Risebot Legal

Privacy Policy

This Privacy Policy explains how Risebot (“we”, “us”) collects, uses, stores, and shares information when you use our AI sales assistant platform at risebot.site.

Last updated: March 6, 2026 · risebot.site

1. Who we are

Risebot is an AI sales assistant built for Algerian e-commerce businesses. We help sellers reply to customers, confirm COD orders, create orders automatically, track shipments, manage catalogs, and analyze performance.

Website: https://risebot.site. Contact: legal@risebot.site.

2. Information we collect

Depending on how you use Risebot, we may collect:

  • Account identifiers: name, business name, email address, phone number, and authentication IDs
  • Login and security events (sign-in method, timestamps, approximate device/browser info)
  • Connected messaging accounts (Facebook Pages, Instagram Business accounts, WhatsApp Business phone numbers) and related Meta identifiers
  • Messages and conversation metadata exchanged with your customers via Messenger, Instagram Direct, and WhatsApp
  • Order and customer data you process in Risebot (customer names, phone numbers, addresses, wilaya/commune, products, amounts, delivery status)
  • Product catalog data (titles, prices, variants, stock notes)
  • Courier connection metadata and parcel tracking references (privacy-minimized where possible)
  • Usage analytics (feature usage, page views, error logs) and cookies/local storage
  • Support messages you send to us

3. Google login

If you sign in with Google (via Supabase Authentication), we receive basic profile information authorized by Google, typically including your name, email address, and a unique Google user ID. We use this only to create and secure your Risebot account.

4. Facebook / Meta login & pages

When you connect Facebook Pages, Messenger, Instagram, or WhatsApp through Meta OAuth, Meta provides access tokens and account identifiers needed to send and receive messages on your behalf. We store access tokens encrypted at rest.

5. Email / password login

If you register with email and password, authentication is handled by Supabase Authentication. Passwords are hashed by Supabase; Risebot does not store plaintext passwords.

6. WhatsApp data

When WhatsApp Business is connected, we process message content, customer phone numbers, delivery statuses, and message IDs necessary to operate the AI assistant, order confirmation, and inbox.

7. Messenger conversations

Messenger messages, sender IDs, page IDs, timestamps, and attachment metadata may be stored so Risebot can display your unified inbox, generate AI replies, and create orders. We do not sell conversation content.

8. Instagram conversations

Instagram Direct messages linked to your professional account are processed for AI replies, order workflows, and analytics inside your workspace.

9. Order information

Orders may include customer contact details, products, COD amounts, delivery addresses, tracking references, and status history. This data is used for your business workflows and is not sold.

10. Customer phone numbers

Phone numbers may be stored for COD risk scoring, lists, WhatsApp confirmation, and orders. You must have a lawful basis to process your customers’ numbers.

11. Cookies & local storage

We use cookies and similar technologies to:

  • Maintain authenticated sessions (including Supabase auth cookies)
  • Remember language preference and UI settings
  • Complete OAuth flows securely
  • Protect against CSRF and abuse

12. Analytics

We may collect product analytics to improve Risebot. Analytics are used in aggregate where possible.

13. Security

We implement HTTPS, encrypted storage of sensitive tokens, access controls, and session management via Supabase Auth. No system is 100% secure—use strong passwords and protect your Meta assets.

14. Third-party services

  • Supabase — authentication and database hosting
  • Meta (Facebook, Instagram, WhatsApp) — messaging APIs and OAuth
  • Google — OAuth sign-in when you choose Google login
  • AI model providers — generating assistant replies
  • Courier / delivery APIs you connect
  • Infrastructure and hosting providers

15. Data retention

We retain data while your account is active and as needed to provide the service and meet legal obligations. See Data Deletion.

16. Contact