Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains how Rutvaa (“Rutvaa”, “we”, “us”) collects, uses, stores, and protects information when you use our website, our internal admin tools, and messaging services we provide to businesses (including WhatsApp features that connect through Meta). By using Rutvaa you agree to the practices described here.

1. Who this policy is for

Rutvaa operates a video-first Indian ethnic wear store and related commerce tools. This policy covers: (a) customers who browse and shop on our store; (b) authorised staff who use our admin tools (including publishing product videos to YouTube); and (c) businesses (“clients”) that connect messaging channels such as WhatsApp through our platform, and the end customers those clients message.

2. Information we collect

  • Customer details: phone number, name, delivery address, and order history that you provide when shopping.
  • Account & usage data: session identifiers and basic device information needed to run the store securely.
  • Google account data (admin only): when an authorised staff member links a Google/YouTube account, we receive the account email address, the list of YouTube channels they manage, and permission to upload and manage videos on those channels.
  • WhatsApp / Meta Platform Data: when a client business connects WhatsApp through our platform, we may process message content and metadata, phone numbers, template content, delivery and read statuses, and related WhatsApp Business Account configuration needed to send and receive messages for that client.

3. WhatsApp messaging platform (Meta Platform Data)

We provide a commerce messaging platform that onboarded businesses (“clients”) can use to send and receive WhatsApp customer messages (for example order updates, payment links, OTP / authentication messages, and support), and to create or manage message templates on their WhatsApp Business Accounts.

  • We process WhatsApp Platform Data only on behalf of and at the direction of each client business, to operate the messaging service they requested.
  • End customers' WhatsApp messages are processed to deliver that client's customer communications and support.
  • We do not sell Platform Data. We do not use client WhatsApp message content to advertise to those users for our own purposes, and we do not use it to train unrelated AI models for our own products outside providing the client's messaging service.
  • Access to WhatsApp credentials and webhooks is limited to systems that send/receive messages and operate the service.

4. How we use Google and YouTube data

When a staff member links a Google account, Rutvaa requests permission to upload videos to and manage the metadata of the YouTube channels that account controls. We use this access only to:

  • list the channels linked to the account so the correct channel can be selected;
  • upload product videos to the chosen channel; and
  • set or update the title, description, and privacy status of those uploads.

Rutvaa's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google or YouTube data for advertising, we do not sell it, and we do not transfer it to others except as needed to provide this upload feature or where required by law.

5. How we store and protect data

Google OAuth tokens are encrypted at rest (AES-256-GCM) and are never displayed or logged. Access is limited to the systems that perform uploads. WhatsApp access tokens and related secrets are stored with equivalent production safeguards and are not exposed in client apps. We use reputable cloud providers and apply reasonable technical and organisational safeguards to protect all data we hold.

6. Data sharing

We do not sell your personal information. We share data only with service providers that help us operate (for example hosting, payments, Meta/WhatsApp for messaging, and Google's own APIs for the upload feature), and only to the extent needed to provide the service or to comply with the law.

7. Data retention and deletion

We keep data only as long as needed for the purposes above or as required by law.

  • Google/YouTube access: a staff member can remove a linked Google account at any time from the admin tool (YouTube accounts → Unlink). Unlinking immediately revokes and deletes the stored Google tokens from our systems. You may also revoke access directly at myaccount.google.com/permissions.
  • Customer and WhatsApp-related data: to request deletion of your account, personal data, or WhatsApp Platform Data we hold, email support@rutvaa.com with the subject line Data deletion request. Include enough detail for us to identify the request (for example your phone number or order id, or the client business name for platform clients). We will process the request as required by Meta Platform Terms and applicable law, subject to any legal record-keeping obligations.

8. Your rights

You may request access to, correction of, or deletion of your personal data. To exercise these rights, contact us using the details below.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated “Last updated” date on this page.

10. Contact us

Questions about this policy or your data? Email us at support@rutvaa.com.