Legal

Privacy Policy

Effective 21 June 2026

SmartSeller (“SmartSeller”, “we”, “us”) operates the growth platform at smartseller.in. This policy explains what data we collect, why, how we use and protect it, and the rights you have. It covers both the businesses who use SmartSeller (our customers) and the end-customers who interact with those businesses through our platform.

1. Who this policy is for

We serve small businesses in India (salons, boutiques, clinics, home chefs and similar). A business signs up for SmartSeller and uses it to run a website/online store, automate WhatsApp and Instagram conversations, and manage customers. This policy applies to that business (“Customer”) and to the people who message or buy from that business (“End Customers”).

2. Information we collect

  • Account data — name, email, phone number and password (hashed) when a business signs up.
  • Business content — the products, prices, descriptions, images, website content and bot configuration a Customer creates on SmartSeller.
  • Messaging data — messages exchanged through connected channels (WhatsApp, Instagram, web chat), including the End Customer’s name, phone number/handle and message content, so the business can reply and fulfil orders.
  • Orders & transactions — order details and payment status. Card/UPI details are processed by our payment partner (e.g. Razorpay) and are never stored on our servers.
  • Integration data — when a Customer connects a channel (see §4), we receive and store the access tokens and account identifiers needed to operate that channel on their behalf.
  • Usage & device data — basic logs, IP address and analytics used to keep the service secure and reliable.

3. How we use information

  • To provide the service — host websites/stores, send and receive messages, generate AI replies, process orders, and show the business its CRM dashboard.
  • To improve and secure the platform, prevent abuse, and provide customer support.
  • To communicate with Customers about their account, billing and service updates.

We do not sell personal data. We do not use the content of End-Customer conversations to advertise to them.

4. Third-party platform integrations (Meta & Google)

When a Customer connects a channel, we access only the data needed to operate that channel for them, under the platform’s terms:

  • WhatsApp Business Platform (Meta) — we send and receive WhatsApp messages on the Customer’s behalf and store the access token and WhatsApp Business Account / phone-number identifiers required to do so. Use of WhatsApp data complies with the Meta Platform Terms and WhatsApp Business policies.
  • Instagram (Meta) — with the Customer’s authorisation, we read and respond to Instagram messages and comments to power automation. We request only the permissions necessary for these features.
  • Google (Analytics / Ads) — with the Customer’s authorisation, we read analytics and advertising data to show reporting in the dashboard.

Tokens obtained through these integrations are stored encrypted and are used solely to provide the features the Customer enabled. A Customer can disconnect any integration at any time, which revokes our access. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. How we store and protect data

  • Data is stored with reputable cloud providers (database and hosting) with access controls in place.
  • Sensitive secrets such as channel access tokens and payment keys are encrypted at rest (AES-256).
  • Access to production data is limited to authorised personnel for operating and supporting the service.

6. Data sharing

We share data only with:

  • Service providers who help us run the platform (hosting, database, AI model providers, payment gateway, email), bound to protect the data.
  • The platforms a Customer connects (Meta, Google), to deliver the messages/features they requested.
  • Authorities where required by law.

7. Data retention

We keep account and business data while a Customer’s account is active. On account closure we delete or anonymise personal data within a reasonable period, except where we must retain it for legal, tax or fraud-prevention purposes.

8. Your rights

Customers and End Customers may request access to, correction of, or deletion of their personal data, and may withdraw consent for optional processing. To make a request, contact us at smartseller.service@gmail.com.

9. Children

SmartSeller is a business tool and is not directed to children under 18.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by an updated effective date at the top of this page.

11. Contact

For any privacy question or request, email smartseller.service@gmail.com.