Legal · Privacy

Privacy Policy

SellSupportAi — AI Sales & Customer Support Agent for Social Commerce

Effective: October 4, 2026  •  Version 1.0  •  SellSupportAi, Dhaka, Bangladesh

In short

  • We run a B2B dashboard. Merchants use SellSupportAi to reply to customer messages, sell products, and take orders across Facebook Messenger, Facebook Page comments, and WhatsApp Business. You are almost certainly reading this as a merchant (our customer) or as an end customer of one of our merchants.
  • Two roles, two rulebooks. For your own account, billing, and usage data, SellSupportAi is the controller. For the messages, orders, and contact details of your buyers that flow through your account, SellSupportAi is a processor acting on your instructions — you are the controller.
  • We don't sell data and we don't run ad tracking. We do not sell or share personal information for cross-context behavioral advertising, we use no analytics or advertising cookies today, and we honor the Global Privacy Control (GPC) signal.
  • AI helps write replies, humans stay in charge. An AI/LLM subprocessor sees message text plus the catalog and FAQ context you configure, in order to draft conversation replies. No solely automated legal or similarly significant decisions are ever made about anyone.
  • You have rights. Access, correction, deletion, portability, restriction, objection, and consent withdrawal — exercise them at privacy@sellsync.com.bd. We respond within 30 days (GDPR) or 45 days (CCPA).
  • Retention, plainly stated. Account data until deletion + 30 days; billing records 7 years (legal obligation); backups rotate ≤ 35 days; security logs ≤ 90 days.

1. Introduction

Welcome to SellSupportAi, an AI Sales & Customer Support Agent for Social Commerce. SellSupportAi is a multi-tenant business-to-business (B2B) software-as-a-service product that lets online sellers connect their sales channels and have an AI agent reply to customer messages, present products, and take orders — across Facebook Messenger, Facebook Page comments, and WhatsApp Business. The product includes a dashboard with an Inbox, Orders, Products, Channels, Analytics, and AI Knowledge modules, plus team roles (Owner, Admin, Agent, and Viewer).

This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you can exercise about it. It applies to the SellSupportAi web application, our website, and related services (collectively, the “Service”).

This policy is written for both audiences of our platform:

  • Merchants — the businesses that subscribe to SellSupportAi and operate a dashboard account. For your account, profile, billing, and product-usage data, SellSupportAi is the controller.
  • End customers — the people who message a merchant's connected Facebook or WhatsApp channel. For your messages, order details, and contact identifiers, SellSupportAi is a processor processing data on the merchant's behalf and instructions. The merchant is the controller.

SellSupportAi operates from Dhaka, Bangladesh. Our website is https://sellsync.com.bd. This policy is version 1.0 and is effective October 4, 2026.

BrandSellSupportAi
OperatorSellSupportAi, Dhaka, Bangladesh
Supporthello@sellsync.com.bd · WhatsApp +880 1300192216

2. Information We Collect

We collect information in several distinct categories, depending on whether you are a merchant using our dashboard or an end customer messaging a merchant's channel. We do not collect everything from everyone — the sections below describe exactly what applies.

2.1 Account Information

When a merchant signs up for and manages a SellSupportAi account, we collect the information needed to create, secure, and administer that account:

  • Identity and contact details: your name and email address, and — where you choose to provide them — a phone number or organization name.
  • Authentication data: account credentials are handled by our authentication provider. Passwords are never stored by us in plaintext; we only ever hold the provider's verified session and the provider's hashed/secret material as designed by that provider.
  • Role and team data: your assigned role within your organization (Owner, Admin, Agent, or Viewer) and team membership records, which we use to enforce access permissions.
  • Organizational records: the tenant/organization record that groups your team, channels, and data together (an internal org_id), which is also the basis of our tenant isolation controls.

2.2 Business & Catalog Data

To let the AI agent answer accurately and take orders, merchants supply business content to the Service. This includes:

  • Product catalog: product names, descriptions, images you upload, prices, stock and variant information, and any product identifiers you enter.
  • AI Knowledge / FAQ content: the merchant-configured knowledge base, frequently asked questions, store policies (shipping, returns, payment instructions), greeting messages, and reply templates that you add so the agent can use them in replies.
  • Channel configuration: which Facebook Pages, Messenger threads, and WhatsApp Business numbers are connected, along with the connection settings the merchant provides.
  • Business profile: store name, brand assets, operating hours, and other profile fields the merchant fills in.

2.3 End-Customer Data Processed for Merchants

When an end customer messages a merchant's connected channel, the following data flows into SellSupportAi so the merchant's agent can respond and fulfil orders. For this category, the merchant is the controller and SellSupportAi is the processor.

End-customer personal data processed by SellSupportAi on behalf of merchants
Data category Examples Why it is processed
Message content The full text of conversations in Messenger, Page comments, and WhatsApp — questions, order requests, complaints, and the agent's replies. To deliver the conversation, generate AI replies, maintain inbox history, and let merchant staff take over.
Platform identifiers (PSIDs / phone numbers) Facebook Page-scoped IDs (PSIDs) for Messenger and Page comment participants; WhatsApp phone numbers and WhatsApp sender identifiers. To route messages to the right conversation thread and to deliver replies on the correct channel.
Names & addresses in orders The customer's name, delivery address, and any contact details the customer supplies while placing an order through the agent. To create and manage the order record the merchant asked us to take, and to show it in the Orders module.
Order details Products ordered, quantities, prices, order status, and internal notes. To record orders accurately and keep merchant operations in sync.
Conversation metadata Channel type, timestamps, delivery/read status, message IDs, assigned agent, and conversation state. To operate the Inbox, provide reliable delivery, and produce aggregate analytics for the merchant.

We collect this end-customer data only because a merchant connected a channel and instructed the Service to process messages on that channel. We do not use end-customer data for our own advertising, and we do not build independent profiles of end customers across unrelated merchants.

2.4 Channel Connection Tokens

When a merchant connects Facebook or WhatsApp, the relevant platform issues access credentials (for example, Page access tokens, Messenger tokens, and WhatsApp Business API tokens) that the merchant's account stores through the Service so messages can be sent and received. We treat these tokens as confidential configuration secrets:

  • They are stored as part of the merchant's channel connection configuration in our database, scoped to that merchant's organization.
  • They are used solely to authenticate to the platform APIs for message delivery and channel management on that merchant's behalf.
  • They are never sold, never exposed in the browser UI in full, and never used for any purpose outside operating the connected channels.
  • Merchants can disconnect a channel at any time from the Channels module, which stops further message processing through that connection.

2.5 Technical & Usage Data

To operate, secure, and improve the Service we collect a limited amount of technical data:

  • Usage metrics: feature usage within the dashboard, module activity (Inbox, Orders, Products, Channels, Analytics, AI Knowledge), message and order volumes, and performance counters. These are tied to your organization so we can show you your own Analytics and so we can capacity-plan the Service.
  • Local storage: we store a single locale (language) preference in your browser's localStorage under the key sellsupportai-locale. That is the only item we write to localStorage or cookies for tracking purposes today.
  • Security and server logs: request metadata such as IP address, timestamp, requested path, response status, and error details, retained for a short period to detect abuse, debug incidents, and protect the Service.
  • Device and browser information: coarse technical details necessarily present in HTTP requests (browser type/version, operating system, screen characteristics you volunteer via standard headers) used for rendering and security — not for profiling.

What we do NOT collect

  • Payment card numbers. We do not store payment card numbers, CVV codes, or full bank credentials. Pricing exists in the product, but card data is not collected by the app itself — payments are handled separately at checkout.
  • Advertising or analytics identifiers. No advertising pixels, no third-party analytics SDKs, no marketing tracking cookies, no cross-site behavioral profiles.
  • Location history or precise geolocation. We do not request or store GPS or continuous location data.
  • Special category data by design. We do not ask for health, biometric, political, religious, or similar sensitive data — and merchants must not solicit such data from their customers through the bot.
  • Children's data. The Service is B2B and not intended to collect data from children (see Section 11).

3. How We Use Information

We use personal information only for the purposes below. Where the GDPR/UK GDPR applies, the corresponding legal basis is stated in Section 5 and summarized in this table.

Purposes of processing and legal bases
Purpose What it involves Data involved Legal basis (GDPR)
Provide the Service Operating the dashboard, delivering messages between channels and the Inbox, generating and sending AI replies, creating and storing orders, showing the product catalog and Analytics. Account, business/catalog, end-customer data, channel tokens Performance of a contract (merchant); legitimate interests / processor instructions (end-customer data)
Account administration Sign-up, sign-in, role assignment, team management, notifications about the account, and support responses. Account information, usage metrics Performance of a contract; legitimate interests
AI reply generation Sending message text plus merchant-configured catalog/FAQ context to our AI/LLM subprocessors so they can draft the reply that is returned to the conversation. Message content, catalog & AI Knowledge context Performance of a contract; legitimate interests (merchant's documented instructions)
Safety, security & abuse prevention Detecting spam, unauthorized access, token misuse, rate-limit violations, and fraud against the Service or a merchant's channels; maintaining security logs. Security logs, technical data, channel configuration Legitimate interests (our security and the security of the platform); legal obligations where applicable
Service reliability & improvement Aggregated usage analytics for capacity planning, debugging, latency reduction, and product decisions. Aggregates do not identify individuals. Usage metrics (aggregated where possible) Legitimate interests
Billing & record-keeping Managing subscription pricing, issuing invoices, and keeping the financial records we are legally required to keep. Account/billing records Performance of a contract; legal obligation
Legal compliance Responding to lawful requests, enforcing our terms, and establishing or defending legal claims. Any relevant category, minimized to what the request requires Legal obligation; legitimate interests
Communications about the policy/service Sending material changes to this policy, security notices, and essential service messages. We do not send marketing emails without consent where consent is required. Account information Legitimate interests; consent where required

We do not use end-customer messages to train general-purpose models for our own benefit outside of producing the reply for that conversation, and we do not sell, rent, or license personal information to anyone.

4. AI Processing Disclosure

The core of SellSupportAi is an AI agent that drafts and sends conversation replies. We believe you deserve a clear picture of what that means for personal data.

What the AI receives

  • Message text from the current conversation — what the customer wrote and, where applicable, the recent turns needed to keep the reply coherent.
  • Merchant-configured context — the product catalog, prices, stock, FAQ entries, store policies, greeting messages, and knowledge-base documents the merchant has supplied in the AI Knowledge and Products modules.
  • Minimal routing metadata needed to return the reply to the right conversation.

Who processes it

This processing is performed by our AI/LLM subprocessors — the artificial-intelligence and large-language-model providers we engage to generate replies on our behalf, under data-processing terms that restrict their use of the data to providing the service to us. Because these subprocessors operate model infrastructure, message text and the supplied context may be processed on servers outside your country (see Section 7, International Data Transfers). A current list of these subprocessors is available on request from privacy@sellsync.com.bd.

How the AI output is used — and where humans stay in the loop

  • Conversation replies only. AI output is used solely to draft and send replies inside the customer conversation — never to make credit, pricing, eligibility, or any other decisions about a person.
  • No solely automated legal or significant decisions. We do not use AI to make decisions that produce legal effects for, or similarly significantly affect, an individual. Nothing in the Service constitutes automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.
  • Human handoff exists. Merchants can take over any conversation at any time from the Inbox. An Owner, Admin, or Agent can read, edit, and send replies manually, and roles can be restricted so the AI does not auto-send at all. Viewer accounts cannot send messages.
  • Merchant control. Merchants choose what goes into the AI Knowledge base and catalog, and can disconnect a channel — which stops AI processing for that channel entirely.
  • No vendor lock-in claim. We describe our AI processing generically as “our AI/LLM subprocessors” because our model provider stack may evolve; the obligations above (purpose limitation, no training on your data for unrelated purposes, security, and transfer safeguards) apply regardless of which subprocessor performs the work.

AI systems can occasionally produce inaccurate or inappropriate text. Merchants remain responsible for reviewing how their agent represents their business, and we provide human takeover precisely so that a person can correct any such output.

Where the EU/UK General Data Protection Regulation applies to your personal data (which, for merchant account data, will typically be the case when you are our customer in the EEA or UK), we rely on the following bases:

  • Performance of a contract (Art. 6(1)(b) GDPR). We need to process your account information and business data to provide the Service you have signed up for, and to process end-customer messages and orders exactly as the merchant's configuration directs.
  • Legitimate interests (Art. 6(1)(f) GDPR). We rely on our legitimate interests — and those of our merchants — to operate a secure, reliable, and improving product: preventing abuse, keeping security logs, understanding aggregate product usage, and responding to support requests. We balance these interests against your rights and do not override them with processing you would not reasonably expect.
  • Consent (Art. 6(1)(a) GDPR). Where we need it — for example, for any non-essential storage on your device or for optional communications — we ask first, and you can withdraw consent at any time with effect for the future, without affecting prior lawful processing.
  • Legal obligation (Art. 6(1)(c) GDPR). Retaining billing and financial records for the periods required by applicable tax and accounting law.

For end-customer data, the merchant is responsible for establishing its own lawful basis (typically its own legitimate interests in responding to a customer inquiry, or the customer's request to enter into a contract when placing an order). SellSupportAi processes that data on the merchant's documented instructions as a processor.

6. Data Sharing

We share personal information only with the categories of recipients below. We do not sell your personal data. We do not share it for cross-context behavioral advertising. We do not rent it, and we do not permit third parties to use it for their own advertising.

Categories of recipients (processors and partners)
Recipient Purpose Data typically involved
Cloudflare
(Cloudflare Workers & Cloudflare D1)
Primary compute and hosting for the application backend and the SQLite-based D1 database where business data, messages, orders, catalog, tokens, knowledge base, usage metrics, and org/user records are stored; global edge processing, caching, WAF, and DDoS protection. All categories stored by the app (scoped per tenant)
Vercel Hosting and delivery of the frontend web application, including build output and static assets. Technical/usage data generated when you load the dashboard
Meta platforms
(Facebook Messenger & WhatsApp Business APIs)
Message delivery — sending and receiving messages on the merchant's connected channels. End-customer identifiers (PSIDs, phone numbers) and message text flow to and from Meta pursuant to the merchant's connection and Meta's platform terms. Message content, PSIDs, phone numbers, conversation metadata
Our AI/LLM subprocessors Generating conversation replies from message text plus the merchant's configured catalog/FAQ context, under our data-processing terms. Message text, catalog & AI Knowledge context, minimal routing metadata
Google Fonts Delivery of the Inter typeface used in the interface. Fonts are requested for rendering the UI; no analytics or advertising data is shared with Google through this mechanism. Technical request data (e.g., IP address and user agent, as with any web request)
Authentication provider Handling sign-up, sign-in, session verification, and password security for merchant accounts. We never store plaintext passwords. Name, email, credentials (hashed/verified by the provider)
Professional advisors & authorities Lawyers, auditors, accountants, and insurers under professional duties of confidentiality; and public authorities or regulators where disclosure is required by law, court order, or is necessary to protect rights, safety, and security. Only what is strictly necessary for the specific matter
Successors in interest In a merger, acquisition, reorganization, or sale of assets, personal data may transfer as part of that transaction — subject to this policy's commitments, and with notice to you where required. Account and business records as applicable

Every processor above is bound by confidentiality, purpose limitation, and security obligations consistent with this policy and, where applicable, by a data processing agreement. We do not authorize our processors to use your personal information for their own purposes.

7. International Data Transfers

SellSupportAi is operated from Dhaka, Bangladesh. Your information is administered by our team there, which means your data may be accessed from Bangladesh.

Our infrastructure is global by design:

  • Cloudflare edge processing. Requests to the Service are handled by Cloudflare's edge network, which may process data in data centers in many countries in order to route, cache, and protect traffic.
  • Cloud-hosted backend and frontend. The D1 database and Workers runtime, and the Vercel-hosted frontend, store and process data in the regions our providers use for our project.
  • AI/LLM subprocessors and Meta platforms process data in their own global infrastructures as described in Section 6.

Where personal data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that does not benefit from an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where applicable, together with supplementary measures such as encryption in transit and at rest, access controls, and purpose limitation. Copies of the relevant contractual safeguards can be obtained by contacting privacy@sellsync.com.bd.

By using the Service, merchants acknowledge that their end-customer data may be processed in countries outside their own, as described here, on the merchant's instructions.

8. Data Retention

We keep personal information only as long as needed for the purposes described in this policy, and then delete or anonymize it. Our standard retention periods are set out below. Where a period is described as running “after deletion,” the deletion begins when the relevant account or record is removed.

Standard retention periods
Data category Retention period Rationale
Account data (profile, org/user records, roles, channel config) Until the account is deleted, plus 30 days Operates the account; the 30-day tail allows recovery from accidental deletion and completion of cascading cleanup.
End-customer messages, orders, and catalog held for a merchant Until the merchant deletes them or closes the account, plus 30 days Processor storage on merchant instructions; deleted on documented instruction.
Billing records (invoices, subscription financial records) 7 years Legal obligation under applicable tax and accounting law.
Backups Rotating backups, retained ≤ 35 days Disaster recovery; older snapshots age out automatically on rotation.
Security logs ≤ 90 days Incident detection, forensics, and abuse prevention.
Channel connection tokens For the life of the connection; immediately upon disconnect (and purged within the backup rotation cycle) Needed only while the merchant wants the channel connected.
Locale preference (sellsupportai-locale) Until you clear your browser storage Client-side convenience only; never transmitted for tracking.

If deletion of specific data is technically impossible in backups at the moment of request, we will isolate that data from any further active use and delete it when the backup cycle next overwrites it (within the ≤ 35-day rotation window above).

9. Merchant Responsibilities for End-Customer Data

SellSupportAi is a processor for the personal data of your buyers — their messages, names, phone numbers, addresses, and order details. You are the controller. This split carries real obligations on both sides.

What SellSupportAi does as processor

  • Processes end-customer personal data only on your documented instructions — namely, to operate the channels you connected and the features you enabled.
  • Ensures personnel authorized to process that data are bound by confidentiality.
  • Implements appropriate technical and organizational security measures (Section 12).
  • Engages sub-processors (Cloudflare, Meta platforms via the APIs, our AI/LLM subprocessors) only as needed to provide the Service, and binds them to equivalent obligations.
  • Assists you, at your reasonable request, in responding to data subject requests, data protection impact assessments, and prior consultations — by providing the controls and export capability for you to satisfy the request yourself.
  • Deletes or returns end-customer personal data after termination of the Service, at your choice, except where retention is required by law.
  • Makes available information necessary to demonstrate compliance and allows for audits, subject to reasonable notice and confidentiality.

What merchants must do as controller

  • Have a lawful basis for collecting and processing your buyers' data through the bot, and provide your own privacy notice to those buyers that covers your use of SellSupportAi.
  • Configure the bot responsibly: do not instruct the agent to collect special category data, government identifiers, payment card details, or data from children.
  • Handle data subject requests: when a buyer asks to access, correct, or delete their data, respond as the controller. Use the Inbox and Orders tools and any export capability we provide; contact us at privacy@sellsync.com.bd for assistance with data under our control.
  • Respect platform rules: comply with Meta's Messenger and WhatsApp policies and applicable messaging/consent rules for the markets you message into (see Section 14).
  • Manage your team: assign the least-privilege role (Owner/Admin/Agent/Viewer) to each teammate, and remove access promptly when someone leaves.
  • Disconnect channels you no longer use so we stop processing messages on your behalf.

10. Your Rights

Depending on where you live and in which capacity your data is held, you have rights over your personal information. If you are an end customer, please contact the merchant you messaged first, because they are the controller of that data; we will assist them in fulfilling your request. If you are a merchant, contact us directly at privacy@sellsync.com.bd.

Rights available to you
Right What it means
AccessObtain confirmation of whether we process your data and a copy of that data, plus information about the purposes, recipients, and retention.
RectificationCorrect inaccurate personal data and complete data that is incomplete.
ErasureHave personal data deleted where there is no compelling legal ground for continued processing (including the “right to be forgotten”).
PortabilityReceive your data in a structured, commonly used, machine-readable format, and (where technically feasible) transmit it to another controller.
RestrictionTemporarily limit how we use your data while a challenge to its accuracy or your objection is being resolved.
ObjectionObject to processing based on legitimate interests, and to direct marketing at any time (we do not currently send direct marketing without consent).
Withdraw consentWhere processing is based on consent, withdraw it at any time — without affecting the lawfulness of prior processing.
Right to complainLodge a complaint with your local supervisory authority. We welcome the chance to resolve your concern first.

California (CCPA/CPRA) — your rights and our promises

  • Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties with whom it is shared.
  • Right to delete personal information, subject to the statutory exceptions (such as completing a transaction, security incidents, or legal obligations).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale/sharing. We do not sell or share your personal information for cross-context behavioral advertising — “share” in the CCPA sense of making it available to third parties for cross-context behavioral advertising. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” link, and no opt-out is required.
  • Right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for purposes to which the limitation right applies.
  • Right to non-discrimination. We will not discriminate against you for exercising any of your rights.

Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC opt-out signal, we treat it as a valid request to opt out of any sale or sharing of your personal information (of which, as stated above, we engage in none) and as a signal of your privacy preferences where applicable law requires us to recognize it. No additional account configuration is needed.

How to exercise your rights

  1. Email privacy@sellsync.com.bd with the subject line “Privacy Rights Request.” Tell us which right you want to exercise and the account or email address it relates to.
  2. We may need to verify your identity before acting — for example, by confirming control of the email address on the account. We will never ask for more information than reasonably necessary for verification.
  3. You may also use WhatsApp at +880 1300192216 or write to us at our address in Section 16, but email is the fastest route.
  4. Authorized agents may submit requests on your behalf with proof of authorization; we will still verify your identity directly where required.

Response times: we respond to GDPR/UK GDPR requests within 30 days, and to CCPA requests within 45 days. If we need more time (for example, for complex or numerous requests), we will inform you of the extension and the reason within the initial period. Requests are fulfilled free of charge unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse — with justification.

11. Children's Privacy

SellSupportAi is a business-to-business service. It is designed for use by businesses and their staff, not by children, and we do not knowingly collect personal information directly from children.

  • Minimum age for account holders: you must be at least 13 years old to use the Service, and at least 16 years old (or the applicable higher digital-consent age in your country) to consent to processing in the EEA/UK where consent would be the lawful basis.
  • Merchants must not collect children's data via the bot. You are responsible for ensuring your agent, forms, and order flows are not used to solicit personal information from children under 13 (or under the applicable age in your market). If you believe a child has provided personal data through a merchant's channel, contact us at privacy@sellsync.com.bd and we will work with the merchant to delete it promptly.
  • If we learn we have collected a child's data directly and without a valid legal basis, we will take steps to delete that information without undue delay.

12. Security

We implement technical and organizational measures appropriate to the risk, layered across the stack:

  • Encryption in transit: all traffic to and from the Service is protected with TLS 1.2 or higher.
  • Encryption at rest: data in our Cloudflare D1 database and related storage is encrypted at rest with AES-256.
  • Tenant isolation: records are scoped by organization (org_id) with row-level-security-style isolation, so one merchant's queries cannot reach another merchant's data.
  • Role-based access control (RBAC): Owner, Admin, Agent, and Viewer roles restrict what each dashboard user can see and do; internal access follows least privilege.
  • Edge protection: Cloudflare WAF and DDoS protection shield the application from malicious traffic, with rate limiting and bot filtering at the edge.
  • Credential hygiene: passwords are handled by our authentication provider and never stored in plaintext; channel tokens are stored as confidential configuration scoped to the owning organization.
  • No card storage: the application does not store payment card numbers — payment details are never entered into or held by the app itself.
  • Logging & monitoring: security logs (retained ≤ 90 days) support incident detection and investigation.

No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by applicable law.

13. Cookies & Similar Technologies

We keep this deliberately simple. We do not use advertising cookies, marketing pixels, or third-party analytics trackers today.

Storage used by SellSupportAi
Technology What it does Category
sellsupportai-locale (localStorage) Remembers your language/locale preference so the interface renders in the language you chose. Essential / functional
Session & authentication cookies/records Keep you signed in securely and protect against session fixation and CSRF-like abuse. Strictly necessary
Security & rate-limiting signals Edge-level cookies or request fingerprints used by our WAF to distinguish humans from abusive bots. Strictly necessary / security

Because we have no non-essential cookies, there is no cookie consent banner to dismiss — and nothing to opt out of. You can clear the locale preference at any time by clearing site data in your browser; the site will simply ask for your language again. Where a future feature would require non-essential storage, we will update this policy and request consent first where the law requires it.

14. Third-Party Platform Rules

SellSupportAi integrates with third-party messaging platforms. Your use of the connected channels is also governed by those platforms' own terms, which operate alongside this policy:

When you connect a channel, end-customer data flows to and from that platform in accordance with your connection and Meta's terms. Meta processes that data under its own privacy policy as an independent or joint controller depending on the context — for example, Meta acts as an independent controller for data it collects to provide the platform to end users. We recommend reviewing Meta's Privacy Policy as well.

Merchants are responsible for complying with the platforms' messaging policies (including opt-in requirements and prohibited content) when using the Service to message customers.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes:

  • We will post the revised policy on this page with an updated Effective date and Version number.
  • We will provide at least 30 days' notice before material changes take effect, by email to the account owner's registered address and/or by an in-product notice. Changes that are purely clarifying, editorial, or required by law may take effect sooner, with notice where required.
  • Where we rely on consent for a particular processing activity, we will ask for consent again if the change materially alters that activity.
  • Continued use of the Service after the effective date constitutes acceptance of the updated policy, to the extent permitted by applicable law. If you do not agree, you may stop using the Service and request account deletion as described in our Account Deletion page.

The version history: Version 1.0 — effective October 4, 2026 (initial publication).

16. Contact Us

For any question about this policy, a privacy or data protection request, or a complaint, please reach out. We answer every request.

WhatsApp support+880 1300192216
Postal addressSellSupportAi, Dhaka, Bangladesh
Effective / versionOctober 4, 2026 · v1.0

Right to complain

You have the right to lodge a complaint with a supervisory authority responsible for data protection. We would appreciate the opportunity to address your concern first — please contact privacy@sellsync.com.bd — but you may contact your local data protection authority at any time, including the authority in your country of residence or place of work, or the Bangladesh authorities where applicable.


End of policy. SellSupportAi Privacy Policy, Version 1.0, effective October 4, 2026. Also see our Account Deletion policy for how to close your account and remove your data.