Privacy Policy

Last Updated: August 18, 2026

At Ruhanir Engine, we take your privacy and data security seriously. As a multi-tenant SaaS provider, we enable our customers (hereafter "Tenants") to spin up their own white-label portals for various categories (education, wellness, e-commerce, and portfolios). This Privacy Policy explains how we collect, store, share, and protect information when you use our platform.

1. Information We Collect

We collect information to provide better services to our tenants and their end-users:

  • Tenant Account Details: When you request or sign up for a portal, we collect details such as your company name, email address, physical address, and contact numbers.
  • End-User Data (Tenant Customers/Students/Patients): Our tenants upload, store, and process end-user data (e.g., student rosters, patient medical records, customer e-commerce orders). This data is isolated and controlled by the respective Tenant as the Data Controller.
  • Technical Logs & Analytics: We automatically log technical data, including IP addresses, browser types, referral links, and system response times for security auditing and debugging.

2. How We Use Information

We process data only for legitimate business interests, including:

  • Provisioning and maintaining dedicated white-label portal systems.
  • Processing subscription billing and invoice transactions securely (via Stripe, bKash, SSLCommerz).
  • Delivering automated communications like SMS alerts, WhatsApp notices, and video sessions on behalf of tenants.
  • Diagnosing system anomalies and monitoring network uptime health.

3. Multi-Tenant Isolation & Sharing

Data in Ruhanir Engine is strictly partitioned. We use PostgreSQL Row-Level Security (RLS) policies to ensure that one tenant can never access or view another tenant's databases, staff lists, or client details. We do not sell or trade any tenant or end-user data. We only share data with critical third-party infrastructure processors (e.g., Supabase database storage, Twilio for SMS, Stripe for gateway transactions) under strict confidentiality terms.

4. Data Subject Rights (GDPR & Local Regulations)

Under global data protection laws (such as GDPR), end-users have rights regarding their personal data, including the right to access, rectify, or delete their information. Because Tenant data is controlled by individual Tenant administrators, end-users requesting data exports or deletions should contact the respective Tenant administrator. We provide built-in tools for Tenant administrators to export or purge data in compliance with GDPR.

5. Updates to This Policy

We may update this Privacy Policy periodically to reflect shifts in technology, operational guidelines, or legal compliance. Any changes will be posted on this page with an updated "Last Updated" timestamp.

6. Contact Us

If you have any questions or concerns regarding our privacy standards or need to report a data protection issue, please contact our support desk at support@ruhanir.app.