Privacy Policy
1. Who we are
ShopGrow ("ShopGrow", "we", "us") is a software platform that helps businesses reply to their customers on Facebook, Instagram, WhatsApp and their own website, using automatic replies they configure and a shared inbox for replying by hand. It is operated by SOS CREATIONS LTD..
| Legal entity | SOS CREATIONS LTD. |
|---|---|
| Registered address | Flat- 6/B, 5th Floor, Plot- 8, Road-8, Avenue- C, Arifabad, Pallabi PS, Dhaka, Dhaka 1216, Bangladesh |
| Tax ID | 0089789320408 |
| Phone | +880 1613-571400 |
Two kinds of people in this policy
- Customers — businesses that hold a ShopGrow account. For their account data we are the data controller.
- End users — people who message or comment on a Customer's Facebook Page, Instagram account, WhatsApp number or website. For their data we act as a data processor on the Customer's instructions; the Customer is the controller.
2. What we collect
2.1 From Customers
- Account details: name, business name, email address and password (stored only as a salted hash).
- Business information you add so the assistant can answer: products, prices, opening hours, policies and similar text.
- Connection credentials: access tokens for the Facebook Pages, Instagram accounts and other channels you connect, and any AI provider key you choose to add.
- Technical data: IP address, browser type and access logs.
2.2 From End users
- The content of messages and comments sent to or from the Customer's connected channels.
- Identifiers supplied by the platform, such as the display name and the page-scoped or app-scoped user ID.
- Contact details an End user chooses to share during a conversation.
- For the website chat widget: approximate location derived from IP address, and device and browser type.
We do not intend to collect sensitive data. ShopGrow is not designed for health records, financial account details, government ID numbers or biometric data. Customers — including clinics and doctors' chambers — should not configure their assistant to ask for such information. If it appears in a conversation it is stored under the same protections as other messages and can be deleted on request.
3. How we use it
- To provide the service: receiving messages and comments, sending the replies the Customer has set up, and showing conversations in the Customer's inbox.
- To sign Customers in and keep accounts secure.
- To provide support when a Customer contacts us.
- To detect abuse, spam, fraud and security incidents.
- To send service notices about the account.
We do not sell personal data, use it for advertising, or build profiles of End users. We do not use Customers' or End users' conversations to train AI models.
4. Data we receive from Meta (Facebook, Instagram, WhatsApp)
A Customer connects a Facebook Page or Instagram professional account by signing in with Facebook and approving ShopGrow on Meta's own permission screen. We never see or store the Customer's Facebook password.
4.1 What we access and why
| Permission | What we use it for |
|---|---|
pages_show_list | Show the Customer the Pages they manage so they can choose which to connect. |
pages_manage_metadata | Subscribe a connected Page to our webhook so new messages and comments reach ShopGrow. |
pages_messaging | Send the Customer's automatic replies and manual inbox replies to people who message the Page. |
pages_read_engagement | Read comments on the Page's posts so they can be answered. |
pages_manage_engagement | Reply to comments on the Page's posts on the Customer's behalf. |
instagram_basic | Identify the Instagram professional account linked to the Page. |
instagram_manage_messages | Receive and reply to Instagram Direct messages for the connected account. |
business_management | List Pages and Instagram accounts that the Customer manages through a Meta Business Portfolio. |
4.2 How we handle it
- Data received from Meta is used only to provide the messaging features described above to the Customer who connected the account, in line with Meta's Platform Terms and Developer Policies.
- We access only the Pages and accounts the Customer selects on Meta's permission screen.
- Access tokens are encrypted at rest and are never shown in the dashboard or sent to the browser.
- Incoming webhook requests are verified with Meta's signature before we process them.
- We do not sell, license or give Meta data to data brokers, advertisers or any third party, other than the service providers listed in section 6 that we need to run ShopGrow.
- Automatic replies are sent only in response to a person who has messaged or commented first, within the time windows Meta allows.
- For WhatsApp, the Customer uses their own WhatsApp Business Account and phone number, and remains bound by Meta's WhatsApp Business Messaging Policy.
A Customer can revoke ShopGrow's access at any time from Facebook: Settings & privacy → Settings → Business integrations, or from the Meta Business Portfolio settings. Access stops immediately. See Data deletion for removing data we already hold.
5. AI processing
If a Customer turns on AI replies, the incoming message, recent conversation history and the business information the Customer provided are sent to an AI model provider to write a reply.
- Providers currently supported include Anthropic (Claude), Google (Gemini) and Groq.
- If the Customer adds their own provider key, the request is made under the Customer's own account with that provider and its terms.
- Some providers' free tiers allow the provider to use submitted content to improve its services. Customers who need to avoid this should use a paid key.
- Only what is needed for the reply is sent — never unrelated conversations or account credentials.
- Customers who do not turn on AI can use keyword-based automatic replies, which are processed entirely on our servers.
6. Who we share with
We share personal data only with service providers needed to run ShopGrow:
| Purpose | Type of recipient |
|---|---|
| Hosting and database | Cloud infrastructure providers |
| Writing AI replies (only when enabled) | AI model providers listed in section 5 |
| Delivering messages | The messaging platforms the Customer connects (Meta and others) |
| Email about the account | Email delivery provider |
We may also disclose data where required by the law of Bangladesh or valid legal process. Some providers are located outside Bangladesh; where that happens we rely on the provider's contractual safeguards.
7. How long we keep it
| Data | Retention |
|---|---|
| Conversations, comments and contacts | While the Customer's account is active, or until deletion is requested |
| Channel access tokens | Until the channel is removed, access is revoked, or the account is closed |
| Account records | Deleted within 30 days of account closure |
| Billing and tax records | As long as Bangladeshi tax law requires |
| Security and access logs | Up to 12 months |
| Backups | Overwritten on normal rotation, within 90 days |
8. Your rights
You may ask for a copy of your data, correction, deletion, or restriction of processing, and you may withdraw consent at any time. To make a request, call +880 1613-571400. We respond within 30 days.
End users: if you messaged a business that uses ShopGrow and want your data removed, you can ask that business directly, or contact us and we will act on the request with that business.
9. Deleting your data
Full step-by-step instructions are on our Data deletion page. In short: remove ShopGrow from your Facebook Business integrations to stop access, then call +880 1613-571400 asking for deletion. We delete the data within 30 days, except records the law requires us to keep, and confirm when it is done.
10. Security
- Traffic is encrypted in transit with HTTPS.
- Channel access tokens and AI provider keys are encrypted at rest.
- Passwords are stored only as salted hashes.
- Access to production data is limited to staff who need it.
No system is perfectly secure. If a breach affects your data we will tell you without undue delay.
11. Cookies
We use cookies and local storage to keep you signed in and to remember your language and theme. Blocking essential cookies will stop sign-in from working.
12. Children
ShopGrow is a business tool and is not directed at children under 13. If we learn we hold a child's data, we delete it.
13. Changes
We may update this policy. Material changes are announced by email or in the app before they take effect, and the date at the top always shows the current version.
14. Contact
SOS CREATIONS LTD.
Flat- 6/B, 5th Floor, Plot- 8, Road-8, Avenue- C, Arifabad, Pallabi PS
Dhaka, Dhaka 1216
Bangladesh
Phone: +880 1613-571400
Support hours: Saturday–Thursday, 9am–9pm (GMT+6)
See also our Terms of Service and Data deletion instructions.