Privacy Policy
Last updated August 2026
CharpOS is an e-commerce operations platform for Bangladeshi sellers. This policy explains what we collect from merchants who use CharpOS, why we collect it, who else it reaches, and what you can ask us to do with it.
“You” means the merchant who holds a CharpOS account. “Your customers” means the people who message or buy from your store through the channels you connect to CharpOS.
1. What we collect
- Account information: your name, email address, phone number, business name, and a hashed password. We never store your password itself.
- Store data: products, prices, stock levels, orders, deliveries and customer records — either entered by you or synced from a store you connect.
- Communication data: messages exchanged with your customers on the channels you connect — WhatsApp, Facebook Messenger and Instagram Direct — including text, images, voice notes, sender name and phone number, and delivery status.
- Payment information: bKash transaction identifiers, amounts and timestamps for the recharges you make. Card numbers and bKash PINs never reach us; they are handled inside bKash’s own checkout.
- AI usage data: the conversation context sent to and returned from the AI model when auto-reply generates an answer, along with token counts used for billing.
- Technical data: standard server logs, IP address, browser type and timestamps.
2. How we use it
- To operate the platform: sync your store, show your dashboard, deliver messages.
- To process and track orders, deliveries and returns on your behalf.
- To generate AI auto-replies to your customers using your product catalogue, stock and policies as context.
- To calculate usage, bill your wallet, and show your billing history.
- To produce analytics for your own store — sales, customer segments, ad results.
- To provide support when you contact us, and to keep the service secure.
We do not sell your data. We do not use your customers’ messages to advertise to them, and we do not use your store data to build products for other merchants.
3. Third-party services
CharpOS depends on the following processors. Each receives only what it needs to do its part:
- Facebook / Meta — Messenger and Instagram Direct integration, so messages sent to your Page and account can be received and answered in CharpOS.
- WhatsApp — connected through the Baileys library using the WhatsApp account you link, so your WhatsApp conversations appear in the same inbox.
- OpenAI and DeepSeek — AI processing. Conversation context is sent to generate a reply, transcribe a voice note or describe an image.
- bKash — payment processing for wallet recharges.
- Cloudflare R2 — storage for product images and message media.
4. Facebook and Meta data
We access your Facebook Pages, Messenger conversations and Instagram Direct messages only after you explicitly grant permission through Facebook’s OAuth consent screen, and only for the Pages and accounts you select there.
- We use the Page access token issued by that consent to send and receive messages on your behalf, and to read the Page and Instagram profile details needed to display the connected account.
- We do not sell, rent or share Facebook or Instagram data with third parties, and we do not use it for advertising or for any purpose other than running the messaging features you connected.
- You can disconnect a Page at any time from your CharpOS dashboard, or revoke access from Facebook’s Business Integrations settings. Revoking access stops all further reading and sending immediately.
5. Data storage and isolation
CharpOS is multi-tenant. Every record — messages, customers, orders, media and AI logs — is stored against the store that owns it, and every query is scoped to that store. One merchant’s data is not visible to another merchant, and staff accounts can only see the stores they have been added to.
6. Data retention
We keep your data for as long as your account is active. If you close your account or ask us to delete your data, we remove your store data, conversations and media, apart from transaction records we are required to keep for accounting and tax purposes. Backups roll off on their own schedule and are overwritten within a short period.
7. Your rights
- Access: view and export your orders, products and customers from the dashboard at any time.
- Correction: edit your account details and store data directly, or ask us to correct anything you cannot.
- Deletion: email support@charpos.com from your account address to request deletion of your account and its data. We confirm within a reasonable period.
- Withdraw consent: disconnect any connected channel or store to stop the data flow at once.
If you are a customer of a merchant using CharpOS and want your data removed, contact that merchant — they control their store’s records. You may also write to us and we will pass the request on.
8. Cookies
We use session cookies to keep you signed in. They are httpOnly, are not used for advertising, and we do not run third-party tracking cookies. Clearing them signs you out.
9. Security
Passwords are hashed with Argon2id, sessions use httpOnly cookies, and platform credentials such as Page tokens are stored encrypted. No system is perfectly secure, but we treat your customer data as the sensitive thing it is.
10. Changes to this policy
We may update this policy. If a change is significant we will tell you in the dashboard or by email before it takes effect.
11. Contact
CharpOS. For privacy questions or data requests, email support@charpos.com.
CharpOS