Security & Data Privacy

How Yeti protects business data, customer conversations and connected accounts.

Last Updated: August 2026

Security Statement

Yeti is operated by IncrediBee Private Limited and is built to help businesses manage customer conversations, campaigns, automations, CRM records and sales workflows. Security is treated as an ongoing operational responsibility across the application, infrastructure and connected third-party services.

We use layered administrative, technical and organisational controls designed to reduce the risk of unauthorised access, data loss, misuse and service disruption. No internet-connected system can be guaranteed to be completely secure, so we continuously review and improve our controls as the product evolves.

Secure Access & Authentication

Access to Yeti is protected through authenticated user accounts and workspace-level permissions. Users are responsible for keeping their credentials confidential and should use strong, unique passwords and any additional account-security features made available to them.

Where supported by connected platforms, Yeti uses official OAuth or token-based authorisation flows so users can grant access without sharing their third-party account passwords directly with Yeti.

Application Security

Yeti is developed with common web-application security risks in mind, including cross-site scripting, cross-site request forgery, injection attacks, unauthorised requests and form tampering. Input validation, access checks, secure API handling and other application-level controls are used where appropriate.

Security-sensitive changes are reviewed as part of ongoing product development, and issues identified through testing, monitoring or customer reports are prioritised according to their potential impact.

Encryption & Data Transmission

Connections to Yeti are protected using HTTPS/TLS so information is encrypted while travelling between supported browsers, applications and Yeti services. We do not intentionally support obsolete insecure transport protocols for normal application traffic.

Sensitive credentials, access tokens and integration secrets are handled with additional application and infrastructure controls appropriate to their use. Where encryption is supported and appropriate, it is used to reduce exposure of sensitive information at rest.

Workspace Access & Data Isolation

Yeti uses workspace and role-based access controls so authorised users can access the information needed for their responsibilities. Features such as lead assignment, team roles and connected-channel access are designed to limit unnecessary access within a business workspace.

Customers remain responsible for configuring their users, roles, integrations and permissions appropriately and for promptly removing access when a team member no longer requires it.

Third-Party Platforms & Integrations

Yeti integrates with third-party services such as Meta products, WhatsApp, Instagram, Facebook, Telegram, Google, Shopify, payment providers and other business tools. We use supported APIs and authorisation methods where available and request permissions required for the features a customer chooses to use.

Third-party platforms maintain their own infrastructure, security controls, terms and privacy practices. Changes or incidents affecting those services may be outside Yeti’s direct control.

Infrastructure & Network Protection

Yeti is deployed on managed server infrastructure with network-level access restrictions, TLS termination, reverse-proxy controls, system-level permissions and monitoring. Production access is limited to personnel who require it for operational or support purposes.

Infrastructure and software components are maintained and updated as part of normal operations. Security controls may include firewalls, rate limiting, access restrictions, service isolation and other protections depending on the relevant system.

Monitoring, Logging & Abuse Prevention

Operational and security logs may be maintained to troubleshoot failures, investigate suspicious activity, protect the Service, improve reliability and support compliance obligations. Access to these records is restricted according to operational need.

We may suspend, limit or investigate accounts or integrations where activity appears to threaten the security, integrity or lawful use of Yeti or connected services.

Backups, Availability & Recovery

Yeti uses backup and recovery procedures designed to reduce the risk of permanent data loss and to support restoration following significant operational failures. Backup scope, frequency and retention may vary by system and data type.

We design production services with resilience in mind, but availability can still be affected by maintenance, infrastructure failures, internet disruptions, third-party platforms or events outside our reasonable control.

Data Retention & Deletion

Yeti retains customer and operational information for as long as needed to provide the Service, maintain security and business records, resolve disputes and meet legal obligations. Certain product features may intentionally minimise storage; for example, temporary files may be deleted after their required processing is complete.

Requests concerning access, deletion or other privacy rights are handled in accordance with our Privacy Policy and applicable law.

Confidentiality & Internal Access

Access to customer information by Yeti personnel is limited to legitimate operational, security, support or legal needs. Employees and authorised contractors are expected to protect confidential information and follow internal access and data-handling requirements.

Where administrative access is required to investigate a customer issue, we aim to limit access to the information necessary to resolve that issue.

Compliance & Infrastructure Providers

Yeti works with infrastructure and technology providers that may maintain independent security or compliance certifications for their own services and data centres. Any such certification applies to the relevant provider and does not automatically mean that Yeti itself holds the same certification unless we expressly state otherwise.

We review legal, platform and security requirements relevant to the services we provide and update our practices as Yeti and its integrations evolve.

Your Security Responsibilities

Security is shared. Customers should use strong credentials, restrict workspace access to authorised users, review team permissions, secure connected third-party accounts, protect API keys and tokens, and promptly report suspected compromise.

Never send passwords, one-time passwords, complete payment-card details or other highly sensitive credentials through public support channels.

Reporting a Security Issue

If you believe you have discovered a security vulnerability or suspect unauthorised access involving Yeti, please contact us at hi@yeti.marketing with enough information for us to investigate. Please do not publicly disclose sensitive vulnerability details before we have had a reasonable opportunity to review and address the issue.

Contact

Legal Entity: IncrediBee Private Limited
Product: Yeti
Email: hi@yeti.marketing

For additional contact details, visit our Contact Us page.