Effective 1 September 2026, last updated 5 October 2026. Ardito ("we") is operated by Eugenio Palmieri, Singapore. Contact: hello@arditohq.com.
Ardito measures whether a business answers its customer enquiries, how fast, and how well. A business connects its own channels through Meta’s official APIs. Once a channel is connected, Meta sends us the following:
Connecting a Facebook Page or an Instagram account is not yet open to every business. Until Meta approves our app, only accounts with a role on the Ardito app at Meta can connect them.
We use this data only to produce response-time and reply-quality reports for the business that connected the channel. The business is the controller of its customer conversations; Ardito acts as its processor.
We keep two things for each connected channel: the messages we extract from what Meta sends, and a log of each event exactly as Meta sent it. Today that event log is not linked to a customer account.
Facebook Page and Instagram: disconnecting in the Ardito workspace tells Meta to stop sending that account’s events. A Page and the Instagram account linked to it share one subscription at Meta, so if one of them is still connected, Meta keeps sending the Page’s events; Ardito stops recording new messages for the one you disconnected, but the event log still receives them.
WhatsApp, account closure and stored data: these are not self-serve yet. To disconnect a WhatsApp number, close an account, or delete stored conversations and the matching event log, email hello@arditohq.com from the account’s email address. We do it by hand within 30 days of the request and confirm by email.
Page access tokens: for each connected Facebook Page and Instagram account we keep the Page access token Meta issues at connection, encrypted, so the owner can reply from Ardito. It is used only to send the owner’s replies and is deleted when the Page or account is disconnected.
Disconnecting a channel does not delete the messages already stored. They stay until you ask us to delete them. DigitalOcean’s automatic database backups can hold deleted data for a limited period after that, until they expire.
We keep the account holder’s email, a hashed password, the business name, industry, country and locations, a log of sign-ins and sign-up events with IP addresses, and billing status with Stripe references, for as long as the account exists and as required by law. Messages sent through the contact form are kept with the sender’s name, email and IP address.
Our public website uses no analytics or advertising trackers. Ardito sets one session cookie when you sign in. Inside the workspace, the page for connecting WhatsApp loads Meta’s JavaScript SDK, which opens Meta’s own connection window and can send Meta its own usage events.
If you are a customer of a business that uses Ardito and want your conversation data removed, contact that business, or email hello@arditohq.com with the phone number or Facebook or Instagram account you messaged from. We will delete the matching data by hand, working with the business, within 30 days, and confirm by email. See also our data deletion instructions.
We will post changes here and email account holders about material ones.