immediately for data collected from this date forward. Data collected before this date is governed by the retention periods in effect at the time of collection.
If anything here does not match your experience of the product, tell us at legal@usevetra.com and we will correct it.
Vetra, LLC (“Vetra,” “we,” “us,” or “our”) operates the Vetra OS software platform and the website located at usevetra.com. Vetra serves local businesses across multiple industries — including bars, auto repair shops, cafés, restaurants, and liquor stores. This Privacy Policy explains what information we collect, how we use it, and your choices and rights regarding that information.
By using our website or services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our services.
1. Who This Policy Covers
This policy covers two categories of individuals:
- Business Owners / Subscribers — Local business owners who purchase and deploy Vetra OS on behalf of their business.
- End Users / Customers — Patrons and customers of those businesses who interact with Vetra-powered features (widget chat, phone, or in-venue flows) on a subscribing business’s behalf.
- Callers — anyone who telephones a business that uses our AI phone service. If you called a business and an AI answered, this policy describes what happens to your call, and you did not have to agree to anything for it to apply to you. Your call may be recorded, transcribed, and processed by AI services, some of which are outside the United States (Section 7A). The business you called — not Vetra — is responsible for telling you that the call is recorded, and the law in some states requires everyone on the call to consent. If you do not want your call recorded, say so and end the call, or ask the business for another way to reach it. To ask what we hold about a recorded call, or to ask us to delete it, contact legal@usevetra.com — see Section 9.
2. Information We Collect
A. From Business Owners (Subscribers)
- Account information: Email address and business name provided during checkout.
- Payment information: Billing details are processed and stored by Stripe, Inc. We do not store your full payment card or bank account numbers on our servers. See Section 6 for details on Stripe.
- Communication data: Any emails or messages you send to us.
B. From End Users (Customers)
When a customer interacts with a Vetra-powered feature on a subscribing business’s behalf, the following information may be collected depending on the business type and features enabled:
- Name and phone number — used to deliver a response and to send a notification to the business.
- Date of birth (liquor stores): where a liquor store's sign-up flow asks for it, your date of birth is collected and stored to confirm you are 21 or older before the store sends you any alcohol-related offer, and is retained with your customer profile. We use it for age verification, not for any other profiling.
- Preferences and purchase interests — where a sign-up or in-venue flow asks (for example, a favourite product), the answer is stored with your profile so the business can serve you better.
- Vehicle information (auto repair): Year, make, model, and mileage.
- Described service needs — symptoms, repair requests, or inquiry details.
- Photos — images uploaded voluntarily by the user or captured as part of a business-initiated scan (see slip photographs below).
- Slip photographs (bar vertical): When a bar subscribes to the Vetra tip-reconciliation feature, staff photograph signed tip slips. Those photographs may contain the customer’s name, the last four digits of their card, the card brand, and the tip amount. How the image is handled, in order: the photograph is uploaded to our image storage (Amazon Web Services S3), then read by an optical character recognition service (Amazon Textract) and an AI text-extraction step, and the resulting text is scanned for a full card number. If a full card number is found, the stored image is deleted and the card number is never written to our database. We keep only the last four digits. Slip photographs are deleted 180 days after capture.
- Card details read from a slip (bar vertical): the cardholder name, card brand and last four digits read from a slip are also written to a separate transaction record, which we use to recognise returning patrons and to answer chargeback enquiries. The cardholder name in that record is removed 180 days after the transaction date (matching the photograph window). The card brand and last four digits are kept longer, because they are needed to answer card disputes. See Section 8.
- Phone calls: where a subscribing business enables our AI phone service, calls to that business are recorded, transcribed and processed by AI. This applies to you as a caller even though your agreement is with the business you called, not with Vetra. Recordings and transcripts may contain your name, your phone number, and anything you say during the call. See Sections 5, 7 and 8, and the notice for Callers in Section 1.
- Interaction metadata — timestamps and workflow status data used to coordinate operational and follow-up workflows when enabled by the subscribing business.
C. Automatically Collected Data
- IP address, browser type, device type, and pages visited on our website — collected via standard web server logs and used solely for security and analytics purposes.
- First-party site analytics: On our own marketing pages (e.g. usevetra.com) we record each page view together with your IP address, a coarse, IP-derived approximate location (city/region and network/ISP), the page path and referrer, and a first-party identifier stored in your browser that lets us recognize return visits. We collect this on a legitimate-interest basis to understand which content and outreach drive interest and to follow up with shops that ask us to. We do not sell it and we do not show it to other visitors. You can clear it any time by clearing your browser storage/cookies for this site.
- Third-party analytics on our marketing pages: our public marketing pages also load Google Analytics 4, which records page views, referrer and a Google-assigned analytics identifier. One page (our auto repair page) additionally loads Microsoft Clarity, which records a replay of the visit — clicks, scrolling and page interactions. These are third-party analytics services and they set their own identifiers. They run on our own marketing pages only; they are not part of the Vetra product and they do not run inside a subscribing business’s dashboard or on a business’s own website. We do not use these services for advertising and we do not operate an advertising network.
3. How We Use Your Information
For Business Owners
- Provision, manage, and support your subscription to the Vetra platform.
- Process payments through Stripe.
- Send you account-related communications (receipts, renewal notices, service updates).
- Respond to support inquiries.
For End Users (Customers)
- Analyze the inquiry using third-party AI services and generate a relevant response or estimate.
- Answer, record and transcribe phone calls where the business has enabled our AI phone service, and extract a summary of the call — including the caller’s name and phone number — so the business can follow up.
- Read photographs of receipts and tip slips captured by the business, to reconcile tips and to answer card disputes.
- Deliver the response to the user and notify the subscribing business.
- When enabled by the subscribing business, support AI-assisted follow-up workflows using prior interaction data and messaging rules.
- We do not send marketing messages to end users. The sole purpose of collecting contact information is to enable the business-to-customer follow-up the user initiates by engaging with the feature.
4. SMS Communications and TCPA Compliance
Vetra operates under the requirements of the Telephone Consumer Protection Act (TCPA) and applicable FCC regulations. Please read this section carefully.
SMS to Business Owners
Business owners who subscribe to Vetra services consent to receive automated SMS notifications — the “SMS handoff” messages — containing lead details from widget interactions. These messages are operational in nature (not marketing) and are a core feature of the subscribed service. Messages are delivered via Telnyx, Inc., our telecommunications carrier, using a toll-free number registered to Vetra. Message frequency varies based on widget traffic. Standard message and data rates may apply.
Consent to receive SMS from Vetra is not required to browse our public website, but is required for full use of SMS-dependent lead handoff features. Business owners may opt out by replying STOP, and may request assistance by replying HELP or contacting legal@usevetra.com. Participating carriers are not liable for delayed or undelivered messages.
SMS Involving End Users (Customers)
The Vetra widget collects a phone number from the end user as part of the inquiry flow. By providing their phone number within the widget, the end user acknowledges that:
- Their information (including phone number and inquiry details) will be shared with the business whose site hosts the widget.
- The business may contact them via phone or text to follow up on the inquiry.
- If enabled by the business, the business may also send follow-up or retention reminders based on prior interaction timing, subject to applicable consent requirements.
- Vetra itself does not send marketing SMS messages to end users. Any subsequent communication comes from the business directly, subject to that business’s own consent practices.
Business owners who use the Vetra platform are solely responsible for ensuring their own customer follow-up communications (calls, texts, emails) are compliant with the TCPA, including obtaining proper written consent before sending marketing or promotional text messages to end users.
Consent is not transferable: A customer’s consent to receive SMS from a subscribing business does not constitute consent to receive SMS from Vetra or any other party. Vetra does not use end-user phone numbers or contact information for its own marketing.
Automated Workflow Timing
Retention workflow timing may be calculated using interaction dates, service history fields, and workflow logic configured by the subscribing business. Vetra provides workflow tooling and infrastructure support, but the subscribing business controls campaign rules, eligibility, and message approvals.
Opt-Out
Business owners receiving operational SMS notifications may reply STOP to unsubscribe or contact us at legal@usevetra.com. Unsubscribing from SMS may affect platform functionality.
5. AI Processing
Vetra uses third-party AI services to read text, answer calls and chats, and pull structured details out of what people write, say and photograph. We do not build or train AI models of our own. The providers we use are named individually at usevetra.com/sub-processors.
What we can commit to:
- We do not sell your information, and we do not use it to train any model of our own — we have none.
- We are working through each AI provider’s terms and account settings and recording what we find on the sub-processor page, including where a provider’s ordinary terms permit training. Where that page does not yet state a provider’s position, it is because we have not finished confirming it — not because we are confident and have not said so.
- We will not add an AI provider whose ordinary terms permit training on customer content without saying so on the sub-processor page.
What we cannot honestly promise, and previously did. An earlier version of this policy said end-user data was “never” used by any provider to train their foundational models. We have removed that, because it was broader than we can enforce. Much of our AI work is routed through a gateway to third-party model providers, and that gateway states in its own terms that it makes no warranty about a downstream provider’s training, retention or security practices. Those providers operate under their own terms, which they can change. Where we know a provider’s default terms permit training on submitted content, we say so on the sub-processor page rather than implying otherwise here.
If you would rather your information were not processed by AI at all, contact legal@usevetra.com. For most features AI processing is the feature, so in practice this may mean the business you are dealing with should use a different channel with you — but tell us and we will tell you honestly what is and is not possible.
6. Payment Processing (Stripe)
All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you complete checkout, you are interacting directly with Stripe’s secure infrastructure. Vetra does not receive, store, or have access to your full payment card number, bank account number, or CVV. Stripe’s privacy policy is available at stripe.com/privacy.
For ACH payments, Stripe processes your bank account information under its own privacy and security standards, including Nacha Operating Rules compliance.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share information in the following limited circumstances:
- Service providers (sub-processors): we use third parties to host, transmit and process data on our behalf — including hosting and databases, SMS and telephony, email delivery, image storage and text recognition, AI inference, speech-to-text, error monitoring and payments. They act on our instructions and under confidentiality obligations. The full, current list — naming each provider, what it does, what data it receives and what country it is in — is published at usevetra.com/sub-processors. Two we are asked about most often: Telnyx, Inc. (SMS and telephony, privacy policy) and Stripe, Inc. (payments).
- AI service providers: we send inquiry text, call transcripts, and text read from captured photographs to third-party AI services in order to generate responses, summaries and extracted fields. These providers are named individually on the sub-processor page. Some AI processing takes place outside the United States — see Section 7A.
- Subscribing businesses: End user data (name, phone, inquiry details, response) is shared with the specific business whose feature the user interacted with. This is the core intended function of the service.
- Legal compliance: If required by law, subpoena, court order, or to protect the rights, property, or safety of Vetra, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of substantially all assets, personal information may be transferred as part of that transaction, subject to the same obligations under this policy.
Mobile privacy commitment: Mobile phone numbers, SMS consent records, and SMS opt-in data are not shared with third parties or affiliates for their own marketing or promotional use.
7A. International Data Transfers
Vetra is based in Tennessee and most of our providers are in the United States. Some are not, and some personal information is therefore transferred outside the United States. We state this plainly because the specific transfers matter more than a general statement does:
- DeepSeek (People’s Republic of China) — an AI provider we use for text drafted in our internal tooling, some recipe and menu processing, and images submitted through our careers page. As of 2026-08-25, DeepSeek is no longer used to process phone call transcripts in normal operation — that processing routes through OpenRouter (United States) instead. A documented technical fallback would still send a call transcript to DeepSeek if OpenRouter becomes unavailable; we are disclosing that fallback rather than promising it can never be exercised.
- Providers in the European Union and the United Kingdom — used for mapping, geocoding and web-search functions that support our own sales and research work. These generally receive business addresses and search queries rather than end-customer personal information.
Countries outside the United States have different data protection laws, and in some cases local authorities may be able to access data held there. If you would prefer that your information not be processed by a provider outside the United States, contact legal@usevetra.com; where the request concerns a recorded call, tell us the business you called and roughly when, so we can find the record.
The country of each provider is listed on the sub-processor page.
8. Data Retention & Deletion Policy
Our retention approach, stated plainly: operational records — interaction history, call transcripts, customer profiles, transaction details — are retained for the duration of the subscribing business's relationship with Vetra, because history is what makes the service useful: recognising a returning customer, answering a card dispute, and showing a business its own patterns all depend on it. We do not apply short deletion timers to this data. What balances that: we honor deletion requests (Section 9), a small number of categories carry fixed automated windows stated below, and payment card numbers are never retained at all.
Periods marked Automated below are carried out by a job that runs daily without anyone asking for it. Periods marked On request are carried out when a deletion request is made or during a manual review — the software to automate them may exist, but it is not switched on, and we would rather say so than imply an automation that is not running. Everything else is governed by a legal retention obligation or by the provider’s own configuration.
Retention Schedule by Data Category
- Subscriber account data (business owner profiles, login credentials, business identity): retained for the duration of the active subscription. After cancellation we retain a billing and audit record for tax and legal compliance. On request. There is no automated job that removes subscriber profile data today; earlier wording here implied a scheduled run that does not exist.
- End user widget interaction data (names, phone numbers, inquiry details, described symptoms, interaction history): retained for the duration of the subscribing business’s active account; no shorter window is applied to active accounts. Our target after a business cancels is deletion approximately 90 days from the account close date. On request. The automated job for this is built but is not currently switched on in production, so this deletion happens when requested or on manual review rather than on a timer. We expect to switch it on; until we do, this row is marked as happening on request rather than on a schedule.
- Bar slip photographs: automatically deleted after 180 days (well past the 120-day card-network dispute window). This deletion runs daily and covers both the photograph file and the database record. Automated.
- Card number detection: every bar slip photograph is checked for a full card number immediately after it is captured — the check runs on the text read out of the image, so the photograph is stored and read first, and then checked. If a full card number is found, the stored photograph is deleted and no card number is written to our database. Only the last four digits are ever retained. Automated. On the rare occasion the deletion itself fails, the image is deliberately kept and the failure is raised to us rather than the record being silently marked as deleted.
- Card details read from a bar slip (cardholder name, card brand, last four digits, transaction time): the cardholder name is automatically removed 180 days after the transaction date — the same window as the slip photograph. The card brand, last four digits, and transaction time are retained for the life of the subscribing business’s account so the business can answer card disputes. Automated. (For the cardholder name field only — the remaining fields are retained until account close or a deletion request.)
- Call recordings (audio): audio of recorded calls is stored in our image and media storage for the duration of the subscribing business's active account. On request.
- SMS communications and consent logs: retained for 4 years per TCPA recordkeeping requirements (47 CFR § 64.1200). Not subject to a deletion request.
- Voice call transcripts: retained for the duration of the subscribing business's active account — transcripts are what let a business see its own call history, follow up on a missed enquiry, and review how calls were handled. On request. An earlier version of this policy stated a 90-day automated deletion for transcripts; that timer has been removed for data collected from the date at the top of this page. Transcripts collected under the earlier policy were deleted on its schedule.
- Transactional email logs (Resend): retained for 12 months in the provider’s logs; metadata copied to our database is retained for 24 months for delivery audit purposes.
- Marketing email engagement data (Customer.io): retained for the duration of the subscription plus 12 months.
- Sales rep contractor records (W-9 forms, contractor agreements, payout history): retained for 7 years per IRS Form 1099 recordkeeping requirements (26 CFR § 6041). Not subject to a deletion request during the statutory retention period.
- Bank account data sourced via Plaid: routing and account numbers are passed through to our payouts provider for recipient creation and are not persisted in Vetra’s database. Only the last 4 digits and an account nickname (for display purposes) are stored.
- Workflow event data (SMS delivery status, reminder timing, follow-up logs): retained as reasonably necessary to operate messaging workflows, prevent duplicate sends, and support compliance/audit requests.
- Payment records (Stripe): retained as required by Stripe and applicable tax and accounting laws.
- Sentry error logs: retained for 90 days (Sentry default). Personally identifiable information is redacted via
sendDefaultPii: falseconfiguration on both backend and frontend Sentry SDKs. Automated by Sentry.
Deletion Rights and Procedures
Subscribers and end users may submit a formal data request (deletion, access, correction, or opt-out) using our data request form or by emailing legal@usevetra.com. We will acknowledge your request within 5 business days and respond within 30 days unless legal, tax, or regulatory retention obligations require longer holding (e.g., 7-year IRS contractor records, 4-year TCPA SMS logs). When a request is partially fulfilled, the requester is notified which data was deleted and which remains under regulatory hold, with the basis for retention.
Deletion is performed across all primary stores (database, file storage, application caches) and propagated to downstream third-party processors (Stripe, Resend, Customer.io, Telnyx) as their APIs permit. Fulfilment is currently carried out manually by a person for each request; we intend to automate it as request volume grows, and this page will say so when that happens.
Policy Review and Enforcement
This retention policy is reviewed at least annually. Automated windows are enforced by a daily retention job in our infrastructure; other periods are enforced manually or by vendor configuration. Material changes to this policy will be communicated to subscribers via email and reflected in the “Last updated” date at the top of this Privacy Policy.
9. Your Rights
All Users
- Request access to the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information, subject to legal retention requirements.
- Submit any of these requests using our data request form or by emailing legal@usevetra.com.
California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You may request details about what personal information we collect, use, disclose, and sell (we do not sell personal information).
- Right to Delete: You may request deletion of your personal information we have collected.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale: We do not sell personal information. No action is required.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
To submit a request, use our data request form or email legal@usevetra.com. We will respond within 45 days.
10. Children’s Privacy
Our services are intended for use by local businesses and adult consumers. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly.
11. Security
We implement technical and organizational safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (HTTPS/TLS), access controls, and secure payment processing via Stripe. Card number detection runs on every bar slip photograph immediately after capture; any image found to contain a full card number is deleted and the card number is never written to our database. No method of transmission over the internet is 100% secure, however, and we cannot guarantee absolute security.
12. Cookies and Tracking Technologies
Our website uses browser cookies and local storage to support core site functionality (such as remembering widget session state) and to measure how our marketing pages are used.
We do use third-party analytics. Our public marketing pages load Google Analytics 4, and one page additionally loads Microsoft Clarity, which records a replay of the visit. Both set their own identifiers and both are third-party services, so we will not tell you our site is free of third-party tracking — it is not. What we do not do is run advertising cookies, build advertising audiences, or sell or share cookie-derived data with anyone for marketing purposes.
You can block these with standard browser privacy settings or an extension, and nothing on the site stops working if you do. Google and Microsoft describe their own handling at Google and Microsoft.
A specific disclosure about Microsoft Clarity, which Microsoft requires us to make: Microsoft collects personal data from visitors to the page where Clarity runs, and acts as an independent controller of that data rather than as our service provider. Microsoft may use it for its own purposes, including improving Microsoft products and providing Microsoft Advertising. We do not receive advertising data back and we do not use Clarity to build profiles. See the Microsoft Privacy Statement.
Do Not Track: Our website does not alter its behavior in response to browser Do Not Track (DNT) signals, as no universal standard for DNT compliance currently exists.
13. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will notify active subscribers via email. Continued use of the service after any changes constitutes your acceptance of the updated policy.
15. Contact Us
For privacy-related inquiries, requests, or complaints:
- Data Request Form: Submit a data request (deletion, access, correction, opt-out)
- Email: legal@usevetra.com
- Website: usevetra.com
- Mailing Address: Vetra, LLC · 2245 Cherokee Ridgeway, Knoxville, TN 37920