1. Introduction
Rako HQ Ltd ("Rako", "we", "us", or "our") is a company registered in England and Wales. We operate the Rako platform, the commission rail for AI agents built on the Agent Attribution Protocol (AAP). This Privacy Policy explains how we collect, use, and protect your information when you visit our website or interact with our services.
2. Information We Collect
2a. Partnership Enquiries
We collect personal data that you provide directly to us through our partnership enquiry form, including:
- Company name
- Your name
- Job title or role
- Email address
- Industry vertical
- Any additional message you choose to include
2b. AI Assistant Integrations (Claude, ChatGPT, and other connectors)
When you use Rako through an AI assistant (such as Claude by Anthropic or ChatGPT by OpenAI), we process the following data through our MCP (Model Context Protocol) server:
- Search queries: product vertical, provider preferences, price filters, and other search criteria you provide to the AI assistant
- Session data: a unique session identifier linking your search to any subsequent recommendations
- Attribution events: when the AI assistant recommends a specific offer, we record the offer ID and session for commission tracking
- Checkout links: when you request a payment link, we generate a URL -- no payment data is processed by Rako
We do not collect, store, or access:
- Your conversation history with the AI assistant
- Your AI assistant account information or identity
- Any payment card details or financial credentials
- Your files, memory, or personal data stored within the AI assistant
All payment processing is handled by the merchant's payment provider on a separate secure domain. Rako acts solely as a comparison and attribution layer -- we surface offers and track which agent recommended them for commission purposes.
3. How We Use Your Information
We use the information we collect to:
- Respond to your partnership enquiries
- Evaluate and manage potential partnerships
- Communicate with you about our services
- Improve our website and services
- Comply with legal obligations
4. Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), we process your personal data on the following bases:
- Legitimate interests: to operate and improve our platform, and to respond to partnership enquiries
- Consent: where you have given us explicit consent to contact you
- Contractual necessity: where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
5. Data Sharing
We do not sell, rent, or trade your personal data. We may share your information with trusted service providers who assist us in operating our platform, such as hosting providers and email services, but only to the extent necessary and under appropriate data processing agreements.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Partnership enquiry data is typically retained for up to 24 months after our last interaction, unless a longer retention period is required for ongoing business relationships or legal obligations.
7. Your Rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate or incomplete data
- Erasure of your personal data in certain circumstances
- Restriction of processing in certain circumstances
- Data portability -- to receive your data in a structured, machine-readable format
- Object to processing based on legitimate interests
To exercise any of these rights, please contact us at the email address below. We will respond to your request within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
Our website uses minimal cookies. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
9. Contact Us
If you have any questions about this privacy policy or how we handle your data, please contact us at:
hi@rako.sh10. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.