Skip to content
Wacord
Features Pricing How it works About Contact
Support Login Demo
Features Pricing How it works About Contact Support Login Demo

Privacy Policy — Wacord

Last updated: 2 August 2026

Company: Wacord (“Wacord”, “we”, “us”, or “our”)

Product: Wacord e-commerce & omni-channel CRM (the “Service”)

Contact: Use the Contact / Support options on wacord.com or your account manager.

Meta data deletion: See our dedicated Meta Data Deletion Instructions.

This Privacy Policy explains how Wacord collects, uses, shares, and protects information when merchants use our B2B SaaS platform. By using Wacord, you agree to this Policy.

Wacord primarily acts as a data processor on behalf of merchant customers (“Merchants”). Merchants remain the data controllers of their end-buyer (“Buyer”) data.


1. Scope & Roles

1.1 Who this Policy covers

  • Merchants and their authorized agents/users of Wacord
  • Buyers whose data Merchants process through Wacord (Messenger, Instagram, webchat, orders, courier booking, VoIP, etc.)

1.2 Data ownership

Merchants retain 100% ownership of their Buyer data and store/commerce data. Wacord does not claim ownership of Merchant or Buyer content. Wacord only processes such data to provide the Service as instructed by the Merchant.


2. Information We Collect

2.1 Account & Merchant information

  • Business name, website/Facebook page URL, contact name, email, phone
  • Billing and subscription details
  • Team seats / agent accounts and role permissions
  • Connected store and channel configuration

2.2 Meta & omnichannel inbox data

To power the unified inbox, we may collect and process:

  • Facebook / Instagram page access tokens and related authentication credentials (stored securely and used only to operate connected channels)
  • Chat messages, attachments metadata, conversation threads, and customer profile identifiers provided by Meta / webchat
  • Channel events needed to sync, reply, assign, and archive conversations

Purpose: Operate the unified inbox and related CRM workflows only. We do not sell Meta inbox data.

2.3 Orders, CRM, and commerce data

  • Order details, product lines, addresses, phone numbers, COD amounts
  • Tags, notes, agent actions, and workflow history
  • Connected store identifiers and sync metadata

2.4 AI processing inputs/outputs (Google Gemini API)

When Merchants enable AI features, Wacord may send limited conversation/order context to Google Gemini (or equivalent AI providers) for:

  • Order extraction
  • Smart reply suggestions
  • Related temporary AI assistance features

2.5 Courier / logistics data

For 1-Click Courier Booking and related logistics features, we process:

  • Buyer name, phone number, delivery address
  • Parcel / consignment metadata, courier selection, booking status

2.6 VoIP & calling data

  • Call logs, timestamps, duration, destination/source identifiers, and billing metadata
  • Audio recording only if explicitly enabled/configured by the Merchant with appropriate consent settings

2.7 Usage, device & technical data

  • IP address, browser/app type, device identifiers
  • Feature usage analytics, diagnostics, and security logs
  • Cookies or similar technologies needed for authentication and product analytics

3. How We Use Information

We use data to:

  1. Provide, maintain, and improve the Service (inbox, CRM, AI assist, courier booking, VoIP, analytics)
  2. Authenticate users and secure accounts
  3. Process subscriptions, invoices, and usage-based add-ons
  4. Provide support and communicate Service-related notices
  5. Detect abuse, spam, fraud, and security incidents
  6. Comply with law and enforce our Terms of Service

We do not sell personal data.


4. Meta & Omnichannel Inbox

  • We collect Facebook/Instagram page tokens and chat data solely to power Wacord’s unified inbox and Merchant-configured automation.
  • Tokens are used only for authorized API calls required by connected pages/channels.
  • Merchants must comply with Meta Platform Terms, Instagram/Facebook commerce policies, and applicable privacy laws when messaging Buyers.
  • Merchants control which pages/channels connect and when to disconnect them.

5. AI Processing (Google Gemini API) & Zero Data Retention Stance

5.1 What AI is used for

Wacord uses Google Gemini AI (and may use similar providers) for order extraction, smart replies, and related assistance.

5.2 No training on Merchant chat data

We do not use Merchant chat data, Buyer conversations, or order content to train Wacord’s own AI models, and we configure AI providers so that data sent for inference is not used to train their models, to the extent the provider contract/settings allow.

5.3 Temporary processing only

Data sent to AI APIs is for temporary processing to return results to the Merchant workflow. Our intended operating standard with AI providers is a Zero Data Retention / no training posture for Merchant content used in inference.

5.4 Merchant control

Merchants should review AI outputs before acting (especially before courier booking). AI suggestions are assistive, not authoritative.


6. Courier Logistics Data Sharing

To fulfill orders via 1-Click Courier Booking and courier integrations, Wacord shares necessary end-Buyer fulfillment details with third-party local courier partners, which may include (without limitation):

  • Steadfast
  • RedX
  • Pathao
  • Other couriers enabled by the Merchant’s plan/configuration

Shared data typically includes: Buyer name, phone number, delivery address, and parcel/order metadata required for booking and tracking.

Courier partners process this data under their own privacy practices and service terms. Wacord shares only what is needed for booking/fulfillment requested by the Merchant.


7. VoIP & Calling Data

  • We collect call logs and related metadata for product functionality, support, security, and billing.
  • We do not record call audio by default.
  • Audio recording occurs only when a Merchant explicitly configures/enables recording and obtains any required consents under applicable law (including Bangladesh law where relevant).

8. Data Sharing & Subprocessors

We may share information with:

  1. Infrastructure & hosting providers (servers, databases, storage, CDN)
  2. AI providers (e.g., Google Gemini) for temporary inference
  3. Courier partners for order fulfillment requested by Merchants
  4. Payment / billing processors for subscription fees
  5. Meta / messaging platform APIs as needed to operate connected channels
  6. Professional advisors or authorities when legally required

We require subprocessors to protect data under appropriate contractual and technical safeguards.


9. International Transfers & Security

Data may be processed in Bangladesh and/or other countries where our providers operate. We apply administrative, technical, and organizational measures designed to protect data against unauthorized access, loss, or alteration (access controls, encryption in transit where applicable, least-privilege access, monitoring).

No method of transmission or storage is 100% secure; Merchants should also secure their own account credentials and staff access.


10. Data Retention & Deletion

This section combines our retention rules, general deletion rights, and Meta Platform data-deletion instructions (required for Facebook / Instagram app compliance).

10.1 Retention

We retain data for as long as needed to:

  • Provide the Service to the Merchant
  • Meet legal, tax, accounting, and dispute requirements
  • Maintain security logs for a limited period

When a Merchant account ends, Merchants may request deletion or export subject to legal retention obligations and technical feasibility. Residual backups may persist for a limited period before irreversible deletion.

10.2 How to request deletion (general)

Depending on applicable law, Merchants (and where applicable individuals) may request:

  • Access to personal data we hold about them
  • Correction of inaccurate data
  • Deletion (subject to legal exceptions)
  • Export / portability of account data where feasible
  • Restriction or objection to certain processing

Submit requests via Support / Contact channels. We may verify identity before acting. Typical deletion completion target is within 30 days after a valid, verified request.

10.3 Meta / Facebook & Instagram data deletion

Apps that access Meta user data must tell users how to request deletion. Wacord uses one clear manual method:

Meta Platform

User Data Deletion Instructions

Request complete data deletion for the Wacord Facebook / Instagram integration with these steps:

  1. Go to Facebook Settings & Privacy → Settings.
  2. Open Business Integrations (or Apps and Websites).
  3. Find Wacord and click Remove to revoke access.
  4. Email support@wacord.com with subject Data Deletion Request, and include your registered Wacord email or Account ID.
  5. We will manually purge associated chat data, tokens, and records within 7 business days and send a confirmation email.
Open full Data Deletion page Email support@wacord.com

Full instructions for Meta App Dashboard: data-deletion.html.

10.4 What is deleted

10.4 What is deleted

After a valid email request, our support team manually purges associated chat data, tokens, and records from our database within 7 business days, then sends a confirmation email. Limited records may be retained only where required by law (for example tax, fraud, or security logs for a limited period).


11. Merchant Responsibilities (Buyers)

Merchants are responsible for:

  • Providing required notices to Buyers
  • Obtaining any required consents for messaging, AI processing, courier sharing, and calling/recording
  • Using Meta channels in compliance with Meta policies and local law
  • Configuring Wacord features (AI, couriers, VoIP recording) appropriately
  • Handling end-Buyer deletion requests that fall under the Merchant’s role as data controller

12. Children’s Data

Wacord is a B2B platform and is not directed to children. Merchants must not knowingly use the Service to target or collect data from children in violation of law.


13. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. Continued use of the Service after changes constitutes acceptance of the updated Policy.


14. Contact

For privacy questions, data deletion requests, or security concerns, contact Wacord through the website Contact / Support channels or your designated account contact. For Meta-linked deletion, follow User Data Deletion Instructions or email support@wacord.com.


This document is provided for product transparency and operational clarity. It is not legal advice. Merchants should consult counsel for jurisdiction-specific compliance (including Bangladesh data protection and Meta Platform requirements).

Wacord

Product

Features Pricing Book a demo

Explore

How it works Book a demo

Company

About us Contact us

© 2026 Wacord. All rights reserved.

Privacy Policy Terms of Service