TheViralMarketing

Privacy Policy

Last updated August 26, 2026

This policy explains what we collect, why, who we share it with, how long we keep it, and your rights. We do not sell personal data. We do not use your content to train our models.

Who we are

The Viral Marketing (“TheViralMarketing”, “we”, “us”) is a software business in India. We operate https://theviralmarketing.co and the product app at https://app.theviralmarketing.co.

We are the data fiduciary under India’s DPDP Act and the controller under the GDPR for account and product data. This policy covers our website, product, and support. Social networks you connect have their own policies.

What we collect

Account information (such as name, email, and workspace details), content you create or upload, information from social accounts you connect, usage and diagnostic data, billing records from our payment processor, and messages you send to support. We do not store full card numbers.

How we use data

We use personal data to provide and secure the service, generate content for your account, publish at your direction, bill you, prevent abuse, send service messages, and comply with law. Marketing email is optional; you can unsubscribe.

Where GDPR or UK law applies, we rely on contract, legitimate interests (security, product analytics, B2B communications), consent (optional cookies and marketing), and legal obligation.

AI and your data

We do not use your content to train our models. Third-party AI providers process prompts only to generate or process content for your account. Where a provider offers a setting that prohibits training on customer content, we use it. Aggregated, de-identified product analytics may be used to improve the service; that is not training on your content.

Connected social accounts

When you connect Instagram, Facebook, LinkedIn, X (Twitter), or other networks, we receive the access those platforms grant — typically account identity and permission to publish, schedule, or read metrics you enable. We use that only to run those features for your account. We do not sell that data, use it to build profiles of other people, or use it to train our models.

You can disconnect a network in the product at any time. After you disconnect or delete your account, we stop using that access and remove it as described under Retention. To request deletion of personal data, email [email protected].

Sharing

We share data with service providers under contract only as needed to run the product: our payment processor (Razorpay); third-party AI providers; hosting, storage, email, and security vendors; and social networks you choose to connect.

We may disclose information if required by law, to protect the service, or in a merger with appropriate safeguards. We do not sell personal information.

International transfers

We serve customers in India, the United States, the EU/EEA, the UK, and other countries. Data may be processed in India and in other countries where our providers operate. Where required, we use appropriate safeguards such as standard contractual clauses. Under India’s DPDP Act, this is notice that personal data may be transferred outside India.

Retention

We keep account data while your account is active. After a verified deletion request we delete or anonymize personal data within 30 days, except where law requires longer retention (for example tax records). Connected-account access is removed when you disconnect or delete your account, to the extent the platform allows.

Security

TheViralMarketing implements commercially reasonable technical, administrative, and organizational measures designed to protect personal information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no security measure or method of data transmission over the internet is 100% secure. In addition, you are solely responsible for protecting your log-in and password, limiting access to your devices, and signing out of websites and accounts after your sessions. See also our Security page. Report issues to [email protected].

Your rights — India (DPDP)

If India’s Digital Personal Data Protection Act applies to you, you may request access, correction, completeness, and erasure of your personal data (subject to legal retention), withdraw consent where processing is based on consent, and raise a grievance. Email [email protected]. We aim to respond within the timelines that law requires.

Your rights — EU/EEA and UK (GDPR)

If you are in the EEA or UK, you may request access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests. You may withdraw consent without affecting prior lawful processing. You may lodge a complaint with your local supervisory authority. Privacy requests go to [email protected]. We respond within one month, extendable as the GDPR allows.

Your rights — United States (CCPA and similar state laws)

We do not sell personal information and we do not share it for cross-context behavioral advertising. If you are a California resident (or a resident of another US state with similar rights), you may request to know, delete, or correct personal information, and you will not be discriminated against for exercising those rights. Email [email protected] from the address on your account. We will verify the request.

Children

The service is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe we have, contact [email protected].

Cookies

We use essential cookies to operate the site and optional analytics cookies you can decline. Details are in the Cookie Policy.

Changes

We may update this policy. The “Last updated” date will change. Continued use after the effective date means you accept the updated policy.

Contact

Privacy requests: [email protected].

Questions about this privacy policy [email protected].