1. Introduction
ChatBD ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our WhatsApp Business automation service.
2. Information We Collect
2.1 Information You Provide
We collect information that you provide directly to us:
- Account Information: Full name, business name, email address, phone number, password
- Profile Information: Business description, industry, preferences
- Payment Information: Billing address, payment method details (processed by our payment provider)
- Communications: Messages you send to our support team
2.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Usage Data: Pages visited, features used, time spent, actions taken
- Device Information: IP address, browser type, operating system, device identifiers
- Location Data: Approximate location based on IP address
- Cookies and Tracking: We use cookies, pixels, and similar technologies (see Cookie Policy)
2.3 WhatsApp Message Data
As part of our service, we collect and process:
- Customer Messages: Messages sent to your WhatsApp Business number
- Response Data: Automated responses and AI-generated replies
- Metadata: Message timestamps, sender information, delivery status
- Media: Images, videos, or documents shared in conversations (if applicable)
2.4 Third-Party Data
We may receive data from:
- WhatsApp Business API: Message delivery and status information
- OpenAI: AI model usage and response quality metrics
- Payment Processors: Transaction status and payment confirmations
- Analytics Providers: Google Analytics, Facebook Pixel, Microsoft Clarity
3. How We Use Your Information
3.1 Service Provision
- Create and manage your account
- Process WhatsApp messages and generate automated responses
- Provide AI-powered customer service features
- Store conversation history and customer data
- Generate analytics and insights
3.2 Business Operations
- Process payments and send invoices
- Provide customer support
- Send service updates and notifications
- Detect and prevent fraud or abuse
- Comply with legal obligations
3.3 Improvement and Development
- Analyze usage patterns to improve the Service
- Develop new features and functionality
- Conduct research and testing
- Personalize your experience
3.4 Marketing (With Consent)
- Send promotional emails about new features
- Share relevant content and tips
- Display targeted advertisements
You can opt-out of marketing communications at any time.
4. Data Storage and Security
4.1 Where We Store Data
Your data is stored on secure servers provided by Supabase (PostgreSQL database) with servers located in Singapore. All data is encrypted in transit (TLS/SSL) and at rest.
4.2 Security Measures
We implement industry-standard security measures:
- Encryption in transit and at rest
- Secure authentication with password hashing
- Regular security audits and updates
- Access controls and role-based permissions
- Automated backups and disaster recovery
4.3 Data Retention
- Account Data: Retained while your account is active
- Message Data: Retained for the duration specified in your plan (typically 90 days to 1 year)
- Analytics Data: Aggregated and anonymized after 2 years
- Legal Requirements: Some data may be retained longer to comply with legal obligations
5. Data Sharing and Disclosure
5.1 We DO NOT Sell Your Data
We will never sell, rent, or lease your personal information to third parties for their marketing purposes.
5.2 Service Providers
We share data with trusted service providers who help us operate:
- Supabase: Database hosting and authentication
- Vercel: Web hosting and CDN
- OpenAI: AI-powered response generation
- 360dialog/Twilio: WhatsApp Business API
- SSLCommerz: Payment processing
- Google/Facebook/Microsoft: Analytics and advertising
All providers are contractually bound to protect your data.
5.3 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations or court orders
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Respond to law enforcement requests
5.4 Business Transfers
If ChatBD is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Your Rights and Choices
6.1 Access and Control
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Export: Download your data in a portable format
- Object: Object to certain data processing activities
- Restrict: Request restriction of processing
6.2 How to Exercise Your Rights
To exercise these rights:
- Log in to your account and go to Settings
- Use the data management tools provided
- Or contact us at: privacy@chatbd.com
6.3 Marketing Preferences
You can opt-out of marketing communications:
- Click "Unsubscribe" in any marketing email
- Update preferences in your account settings
- Contact support to opt-out
6.4 Cookie Management
You can control cookies through:
7. International Data Transfers
Your data may be transferred to and processed in countries other than Bangladesh. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses
- Adequacy decisions by relevant authorities
- Encryption and security measures
8. Children's Privacy
Our Service is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
9. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. Please review their privacy policies.
10. Compliance
10.1 GDPR (European Users)
If you are in the European Union, you have additional rights under GDPR, including the right to lodge a complaint with a supervisory authority.
10.2 Bangladesh Data Protection
We comply with Bangladesh Digital Security Act 2018 and any applicable data protection regulations.
10.3 California Privacy Rights (CCPA)
California residents have specific rights under CCPA, including the right to know what personal information is collected and the right to opt-out of sale (though we don't sell data).
11. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via:
- Email notification
- In-app notification
- Updated "Last updated" date at the top
Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices:
Summary (Plain English)
What we collect: Your account info, WhatsApp messages, usage data
Why: To provide our automation service, improve features, keep you secure
Sharing: Only with service providers (Supabase, OpenAI, etc.) - we never sell data
Your control: You can access, export, or delete your data anytime
Questions? Email us at privacy@chatbd.com