Legal

Privacy Policy

Effective date: 3 August 2026

This policy explains what Adtro Media Pte. Ltd. collects, how we use it, who we share it with, and what rights you have. We've written it in plain language.

1. Information we collect

Account information

When you register, we collect your business name, email address, selected business type and plan, acceptance of our legal terms, and a password stored only as a one-way hash. We also process team-member names, email addresses, roles, permissions, verification records, and support communications where you provide them.

Business and product data

Product and service catalogues, images, pricing, inventory, outlet and table details, orders, bookings, queues, loyalty and prepaid-package settings, advertising content, workflows, reports, and other content or configuration you submit to run your business.

Documents and files you upload

If you or your team upload documents to iBot or eBot (such as SOPs, menus, contracts, reports, or policy files), we store these files and process their content — including any personal data they contain — using OCR (optical character recognition) and AI to extract, classify, and index information for your AI assistants. Do not upload documents containing personal data of third parties (such as your staff or customers) unless you have a lawful basis to do so.

Customer data you collect

When customers browse a storefront, place orders, make bookings, join a queue, use loyalty or wallet features, upload payment evidence, or communicate through a connected channel, we may process their name, email address, WhatsApp or telephone number, session identifier, order and booking history, loyalty activity, messages, notes, and preferences. Notes may reveal sensitive information, such as allergens or dietary needs, so merchants should request only what is necessary. The merchant generally controls this data and Adtro Media acts as its data intermediary, as explained in Section 8.

Payment information

Stripe processes card and billing details for platform subscriptions and, where enabled, merchant checkout. We receive related customer, transaction, subscription, invoice, status, amount, currency, and fraud-prevention identifiers but do not store full payment-card numbers. For PayNow or QR verification, we may store an uploaded proof image and extracted recipient, amount, currency, reference, and review information. Merchants may also record cash or cashier payment status.

Social media account data

If you connect Meta or another supported platform, we receive identifiers for the authorising user, business, Page, Instagram account, WhatsApp Business Account and phone number as applicable; account names, usernames and profile images; granted permissions; encrypted access or refresh tokens and expiry information; post and template identifiers, publishing results and available analytics; webhook events; and messages and delivery status where inbox features are enabled. We use this data only to provide the connection, publishing, analytics, messaging, support, security, and deletion functions you request. We do not use connected-platform data to build advertising profiles or sell it.

Usage data

We automatically process IP address, request and event time, browser and device information, referring page, pages or features used, session and CSRF identifiers, diagnostic events, security logs, and approximate location inferred from IP where available. Storefronts may use local storage or session storage to preserve a cart, guest session, preferences, and registration progress.

2. How we use your information

  • Operate and deliver the Adtro Media platform and its features
  • Power AI features (iBot and eBot) that help you and your customers interact with your business data and knowledge base
  • Process transactions and send order confirmations
  • Send transactional emails such as email verification and password resets
  • Provide customer support and respond to enquiries
  • Improve platform performance, fix bugs, and develop new features
  • Comply with legal obligations including tax, anti-fraud, and data protection laws
  • Send product updates and announcements (you can opt out at any time)

3. AI and automated processing

Our AI assistants

iBot (a staff-facing assistant) and eBot (a customer-facing assistant) use AI models hosted on Amazon Web Services (AWS) Bedrock — including models developed by Amazon and Anthropic — to answer questions, generate suggestions, and, where enabled, automatically reply to customer WhatsApp messages.

Data sent to AI models

To provide these features, relevant business data (such as orders, bookings, inventory, customer profiles, uploaded documents, and conversation context) and customer messages may be sent to AWS Bedrock. AWS states that Bedrock inputs and outputs are not shared with model providers and are not used to train the underlying foundation models. Provider-side retention depends on the Bedrock feature and configuration in use. Adtro Media separately stores chat, message, tool, audit, and knowledge-base records when needed to provide the service, maintain context, investigate issues, and meet the retention periods below.

Document processing

Uploaded documents may also be processed using AWS Textract (optical character recognition) to extract text from scanned files, and may be embedded into a vector index to support knowledge-base search.

Human oversight

AI-generated suggestions for actions such as marketing campaigns, loyalty changes, or product updates require a staff member to review and confirm them before they take effect. eBot may send automated replies to customers without prior review, depending on your configuration — you control whether this is enabled.

4. Who we share your data with

Service providers

We disclose data as necessary to providers that host, secure, support, and deliver the platform, including Amazon Web Services for cloud, storage, AI, and document processing; Stripe for payment and billing services; our configured email provider for transactional messages; and Meta or other platforms you choose to connect. Their handling is governed by the applicable contract, product terms, privacy terms, and our configuration.

AI infrastructure providers

To power iBot and eBot, relevant data is processed by AWS Bedrock (including underlying models from Amazon and Anthropic) and AWS Textract, as described in Section 3. These providers process data only to deliver the AI response and do not use it to train their own models.

Meta (Facebook, Instagram, Messenger, and WhatsApp)

When a merchant initiates a connection, we exchange authentication data with Meta and call Meta APIs to identify selected assets, store encrypted credentials, publish requested content, retrieve permitted analytics, subscribe to webhooks, operate a connected inbox, register WhatsApp phone numbers, manage approved templates, and send or receive authorised messages. Meta also receives information necessary to perform those requests. Meta processes information under its own terms and privacy policies. We handle data received from Meta in accordance with the permissions granted, Meta Platform Terms, and applicable Meta product policies.

Legal obligations

We may disclose information if required by law, court order, or to protect the rights, property, or safety of Adtro Media, our users, or the public.

No selling of data

We do not sell, rent, or trade your personal information or your customers' data to any third party for marketing purposes.

5. International data transfers

Our primary cloud infrastructure is configured in the AWS Asia Pacific (Singapore) region. Meta, Stripe, email, support, and other providers may process data in other countries. Where the Singapore PDPA requires comparable protection for an overseas transfer, we use contractual, organisational, and technical safeguards appropriate to the transfer and assess the provider and service involved.

6. How long we keep your data

Active accounts

We retain your account and business data for as long as your account is active.

After account closure

When a merchant account is closed and no legal or operational exception applies, we begin removing or anonymising active account data within 30 days. We may retain information longer where needed for tax and accounting, security, fraud prevention, legal claims, dispute resolution, enforcement, or another lawful purpose. Financial documents and transaction records may be retained for up to 7 years.

Documents and AI knowledge base

Documents you upload to iBot or eBot, and the data extracted or indexed from them, are retained while your account is active. When you delete a document, it and its extracted data are removed from active storage and the AI knowledge base, subject to routine backup retention.

Automated retention schedules

Current default maximum schedules are 365 days for WhatsApp event and message telemetry, 730 days for QR payment proof, 730 days before audit-log personal data is anonymised, 1,825 days before consent evidence is anonymised, and up to 7 years for financial documents. Connected-platform credentials are kept while needed for an active connection and are deleted when that connection or the related Meta deletion request is processed, subject to security logs and legal exceptions. Operational settings may shorten these periods. Active conversations, orders, bookings, profiles, and merchant content are generally retained while the account or relevant merchant relationship remains active.

Backups and deletion records

Deleted data may remain temporarily in encrypted, access-restricted backups until those backups rotate, and is not restored to ordinary use. We may keep a minimal deletion request, confirmation code, status, and audit evidence to demonstrate that a request was handled.

7. Your rights

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate or incomplete information
  • Deletion or account closure — ask us to remove data where applicable, subject to merchant instructions and lawful retention
  • Withdraw consent — withdraw consent for future processing where consent is the basis, without affecting prior lawful processing
  • Complain — contact our Data Protection Officer or the competent data protection authority
  • Other rights — portability, objection, restriction, or similar rights where and when the law that applies to you provides them

Email contactus@adtromedia.com with enough information for us to identify the relevant account and request. We may verify your identity and authority before acting. Under the Singapore PDPA, we generally respond to an access or correction request within 30 calendar days or tell you in writing when we expect to respond. Some requests may be refused, limited, charged a permitted fee, or handled by the merchant that controls the data. Singapore's statutory data-portability obligation has not taken effect unless and until implementing regulations bring it into force.

8. Our role under data protection law

Your business and your customers

When you use Adtro Media to operate your storefront, you collect and control personal data about your own customers and staff (such as names, WhatsApp numbers, order history, and booking details). For this data, you are the "organisation" under Singapore's PDPA (or "data controller" under GDPR), and Adtro Media acts as your "data intermediary" (or "data processor") — we process this data only on your instructions, to provide the platform's features.

Your obligations

You remain responsible for ensuring you have a lawful basis (such as consent) to collect and process your customers' and staff's personal data, for honouring their rights — including access, correction, and deletion requests — and for complying with the PDPA and any other laws that apply to your business.

Adtro Media's account and platform data

For data we collect about you and your business directly — such as your account details, billing information, and usage data — Adtro Media is the organisation/data controller, as described elsewhere in this policy.

9. Meta data, permissions, and deletion

Permissions and purpose limitation

We request only the Meta permissions needed for the selected Facebook, Instagram, Messenger, or WhatsApp feature. We do not use Meta data for unrelated advertising, data brokerage, surveillance, or eligibility decisions. Removing a permission or disconnecting an account may stop the related feature.

How to remove Meta data

A merchant may disconnect the related account in Adtro Media settings. A Meta user may also remove Adtro Media from Facebook settings, use Meta's data-deletion mechanism, or follow our Data Deletion Instructions. A valid Meta signed deletion request creates a confirmation code and triggers deletion of locally stored credentials and connected-account records associated with the authorising Meta user. Other customer, order, accounting, safety, or audit records are deleted or anonymised only where the requester is entitled to that action and no lawful exception applies.

Deauthorisation

When Meta sends a valid deauthorisation or data-deletion callback, we verify the signed request using the app secret before processing it. We may retain the minimum callback and completion evidence required to secure and demonstrate the deletion process.

10. Cookies and local storage

Session cookies

We use secure, HTTP-only session cookies to keep you logged in. These expire when you log out or when your session times out.

CSRF protection

A CSRF token cookie is set alongside your session to protect against cross-site request forgery attacks.

No advertising cookies

We do not currently place third-party advertising or behavioural-tracking cookies on Adtro Media pages. A connected provider's authorisation page or embedded connection tool may set cookies under that provider's own policy.

Local and session storage

We use browser storage for functional purposes such as carts, guest storefront sessions, preferences, draft registration information that excludes your password, and temporary workflow state. Clearing browser data may reset these features.

11. How we protect your data

  • All data in transit is encrypted with TLS 1.2 or higher
  • Passwords are stored using scrypt — a memory-hard one-way hashing algorithm
  • Social platform access tokens (WhatsApp, Instagram, Facebook, YouTube, TikTok) are encrypted at rest using AES-256
  • Cloud infrastructure is hosted on AWS with access controls and audit logging
  • We use access controls, tenant isolation, audit records, rate limits, signed webhook checks, and security review processes appropriate to the service

12. Data incidents

No security measure is perfect. We investigate suspected personal-data incidents and notify affected merchants, individuals, regulators, or providers when applicable law or contract requires it. Merchants must promptly tell us about credentials, accounts, or customer data they believe have been compromised.

13. Children's privacy

Merchant accounts are intended for people aged 18 or older. Storefronts may be visible to the public, but Adtro Media is not directed to children and merchants should not intentionally request children's personal data through the platform unless they have all permissions and safeguards required by law. Contact us if you believe a child's data was submitted improperly.

14. Changes to this policy

We may update this Privacy Policy to reflect service, provider, or legal changes. We will post the new effective date and give reasonable notice of material changes through the service or account email. Where consent is legally required for a new purpose, we will request it rather than relying only on continued use.

15. Data Protection Officer and contact

Adtro Media Pte. Ltd. (UEN 202519799G), whose registered office is Jean Yip Building, #06-01, Kaki Bukit Place, Singapore 415926, is responsible for this policy. Contact our Data Protection Officer at contactus@adtromedia.com with the subject “Data Protection” for privacy questions, complaints, access or correction requests, withdrawal of consent, or deletion requests. This is our public business contact for data-protection matters.