Privacy Policy
Overview
Suggesto (operated by Adhish.in) lets ecommerce businesses create Product Advisors — short, on-brand quizzes that help a shopper answer a few product-related questions and get matched to the right product in the business's catalogue. This Privacy Policy explains what personal data we collect, how we use it, who we share it with and what rights you have over it.
This policy covers two categories of people: businesses (the people who sign up and build Product Advisors) and shoppers (the visitors who use those Product Advisors on a business's site). Where the law assigns different roles to the business and Suggesto, we call them out explicitly.
Data we collect
Account data (businesses). Name, email address and a bcrypt-hashed password used to sign in. If you sign in with Google, we receive the email and name associated with your Google account.
Product Advisor content (businesses). The questions, answers, products, themes, tags, weights and any copy or images you upload to build a Product Advisor.
Shopper interactions (shoppers). The answers a shopper selects, the products recommended to them, basic timing information, and which recommended products they clicked.
Lead data (shoppers). Email address and any optional custom fields the business has added to the lead-capture form. We only collect lead data when the business has explicitly enabled lead capture on the Product Advisor. The consent text shown at the time of capture is stored alongside the lead.
Performance metrics. Aggregate Product Advisor analytics — views, starts, completions, leads captured and conversion rate — so the business can see how their Product Advisor is performing.
Usage and diagnostics. Standard server logs we use to keep the Service running and to debug errors.
How we use the data
To operate the Service: authenticate businesses, render Product Advisors, compute product recommendations, deliver leads to the business's dashboard and send transactional emails.
To support businesses: respond to support requests, prevent fraud and abuse.
To improve the product: identify which features get used, debug errors and measure performance.
To meet legal obligations: respond to lawful requests and enforce our Terms of Service.
Controller and processor roles
For account data and product usage, Suggesto is the data controller.
For shopper responses and captured leads, the business is the data controller and Suggesto is the data processor. The business decides what fields are collected, what notice is shown to shoppers, and how the leads are used downstream.
If you are a shopper and want your data corrected or removed, please contact the business whose Product Advisor you completed. We can assist on their behalf if you cannot reach them.
Legal basis (EEA / UK / India)
Where the GDPR or UK GDPR apply, we rely on the legal bases of contract (to deliver the Service to businesses), legitimate interests (to secure and improve the Service) and consent (for any optional consent the business collects through the lead-capture form).
For users in India, we comply with the Digital Personal Data Protection Act, 2023. Consent is obtained at sign-up for businesses, and at each lead-capture form for shoppers.
Data retention
Account data and Product Advisor content: retained for the life of your account. On account closure, account data is deleted; billing or compliance records we are legally required to keep are retained for the period required.
Shopper responses and leads: retained for the life of the parent Product Advisor. Businesses may delete individual leads from the dashboard at any time. Deleting a Product Advisor removes its questions, recommendations and captured leads from the database immediately.
Server logs: retained for security and debugging for a limited period, then truncated to anonymous aggregates.
Security
Suggesto runs on managed cloud infrastructure with TLS in transit, encryption at rest, principle-of-least-privilege access and regular dependency scans. Passwords are stored as bcrypt hashes and are never visible to staff.
We do not promise that any system is perfectly secure, and we ask businesses to use strong passwords or to sign in with Google.
International transfers
Personal data may be processed in India and in the cloud regions of our infrastructure providers (which may include the United States and the European Union). Where we transfer personal data out of the EEA / UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as appropriate.
Your rights
Subject to local law, you have the right to access, correct, port, delete or restrict our processing of your personal data, and to object to processing based on legitimate interests. Businesses can exercise most of these rights directly from the admin panel; for anything else, write to support@suggesto.me.
You also have the right to lodge a complaint with your local data-protection authority. We would, however, appreciate the chance to address your concern first.
Children
Suggesto is not intended for children under sixteen. We do not knowingly collect personal data from anyone under that age. If you believe a child has shared personal data with us, please contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will notify businesses by email or with a notice in the admin panel at least fourteen days before it takes effect. The “Last updated” date above always reflects the current version.
Contact
Privacy questions, account-deletion requests or any other data-related concerns can be sent to support@suggesto.me. We aim to respond within one business day.