Legal
Privacy Policy
What we collect, why we collect it, who we share it with, and how you get it back or get it deleted.
Effective 9 September 2026
01Who we are
Emarze Commerce (“Emarze”, “we”, “us”) operates an AI agent that answers messages arriving on a merchant’s social channels, confirms sales, and writes the resulting orders into the merchant’s store. We are based at Gazipur, Dhaka, Bangladesh.
This policy covers two very different groups of people, and the difference runs through everything below:
- Merchants — the businesses that hold an Emarze account. We decide how their account data is handled, so for that data we are the data controller.
- End customers — the people who message a merchant on Instagram, Facebook, Messenger, WhatsApp or TikTok. We process their messages on the merchant’s instructions, which makes the merchant the controller and us the processor.
02What we collect
| Category | What it includes |
|---|---|
| Account data | Name, business name, email address, phone number, password hash, and the trade licence or BIN you give us if you ask for a VAT invoice. |
| Channel data | The access tokens, page IDs and account IDs you authorise when you connect Facebook, Instagram, WhatsApp Business or TikTok. |
| Conversation data | Messages, comments, attachments and sender profile details — name, profile photo, platform user ID — arriving on the channels you have connected. |
| Catalogue data | Products, variants, prices, stock levels and delivery rules you upload or sync, so the agent can quote them accurately. |
| Order data | Names, delivery addresses, phone numbers, order contents and payment status captured in a conversation and written to your store. |
| Billing data | Plan, invoices and payment status. Card numbers and mobile wallet PINs never reach us — the payment gateway handles those. |
| Technical data | IP address, browser and device type, pages viewed, and error logs, collected to keep the service running and secure. |
We do not ask for national ID numbers, dates of birth or any special category data, and the agent is not built to collect them. If an end customer volunteers something sensitive in a message, it is stored as part of that conversation and protected the same way as the rest of it.
03How we use it
- To run the service — reading incoming messages, drafting replies in your voice, quoting your catalogue, and creating orders.
- To bill you — issuing invoices, taking subscription payments, and following up failed ones.
- To support you — answering your questions, which sometimes means our staff opening a specific conversation you have pointed us to.
- To keep the service safe — detecting abuse, fraud and intrusion attempts, and meeting our obligations under Bangladeshi law.
- To improve the product — using aggregated usage statistics that identify no person and no business.
04Why we are allowed to
Bangladesh does not yet have a single comprehensive data protection statute in force. We therefore hold ourselves to the standards that do apply to us and to the ones our merchants’ customers reasonably expect:
- Contract — most processing is simply what is needed to deliver the service you signed up for.
- Consent — you consent when you connect a channel and grant the permissions requested; you withdraw it by disconnecting that channel.
- Legal obligation — tax and company records we are required to keep, and lawful requests from Bangladeshi authorities.
- Legitimate interests — security, fraud prevention and product improvement, where those interests do not override anyone’s rights.
Where a merchant serves customers in the EU or UK, the GDPR may apply to that merchant. In those cases we act as processor under a data processing agreement, which we will provide on request.
05Data from Meta and other platforms
When you connect Facebook, Instagram or WhatsApp, we receive data through Meta’s official APIs under permissions you approve. We use it only to provide the features you asked for, and we comply with the Meta Platform Terms and Developer Policies, including their limits on retention and onward transfer.
- We request the narrowest set of permissions that makes a feature work, and drop permissions we no longer need.
- Platform data is never sold, never used for advertising, and never combined with data belonging to another merchant.
- Disconnecting a channel revokes our access immediately and starts deletion of the data we held for it.
You can delete platform data at any time by following our data deletion instructions.
07Where your data is stored
Our servers and several of our providers are located outside Bangladesh, so running the service involves transferring data abroad. Where a provider is in a country without an equivalent data protection regime, we rely on contractual safeguards — standard contractual clauses or their equivalent — to keep the protections travelling with the data.
08How long we keep it
| Data | Kept for |
|---|---|
| Account data | While your account is open, then 90 days after closure. |
| Conversation data | 24 months by default, or the shorter period you set in your account. |
| Order data | As long as your account is open, since you rely on it as business records. |
| Invoices and tax records | Five years, as required by Bangladeshi tax law. This applies even after you delete your account. |
| Security and access logs | 12 months. |
| Backups | Rolling 30 days. Deleted data disappears from backups within that window. |
09How we protect it
- Traffic is encrypted in transit with TLS, and data is encrypted at rest.
- Passwords are hashed, never stored in a readable form, and never visible to our staff.
- Access to production data is limited to the staff who need it, and every access is logged.
- Channel access tokens are stored encrypted and are usable only by the account that authorised them.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authorities without undue delay, and explain what happened and what we are doing about it.
10Your rights
- Access — ask what we hold about you and get a copy.
- Correction — have anything inaccurate fixed.
- Deletion — have your data erased, subject to records we must keep by law.
- Export — take your orders, customers and catalogue with you in a machine-readable file.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — disconnect a channel at any time, without affecting anything done before you did.
Write to contact@emarze.com to exercise any of these. We will respond within 30 days and will not charge you. If you are unhappy with the outcome, you may complain to the Directorate of National Consumer Rights Protection or take the matter to the courts of Dhaka.
11Children
Emarze is a business tool and is not for anyone under 18. We do not knowingly collect data from children. If you believe a child’s data has reached us, tell us and we will delete it.
12Changes to this policy
We update this policy when the service or the law changes. The effective date at the top always reflects the current version. If a change materially affects your rights, we will email you at least 14 days before it takes effect.
13Contact us
Questions about this policy can go to our team, who will answer within five working days.
Emarze Commerce
contact@emarze.com
Gazipur, Dhaka
Bangladesh
