Privacy Policy
Last updated: 9 August 2026
Who we are
Ritmo is an omnichannel customer-messaging platform operated by Ritm Digital Solutions. It lets a business connect its own messaging accounts — WhatsApp Business, Facebook Messenger, Instagram, TikTok, and a website chat widget — and handle the resulting conversations from a shared team inbox.
This policy explains what we collect, why, and what you can do about it. It covers both the businesses that sign up for Ritmo (our customers) and the people who message those businesses (end users).
It applies specifically to the Ritmo product. For how Ritm Digital Solutions handles personal data across the company as a whole, see our company privacy policy.
Information we collect
Account information. When a business signs up we store its workspace name, email address, phone number, and a hashed password. Passwords are hashed with bcrypt and are never stored or transmitted in plain text.
Conversation data. When an end user messages a connected channel, we store the message content, the timestamp, the direction (incoming or outgoing), and the platform-assigned identifier for that message. We also store a contact record for that person, which may include the identifier their platform provides (such as a phone number for WhatsApp or a page-scoped ID for Messenger) and any name, email, phone number, or custom fields the business collects during the conversation.
Channel credentials. When a business connects a Meta or TikTok account, we store the access tokens that platform issues. These tokens are encrypted at rest using AES-256-GCM before being written to the database.
Files and media. Images and attachments sent through the platform are stored in object storage (Cloudflare R2 and Google Firebase Storage).
Technical data. We keep server logs of webhook deliveries and API requests for debugging and abuse prevention. If a business enables mobile push notifications, we store the device token needed to deliver them.
How we use it
- To deliver the core service — receiving, routing, displaying, and sending messages on behalf of the business.
- To authenticate users and keep accounts secure.
- To enforce plan limits, such as the monthly message allowance on the free tier.
- To diagnose faults and investigate abuse.
- To send service-related notifications about the account.
We do not sell personal data. We do not use conversation content to train machine-learning models, and we do not use it for advertising.
Who processes data on our behalf
We rely on a small number of infrastructure providers, each of which processes data only to provide their service to us:
- Meta Platforms — delivery of WhatsApp, Messenger, and Instagram messages.
- TikTok — delivery of TikTok direct messages.
- Google Firebase — mobile push notifications and file storage.
- Cloudflare R2 — file and media storage.
- Hosting and email providers — running the application servers, database, and transactional email.
Roles and responsibilities
For conversation data, the business using Ritmo is the data controller and Ritmo is the data processor. The business decides what to collect from its customers and how long to keep it. If you messaged a business through Ritmo and want your data removed, contact that business directly — or contact us and we will route your request to them.
For account data belonging to the businesses themselves, Ritmo is the controller.
Retention
Conversation and contact data is retained for as long as the business keeps its account open. When an account is deleted, associated data is removed as described on our data deletion page. Server logs are retained for a shorter period and then rotated out.
Security
All traffic is served over HTTPS. Platform access tokens are encrypted at rest with AES-256-GCM. Incoming webhooks from Meta are verified using HMAC-SHA256 signatures, and unsigned deliveries are rejected. Access to conversations is scoped per workspace, and individual channels can be restricted to named team members.
No system is perfectly secure. If we become aware of a breach affecting personal data, we will notify affected customers without undue delay.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email privacy@uritm.com. See our GDPR page for more detail.
Changes to this policy
We may update this policy as the product changes. Material changes will be communicated to account holders by email or in-app notice. The date at the top of this page reflects the most recent revision.
Contact
Questions about this policy can be sent to privacy@uritm.com.