Skip to main content
Gerai information centre

Privacy Policy

How Gerai handles personal data across corporate enquiries, merchant platform use, and buyer interactions with merchant storefronts.

Effective
Last updated
Authoritative language
English

1. Scope and our roles

This policy applies to personal data handled by World Council for AI PTE. LTD., trading as Gerai, through gerai.shop, the Gerai merchant platform, Gerai-powered storefronts, and related communications.

Gerai supports merchants who sell their own products to buyers. The merchant remains the seller and controls its product offer, order fulfilment, customer relationship, and many decisions about buyer data. Depending on the interaction, Gerai may handle personal data for its own purposes, such as operating and securing the platform, or on a merchant’s instructions to provide storefront and order-management functions.

Questions about a merchant’s products, fulfilment, returns, or use of buyer information should normally be directed to that merchant. Questions about Gerai’s own handling of personal data can be sent to hello@gerai.shop.

2. Personal data we handle

ContextExamples of dataHow it reaches Gerai
Corporate enquiriesName, business contact details, organisation, role, message, and correspondenceDirectly from you or a colleague who introduces you
Merchant accountsAccount identifiers, contact details, business and storefront settings, and access recordsFrom merchants and their authorised users
Merchant contentProduct details, catalogue files, images, prices, availability, and fulfilment informationUploaded or supplied by the merchant
Buyer ordersContact, delivery, cart, order, payment-status, and fulfilment detailsFrom the buyer, merchant, and licensed payment service involved in the transaction
CommunicationsSupport messages, feedback, attachments, and related correspondenceFrom the people participating in the conversation
Technical operationsIP address, request time, route, device or browser information, diagnostic events, and security signalsGenerated when a browser, device, or connected service communicates with Gerai

A buyer’s cart may be stored in that browser under the functional localStorage keygerai-cart. Gerai also uses server-side operational analytics derived from requests to understand service operation and reliability. See the Cookie and Browser Storage Notice.

Please do not send sensitive personal data that is not needed for the relevant transaction or enquiry. Merchants are responsible for ensuring that the information they place in Gerai is lawful, relevant, and appropriate for their business.

3. How we use personal data

Gerai may use personal data to:

  • respond to corporate, sales, legal, privacy, and support enquiries;
  • create, administer, and secure merchant access;
  • build and operate merchant storefronts and catalogues;
  • route buyer order information to the relevant merchant;
  • show transaction status received from payment services without holding buyer funds;
  • support merchant fulfilment and buyer communications;
  • detect misuse, investigate faults, maintain logs, and protect the service;
  • understand service operation through server-side operational analytics;
  • comply with applicable law and enforce our agreements; and
  • establish, exercise, or defend legal claims.

We do not use browser analytics cookies for cross-site advertising or behavioural profiles. If our practices materially change, this policy and the storage notice will be updated.

4. Reasons for handling data

The legal characterisation of a processing activity depends on the person, place, and context involved. Where applicable, Gerai relies on one or more of the following grounds:

  • Contract or steps before a contract, such as onboarding a merchant, administering an account, or providing a requested walkthrough.
  • Legitimate interests, such as operating, improving, and securing Gerai, responding to business communications, and preventing misuse, where those interests are not overridden by individual rights.
  • Legal obligations, including responding to valid legal process and maintaining information the law requires us to keep.
  • Consent, where consent is the appropriate basis and can be withdrawn for future processing.

When Gerai processes buyer data solely on a merchant’s documented instructions, the merchant is responsible for identifying its own lawful basis and giving buyers the notices required for its selling activity.

5. Sharing, merchants, and payments

Personal data may be disclosed only as relevant to the service or legal context, including to:

  • the merchant from whom a buyer places an order;
  • people authorised by that merchant to manage its storefront and fulfilment;
  • service providers that support hosting, communications, security, diagnostics, and platform operations;
  • licensed payment services selected for the transaction;
  • professional advisers, counterparties, or successors involved in a legitimate corporate transaction; and
  • courts, regulators, law enforcement, or other recipients where disclosure is lawfully required or necessary to protect rights and safety.

We do not publish a provider or subprocessor list on this page because arrangements may depend on the merchant deployment and procurement scope. Merchants evaluating processing terms can review the Data Processing Addendum information page and contact us for current, relevant details.

6. AI-assisted features

Gerai may use narrow AI-assisted features for tasks such as helping prepare catalogue content or assisting with routine conversations. AI-generated material is labelled where it is presented as such, can be wrong or incomplete, and is not a substitute for merchant or human judgement. Material used on a live shop is subject to human review.

Gerai does not describe its AI as making legal or similarly significant decisions about a person. When an interaction needs judgement, involves an exception, or cannot be handled reliably, it should be escalated to a person. Read the AI Transparency Notice for the operational boundary.

7. Retention and security

Gerai keeps personal data only for as long as it is reasonably needed for the purpose for which it was collected, to provide and secure the service, to address disputes, and to meet applicable legal requirements. The appropriate period varies by data type, merchant instructions, account status, operational need, and any legal hold. We do not state fixed periods where no verified, universal period applies.

Gerai uses reasonable technical and organisational measures appropriate to the nature and context of the information. No online system can guarantee absolute security. Merchants and their users must protect their access methods, use authorised accounts only, and promptly report suspected compromise.

A verified request to delete data may be limited where data must be retained for a legal obligation, security investigation, dispute, or another lawful reason. Data processed for a merchant may need to be handled through that merchant so that Gerai can follow the correct controller’s instructions.

8. International processing

Gerai serves Southeast Asia and may use people or service providers in more than one country. This means personal data may be accessed or processed outside the country where it was collected. The specific locations and transfer arrangements can depend on the service configuration and merchant engagement.

Where applicable law requires safeguards for an overseas transfer, Gerai and the relevant parties will address those requirements in the applicable service or procurement terms. We do not claim a universal data location or transfer mechanism on this public page. Prospective merchants with location requirements should raise them before onboarding through our contact channel.

9. Your choices and rights

Depending on applicable law and Gerai’s role, you may be entitled to ask for access to or a copy of personal data, correction, deletion, restriction, portability, withdrawal of consent, or objection to particular uses. You may also be entitled to complain to the data protection authority responsible for your location.

Email hello@gerai.shop with enough detail to identify the relevant interaction, merchant, storefront, or account. We may ask for information needed to verify identity and protect other people’s data. We will assess and respond under the law that applies rather than promise a single response period for all jurisdictions.

For buyer order data, contacting the seller first is often the fastest route because the merchant controls the sales relationship. Gerai may forward a request to the merchant or assist the merchant where Gerai processes the data on its behalf. Singapore-specific information is available in the Singapore PDPA Notice.

10. Children

Gerai’s merchant platform is intended for businesses and authorised business users, not for children. Merchant storefronts sell the merchant’s products to the public. Merchants are responsible for ensuring that their offers, buyer communications, and collection of buyer data are appropriate for their audience and comply with laws concerning children.

If you believe a child has provided personal data to Gerai or through a Gerai-powered storefront in circumstances that should be reviewed, contact us and identify the relevant merchant or storefront.

11. Changes and contact

We may update this policy as Gerai, our legal obligations, or our data practices change. The effective and last-updated dates shown above identify the current public version. Material changes may also be communicated through an appropriate service channel where required.

World Council for AI PTE. LTD.
UEN 202412852R
1 Paya Lebar Link, #04-01
Paya Lebar Quarter
Singapore 408533
Email: hello@gerai.shop

Legal review notice

This published document explains Gerai’s current approach and intended practices. It does not constitute legal advice to the reader. Gerai recommends obtaining advice from a qualified lawyer about the laws and contractual requirements that apply to your circumstances.

Privacy Policy | Gerai