MENA & GLOBAL E-COMMERCE PRIVACY STANDARDS
Privacy Policy & Data Protection
At Sellora ("The Operating System for Social Commerce"), safeguarding your store's operational data and your customers' personal information is our absolute highest priority. This Privacy Policy details how we collect, process, encrypt, and isolate information across our multi-channel platform.
### 1. Introduction & Scope
This policy applies to all merchants, store owners, team members, and buyers interacting with Sellora across Egypt, the Middle East and North Africa (MENA), the European Union, and globally. By connecting your social sales channels (Instagram DMs, Facebook Messenger, WhatsApp, Telegram, or Email) and e-commerce storefronts (Shopify), you entrust us with critical business data. We honor that trust through total transparency and bank-grade architecture.
### 2. Information We Collect
We collect only the precise data points required to run your social commerce operations autonomously:
- **Merchant Account Data:** Store name, owner email, phone number, business registration details, and team member role assignments.
- **Connected Channel Logs:** Incoming message text from Instagram DMs, Facebook Messenger, WhatsApp, Telegram, and Email for natural language intent recognition, dialect processing, and automated replying.
- **E-Commerce Transaction Data:** Product catalogs, SKUs, inventory counts, order values, customer names, delivery addresses, and shipping statuses.
- **Payment Verification Metadata:** Webhook transaction tokens from Paymob, InstaPay Egypt, Fawry digital invoicing, and mobile wallets (Vodafone Cash). **We never collect or store raw credit card numbers or bank account PINs.**
### 3. How We Use Your Information
Your data is utilized exclusively to power your autonomous store workflows:
- Generating instant, dialect-accurate AI replies to customer inquiries across Instagram, Messenger, and WhatsApp.
- Automatically reserving Shopify inventory when a customer requests a specific product size or color.
- Issuing unique, encrypted payment checkouts via Paymob and verifying InstaPay/Fawry receipts without manual human review.
- Dispatching shipment orders to courier partners (Bosta and Mylerz) and sending real-time tracking updates to buyers.
- Generating aggregated, anonymized revenue and conversion analytics for your command center dashboard.
### 4. Row-Level Security (RLS) & Strict Data Isolation
A core architectural pillar of Sellora is absolute tenant isolation. We utilize Supabase Server-Side Row-Level Security (RLS) policies. Every database query, order record, customer profile, and chat thread is cryptographically tagged with your unique `store_id`. It is technically impossible for another merchant or unauthorized team member to view, access, or query your store's customer data or message history.
### 5. Third-Party Integrations & Gateways
To provide an end-to-end operating system, Sellora securely transmits necessary operational payloads to verified cloud partners:
- **Meta Cloud APIs (Instagram, Messenger, WhatsApp):** Message routing adheres to Meta's strict enterprise encryption and privacy protocols.
- **Shopify Cloud:** Catalog sync and order creation via secure OAuth 2.0 token exchange.
- **Paymob & Banking Gateways:** Signed webhook listeners verify transaction completion.
- **Bosta & Mylerz Shipping Gateways:** Delivery address and recipient contact transmission for courier dispatch.
### 6. Data Retention & Permanent Deletion
You maintain complete ownership and control over your data lifecycle:
- Depending on your subscription plan (Starter, Professional, or Business), conversation history and transaction logs are retained for 30 days, 6 months, or indefinitely.
- **Right to Erasure:** Under the Egyptian Data Protection Law (Law No. 151 of 2020) and European GDPR, you may request the immediate and permanent deletion of your merchant account, store catalog, and customer CRM. Upon cancellation and request, all data is purged from active databases and encrypted backups within 30 days.
### 7. Bank-Level Encryption Standards
All data managed by Sellora is protected by industry-leading cryptographic standards:
- **Encryption at Rest:** All databases, message archives, and customer files are encrypted using AES-256 bit encryption.
- **Encryption in Transit:** All API traffic, webhook transmissions, and dashboard communications enforce TLS 1.3 encryption.
- **Two-Factor Authentication (2FA):** Server-side TOTP 2FA enforcement prevents unauthorized administrative account access.
### 8. Cookies & Local Storage
Sellora uses minimal, essential cookies and browser local storage strictly for operational functionality:
- Maintaining secure, encrypted authentication sessions and preventing Cross-Site Request Forgery (CSRF).
- Storing interface preferences such as language selection (`en`, `ar`, or `fr`) and theme toggle (`light` or `dark` mode).
- We do not use third-party tracking or advertising pixel cookies on our merchant dashboard.
### 9. Your Rights & Data Portability
As the rightful owner of your business data, you have the right to:
- **Export Your Data:** Download your complete customer CRM, order logs, product performance metrics, and conversation history in standard CSV or JSON formats at any time.
- **Revoke API Access:** Disconnect any social channel (Instagram, Facebook Messenger, WhatsApp) or e-commerce storefront (Shopify) with a single click, instantly terminating data synchronization.
- **Audit Logs:** Review detailed security logs tracking team member logins, RBAC role modifications, and inventory adjustments.
### 10. Contacting Our Data Protection Office
If you have any questions regarding data encryption, RLS policies, or privacy compliance, please contact our founding engineering team and Data Protection Officer directly at:
- **Email:** support@sellora.app
- **Location:** Cairo, Arab Republic of Egypt