Kotha AI ("we", "us", "the Service") provides Facebook-commerce automation — auto chat replies, comment replies, and order management — to sellers in Bangladesh and beyond. This policy explains what data we collect, why, and how we protect it. By using the Service you agree to this policy.
1. Data we collect
- Account data — your name, email address, shop name, and password (stored hashed with bcrypt; we can never read it).
- Page & channel data — Facebook Page IDs, access tokens, WhatsApp Business credentials, and webhook secrets you provide to connect your channels. These are stored encrypted at rest.
- Customer conversation data — messages your customers send to your connected pages, their public profile name, and order details they share (phone, delivery address). This data belongs to you, the seller; we process it only to run your automation.
- Commerce data — the products, orders, customers, shipments, expenses, and ledger entries you create in your dashboard.
- Billing data — subscription plan, payment method, transaction IDs (bKash/Nagad), and amounts. We never see or store full card or wallet PINs.
- Usage & technical data — login timestamps, an audit trail of account actions, and application logs kept for security and debugging.
2. How we use data
- To operate the Service: replying to your customers, creating orders, sending your SMS/email notifications, booking couriers you request.
- To bill you: counting qualified conversations (product inquiries, orders, bookings, support requests). Greetings, spam, and emojis are never counted or billed.
- To keep the platform safe: rate-limiting, webhook signature verification, fraud prevention, and audit logging.
- To support you: our support staff can view your account details when you open a ticket or ask for help. Support access is role-restricted and every admin action is logged.
3. AI processing
If you enable the AI assistant, the text of a customer's message (and a short recent history) is sent to the AI provider you configure (e.g. Synterolink, OpenAI, or your own endpoint) to generate a reply. Your API key is stored encrypted and used only for your account. Disable AI at any time — the bot then runs purely on your rules and product catalog.
4. Sharing
We do not sell your data or your customers' data. Data is shared only with processors needed to deliver features you use: Meta (Messenger/Instagram/WhatsApp APIs), courier providers (Steadfast, Pathao, RedX), payment gateways (bKash, Nagad), your SMS gateway, and your chosen AI provider — each receiving only what that feature requires.
5. Retention & deletion
- You control message retention per page (auto-prune after N days, optional).
- Deleting a customer erases their conversations and anonymises their orders.
- Items you delete go to Trash and can be restored or purged permanently by you.
- Deleting your account removes your pages, products, orders, conversations, and customers permanently.
- You may request a full export of your account data at any time via support.
6. Security
Access tokens, app secrets, API keys, and courier credentials are encrypted at rest. Webhooks require HMAC signatures. Logins are rate-limited with optional two-factor authentication (TOTP). Sessions are encrypted, databases are backed up nightly, and all administrative actions are recorded in an audit trail.
7. Your rights
You may access, correct, export, or delete your data at any time from your dashboard or by contacting support. If you believe data is processed unlawfully, contact us first — we resolve privacy complaints with priority.
8. Changes
We may update this policy as the Service evolves. Material changes are announced in-app before they take effect. Continued use after a change means acceptance.
9. Contact
Questions about privacy? Open a support ticket from your dashboard, or reach the operator of this Kotha AI installation directly.