Legal

Privacy Policy.

What we collect, what we never touch, and who else can see it. Your business data is yours — we only process it so the product can work.

Last updated

Scope, and who controls what.

This policy explains how Shaitrish handles personal data in Artho (https://artho.app). It covers our website, the application, and the emails we send.

Two different roles

  • Your account data — your name, email, mobile, organization and billing records. Here we are the controller: we decide why and how it is processed.
  • Your business data — the customers, suppliers, employees, orders and transactions you record. Here we are a processor acting on your instructions. You are the controller. You decide what to enter, how long to keep it, and what to tell the people it concerns.
Practically: we never mine your business data, never sell it, and never use it to train models or to market to your customers. We access it only to keep the Service running or when you ask us for support.

What we collect.

CategoryExamplesWhy
Account dataName, email, mobile, hashed password, organization and company names, role and permissionsTo create and secure your account and to apply access control
Business dataEverything you enter: products, customers, suppliers, employees, orders, payments, expenses, journal entriesTo provide the Service to you — we process it on your instructions
Billing recordsPlan, invoices, amounts, payment reference and dateTo bill you and to keep required financial records
Technical dataIP address, browser and device type, timestamps, and server logs of errors and requestsSecurity, abuse prevention, and diagnosing faults
Support messagesEmails and WhatsApp messages you send usTo answer you and to keep a record of the issue

We do not knowingly collect special-category personal data (health, biometrics, political or religious belief) and ask you not to enter it into the Service.

How we use it.

  • To provide, maintain and secure the Service.
  • To authenticate you, and to verify your email address and reset your password.
  • To bill you and to keep accounting records we are required to keep.
  • To answer support requests.
  • To send service messages — billing, security and material changes. These are not marketing and cannot be opted out of while your account is active.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To understand aggregate usage so we can improve the product. This works on counts and totals, not on the content of your business data.

Where the GDPR or a similar law applies to you, our lawful bases are: performance of a contract (providing the Service and billing), legitimate interests (security, abuse prevention, product improvement), legal obligation (financial records), and consent where we ever ask for it.

We do not sell personal data, and we do not use your data to train machine-learning models.

Cookies and local storage.

  • Session cookie — a signed, HTTP-only cookie that keeps you logged in. Strictly necessary; the Service cannot work without it.
  • Local storage — your theme choice (light/dark) and a few interface preferences, held in your own browser and never sent to us.

We run no third-party advertising cookies, no cross-site trackers and no advertising pixels. Because we set only strictly necessary cookies, there is no consent banner to click through.

Who else touches the data.

We share data only with the service providers that make the product run:

ProviderPurposeWhere
VercelApplication hosting and deliverySingapore region
Supabase (managed PostgreSQL on AWS)Database and backupsSingapore (ap-southeast-1)
ResendTransactional email — verification, password reset, service noticesUnited States / EU

Beyond those, we disclose data only:

  • When you ask us to, or direct us to.
  • When a valid legal order requires it. We tell you unless the law forbids it.
  • To protect the rights, safety or property of us, our customers or the public.
  • To a successor if the business is transferred — under the same commitments as in this policy, with notice to you.

Ask at contact@shaitrish.com for the current list of processors; we update it when it changes.

Where data lives, and for how long.

The application and database run in Singapore, chosen for latency from Bangladesh. Transactional email may be processed in the United States or the European Union. Data crossing a border is protected by the provider’s contractual safeguards.

  • While your account is active we keep your data so the Service can work.
  • After cancellation or termination, you may request an export for 90 days. After that the data may be deleted.
  • Backups roll off on their own schedule, typically within 30 days of deletion from the live database.
  • Billing records are kept as long as tax and company law requires, even after an account closes.
  • Server logs are kept for a short period for security and diagnosis, then discarded.

How we protect it.

  • Passwords are stored as salted hashes. Nobody here can read yours, and a reset is the only route back in.
  • Sessions use signed tokens in HTTP-only cookies, so page scripts cannot read them.
  • All traffic is encrypted in transit with TLS.
  • Every request re-checks, on the server, that you belong to the organization, may open that company, and hold that module permission. Interface restrictions are convenience, not the control.
  • Email verification and password reset use single-use tokens that expire.
  • The database is managed, access-controlled and backed up regularly.
  • Administrative access is limited to staff who need it for operations or support.

No system is perfectly secure. If a breach affects your personal data, we will tell you and any regulator that must be told, without undue delay, and explain what happened and what to do.

Your rights.

  • Access — ask what we hold about you.
  • Correction — fix anything wrong. Most of it you can edit yourself on Account.
  • Export — get a copy of your data in a portable format.
  • Deletion — ask us to delete your account and data, subject to records we must keep by law.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to pause it.
  • Complaint — complain to your data protection authority if one covers you.

Write to contact@shaitrish.com to exercise any of these. We answer within 30 days and may need to verify your identity first. If you are a customer, supplier or employee of an Artho user and want your data corrected or removed, contact that business directly — they control it, and we act on their instruction.

Children.

The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to contact@shaitrish.com and we will delete it.

Changes to this policy.

We update this policy when the product or the law changes. The date at the top always reflects the current version, and material changes are announced by email or in the application before they take effect.

Contact.