Privacy policy
Last updated 28 September 2026
Social Commerce AI Sales Agent is operated by the operator of this service. It answers customer messages for online shops ("merchants") on Facebook Messenger, Instagram Direct and WhatsApp, and takes orders on their behalf. This policy explains what we store, why, and how to have it deleted.
Who is responsible for which data
For a merchant's own account we decide how the data is used. For the messages and orders of a merchant's customers, the merchant decides, and we process that data on the merchant's instructions to provide the service.
What we store
- Merchant account: business name, the admin's name and email, and a hashed password.
- Store data: products, prices, stock and store policies the merchant uploads or that we read from the merchant's own website at their request.
- Connected channels: the Page, Instagram account or WhatsApp number connected, the access token Meta issues for it (encrypted at rest), and the id of the Facebook user who connected it.
- Customer conversations: messages customers send to a connected channel and the replies sent, the customer's Meta user id, the name Meta shares with the Page, and any phone number and delivery address the customer types in the chat. A photo a customer sends is read to find the product it shows; it is not stored by us beyond the link Meta provides.
- Orders: items, prices, delivery details and a fraud-risk score for cash-on-delivery orders.
- Billing: the plan, usage counts, and bKash payment records (with the wallet number masked).
How we use it
Only to run the service for the merchant: to reply to customers, take and show orders, book couriers the merchant has connected, show the merchant reports about their own store, and bill the merchant. We do not sell personal data, and we never use the conversations, orders or details of a merchant's customers for advertising.
Our website and the Meta Pixel
When the operator has enabled it, our public pages (home, sign-up, sign-in and these legal pages) load the Meta Pixel, so we can tell whether our ads on Facebook and Instagram lead to sign-ups. It sends Meta the pages you view on those pages, that you started or completed sign-up, or that you opened a chat with our support, together with the identifiers Meta's own cookies carry. It does not run on the dashboard and never receives store, conversation or order data. You can limit this in your Facebook ad settings or by blocking cookies in your browser.
Who else processes it
- Meta Platforms, to receive and send messages on the connected channels, and to measure our own ads through the Meta Pixel as described above.
- The AI model provider configured for the service (for example OpenRouter or OpenAI), which receives the conversation text and store data needed to write each reply.
- A courier company (such as Steadfast), only when the merchant books a parcel: the recipient's name, phone, address and cash-to-collect amount.
- bKash, to process the merchant's subscription payments.
- Our hosting provider, which stores the database.
How long we keep it
While the merchant's account is active. When a merchant deletes their store, its products, conversations, customers and orders are deleted with it. Channel tokens are erased as soon as a channel is disconnected.
Deleting your data
Merchants can disconnect channels in Settings and ask us to delete their store by email. If you connected a Page with Facebook Login, removing this app in your Facebook settings disconnects it and deletes the conversations received through it; see Data deletion. A shop's customer who wants their messages deleted can ask that shop, or write to us and we will pass the request on and act on it.
Security
Access tokens are encrypted at rest, passwords are hashed, each merchant can see only their own store's data, and every request from Meta is checked against Meta's signature.
Changes
We will post any change to this policy on this page and update the date above.
Contact: the operator of this service