Privacy Policy
Last updated 16 September 2026. This draft is reviewed by counsel before launch.
1. Who we are
AdMeDaddy is an AI commerce assistant for Indian sellers on Instagram and WhatsApp. This policy follows the Digital Personal Data Protection Act, 2023.
2. Seller data (we are the data fiduciary)
We collect your email, business details, catalogue, configuration and usage data to provide and bill the service. Access tokens for Instagram and WhatsApp and payment gateway credentials are stored encrypted and used only to operate your account.
3. Customer data (we are the data processor)
Messages, names, phone numbers, addresses and order details of your customers are processed on your behalf so the AI can reply and create orders. We do not use customer data to train models. Customers can stop business-initiated messages at any time by replying STOP.
4. AI processing
Message text, images and voice notes are sent to AI model providers (via OpenRouter) to generate replies, transcribe audio and match images. Providers are contractually restricted from using the data for training.
5. Retention
Conversation content is retained for 12 months and media for 90 days by default, then anonymised or deleted. Orders and invoices are retained as required by tax law. You can export or delete all your data from Settings → Account at any time.
6. Sharing
Data is shared only with sub-processors needed to run the service: Supabase (database and storage), Vercel (hosting), Inngest (background jobs), OpenRouter (AI), Meta (messaging), Razorpay and other gateways you connect (payments), OneSignal (notifications), Resend (email) and Dodo Payments (billing).
7. Security
Encryption in transit and at rest for secrets, row-level access controls per business, signed webhooks, audit logs of sensitive actions.
8. Your rights and contact
Access, correction, erasure and grievance requests: privacy@admedaddy.com. We respond within 30 days.