1. What Data We Collect
ISR collects the following information to provide and improve our service:
- Business information: name, email, phone number, bKash number
- Facebook Page access tokens and Page IDs (encrypted at rest)
- Customer messages and interactions via Messenger (collected automatically when you connect your page)
- Customer names, Messenger PSIDs, and phone numbers (shared by customers in DMs)
- Order information: products, prices, delivery addresses, payment method
- Fraud detection data: phone hashes (SHA-256), RTO rates, delivery outcomes
- Ad campaign performance data (if you connect your ad account)
2. Why We Collect It
- To automate Messenger replies and manage customer conversations
- To create and track orders, deliveries, and payments
- To detect fraudulent behavior and protect sellers from RTO (return-to-origin) losses
- To calculate advertising return on investment
- To maintain the CRM database for your business
- To comply with legal obligations
3. Data Retention
We retain customer data (messages, orders, fraud records) for up to 12 months from last interaction. After 12 months of inactivity, customer data is automatically purged. Business account data is retained while your account is active. You may request full deletion at any time via the Meta Data Deletion callback or by contacting us.
4. Data Sharing
We share limited data with third parties only when strictly necessary to provide our service:
- Courier services (Pathao, Steadfast, REDX): customer name, phone, and shipping address to create shipments
- AI model providers (OpenCode Go API): message content to generate automated replies (no customer identities shared)
- Meta Platforms: messages sent via the Send API to deliver replies to your customers
We never sell customer data to any third party.
5. Seller Obligations
As a seller using ISR, you are responsible for:
- Informing your customers that you use automated messaging
- Obtaining necessary consent before sending marketing messages
- Honoring data deletion requests from your customers
- Complying with Bangladesh PDPO 2025 and applicable privacy laws
- Not using ISR to collect or store sensitive personal data beyond what is necessary for order fulfillment
6. Buyer Rights
Customers who interact with your Messenger page through ISR have the right to:
- Request access to their personal data stored in your ISR account
- Request correction of inaccurate data
- Request deletion of their data (via Meta's Data Deletion callback)
- Opt out of automated messaging by messaging "Stop" or "Unsubscribe"
7. Data Deletion Process
When a data deletion request is received through Meta's Data Deletion callback:
- The customer's Messenger PSID, name, and phone number are de-identified
- All message content from that customer is anonymized
- Fraud detection records linked to the customer are cleared
- A confirmation code is generated and provided for verification
- This process is completed within 30 days
8. PDPO 2025 Compliance
ISR is designed to comply with the Bangladesh Personal Data Protection Ordinance 2025. Key compliance measures include:
- Purpose limitation: data collected only for order processing and fraud prevention
- Data minimization: only essential data is stored
- Encryption: sensitive tokens and API keys are encrypted at rest
- Access control: sellers can only access their own business data
- Deletion mechanism: full data deletion available through Meta callback
9. Security
We implement industry-standard security measures:
- All data is encrypted in transit (TLS 1.3). Conversation data is stored in access-controlled databases.
- Page access tokens are encrypted at rest using AES-256-GCM. Full message-level encryption at rest is on our security roadmap.
- Database access is restricted to the application server
- Access to data is enforced at the application level, not by the database itself: every query is scoped to a business id read from your authenticated session, never from a value the request sends, so a request cannot retrieve another seller's data by changing an id in a URL or payload. This is a narrower guarantee than a database-level control, which is why PostgreSQL row-level security policies remain on our infrastructure roadmap. In the meantime, state-changing actions are written to an audit log recording who made the change and when, so access stays accountable while that work is in progress.
- API rate limiting prevents abuse
- Regular security audits and dependency updates
10. Connected AI Apps (ISR AI Connector)
A seller can connect an AI app of their choice (for example Claude, ChatGPT or Gemini) to their ISR shop through the ISR AI Connector. When they do:
- The seller approves each connection on an ISR page that names the shop, the app and every permission. The AI app never receives the seller's ISR password; it receives a short-lived access token limited to that one shop.
- The connected app can read and change only the data the seller's role allows in that shop: products and photos, stock, customer records and orders, recent conversations, and the sales agent's setup.
- Data the seller asks for is sent to the AI app the seller chose. That provider then handles it under its own terms and privacy policy, which the seller accepted when they signed up with it. ISR does not receive the seller's conversations with that AI app.
- Every change made through a connected app is recorded in the shop's activity log. ISR stores connection records (which app, which staff account, which permissions, when it was last used) and hashed tokens, never tokens in plain text.
- The seller can disconnect any app at any time under Settings → Connected Apps; access ends within a minute.
11. Contact
For privacy inquiries or data deletion requests, contact us at [email protected].