Privacy Policy
Last updated: 1 September 2026
This Privacy Policy explains how RiteModus (“we”, “us”), based in Dhaka, Bangladesh, collects, uses, shares and protects personal data when you visit ritemodus.com, when you use our dashboard as a merchant, and when our agents run on a merchant’s storefront.
The short version. We collect the minimum we need to run the service. We read a merchant’s catalogue live at request time and do not keep a copy of products, orders or customer records. Shopper chat memory is off unless the shopper consents. We do not sell personal data, and we do not use merchant or shopper data to train third-party AI models.
1. Our role
- For merchants: when you sign up, we are the controller of your account and billing data.
- For shoppers: when our agents run on a merchant’s storefront, the merchant is the controller and we act as a processor on their instructions, under our Terms and, where required, a data processing agreement.
2. What we collect
Merchant account data
- Name, business name, email address and password hash.
- Store connection details, platform type, store URL and API credentials (encrypted at rest).
- Plan, usage counters, invoices and payment status (payment card details are handled by Paddle, never by us).
- Support correspondence.
Store operating data
- Product, price, stock, policy and shipping data — read live at request time and discarded. We do not maintain a mirror of a merchant’s catalogue, orders or customers.
- Configuration you create in the dashboard: brand tone, discount limits, price floors, agent settings and generated content you choose to save.
Shopper data (on merchant storefronts)
- Message content sent to the chatbot during a session, and the agent’s replies.
- A pseudonymous session identifier, coarse device type and page context.
- Optional chat memory (remembered preferences) — only where the shopper has given consent, stored per store and never shared across merchants.
We instruct our agents not to request payment card details, government identifiers or health information, and we filter such data out of our logs.
Website and technical data
- IP address (truncated in logs), user agent, request timestamps and error diagnostics.
- Cookies strictly necessary to keep you signed in to the dashboard. Our marketing site does not use advertising or cross-site tracking cookies.
3. Why we use it, and our legal bases
- To provide the Service — performance of a contract.
- To bill and prevent fraud — contract and legitimate interests.
- To secure, debug and improve the Service — legitimate interests.
- To send service and security notices — contract and legal obligation.
- To remember a shopper’s preferences — consent, obtained by the merchant’s storefront and revocable at any time.
- To send marketing email to merchants — consent, with one-click unsubscribe.
4. AI processing
To produce agent output we send the relevant context — such as product details, your configured brand rules and the shopper’s message — to third-party AI model providers under contract. We configure these providers so that:
- your content is not used to train their models;
- zero-retention or minimum-retention settings are applied where the provider offers them;
- only the data needed for that single request is sent.
5. Who we share data with
We do not sell personal data. We share it only with the following categories of sub-processor:
- Paddle.com — merchant of record, payment processing, invoicing and tax.
- AI model providers — to generate agent output, under the terms in section 4.
- Cloud hosting, database and email providers — to run and support the Service.
- Analytics and error monitoring — limited, privacy-respecting diagnostics.
- Authorities — where we are legally required to disclose.
A current list of sub-processors is available on request from support@ritemodus.com.
6. International transfers
We operate from Bangladesh and use providers located in other countries, including the United States and the European Union. Where personal data of EEA or UK residents is transferred, we rely on appropriate safeguards such as Standard Contractual Clauses together with technical measures including encryption in transit and at rest.
7. How long we keep data
- Catalogue and price data: not retained — used in-request and discarded.
- Chat transcripts: retained for a limited operational window (by default up to 30 days) and then deleted or aggregated.
- Shopper memory: kept while consent lasts, and erased on request or when the shopper withdraws consent.
- Usage and analytics aggregates: retained in non-identifying form for reporting.
- Merchant account and billing records: kept while the account is active, and afterwards only as long as required for legal, tax and accounting obligations.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with your local data protection authority.
Merchants can exercise these rights from the dashboard or by emailing support@ritemodus.com. Shoppers should contact the store they interacted with; we will support that merchant in responding, and we honour erasure requests passed to us, including deletion of chat history and any stored preferences. We respond within 30 days.
9. Security
- Encryption in transit (TLS) and at rest for credentials and tokens.
- Access controls, least-privilege and audit logging for internal access.
- Tenant isolation enforced at the database query level, so one merchant can never read another merchant’s data.
- Log scrubbing that strips personal identifiers before storage.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
10. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Cookies
Our marketing site uses no advertising or cross-site tracking cookies. The merchant dashboard uses strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. Our storefront widget stores a pseudonymous session identifier so a conversation survives a page refresh; where a merchant enables shopper memory, that identifier is only persisted after the shopper consents.
12. Changes to this policy
We may update this policy. The “last updated” date above always reflects the current version, and we will notify merchants by email or in the dashboard about material changes before they take effect.
13. Contact us
For any privacy question, request or complaint, email support@ritemodus.com.
RiteModus Dhaka, Bangladesh support@ritemodus.com