Privacy Policy
Last updated: June 2025
1. What Data We Collect
ISR collects the following information to provide and improve our service:
- Business information: name, email, phone number, bKash number
- Facebook Page access tokens and Page IDs (encrypted at rest)
- Customer messages and interactions via Messenger (collected automatically when you connect your page)
- Customer names, Messenger PSIDs, and phone numbers (shared by customers in DMs)
- Order information: products, prices, delivery addresses, payment method
- Fraud detection data: phone hashes (SHA-256), RTO rates, delivery outcomes
- Ad campaign performance data (if you connect your ad account)
2. Why We Collect It
- To automate Messenger replies and manage customer conversations
- To create and track orders, deliveries, and payments
- To detect fraudulent behavior and protect sellers from RTO (return-to-origin) losses
- To calculate advertising return on investment
- To maintain the CRM database for your business
- To comply with legal obligations
3. Data Retention
We retain customer data (messages, orders, fraud records) for up to 12 months from last interaction. After 12 months of inactivity, customer data is automatically purged. Business account data is retained while your account is active. You may request full deletion at any time via the Meta Data Deletion callback or by contacting us.
4. Data Sharing
We share limited data with third parties only when strictly necessary to provide our service:
- Courier services (Pathao, Steadfast, REDX): customer name, phone, and shipping address to create shipments
- AI model providers (OpenCode Go API): message content to generate automated replies (no customer identities shared)
- Meta Platforms: messages sent via the Send API to deliver replies to your customers
We never sell customer data to any third party.
5. Seller Obligations
As a seller using ISR, you are responsible for:
- Informing your customers that you use automated messaging
- Obtaining necessary consent before sending marketing messages
- Honoring data deletion requests from your customers
- Complying with Bangladesh PDPO 2025 and applicable privacy laws
- Not using ISR to collect or store sensitive personal data beyond what is necessary for order fulfillment
6. Buyer Rights
Customers who interact with your Messenger page through ISR have the right to:
- Request access to their personal data stored in your ISR account
- Request correction of inaccurate data
- Request deletion of their data (via Meta's Data Deletion callback)
- Opt out of automated messaging by messaging "Stop" or "Unsubscribe"
7. Data Deletion Process
When a data deletion request is received through Meta's Data Deletion callback:
- The customer's Messenger PSID, name, and phone number are de-identified
- All message content from that customer is anonymized
- Fraud detection records linked to the customer are cleared
- A confirmation code is generated and provided for verification
- This process is completed within 30 days
8. PDPO 2025 Compliance
ISR is designed to comply with the Bangladesh Personal Data Protection Ordinance 2025. Key compliance measures include:
- Purpose limitation: data collected only for order processing and fraud prevention
- Data minimization: only essential data is stored
- Encryption: sensitive tokens and API keys are encrypted at rest
- Access control: sellers can only access their own business data
- Deletion mechanism: full data deletion available through Meta callback
9. Security
We implement industry-standard security measures:
- All data is encrypted in transit (TLS 1.3). Conversation data is stored in access-controlled databases.
- Page access tokens are encrypted at rest using AES-256-GCM. Full message-level encryption at rest is on our security roadmap.
- Database access is restricted to the application server
- Access to data is enforced at the application level. Every database query is scoped to the authenticated seller's account. PostgreSQL row-level security policies are on our infrastructure roadmap.
- API rate limiting prevents abuse
- Regular security audits and dependency updates
10. Contact
For privacy inquiries or data deletion requests, contact us at privacy@fcms.app.