Privacy Policy
How we handle personal data, what we do not do with it, and the rights you have. Note the distinction between data we control and data you control.
Last updated:
1. Who we are
RABT operates the RABT platform. This policy explains what personal data we handle, why, and what rights you have. It applies to our website and to the RABT application.
2. Two different roles — please read this first
This distinction matters, because it decides who is responsible for what.
ACCOUNT DATA — we are the controller. This is data about you as our customer: your name, email, company, subscription and billing records, and how you use the Service. We decide how this is handled and this policy governs it.
CRM DATA — you are the controller and we are only a processor. This is the data you enter about your own customers and contacts. We store and process it strictly on your instructions, we do not decide what you collect, and we do not use it for our own purposes. If one of your customers wants their data corrected or deleted, that request goes to you, not to us.
3. What we collect
- Account details: name, email address, company name, preferred language, role.
- Authentication data: password hashes (never the password itself) and session records.
- Billing data: subscription plan, status and invoice history. Card details are handled by Stripe and never reach our servers.
- Usage and audit data: sign-in events, actions taken in the Service, IP address (stored only as a one-way hash) and browser type.
- CRM content you create: customers, contacts, opportunities, quotations, notes and messages.
4. Why we process it
- To provide, maintain and secure the Service — necessary to perform our contract with you.
- To process payments and manage subscriptions.
- To provide support and respond to your requests.
- To detect, prevent and investigate abuse, fraud and security incidents — our legitimate interest.
- To comply with legal, tax and accounting obligations.
5. What we do NOT do
- We do not sell your data, or your customers’ data, to anyone.
- We do not use your CRM content to train AI models.
- We do not access your CRM data except where necessary to provide support, resolve a fault, or comply with the law — and such access is recorded in an audit log.
- We do not share data between tenants. Each workspace is isolated at the database level.
6. Service providers we rely on
We use the following sub-processors. Each is bound by contractual confidentiality and data protection obligations, and processes data only on our instructions.
- Supabase — Database, authentication and file storage (EU / US)
- Vercel — Application hosting and content delivery (Global)
- Stripe — Subscription billing and payment processing (US / EU)
- Meta Platforms — WhatsApp Business Cloud API messaging (only if you connect it) (Global)
- Anthropic — AI features (only if enabled on your plan) (US)
- Resend — Transactional email delivery (US / EU)
7. AI processing
If AI features are enabled on your plan and you choose to use them, the specific text you submit for that request is sent to our AI provider to generate a response. It is not used to train models and is not retained by us beyond what is needed to return the result. AI features are optional and can be disabled.
8. International transfers
Our providers operate data centres in several regions, so your data may be processed outside your country. Where that happens we rely on appropriate safeguards such as standard contractual clauses.
9. Security
- All traffic is encrypted in transit using TLS.
- Tenant data is isolated at the database level using row-level security.
- Third-party access credentials you provide are encrypted at rest.
- Administrative access is restricted, and support access to a workspace is recorded in an audit log.
- No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your own credentials safe.
10. Retention
We keep account and CRM data for as long as your subscription is active. After termination we retain it for a limited period so you can export it, after which it is deleted. Billing records and audit logs are kept longer where law requires.
11. Your rights
Depending on where you are, you may have the right to access, correct, delete or export your personal data, to object to or restrict processing, and to complain to a supervisory authority. To exercise these rights regarding your ACCOUNT data, contact us at the address below. For CRM data about your own customers, the request should be directed to the business that holds it.
12. Cookies
We use only the cookies necessary to operate the Service: keeping you signed in and remembering your language choice. We do not use advertising or third-party tracking cookies.
13. Children
The Service is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
14. Changes to this policy
We may update this policy. Material changes will be notified by email or in-app before they take effect.
15. Contact
For privacy questions or to exercise your rights, contact support@hellorabt.com.