Legal · Privacy

Privacy Policy

A clear account of what Jimbo handles, why we need it, who can receive it, and the choices available to businesses and their customers.

Effective July 26, 2026Last updated July 26, 2026
Your business data stays yoursBusinesses control the customer data they place in Jimbo; we process it to provide and secure the service.
No sale or ad targetingWe do not sell personal information or use customer conversations for third-party behavioral advertising.
Rights travel with youWe support applicable access, correction, deletion, portability, objection, and consent rights worldwide.
01

Scope and who we are

This Privacy Policy explains how YantraCore, based in Nepal, handles personal information in connection with Jimbo’s website, business portal, AI assistants, support, integrations, and related services (the “Service”). “Jimbo,” “YantraCore,” “we,” “us,” and “our” refer to YantraCore as the provider.

This policy applies to business account holders, their team members, website visitors, support contacts, and people who interact with a business through a Jimbo-powered channel. It does not govern a Customer’s own privacy practices or a third-party website, social network, telecom provider, or payment service. Those parties have their own notices.

We use “personal information” broadly to mean information that identifies, relates to, describes, or can reasonably be linked to an individual. The exact legal definition and your rights vary by jurisdiction.

02

Our role and your business’s role

Jimbo serves businesses that decide which channels to connect, what information the assistant knows, which End Users it communicates with, and why their data is used. For personal information Jimbo processes on a Customer’s instructions—such as customer chats, orders, contacts, or uploaded knowledge—the Customer generally acts as the controller or business, and we act as its processor or service provider.

If you are an End User of a Jimbo Customer, contact that business first about its privacy practices or to exercise rights over your conversation, order, or customer record. We will assist the business as required and may refer your request to it.

We act as a controller for information used to operate our own relationship with Customers and visitors—for example account registration, authentication, subscriptions, support, security, service analytics, and legal compliance. A separate data processing addendum may apply to Customer Data.

03

Information we collect

CategoryExamples
Account and identityName, business email, phone, role, user ID, login records, password credentials in protected form, OAuth identity, profile image, and account permissions.
Business and subscriptionBusiness name, industry, address, website, size, managers, plan, usage, subscription and billing history, payment method metadata, payment QR information, and payment proof.
Business contentFAQs, instructions, prompts, documents, menu and product data, images, prices, events, announcements, policies, and assistant configuration.
End User and conversation dataNames, handles, account or session IDs, email, phone, delivery address, preferences, messages, attachments, chat history, call audio or transcripts where enabled, inquiries, orders, and payment status or proof.
AI and derived dataPrompts, replies, summaries, detected intent, classifications, recommendations, conversation analytics, and other inferences generated from submitted information.
Integrations and credentialsConnected platform name, account and page IDs, access tokens, credential status, permissions, token expiry, OAuth codes, and information returned by the connected service.
Support and communicationsSupport tickets, email, feedback, call or chat content, attachments, onboarding notes, and notification preferences.
Device, usage, and securityIP address, browser, device and operating system, timestamps, pages and features used, referring URL, cookie and local-storage data, diagnostic events, logs, and suspected abuse signals.

Please do not submit sensitive personal information unless it is genuinely needed for a supported business purpose and you are authorized to do so. Depending on a Customer’s use, conversation content can incidentally include sensitive details. Customers are responsible for minimizing that collection and configuring appropriate safeguards.

04

Where information comes from

  • Directly from you, when you register, configure a business, upload content, contact support, subscribe, or use the portal.
  • From our Customers, when they upload business or customer data, add managers, or configure Jimbo to collect information.
  • From End Users, when they message, call, place an order, upload a file, complete a form, or otherwise interact with Jimbo.
  • From connected services, such as Google sign-in and maps, Meta platforms, WhatsApp, Instagram, Facebook, websites, messaging and telecom services, according to permissions selected by the Customer.
  • Automatically, through necessary cookies, local storage, server logs, security tools, and normal internet protocols.
  • From generated and inferred results, when Jimbo analyzes interactions to create replies, intents, summaries, and reports.
05

How we use information

We use personal information to:

  • provide, personalize, and maintain Jimbo; authenticate users; scope data to the correct business; and deliver messages, conversations, orders, reports, uploads, and configured workflows;
  • generate AI replies, summaries, classifications, search results, and recommendations based on Customer instructions and business knowledge;
  • connect and operate requested channels and integrations, including exchanging information with third-party platforms;
  • administer plans, usage allowances, renewals, billing, trials, support, onboarding, announcements, and service communications;
  • monitor reliability, debug errors, prevent fraud and abuse, protect accounts, investigate incidents, enforce terms, and preserve system integrity;
  • understand feature performance and improve usability, quality, safety, and service design;
  • comply with law, respond to lawful requests, establish or defend legal claims, and protect people, rights, and property; and
  • send product news or offers where permitted. You can opt out of marketing at any time; necessary account and service messages will continue.
07

AI processing and automated features

Information submitted to AI features may be sent to vetted model and infrastructure providers to generate an answer, summary, classification, or other requested result. We limit provider access through contracts, configuration, and technical controls appropriate to the service and data. Providers may process information in other countries.

We may use limited interaction data to operate, secure, evaluate, and improve Jimbo—for example, to identify failed replies or unhandled requests. Any use of Customer Data to train a generally available model will be governed by the Customer’s contract, available controls, additional notice, and applicable law. Customers should not place regulated or highly sensitive information in prompts unless the use is approved and necessary.

Jimbo automatically creates replies and operational insights, but YantraCore does not use that automation to make employment, credit, housing, insurance, medical, or other decisions about End Users that produce legal or similarly significant effects. A Customer must disclose and govern any high-impact use it chooses to make.

08

How we disclose information

We may disclose personal information to:

  • the Customer and its authorized team, including account owners, managers, and administrators who can access business records, customer interactions, reports, and user activity;
  • service providers and subprocessors supporting cloud hosting, storage, databases, AI models, communications, voice and SMS, email, security, monitoring, analytics, maps, support, and billing;
  • connected platforms and services at the Customer’s direction, including Google and Meta services, messaging networks, telecom providers, and a Customer’s website;
  • professional advisers and business counterparties, such as auditors, insurers, lawyers, investors, or a buyer in a financing, reorganization, merger, or sale, subject to appropriate confidentiality;
  • authorities or other parties where reasonably necessary to comply with law, enforce agreements, investigate fraud or security issues, protect safety and rights, or respond to an emergency; and
  • another party at your direction or with your consent.
We do not sell personal information.We do not share personal information for cross-context behavioral advertising and do not use End User conversation data to target third-party ads.
09

Cookies and local storage

Jimbo uses cookies and browser storage that are necessary to sign users in, keep a session secure, remember account context, maintain interface preferences such as theme and list views, support real-time features, and prevent abuse. Some preferences are stored locally on your device rather than sent to us.

Connected features such as Google Sign-In or Google Maps may set or access their own cookies and receive technical information under their policies. We do not currently use advertising cookies on Jimbo. If we introduce optional analytics or advertising technologies, we will provide any consent or preference controls required by law.

You can clear cookies and local storage using browser settings. Blocking strictly necessary storage may prevent login, security, or portal features from working.

10

International data transfers

We are based in Nepal and serve customers globally. We and our providers may process information in Nepal and in other countries where we or they operate. Those countries may have privacy laws different from the laws where you live.

Where required, we use recognized safeguards for restricted transfers, such as contractual protections, approved standard contractual clauses or UK addenda, transfer assessments, consent, or another lawful mechanism. We also apply security and access controls intended to protect information wherever it is processed. Customers remain responsible for authorizing transfers arising from their channel choices and providing any required End User notice.

11

How long we keep information

We keep information only as long as reasonably needed for the purposes described here, a Customer’s documented instructions, and legal or operational requirements. Retention depends on the type of record, account status, plan, sensitivity, contractual commitments, dispute needs, and applicable tax, accounting, communications, and limitation periods.

  • Account, business, and subscription records are generally retained while the account is active and for a reasonable period afterward.
  • Customer Data is retained for the subscription and deletion or export period set by the Service, contract, or Customer instruction.
  • Support, billing, security, and audit records may be kept longer where needed for compliance, fraud prevention, dispute resolution, and system integrity.

Deletion from active systems may not immediately remove information from encrypted backups, logs, or records we must preserve. Such information is isolated from ordinary use and deleted or overwritten on the applicable cycle. We may retain de-identified information that cannot reasonably be linked to a person.

12

How we protect information

We use administrative, technical, and organizational measures designed to protect personal information, including access controls, authenticated sessions, protected credentials, scoped business access, monitoring, provider diligence, and security-focused development and incident response. Measures are selected according to the nature and risk of the information.

No transmission or storage system is completely secure. Customers must configure user permissions carefully, protect passwords and platform tokens, use trusted devices, keep business data accurate and minimized, and notify us promptly about suspected compromise. If a personal-data incident occurs, we will investigate and provide notices required by applicable law and contract.

13

Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to request access, confirmation, correction, deletion, restriction, objection, portability, or a copy of personal information; withdraw consent; opt out of marketing; or complain to a privacy or data-protection authority. You may also have rights concerning automated decisions.

Send a request to contact@yantracore.com. Describe your relationship with Jimbo, the relevant business, and the right you wish to exercise. We may need to verify your identity and authority. An authorized agent may submit a request where local law allows, but we may ask for proof of authorization.

If your information belongs to a Customer workspace or a conversation with a Customer, contact that Customer first. We will support its response as appropriate. We will not discriminate against you for exercising a privacy right. Some information may be exempt—for example where retention is needed for security, legal obligations, or claims.

14

Additional regional information

European Economic Area, United Kingdom, and Switzerland

You may contact us about our legal basis, legitimate-interest balancing, transfer safeguards, or processor terms. You may lodge a complaint with the supervisory authority where you live or work. Where required for a Customer, we will support appropriate contractual transfer mechanisms and data-subject requests.

California and similar U.S. state laws

The categories collected, sources, purposes, disclosures, and retention approach are described above. We do not sell personal information or share it for cross-context behavioral advertising. We do not knowingly use sensitive personal information to infer characteristics beyond providing and securing the Service. Where applicable, residents may request to know, access, correct, delete, or obtain portable information and may use an authorized agent.

Nepal

We handle personal information with regard to Nepal’s Privacy Act, 2075 (2018), Electronic Transactions Act, 2063 (2008), and other applicable laws. Nothing in this policy limits privacy, confidentiality, or consumer rights that cannot lawfully be limited.

15

Children’s privacy

Jimbo business accounts are not for anyone under 18, and the Service is not directed to children. We do not knowingly collect children’s personal information for our own purposes without legally sufficient authorization.

A Customer whose business serves children must configure Jimbo appropriately, minimize collection, provide child-friendly notices, obtain verifiable parental or guardian consent where required, and avoid high-risk profiling or marketing. If you believe a child provided information unlawfully, contact the relevant Customer and us so the record can be reviewed.

16

Communications and preferences

We may send account verification, password, security, billing, support, feature, outage, and policy notices needed to operate the Service. These are transactional communications and cannot always be opted out of while an account is active.

You may opt out of our marketing emails through the link in the message or by contacting us. For messages sent by a Jimbo Customer, follow the opt-out instructions in that message or contact the Customer. The Customer—not YantraCore—determines the audience and purpose of its campaigns.

17

Changes to this policy

We may update this Privacy Policy as Jimbo, our providers, or privacy laws change. We will post the updated policy and revise the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice through the Service, by email, or by another appropriate method and request consent where required.

18

Contact us

For privacy questions, requests, complaints, or information about transfer safeguards or subprocessors, contact:

YantraCore · Jimbo PrivacyNepal
contact@yantracore.com
+977 985-1356363

Please do not include passwords, access tokens, full payment details, or unnecessary sensitive information in your request. We aim to acknowledge privacy requests promptly and respond within the period required by applicable law.