MuthoCommerce Privacy Notice
Version: 2026-08-03
Effective date: 3 August 2026
This Notice explains how MuthoCommerce, the trade name used for the Bangladesh-based sole-proprietorship business that provides the Service, handles personal data when MuthoCommerce determines why and how that data is used. In this Notice, MuthoCommerce, we, us, and our refer to that business. Public channels are listed on Contact MuthoCommerce. This Notice covers public-site visitors, merchants, Authorised Users, support contacts, applicants to partner programmes, and people who submit privacy, legal, abuse, or security requests.
For shopper, order, delivery, review, loyalty, inbox, and similar store data, the merchant ordinarily determines the purpose and MuthoCommerce processes the data for that merchant under the Data Processing Addendum. The merchant's own privacy notice should explain that processing. MuthoCommerce may separately handle limited storefront security and service-integrity data for the purposes described here.
1. Data we collect
We collect only data reasonably needed for the stated purpose:
- Identity and account data: name, business name, username, email address, telephone number, profile image, account role, authentication identifiers, chosen language, and ownership or authority verification.
- Business and compliance data: store name and domain, business address, registration or licence information supplied for verification, tax status, connected-service configuration, policy acceptance, and records needed to address fraud, complaints, or legal obligations.
- Subscription and transaction data: plan, billing interval, invoices, tax, discount, credit, payment status, payment-provider transaction reference, and the last four digits or brand of a payment instrument when supplied by the payment provider. We do not intend to receive or store full card numbers, card security codes, mobile-financial-service PINs, passwords, or one-time codes.
- Support and communications: messages, attachments, call or meeting notes when a call occurs, feedback, survey responses, and records of notices and decisions. A call will not be recorded without notice and any consent required by law.
- Device, usage, and security data: IP address, approximate network location, browser and device type, timestamps, requested URLs, response status, session and authentication events, administrative actions, integration events, rate-limit and abuse signals, error diagnostics, and security logs.
- Cookie and preference data: session, cart, checkout-intent, account-surface, security, language, and consent choices described in the Cookies and Tracking Notice.
- AI feature data: prompts, selected store context, generated drafts, feedback, action approvals, and safety telemetry when an Authorised User invokes an AI feature. Merchant Personal Data in a prompt remains governed by the DPA.
- Information from others: identity and payment status from authentication or billing providers; technical events from connected services; referrals from a partner; and lawful public or authority sources used to prevent fraud or verify a business.
2. Why we use data
Depending on the context and applicable law, we process data to perform a contract, take requested pre-contract steps, comply with law, protect legitimate interests that do not override individual rights, or act on valid consent. The purposes are:
- create, authenticate, secure, administer, and support accounts;
- provide selected features, invoices, service messages, and requested support;
- verify ownership and authority for high-risk account actions;
- calculate disclosed subscription and usage charges and maintain tax and audit records;
- detect, prevent, investigate, and respond to fraud, abuse, intrusion, malware, service disruption, prohibited content, and policy violations;
- monitor reliability, diagnose errors, plan capacity, and improve Service usability using data minimised and aggregated where reasonably possible;
- communicate product or policy changes and send marketing only where permitted;
- respond to privacy, legal, intellectual-property, consumer, and security requests;
- establish, exercise, or defend legal claims and comply with valid authority orders; and
- evaluate, secure, and improve AI features. Merchant Content is not used to train a general-purpose AI model without a separate, express, written opt-in.
We do not sell personal data. We do not use Merchant Personal Data to build advertising profiles for unrelated third parties. We do not make a decision that produces legal or similarly significant effects about an individual solely through MuthoCommerce AI without meaningful human review.
3. When we disclose data
We disclose the minimum relevant data to:
- the merchant Owner and Authorised Users according to server-enforced permissions;
- service providers acting under contract as listed in the Subprocessors and Connected Services Notice;
- a payment, courier, social, messaging, analytics, domain, or other connected service when the merchant selects and directs the connection;
- professional advisers, auditors, insurers, and finance providers bound by confidentiality where reasonably necessary;
- a competent authority or other party when we reasonably believe disclosure is legally required, needed to protect rights or safety, or necessary to investigate fraud or abuse; and
- a successor in a merger, financing, reorganisation, or sale, subject to confidentiality and notice before a materially different use.
We scrutinise government requests, seek clarification or narrowing where appropriate, disclose only what is legally required, and notify the affected customer before disclosure unless prohibited or an emergency makes prior notice impracticable.
4. International processing
MuthoCommerce is built on global cloud and communications services. Data may be processed outside Bangladesh in the locations listed for relevant subprocessors. Before a cross-border transfer, MuthoCommerce will document the purpose, data categories, recipient, destination, security, retention, and transfer mechanism required by the law then in force. A subprocessor may not make a materially new location or purpose change without the review and notice required by the DPA.
5. Retention
We retain identifiable data for the shortest of the period below, the period needed for the stated purpose, and any mandatory legal period. A documented legal hold may temporarily override deletion for the affected records only.
| Record | Standard retention |
|---|---|
| Active account and configuration | For the active relationship |
| Deactivated store content and Merchant Personal Data | 30-day restricted recovery/export period, then deletion or irreversible anonymisation from active systems |
| Residual encrypted disaster-recovery copies | No normal access; targeted for overwrite or destruction within 90 additional days where MuthoCommerce controls the schedule, or blocked until a subprocessor's fixed secure recovery cycle overwrites them |
| Contract, policy acceptance, invoice, tax, payment, and material business-compliance records | 6 years after the relevant transaction or relationship ends |
| Ordinary application and error logs | Up to 30 days unless converted into a security, fraud, or incident record |
| Security, fraud, abuse, and incident evidence | Up to 1 year after closure, or longer only for a documented claim, authority requirement, or legal hold |
| Support communications | 3 years after ticket closure; material contract or dispute records may move to the 6-year record set |
| Unsuccessful onboarding record with no active store | 30 days after expiry or abandonment |
| Marketing preference and suppression record | Until consent is withdrawn; a minimal suppression record is retained while needed to honour the opt-out |
| Privacy and legal requests | 6 years after closure, with unnecessary identity evidence removed earlier |
Where irreversible aggregation or anonymisation reasonably prevents re-identification, the result is no longer retained as personal data. If a backup is restored, valid deletion instructions are re-applied. We do not keep an entire store merely because one invoice or complaint must be retained.
6. Your choices and rights
Subject to applicable law and appropriate identity verification, an individual may ask us to:
- confirm whether we process their data and provide access or a portable copy;
- correct incomplete or inaccurate data;
- delete data that is no longer lawfully required;
- restrict or object to particular processing;
- withdraw consent without affecting earlier lawful processing;
- stop direct marketing;
- explain a significant automated process and request meaningful human review; or
- review a refusal or complain to the competent Bangladesh authority.
Where the request concerns store data controlled by a merchant, contact that merchant first. We will assist the merchant under the DPA and will not silently use the request for a different purpose.
A request must use the privacy channel on Contact MuthoCommerce. We acknowledge it within 3 business days and ordinarily respond within 30 calendar days. If a complex or high-volume request lawfully needs more time, we will explain the reason and expected date before the initial period ends. We may request only the identity evidence reasonably necessary to prevent unauthorised disclosure or deletion. An authorised agent must prove authority. We do not charge for an ordinary request, but may refuse or charge a reasonable cost for a manifestly unfounded or excessive repeat request where law permits, after explaining the basis.
7. Marketing
Service, security, billing, and legal notices are not marketing and may be sent while an account is active or an obligation remains. Marketing messages identify the sender, are not deceptive, and include a working opt-out. We act on an electronic marketing opt-out without undue delay and no later than 5 business days. A minimal suppression record may remain so the person is not re-added. Withdrawing marketing does not cancel a subscription or stop transactional messages.
8. Children
A person must be at least 18 to create or control a MuthoCommerce merchant account. The public MuthoCommerce service is not directed to children. A merchant whose lawful store is intended for children or processes children's data must obtain any required parental or guardian authorisation, use age-appropriate notices, minimise the data, and contact MuthoCommerce before enabling processing that requires special controls. MuthoCommerce may disable an unsupported use. We do not knowingly use children's store data for behavioural advertising or general AI training.
9. Security
We use the contractual and technical measures in the DPA, including tenant separation, access control, encryption in transit, secret protection, logging, incident response, backups, and vendor review. No system is perfectly secure. A person who discovers a suspected vulnerability should follow the Security and Responsible Disclosure Policy, not test it against real customer data.
10. Changes, questions, and complaints
We will give at least 30 days' advance notice of a material change that reduces a right or introduces a materially new use, unless law or an urgent security need requires faster action. We will not treat silence as new consent where consent is required.
Questions, complaints, and appeals must use the privacy channel on Contact MuthoCommerce. We will investigate without retaliation. This internal route does not restrict a complaint to the competent Bangladesh authority, the Directorate of National Consumer Rights Protection where relevant, or a court.