ardito.
How it worksFeaturesPricingSample reportFAQLog inGet your audit

Privacy Policy

Effective 1 September 2026, last updated 5 October 2026. Ardito ("we") is operated by Eugenio Palmieri, Singapore. Contact: hello@arditohq.com.

What we process, and why

Ardito measures whether a business answers its customer enquiries, how fast, and how well. A business connects its own channels through Meta’s official APIs. Once a channel is connected, Meta sends us the following:

  • WhatsApp: one-to-one messages between the business’s WhatsApp Business number and its customers, including the replies the business’s team sends, with the customer’s phone number. If the business chooses to share earlier message history while connecting, Meta sends that history too. Group chats are not included.
  • Facebook Page: Messenger messages sent to the Page and the Page’s replies, with reactions, button taps and ad referral details attached to them; activity on the Page’s posts, such as comments and reactions, with the name and account id of the person; reviews and recommendations of the Page; and mentions of the Page.
  • Instagram: direct messages and story replies sent to the business account and the business’s replies, with reactions, button taps, read receipts and ad referral details attached to them, and the sender’s Instagram account id. Instagram delivery runs through the Facebook Page the account is linked to, so connecting an Instagram account also switches on Meta’s delivery of that linked Page’s events, as listed under Facebook Page above. Ardito records messages from that Page only if the Page is connected too, but its events still reach the event log described under Storage and deletion.

Connecting a Facebook Page or an Instagram account is not yet open to every business. Until Meta approves our app, only accounts with a role on the Ardito app at Meta can connect them.

We use this data only to produce response-time and reply-quality reports for the business that connected the channel. The business is the controller of its customer conversations; Ardito acts as its processor.

What we never do

  • We never send a message to a business’s customers on our own, and never start a conversation. On Facebook Messenger and Instagram, the business owner can reply from Ardito to a customer who wrote first, within Meta’s 24-hour window; Ardito sends that reply only when the owner clicks Send.
  • We never sell, share, or pool conversation data across customers.
  • We never use one customer’s data in demos, marketing, benchmarks, or to train models.

Who else processes it

  • Meta delivers the channel data described above to our server.
  • DigitalOcean hosts our application server and our managed PostgreSQL database, both in Singapore. Everything we store is stored there.
  • Anthropic receives the text of answered conversations for reply-quality grading, only for businesses on the Coach plan. The customer’s phone number or account id is not attached, but anything written inside a message, such as a phone number, is sent as written. It is sent under Anthropic’s commercial API terms, which do not allow the data to be used for model training.
  • Cloudflare sends our email (Cloudflare Email Sending), including password resets and the weekly summary email to the business. The weekly summary can include the first 90 characters of unanswered customer messages. Cloudflare also receives email sent to hello@arditohq.com (Cloudflare Email Routing).
  • Stripe processes payments for paid plans. Card details go to Stripe and never reach our servers.
  • Google receives messages sent through our website contact form, which we forward to our team’s Gmail inbox. Our public website pages also load fonts from Google Fonts, which sees your IP address.

Storage and deletion

We keep two things for each connected channel: the messages we extract from what Meta sends, and a log of each event exactly as Meta sent it. Today that event log is not linked to a customer account.

Facebook Page and Instagram: disconnecting in the Ardito workspace tells Meta to stop sending that account’s events. A Page and the Instagram account linked to it share one subscription at Meta, so if one of them is still connected, Meta keeps sending the Page’s events; Ardito stops recording new messages for the one you disconnected, but the event log still receives them.

WhatsApp, account closure and stored data: these are not self-serve yet. To disconnect a WhatsApp number, close an account, or delete stored conversations and the matching event log, email hello@arditohq.com from the account’s email address. We do it by hand within 30 days of the request and confirm by email.

Page access tokens: for each connected Facebook Page and Instagram account we keep the Page access token Meta issues at connection, encrypted, so the owner can reply from Ardito. It is used only to send the owner’s replies and is deleted when the Page or account is disconnected.

Disconnecting a channel does not delete the messages already stored. They stay until you ask us to delete them. DigitalOcean’s automatic database backups can hold deleted data for a limited period after that, until they expire.

Account data

We keep the account holder’s email, a hashed password, the business name, industry, country and locations, a log of sign-ins and sign-up events with IP addresses, and billing status with Stripe references, for as long as the account exists and as required by law. Messages sent through the contact form are kept with the sender’s name, email and IP address.

Website

Our public website uses no analytics or advertising trackers. Ardito sets one session cookie when you sign in. Inside the workspace, the page for connecting WhatsApp loads Meta’s JavaScript SDK, which opens Meta’s own connection window and can send Meta its own usage events.

End-user deletion requests

If you are a customer of a business that uses Ardito and want your conversation data removed, contact that business, or email hello@arditohq.com with the phone number or Facebook or Instagram account you messaged from. We will delete the matching data by hand, working with the business, within 30 days, and confirm by email. See also our data deletion instructions.

Changes

We will post changes here and email account holders about material ones.

How it worksFeaturesPricingFAQSecurity & dataSample reportContactPrivacyTermsData deletionhello@arditohq.com

© 2026 Ardito · every enquiry answered

Ardito is an independent product and is not affiliated with, endorsed by, or connected to Meta Platforms or WhatsApp.