Privacy Policy
Last Updated: August 24, 2026 • Version 2.4
1. Introduction & Scope
Welcome to Turtle ("we", "us", or "our"). We provide a premium Software-as-a-Service (SaaS) commerce platform allowing merchants to quickly construct online storefronts, manage products, synchronize WhatsApp order pipelines, and process global customer payments.
We hold your privacy in the highest regard. This Privacy Policy details how we collect, process, utilize, share, and protect information pertaining to merchants (our clients), customers of those merchants (end consumers), and visitors to our promotional domains.
By accessing or registering with Turtle, you explicitly agree to the collection and handling of data as described herein. If you disagree with any terms in this policy, you must cease use of our services immediately.
2. Information We Collect
Depending on your interaction with the Turtle platform, we collect varying categories of operational and personal data:
A. Merchant-Specific Information
When you create an account to sell products through Turtle, we collect:
- Account Details: Contact details (email address, full name) and authentication tokens managed via Google and Supabase.
- Store & Business Metadata: Product catalogs, inventory logs, pricing tiers, and WhatsApp contact parameters for messaging integration.
- Financial Metrics: Transaction histories, billing contacts, and subscription statuses. We do not store raw card numbers; transaction data is managed securely by tier-1 payment partners.
B. End-Customer Information
When consumers access, browse, or place orders through a Turtle-powered merchant storefront, we collect:
- Transaction Details: Contact numbers (for WhatsApp ordering), delivery addresses, items ordered, and totals.
- Usage Logs: Clickstreams, cart additions, and timestamp information indicating how customers interact with merchant checkouts.
| Data Category | Source | Primary Purpose |
|---|---|---|
| Email & Auth Tokens | Merchants | Account lifecycle & security verification |
| WhatsApp Credentials | Merchants | Enabling direct store-to-app routing |
| Order Logs | Customers | Fulfillment processing & dashboard analytics |
3. How We Use Information
We compile and handle collected information to fulfill operational demands, specifically:
- Core Service Provisioning: Hosting, generating, and maintaining fast, high-performance storefronts.
- Integrations: Routing checkout forms to WhatsApp nodes to facilitate chat-based commerce.
- Operational Analytics: Computing store statistics, visit counts, and conversion patterns to keep merchant dashboards accurate.
- Billing Support: Validating accounts, processing subscription cycles, and handling service alerts.
- Compliance & Protection: Safeguarding against fraudulent storefront listings, malicious access, and platform abuse.
5. Data Security & Storage
We implement robust, modern defenses. All traffic routes through encrypted TLS protocols, and store data rests in secure, firewall-protected database infrastructures.
No transmission medium is 100% secure. While we deploy strict controls, we cannot guarantee absolute security. Merchants are encouraged to safeguard their credentials and notify us immediately if unauthorized access is suspected.
7. Your Rights & Choices
Depending on your jurisdiction (such as EEA under GDPR or California under CCPA/CPRA), you retain key legal privileges:
- Access & Portability: Obtain a detailed report of all personal profiles stored in our systems.
- Correction: Instantly update profile credentials directly in your dashboard interface.
- Erasure ("Right to be Forgotten"): Request complete erasure of your merchant profile, catalogs, and analytics records.
- Opt-Out: Unsubscribe from news alerts or product announcements via footer links.
8. Data Retention
We retain merchant details only as long as an account is active. Upon account deletion, we purge or anonymize merchant databases within 30 business days, excluding records required to comply with financial audits or legal obligations.
Order Ledger & Transaction Retention Rules
- Rejected Orders: Orders that are flagged as rejected by the merchant are stored for active operational logging and auditing before archival.
- Completed Orders Deletion Lock: Completed orders represent permanent transaction records and cannot be deleted or removed from the system log for a minimum duration of one (1) year from the completion timestamp. This is required to maintain legal ledger compliance, tax reporting, and dispute mediation.
- Post-1-Year Retention Settings: After the one-year regulatory hold period, merchants can configure their preferences to decide whether they wish to archive, purge, or indefinitely keep completed order records. By default, unless configured otherwise by the merchant, completed transaction logs are preserved permanently.
9. Inquiries & Contact Info
If you have clarifying questions, security inquiries, or require help enforcing access rights, please contact the Softrover Legal & Privacy Desk:
Mailing & Support
Email: legal@Turtle.softrover.tech
Address: Softrover SaaS Division, Legal Operations, Dhaka, Bangladesh