1. General
This policy describes what data the RetailOS service (including the RetailOS Market storefront) collects, what it is used for, and how it is protected. By using the Service you agree to the processing described here. The operator’s details are given in section 13.
2. What data we collect
- Account: email, password (stored only as an irreversible hash), name and avatar if you provide them.
- Company data: name, industry, country, currency, time zone, phone, logo.
- Operational company data: products, stock, sales, purchasing, the company’s own customer records, role settings and the staff action log.
- Storefront buyer data: display name, follows, likes, comments and messages to sellers.
- Technical data: request logs (IP address, request id, timestamp and response code), sign-in history, device and browser type.
3. What the data is used for
Only to operate and improve the Service: authentication and access control, running its features (point of sale, stock, storefront, chat), user support, security and incident investigation, and service notifications. We do not sell data and do not use it for third-party advertising.
4. Where and how data is stored
Data is stored in Supabase cloud infrastructure (managed PostgreSQL database and file storage), physically located in the ap-south-1 region (Mumbai, India). Data belonging to different companies is isolated at the database level (Row Level Security): a query made by one company physically cannot return another company’s rows. Traffic between your device and the Service is encrypted (HTTPS).
5. Data from connected messaging services (Instagram and others)
A company may connect its own messaging accounts to the Service in order to handle customer conversations in one place. The company performs the connection itself through the official login flow of the corresponding service. We never ask for, see or store the password of a messaging account — for Instagram the sign-in happens on Instagram’s own pages, and the Service only receives an access token.
When Instagram is connected, we receive and store:
- the id and username of the connected shop account;
- the conversation id and the sender id of each incoming message, and the sender’s username;
- message text, attachments and timestamps — both incoming messages and the shop’s replies;
- the access token issued by Instagram and its expiry.
This data is used solely so that a member of the company’s staff can see a customer enquiry and reply to it, and so that the enquiry becomes a lead and a deal in that company’s CRM. We do not use it for advertising, do not share it with ad networks, and do not sell, buy or license it.
Conversations are visible only to staff of the company that connected the account and are isolated from other companies at the database level.
6. Artificial intelligence
The Service includes an assistant built on a large language model. It answers questions about the shop’s business and, subject to explicit staff confirmation, performs actions such as changing a price.
To be explicit: if a member of staff asks the assistant to review a specific conversation, the content of that conversation — including Instagram Direct messages — is sent to the language model provider (see section 8). This happens only on an explicit request from a staff member and only for conversations belonging to their own company. Conversations are never processed by the model in the background.
A company that does not want this processing can simply not use the assistant; no other feature of the Service depends on it.
7. Who data is shared with
Only with contractors technically necessary to operate the Service, limited to what their services require, and with government authorities in cases expressly provided for by law. There are no other transfers. We do not sell data and do not share it with ad networks or data brokers.
8. Sub-processors
As of this revision, processing on our behalf is carried out by:
- Supabase, Inc. (USA) — managed PostgreSQL database and file storage. Data is physically located in region ap-south-1, Mumbai, India.
- Render Services, Inc. (USA) — hosting for the backend and web application.
- Groq, Inc. (USA) — language model inference for the AI assistant (section 6). Data is sent only at the moment a staff member queries the assistant.
This list is kept current on this page. If a sub-processor changes, we notify users as described in section 14.
9. Company customer records
Customer records that a company keeps in the Service (names, phone numbers, balances, loyalty points) are entered and controlled by the company itself: for that data the company is the controller and the Service is a processor acting on its instructions. Questions about such data should be addressed to the relevant company.
10. Cookies and local storage
The Service uses browser local storage for the sign-in session, the chosen theme and language, and technical interface settings. There are no advertising trackers and no third-party analytics cookies.
11. Retention and deletion
Data is retained while the account or the company workspace is active. At the request of the account owner we delete the account and the personal data associated with it, except for information we are required to keep by law and anonymised technical logs. Requests go to the contact in section 13.
Data from connected messaging services (section 5) is deleted in three cases:
- An Instagram user removes our app in their Instagram settings or submits a deletion request — Instagram forwards the request to us, and the conversation together with its identifiers is deleted immediately and across every company that held it. Details and status are on the data deletion page.
- A company disconnects the channel — the access token is erased immediately, and messages and identifiers received through that channel are deleted within 30 calendar days.
- A company stops using the Service — on the same schedule as the rest of that company’s data.
Instagram identifiers (sender id, username, conversation reference) are removed from the related lead and deal records together with the conversation. The deal record itself may be retained by the company in anonymised form: it is that company’s accounting record of a sale, which it is required by law to keep.
12. Your rights
You may request information about the data being processed, its correction, an export or its deletion. Company staff should go through the owner of their company; storefront buyers may contact support directly.
13. Operator and contact
Operator of the Service: Abdulaziz Kydyraliev, sole proprietor, Keremet Street 77/8, Kok-Zhar, Oktyabrsky district, Bishkek, Kyrgyz Republic, tax ID 22103200750536.
For any question about data processing, including export and deletion requests, write to privacy@retailos.kg. We respond within 30 calendar days.
14. Changes to this policy
For material changes we give notice in the Service interface or by email at least 7 days before they take effect. The current revision is always available on this page.