Privacy Policy
Fundas LLC ("Fundas", "we", "us", or "our") operates the RiseIQ application, analytical platform, API endpoints, storefront scripts, and related online services (collectively, the "Service").
This Privacy Policy governs our data processing practices and explains how information is collected, accessed, processed, transmitted, and retained when e-commerce merchants ("Merchants", "you", or "Customer") install, integrate, or use RiseIQ in connection with supported e-commerce platforms (including Shopify, BigCommerce, WooCommerce, and other integrated systems).
1. Legal Framework & Data Protection Roles
-
Fundas as Data Controller (Merchant Account Information): With respect to Merchant account registration, subscription management, direct communications, and billing administration, Fundas operates as an independent Data Controller.
-
Fundas as Data Processor / Service Provider (Store Data): With respect to end-customer order records, store catalog metadata, customer IDs, and transaction data accessed via platform APIs or storefront scripts, the Merchant operates as the Data Controller (or Business under the CCPA/CPRA). Fundas operates strictly as a Data Processor (or Service Provider under the CCPA/CPRA), processing such data solely pursuant to the Merchant's instructions and the Terms of Service.
2. Categories of Information Processed
2.1 Merchant Account Information (Minimal Data Collection)
When you install or authenticate RiseIQ, we collect only the minimal technical data required for the app to function:
-
Store Identification & Contact: Store domain/URL, store ID/name, and the Merchant primary contact email address provided via the e-commerce platform API during app installation. We do not collect, request, or store merchant personal names, physical street addresses, or phone numbers.
-
Authentication Credentials: Platform-issued OAuth authorization tokens, webhook endpoints, and API security keys necessary to maintain store connection.
-
Platform-Managed Billing Metadata: For platforms with managed billing (such as Shopify App Billing API and BigCommerce Marketplace Billing), all payment processing, invoicing, and credit card handling are managed exclusively and directly by the respective e-commerce platform. Fundas receives only plan tier status, active billing confirmation, and charge IDs; we never receive or store financial account or credit card numbers.
2.2 Storefront & Catalog Data
To generate predictive analytics and recommendation models, RiseIQ synchronizes non-sensitive store catalog data:
-
Product titles, handles, SKU identifiers, product categories/types, variant hierarchies, pricing, inventory availability, and product image URLs.
2.3 Sales Data (Zero-Persistent Consumer PII Architecture)
RiseIQ's core analytical architecture is designed around data minimization and privacy-by-design:
-
Pseudonymous Customer Identifiers: Internal platform-generated customer IDs, pseudonymous identifiers, or cryptographic hashes. RiseIQ does not ingest, parse, or store consumer real names, physical/shipping addresses, phone numbers, or credit card numbers in its database.
-
Order & Invoice Records: Transaction timestamps, order identifiers, line items (SKUs, quantities, unit prices, discounts), aggregate cart totals, and currency codes.
2.4 Ephemeral / In-Transit Processing (Third-Party Marketing Dispatches)
When a Merchant enables third-party marketing integrations (such as Klaviyo):
-
Real-Time Payload Delivery: RiseIQ scripts execute real-time, on-the-fly API lookups to map internal customer IDs to end-customer email addresses solely to deliver predictive payloads (such as predicted CLTV tiers, churn risk scores, reorder dates, and personalized SKU recommendations) to the Merchant's designated third-party destination account.
-
Strict Zero-Storage in Transit: Customer email addresses are held transiently in volatile memory (RAM) only for the duration of the HTTPS payload dispatch. Email addresses are never written to disk, never indexed in our database, and never retained post-transmission.
3. Purpose and Legal Basis for Processing
We process data on the legal bases of contractual necessity, legitimate business interests in securing our services, and compliance with legal obligations, specifically to:
-
Compute predictive models: Customer Lifetime Value (CLTV) annualized forecasts and tiers (High/Medium/Low), customer churn/attrition risk scores, buy-again/reorder interval predictions, and collaborative/item-based upsell and cross-sell recommendations.
-
Deliver no-code storefront recommendation cards across Home, Product Detail (PDP), and Cart pages.
-
Synchronize segment profiles and automated event triggers into Merchant-authorized external marketing applications (e.g., Klaviyo).
-
Provide merchant-facing AI Assistant querying and operational reporting.
-
Monitor infrastructure uptime, diagnose technical defects, prevent fraudulent abuse, and enforce security integrity.
4. Sub-Processors and Third-Party Disclosures
Fundas engages select third-party service providers ("Sub-Processors") to deliver cloud infrastructure and SaaS functionality. All Sub-Processors are bound by data protection obligations at least as restrictive as those in this Policy:
-
Cloud Infrastructure & Hosting: Managed cloud hosting, compute runtimes, and isolated managed databases (e.g., Railway.app, secure cloud hosting facilities in the United States) utilizing industry-standard encryption standards.
-
E-Commerce Platforms: API connectivity to authorized platforms (Shopify, BigCommerce, WooCommerce) in accordance with their respective developer terms and data protection policies.
-
Merchant-Activated Integrations: API dispatch to merchant-connected CRM/marketing applications (e.g., Klaviyo) strictly as directed by Merchant settings.
-
Legal & Regulatory Disclosures: To law enforcement, regulatory authorities, or legal claimants only when strictly mandated by valid legal process, court order, or applicable statutory rule.
Fundas does not sell, rent, lease, trade, or share personal data or store data with data brokers or unaffiliated third parties for commercial or behavioral advertising purposes.
5. Data Retention and Account Deletion
-
Active Accounts: Store transactional metadata, catalog indices, and calculated predictive model outputs are retained in encrypted databases for the active duration of the Merchant’s subscription.
-
In-Transit Marketing Data: Personal identifiers processed ephemerally during third-party marketing dispatches are flushed from volatile memory immediately upon API completion.
-
App Uninstallation & Termination: Upon app uninstallation or formal account termination, platform API access tokens are immediately revoked. All stored merchant-specific transaction histories and predictive datasets are permanently queued for secure cryptographic erasure and deleted within thirty (30) days, except where retention is strictly required by statutory tax or accounting rules.
6. Security Safeguards
Fundas implements robust administrative, physical, and technical safeguards engineered to protect data against unauthorized access, destruction, alteration, or disclosure:
-
End-to-end transport layer security (TLS 1.2 / TLS 1.3) for all external and internal API transmissions.
-
Industry-standard AES-256 encryption at rest for all database volumes and backups.
-
Logical database multi-tenancy and data isolation barriers preventing cross-merchant access.
-
Strict least-privilege role-based access control (RBAC) and automated audit logging.
7. Compliance with Global Data Privacy Laws (GDPR, UK GDPR, CCPA/CPRA)
-
Data Subject Rights: RiseIQ processes data exclusively as a commercial B2B Service Provider / Data Processor on behalf of the Merchant. End consumers seeking to exercise access, portability, correction, or deletion rights under the GDPR, UK GDPR, California Consumer Privacy Act (CCPA), or California Privacy Rights Act (CPRA) should direct requests directly to the Merchant (the Data Controller).
-
Merchant Support for Data Subject Requests: Fundas shall promptly assist Merchants in fulfilling verified consumer deletion requests (e.g., purging specific customer ID records) upon receipt of an official notice sent to privacy@fundas.ai.
-
International Data Transfers: For Merchants operating in the European Economic Area (EEA), United Kingdom, or Switzerland, Fundas executes standard Data Processing Agreements (DPAs) incorporating standard contractual clauses (SCCs) upon request.
8. Privacy Contact Information
For legal inquiries, Data Processing Agreements, or security notices:
Fundas LLC
Attention: Legal & Privacy Operations
Website: https://www.fundas.ai
Email: privacy@fundas.ai / support@fundas.ai
