1. Scope and who is responsible
This policy applies to Farosh's website, seller workspace, buyer portal, public catalog and request-for-quote experiences, and related communications and services (together, the "Service").
Faroshcontrols information used to operate Farosh, such as account, billing, website, security, and support information. When an organization uses Farosh to manage its customers, contacts, messages, and commercial records, the organization generally decides why and how that information is used. Farosh processes that data on the organization's instructions to provide the Service.
If an organization invited you, communicated with you, or shared a catalog with you, its own privacy notice may also apply. That organization is responsible for its customer relationships, notices, permissions, and instructions to Farosh.
2. Information we collect and process
Account and organization information
Name, business email address, password or authentication records, email-verification status, organization details, membership, role, permissions, invitations, and account preferences.
Buyer and contact information
Names, business contact details, organization or market information, catalog activity, quote requests, and information submitted through the buyer portal, a public catalog, or another shared Farosh link.
Business content and commercial records
Customer and contact records, product and catalog information, uploaded product images, conversations and attachments, notes, assignments, requests for quote, quotes, purchase orders, invoices, references, statuses, and related activity and timestamps.
Connected communications
For connected channels such as WhatsApp, we process business-account and phone identifiers, senders and recipients, message content, attachment references, templates, consent and opt-out records, timestamps, and delivery states. We also process the information needed to send account, catalog, transactional, realtime, and browser push notifications.
Device, usage, and security information
IP address, browser and device details, session information, request identifiers, page or action timestamps, push-subscription details, diagnostic events, rate-limit information, and security and audit logs. We design application logs to exclude passwords, access tokens, raw connection credentials, and message content.
3. How information reaches us
We receive information:
- Directly from users, buyers, and organization administrators.
- From organizations that import, enter, or share business records.
- From connected services, including Meta and WhatsApp, when an organization authorizes the connection.
- Automatically from browsers, devices, and infrastructure when the Service is used.
4. How we use information
- Provide, maintain, and secure the Service.
- Authenticate users, deliver verification codes and links, and enforce organization and role-based access.
- Send, receive, organize, search, and reconcile business messages and commercial workflows.
- Provide catalogs, quote requests, quotes, purchase orders, invoices, notifications, and realtime updates.
- Troubleshoot failures, prevent abuse, enforce limits, and protect users and connected services.
- Provide support, communicate service changes, and comply with law.
- Analyze aggregate service performance and improve reliability and usability.
5. Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract to provide the Service; legitimate interests in operating, securing, supporting, and improving Farosh; compliance with legal obligations; and consent where required. An organization is responsible for establishing its own legal basis for customer data it directs Farosh to process.
6. When we disclose information
We may disclose information to:
- Hosting, database, cache, object-storage, email, security, and support providers that help operate Farosh.
- Meta and WhatsApp when an organization uses connected WhatsApp services.
- Realtime and browser-push providers, including Ably and the push service operated by the user's browser or operating-system vendor.
- Organization owners, administrators, members, buyers, suppliers, or recipients as required by their roles and the workflow being performed.
- Professional advisers, insurers, auditors, authorities, or courts when reasonably necessary or legally required.
- A buyer, successor, or financing party involved in a proposed or completed business transaction, subject to appropriate safeguards.
- Other parties when the relevant organization directs us.
Service providers may use information only to perform services for us or as otherwise permitted by their agreement and applicable law. Connected third-party platforms also process information under their own terms and privacy policies.
7. Our data-use commitments
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use organization customer messages or commercial records to train a general-purpose artificial-intelligence model. If these practices change, we will update this policy and provide any choices required by law before the change applies.
8. Retention and deletion
We retain information for as long as reasonably needed to provide the Service, follow an organization's instructions, maintain security and audit records, resolve disputes, and meet legal obligations. The period depends on the type of record, account status, contractual commitments, and legal requirements.
Verification codes and sign-in links are short-lived even though limited security records may be retained longer. When an account or data is deleted, residual copies may remain temporarily in restricted backups and logs until they expire through normal retention cycles. We may retain information when required by law or needed to establish, exercise, or defend legal claims.
9. Security
Farosh uses safeguards designed for the nature of the Service, including encrypted transport, organization-scoped authorization, role-based access, encrypted integration credentials, hashed short-lived verification values, restricted logging, rate limits, and operational monitoring. No service can guarantee absolute security. Users must protect their devices and credentials, grant team access carefully, and promptly report suspected misuse.
10. Public and shared links
Catalog and buyer links may be accessible to anyone who receives them. Organizations and users should share these links only with intended recipients and avoid placing sensitive information in public fields. We may use expiration, verification, and access controls where the relevant workflow supports them, but recipients can still forward content they are permitted to view.
11. International processing
Farosh and its providers may process information in countries other than where it was collected. Where required, we use recognized legal transfer mechanisms and contractual or other safeguards appropriate to the transfer.
12. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, withdraw consent, or complain to a supervisory authority. These rights may be subject to exceptions under applicable law.
If an organization supplied your information or communicates with you through Farosh, contact that organization first because it controls the business relationship. We will assist it with valid requests. For Farosh-controlled account, website, or security information, contact us directly at info@faroshtech.com. We may verify your identity before completing a request.
13. Cookies, local storage, and analytics
The marketing website stores a device-local theme preference. The Service uses storage that is necessary for authentication, security, sessions, installation, notifications, and user preferences. Farosh does not currently use advertising cookies or cross-site behavioral tracking. Before adding optional analytics or advertising technology, we will update this notice and provide consent or opt-out controls where required.
14. Children
Farosh is a business service and is not directed to children. We do not knowingly collect personal information from children through the Service. If you believe a child has provided information improperly, contact us so we can investigate and take appropriate action.
15. Changes and contact
We may update this policy as Farosh, our providers, or applicable law changes. We will post the revised policy with a new effective date and provide additional notice of material changes where appropriate. Questions, complaints, and privacy requests can be sent to info@faroshtech.com. The final legal entity, business address, jurisdiction-specific disclosures, and production retention schedule must be confirmed before commercial launch.