Privacy & Data Security Policy
Effective Date: 1 January 2026 • Rupokar Technologies Ltd., Dhaka, Bangladesh
1. Information We Collect
To provide our SaaS solutions, Rupokar collects the minimum information required for business provisioning and localized verification:
- Client Account Details: Company trade name, owner name, verified business contact number/MSISDN, business email, country, and district/city.
- Billing Information: Transaction IDs (TRXID) from authorized gateways (bKash, SSLCommerz, Stripe). Rupokar does not store customer credit card CVVs or payment PINs on our servers.
- Audit Telemetry: Immutable timestamps, operator IP addresses, and license status modifications for forensic security.
2. Encryption & Financial Security
All communications between your browser, our cloud command center, and child SaaS microservices are encrypted using Transport Layer Security (TLS 1.3). Sensitive credentials (such as JWT secrets, bKash app secrets, and child platform tokens) are stored using military-grade AES-256 GCM encryption at rest.
3. Zero-Knowledge Commercial Data
Rupokar respects the commercial secrecy of your trade. Whether you hold 100 Vori of gold in your vault or manufacture proprietary Jamdani saree patterns, your business inventories are logically and cryptographically sealed. Our employees and automated workers cannot view, query, or export your sales numbers without your explicit written authorization during a support session.
4. WhatsApp & SMS Communications
When you enable WhatsApp notifications or SMS customer reminders, we transmit transactional messages solely to the recipient numbers provided by your system. We do not use your customer phone book for third-party marketing or spam campaigns.
5. Contact Our Privacy Officer
For questions regarding data retention, GDPR compliance for overseas orders, or to request a full cryptographic export or deletion of your tenant data, please contact:
