Privacy Policy
Last updated: 11 July 2026
Rigpa ("we", "our") provides an AI assistant and a self-serve online storefront that let businesses handle customer conversations, orders and bookings — through a shop's web chat link, its public storefront page, and, where connected, Instagram, WhatsApp, or TikTok direct messages. This policy explains what data we process and why.
Information we process
- Messages you send to a connected business — via the shop's web chat or, where enabled, Instagram, WhatsApp, or TikTok direct messages.
- Photos you upload in chat (for example, a payment screenshot). These are kept in private storage — only the shop you are messaging can view them, through temporary secure links — and are deleted when the conversation is deleted.
- Voice notes you record in chat. Audio is sent to our AI provider to be transcribed into text so the bot can understand it.
- Your profile basics (such as your platform or session user ID and, if provided, your name) needed to reply to you.
- Order details you provide while placing an order — in chat or through a shop's storefront checkout: products, quantities, delivery name/address/phone, an optional order note, and payment method.
- Booking details you provide when reserving a table, appointment, session or viewing: your name, phone, the date/time, and any note.
How we use it
- To answer your questions and take and fulfil your orders.
- To generate chatbot replies and transcribe voice notes using an AI provider.
- To let the business owner manage conversations and orders through their dashboard.
- To send service emails — account confirmation, password resets, and new-order or hand-off alerts to shop owners.
- To send browser push notifications to shop owners who enable them (new orders, hand-offs). If you enable these, we store the push subscription token your browser provides; you can revoke it anytime in your browser settings.
If you create a shop (account holders)
If you sign up to run a shop on Rigpa, we also process your name, email address, phone number, and password (stored securely, never in plain text) along with your business details (shop name, products, FAQs, and payment instructions). We use these to create and secure your account, show you your dashboard, and send you the service emails described above. New shops are reviewed before going live.
On eligible plans we also publish a public storefront page for your shop (rigpanepal.com/s/your-shop) built from your business details, product listings, and any logo or cover photo you upload. This information is intentionally public and may be indexed by search engines. It never includes your login, payment, or customer data. You can turn the storefront off at any time in Settings. If a customer places an order through the storefront checkout, we process the order details above (name, phone, delivery address, items and payment method) to fulfil that order, exactly as for an order placed in chat.
Subscription & payments (account holders)
Paid plans are purchased up-front via eSewa. When you subscribe we process your shop name, phone, email, chosen plan, amount, and any eSewa transaction reference you provide, so we can verify your payment and activate your plan. Your eSewa account credentials are never shared with us — you pay directly through eSewa, and we only see the reference you enter and confirm receipt on our side.
Instagram, WhatsApp & Meta data
If a shop connects its Instagram or WhatsAppaccount (both are Meta products), Rigpa accesses that account's direct messages and basic account infoonlyto: read incoming messages, generate and send the bot's replies, and show those conversations in the shop owner's dashboard. We store a secure access token for the connected account on our server (never shared with other shops or exposed in the browser). We use this data solely to operate the messaging features described here — we do not sell it or use it for advertising — and we handle it in line with Meta's Platform Terms. A shop can disconnect Instagram or WhatsApp at any time from Settings, which deletes the stored token; you can also revoke access from your Instagram / WhatsApp / Meta account settings.
How it is shared
- The business you are messaging (the owner of the shop) can see your conversation, photos, and orders.
- Delivery couriers— when a shop dispatches your order for home delivery, we pass your delivery name, phone number, address, a short summary of the parcel contents, and any cash-on-delivery amount to the shop's chosen courier (e.g. Pathao) so they can pick up and deliver your parcel and, for COD, collect payment. The courier handles this information under its own privacy policy. We also use your address (before you order) to ask the courier for a delivery price quote.
- Service providersthat operate the service: Meta (Instagram & WhatsApp) and TikTok (messaging, where connected), Supabase (database and file storage), Vercel (application hosting), Cloudflare (domain, DNS, and email routing), Resend (sending service emails), and an AI provider (Groq, or OpenAI) to generate replies and transcribe voice notes. We do not sell your data.
Data security
Data is transmitted over encrypted HTTPS. Passwords are hashed (never stored in plain text), access tokens are kept server-side, and each shop's data is isolated so one shop can never read another's. No system is perfectly secure, but we take reasonable measures to protect your information.
Where your data is processed
Our service providers (listed above) may store and process data on servers outside Nepal. By using Rigpa you understand your data may be processed in those locations under their respective safeguards.
Retention
We keep conversation, photo, and order data for as long as needed to provide the service and meet the business's record-keeping needs. Conversations a shop marks as closedare automatically deleted about a day later — including their messages and any uploaded photos, which are removed from storage. You can request deletion of your data at any time (see below).
Children
Rigpa is intended for businesses and adult customers. It is not directed to children under 13, and we don't knowingly collect their data. If you believe a child has provided us data, contact us and we'll remove it.
Your choices & data deletion
To request access to or deletion of your data, see our Data Deletion Instructions or email admin@rigpanepal.com.
Cookies
We use only essential cookies and similar storage — see our Cookie Policy. We don't use advertising or cross-site tracking cookies.
Changes to this policy
We may update this policy as the service evolves. We'll revise the "Last updated" date above, and significant changes will be highlighted where appropriate.
Contact
Rigpa is operated by Rigpa Nepal (PAN 159975497), Ward 8, Boch, Bhimeshwar Municipality, Dolakha, Bagmati, Nepal. Questions about this policy? Email admin@rigpanepal.com or message us on WhatsApp.