1. Scope and Privacy Principles
This Privacy Policy explains how VauPrime collects, uses, processes, stores, and shares information when you use VauPrime websites, applications, accounting and ERP features, support services, and connected integrations such as ChatGPT or other Model Context Protocol (MCP) clients.
We follow data-minimization and purpose-limitation principles. We aim to process only the information needed to provide the feature you choose to use, secure the service, meet legal obligations, and support your account. We do not sell personal information for monetary consideration.
2. Information We Collect and Process
Depending on the VauPrime features you use, we may process the following categories of information:
- Account and authentication information: name, email address, account identifiers, authentication state, and security information needed to sign you in and protect your account. Passwords are handled through our authentication systems and are not exposed through VauPrime MCP tool responses.
- Organization and business information: organization name, organization identifiers, business settings, currency, branch or business configuration, industry information, and other organization metadata stored in VauPrime.
- Customer, supplier, party, and account information: party or account names, account classification, balances, contact information such as phone number and email address, postal or business address information, city/state/country/postal code, GSTIN or other tax identifiers, and related account metadata where you have entered or imported that information into VauPrime.
- Accounting and financial information: opening and closing balances, debit and credit amounts, ledgers, vouchers, sales and purchase totals, payment or receipt information, financial-year dates, transaction references, statement information, and other accounting records required to provide VauPrime accounting features.
- Product and inventory information: product names, categories, units, item codes, barcodes, HSN or tax classification codes, sale and purchase prices, stock quantities, stock values, stock movements, warehouse or material-center information, and low-stock settings.
- Usage and technical information: service usage, browser or device information, IP address, security events, request status, performance information, and limited diagnostic information needed to operate, secure, troubleshoot, and improve the service.
- Support and communications: information you send to us in support requests, emails, feedback, or other communications.
The exact information processed depends on the feature and your request. VauPrime does not require every category above for every user or every operation.
3. ChatGPT, AI and MCP Connected Services
VauPrime provides an MCP integration that can allow a connected service, including ChatGPT, to access selected VauPrime business information after you authorize your VauPrime account. The current MCP endpoint is designed for read-only accounting and ERP queries unless a future feature clearly states otherwise and requires any additional authorization or confirmation.
How the connection works:
- You choose to connect your VauPrime account through an OAuth authorization flow.
- The connected MCP client sends an access token to the VauPrime MCP service. VauPrime verifies that token with the VauPrime authentication system and uses the verified user identity to enforce organization-level access.
- VauPrime uses the token to authenticate and authorize the requested operation. Authentication tokens are not intentionally returned in MCP tool output.
- For organization-scoped tools, VauPrime verifies that the connected user is authorized for the selected organization before reading its accounting or ERP data.
- When a tool is called, the minimum response data needed for that tool is transmitted to the connected MCP client so it can answer the user's request.
Data categories that may be processed for current MCP requests:
- Organization display information needed to select an authorized business. The public organization selector uses an organization id for scoping, display name, and currency; internal FVS identifiers and unrelated organization metadata are not returned.
- High-level business summaries such as sales, purchases, inventory values, account counts, transaction counts, and financial-year information.
- Customer or party account name, accounting classification, tier, currency, and balance information when searching for or selecting a customer. Current MCP customer search and customer-detail tools do not query or return customer phone numbers, email addresses, postal addresses, GSTIN/tax identifiers, or internal customer/account database ids.
- Ledger and statement information, including dates, debit/credit amounts, balances, particulars, and voucher labels when a ledger is requested. Current ledger outputs do not return internal account ids, transaction ids, free-form narration, or unrelated party contact/tax fields.
- Product, price, stock, valuation, and limited stock-movement information when product or inventory tools are requested. A product query may use barcode, HSN, item code, category, or material-center values when the user explicitly supplies those values as search/filter inputs; those identifiers are not automatically echoed in the minimized product result.
MCP response minimization:
VauPrime's MCP implementation is designed not to expose unrelated nested data or debug information. Current tool responses intentionally omit authentication tokens, raw database responses, internal FVS identifiers, internal customer/account database ids, unnecessary branch/location metadata, backend error payloads, fuzzy-match scores, raw transaction identifiers, manufacturing identifiers, raw quantities used only for calculations, free-form stock notes, filter echoes, and diagnostic timestamps that are not necessary to answer the user's request. Customer phone numbers, email addresses, postal addresses, and GSTIN/tax identifiers are omitted from the current customer-facing MCP queries and result schemas.
Information sent to a connected third-party service is also subject to that service's privacy terms and settings. For ChatGPT and other OpenAI services, review OpenAI's applicable privacy documentation and your ChatGPT data controls. You can disconnect or revoke a connected service to stop future authorized MCP access.
4. How We Use Information
We use information for purposes including:
- Providing accounting, ERP, reporting, inventory, customer, ledger, and other VauPrime features you request.
- Authenticating users and enforcing access to the correct organizations and business records.
- Providing connected integrations that you choose to authorize, including MCP-based access.
- Maintaining service reliability, preventing abuse, investigating security incidents, and protecting accounts.
- Providing customer support and communicating important service, security, billing, or product information.
- Improving performance and usability using appropriately limited usage and diagnostic information.
- Complying with applicable legal obligations and resolving disputes.
We do not use your accounting records or customer lists to sell advertising audiences to third parties.
5. When Information Is Shared
We may share or make information available only where needed for the service or where legally required, including:
- Service providers: infrastructure, hosting, authentication, communications, analytics, payment, security, and support providers that process information on our behalf.
- Connected services you authorize: when you choose to connect VauPrime to ChatGPT, an MCP client, or another integration, requested data may be transmitted to that service to complete your request.
- Legal and safety requirements: where disclosure is required by applicable law, valid legal process, or reasonably necessary to protect users, VauPrime, or others from fraud, abuse, or security threats.
- Business transfers: if VauPrime is involved in a merger, acquisition, restructuring, or sale of assets, information may transfer subject to appropriate privacy protections and applicable law.
- With your direction or consent: where you explicitly ask us to share or connect information for a particular purpose.
6. Data Security
We use technical and organizational safeguards intended to protect information from unauthorized access, alteration, disclosure, or destruction. These include authenticated access, authorization checks, encrypted network transport, access controls, and security monitoring appropriate to the service.
For MCP access, authentication and authorization are separate controls: the server verifies the connected account and additionally scopes organization-related requests to the authorized user and organization. We also design tool output schemas to limit the information returned by each tool.
No internet service can guarantee absolute security. Users are responsible for protecting their devices, credentials, and any third-party accounts they connect to VauPrime.
7. Data Retention
We retain active-account information for as long as reasonably necessary to provide the VauPrime services you use and to maintain accounting and business functionality, subject to applicable legal, tax, regulatory, contractual, security, and dispute-resolution requirements.
- Inactive accounts: if an account has not been used for 24 months, we may send advance notice before permanently deleting eligible account data, subject to legal or business-record retention requirements.
- Deleted accounts: when an eligible account-deletion request is completed, we target removal of personal information from active systems within 30 days, except information that must be retained for legal, accounting, tax, billing, fraud-prevention, security, or dispute-resolution purposes.
- Backups: information remaining only in backup systems is generally overwritten or purged according to backup retention schedules, typically within 90 days, unless a longer period is required for security, disaster recovery, or legal reasons.
- Accounting/business records: some invoices, ledgers, tax-related records, transaction records, or other business records may need to be retained longer where applicable law or the user's own business-record obligations require it.
Disconnecting a connected MCP or AI service stops new authorized access through that connection but does not automatically delete the underlying VauPrime accounting or business records. You may separately request eligible account or data deletion using the contact details below.
8. Cookies, Analytics and Similar Technologies
Our websites may use essential cookies for authentication, security, preferences, and core functionality. We may also use analytics or conversion-measurement technologies to understand service usage and measure marketing performance. Where required, available controls or consent mechanisms can be used to manage non-essential technologies.
Disabling essential cookies may prevent parts of the website or account experience from working correctly.
9. Your Choices and Rights
Depending on applicable law and your relationship with VauPrime, you may be able to:
- Access, correct, or update account information.
- Request a copy or export of information available through supported VauPrime features.
- Request deletion of eligible personal information, subject to legal and accounting retention requirements.
- Object to or restrict certain processing where applicable.
- Opt out of non-essential marketing communications.
- Disconnect or revoke connected services such as an MCP or AI integration.
To make a privacy or account-data request, contact us using the details below. We may need to verify your identity before acting on a request.
10. Children
VauPrime business and accounting services are not designed to collect personal information from children in circumstances where parental or guardian consent is legally required. If you believe information has been provided contrary to applicable law, contact us so we can review the request.
11. Changes to This Policy
We may update this Privacy Policy when our products, integrations, legal requirements, or data practices change. The current version and its last-updated date will be published on this page. Material changes may also be communicated through appropriate VauPrime channels.
12. Contact Us
For privacy questions, account-data requests, or concerns about VauPrime's handling of information, contact VauPrime support at support@vauprime.com.
VauPrime · Jodhpur, Rajasthan, India.
