Retail Commerce AI

Privacy Policy

Effective
6 August 2026
Version
1.0
Controller
RETAIL COMMERCE AI F.Z.E

We build customer-support automation that runs inside messaging apps. That means we handle conversations between businesses and their customers. This page sets out exactly what we hold, why we hold it, who else touches it, and how to get it deleted.

01

Who we are

RETAIL COMMERCE AI F.Z.E(“Retail Commerce AI”, “we”, “us”) is a company registered in Ajman Free Zone, United Arab Emirates, licence number 56607, with its registered office at B.C. 1304575, Ajman Free Zone C1 Building, AJMAN, UAE.

We operate the Retail Commerce AI platform: the website at retailcommerceai.com, the agent console at panel.retailcommerceai.com, and the automation services that connect a business’s messaging channels to that console.

For any question about this policy, or to exercise a right described in clause 12, write to hello@retailcommerceai.com.

02

Two kinds of people, two different roles

This distinction matters, because it decides who you should contact about your data.

Client businesses

If you sign up for the platform, request a demo, or use the agent console, we are the controller of your account data. We decide what to collect and why, and this policy governs it.

End customers

If you are a shopper who messaged a brand on WhatsApp, Facebook Messenger or Instagram, and that brand uses our platform, we act as a processor on that brand’s behalf. The brand decides what happens to your conversation; we handle it under their written instructions and our contract with them.

You can still ask us directly to delete your data using clause 12, and we will act on it. We will also tell the brand, because in most cases they hold the same records independently.

03

Lawful basis

Where you try our interactive demo, our basis is your consent. You give it when you enter your details and continue, and we record the moment you gave it against your demo record. You can withdraw it at any time using clause 12; withdrawal does not affect processing carried out before you withdrew.

Where you are a client business, our basis is performance of a contract: we process your account, console and billing data because we cannot provide the platform you signed up for without it.

For security, abuse prevention and the server logs described in clause 4, our basis is our legitimate interests in keeping the platform available and free from misuse. Where we act as a processor for a client business on end-customer conversations, that business sets the lawful basis and we act on its instructions.

04

What we collect

From client businesses

  • Name, work email address, phone number, company name and role, given at sign-up or in a demo request.
  • Authentication data: password hash, session tokens, and password reset tokens. We never store passwords in readable form.
  • Product usage: pages viewed in the console, actions taken on conversations, and timestamps.
  • Billing and contract details where a commercial agreement is in place.

From the demo

If you try the interactive demo on our website, we store the name and phone number you enter, the content of the messages you exchange with the demo assistant, and a record that you agreed to this policy, including the time you agreed.

The demo sets one cookie: a random session identifier that lets your conversation continue if you refresh the page or come back later. It holds no name or phone number, is not readable by other websites, and expires after 30 days. It is not used for advertising or for tracking you across other sites.

From Meta platforms

When a business connects its Facebook Page or Instagram professional account to our app through Facebook Login for Business, we receive and store the following:

  • Account identifiers. Facebook Page ID and name, Instagram professional account ID and username, and the Business Portfolio ID the assets belong to.
  • Access tokens. Page access tokens and user access tokens issued by Meta, used solely to send and receive messages on behalf of the connected business.
  • Message content. The text of messages sent to and from the connected account, along with story replies and message timestamps.
  • Sender identifiers. The page-scoped ID (PSID) or Instagram-scoped ID (IGSID) of the person messaging, plus the name Meta returns for that person.
  • WhatsApp data,where the business uses that channel: the customer’s phone number, WhatsApp profile name, message content and delivery status.

We do not request or receive a person’s email address, friend list, posts, ad data, or any profile field beyond the name attached to the conversation.

Automatically

IP address, browser and device type, and referring page, collected in server logs for security and abuse prevention. Our website uses strictly necessary cookies for session management. We do not run advertising or cross-site tracking cookies.

05

Why we ask for each Meta permission

Meta requires apps to justify every permission. Ours are used only as described here.

PermissionWhat it is used for
pages_show_listShow a business the list of Pages it administers, so it can pick which one to connect.
pages_messagingReceive customer messages sent to the connected Page and send replies, whether generated by the assistant or typed by a human agent.
pages_manage_metadataSubscribe the Page to our webhook so messages arrive in real time, and unsubscribe it on disconnection.
instagram_basicIdentify the connected Instagram professional account and display its username in the console.
instagram_manage_messagesReceive and reply to Instagram direct messages and story replies for the connected account.
business_managementConfirm that the assets a business connects belong to its own Business Portfolio.
whatsapp_business_messagingReceive customer messages sent to the connected WhatsApp business number and send replies, whether generated by the assistant or typed by a human agent.
whatsapp_business_managementRegister and manage the connected WhatsApp Business Account, including message templates used for order and delivery updates.

The WhatsApp permissions are submitted under the WhatsApp Business Platform product; the remaining permissions are submitted under Facebook Login for Business.

06

How we use it

  • Deliver incoming messages to the correct business and show them in the agent console.
  • Generate suggested or automatic replies about products, orders, store locations and policies.
  • Look up order status against the business’s own systems when a customer asks.
  • Hand a conversation to a human agent when the assistant cannot resolve it, or when the customer asks for a person.
  • Recognise a returning customer across channels, so someone who messaged on Instagram and later on WhatsApp does not have to repeat themselves. Where we do this, the linking key is an identifier the customer has already given the same business.
  • Produce aggregate reporting for the business: volumes, response times, common questions.
  • Maintain security, prevent abuse, and meet legal obligations.

We do not sell personal data. We do not use Platform Data for advertising, ad targeting, audience building, or credit and eligibility decisions. We do not use one client’s conversation data to serve another client.

07

Automated processing and AI

Replies are generated by large language models. To produce a reply, we send the relevant part of the conversation, plus product and policy information supplied by the business, to Anthropic through the Claude API. Anthropic is the only provider that receives conversation content for reply generation. Where a customer sends a voice message, the audio alone is sent to OpenAI for speech-to-text transcription.

Both providers are contractually bound not to use data submitted through their APIs to train their models. We do not train any model on your conversations for use outside the business the conversation belongs to.

Automated replies are informational. They do not make decisions that produce legal effects for a person. A human agent can take over any conversation at any point, and customers can ask for one at any time.

08

Who else touches the data

We use a small set of service providers. Each is bound by a data processing agreement and may use the data only to provide their service to us.

ProviderRole
SupabaseDatabase, authentication and storage
Amazon Web ServicesHosting for the automation layer (including our self-hosted automation layer)
VercelWebsite and console hosting
AnthropicLanguage model inference (generating replies)
OpenAISpeech-to-text transcription of voice messages
Meta PlatformsMessage delivery on WhatsApp, Messenger and Instagram

We will also disclose data where we are legally required to, or to establish or defend legal claims. A current list of subprocessors is available on request from hello@retailcommerceai.com.

09

Where it is stored

Each client’s data is held in a Supabase project provisioned for that client alone, together with an automation layer deployed separately for that client. The region is chosen per client. Our own project, which holds the website demo and the agent console, is in AWS Northeast Asia (Seoul, ap-northeast-2); demo conversations are separated within it by row-level security.

Our own project, and some of our providers, process data outside the United Arab Emirates. Where a client requires their data to remain in a specific country, we provision that client’s project in that country’s region. Transfers outside a client’s chosen region are made under the relevant provider’s standard contractual clauses or an equivalent safeguard.

10

How long we keep it

DataRetained for
Conversation history and message content730 days from the last message, unless the client instructs a shorter period
Demo visitor details and demo conversations730 days (24 months) from your last activity in the demo
Server and access logsHeld by our hosting providers under their own retention settings. We do not copy them into our systems or extend them
Console account recordsDeleted within 30 days of a request to close the account
Access tokensWhere we hold an access token for a connected channel, it is deleted when that channel is disconnected
Deletion request records365 days, so we can answer status checks

When a client’s contract ends, we delete or return their data within 30 days of the final export.

11

Security

  • Encryption in transit (TLS) and at rest.
  • Separation between clients is at the instance level: each client has its own database project, as described in clause 9. Row-level security operates inside a project as defence in depth, so records are not reachable from a session that should not see them even if a query is wrong.
  • Access tokens and API keys held in a secrets store, never in client-side code.
  • Role-based access in the console, with owner and agent roles separated.
  • Access to production systems restricted to named personnel and reviewed periodically.

No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority as required by law.

12

Your rights, and how to delete your data

You can ask us to:

  • Tell you what data we hold about you.
  • Give you a copy of it in a portable format.
  • Correct it if it is wrong.
  • Delete it.
  • Restrict or object to how we process it.
  • Withdraw your consent, where consent is the basis we rely on under clause 3. Withdrawing stops any further processing on that basis but does not undo processing already carried out.

The fastest route is our data deletion page, which explains both the automatic route (removing our app from your Facebook or Instagram settings) and the manual route (emailing us). We respond within 30 days.

If you are an end customer of a brand that uses our platform, you may also contact that brand directly. If you are unhappy with how we have handled a request, you can complain to the UAE Data Office, the supervisory authority for our jurisdiction. If you are outside the United Arab Emirates, you may instead complain to the data protection authority where you live.

13

Meta Platform compliance

Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements. We use Platform Data only to provide the messaging features described in this policy, and we delete it when it is no longer needed for that purpose or when the connected business disconnects the channel.

14

Children

Our platform is sold to businesses and is not intended for anyone under 18. We do not knowingly collect data from anyone under 18, and our demo is not intended for them either. If you believe a child has messaged a business using our platform and you want that record removed, contact us and we will delete it.

15

Changes to this policy

We will update this page when our processing changes, and revise the effective date and version at the top. For material changes affecting client businesses, we will give notice by email at least 14 days before the change takes effect. Previous versions are available on request.

RETAIL COMMERCE AI F.Z.E · Ajman Free Zone, United Arab EmiratesPrivacyTermsDelete your datahello@retailcommerceai.com