1. Introduction
EcomWizzard ("we", "our", or "us") operates the EcomWiz Customer Service platform — a SaaS application that helps e-commerce merchants centralize customer support across email, Facebook Messenger, and Instagram Direct. This Privacy Policy explains how we collect, use, store, and disclose information when you use our service.
2. Information We Collect
We collect the following categories of information:
Account information
- Name, email address, and login credentials when you create an account.
- Billing information (processed by our payment processor; we never store full card numbers).
Connected platform data
- WooCommerce: Orders, products, customers, refunds, and shipments synced via the WooCommerce REST API.
- Facebook & Instagram (via Meta APIs): Page profile, Instagram Business profile, messaging threads, sender display names, and message content of conversations you authorize us to manage.
- Gmail: Email message metadata and content from connected mailboxes, used to display customer conversations in your inbox.
Usage data
- Log data: IP address, browser type, pages viewed, actions taken.
- Device and session information needed to authenticate and secure your account.
3. How We Use Information
- To provide, operate, and maintain the EcomWiz Customer Service service.
- To display incoming customer messages from Facebook, Instagram, and Gmail in a unified inbox.
- To send replies back to customers on your behalf through the channels you authorized.
- To generate AI-assisted reply drafts using third-party large language models. Message content sent to these models is processed transiently and is not used by the providers to train public models.
- To analyze service usage, debug errors, and improve product quality.
- To communicate with you about your account, security alerts, and product updates.
4. Meta Platform Data
When you connect a Facebook Page or Instagram Business account
through EcomWiz Customer Service, we receive data from Meta's APIs under the
permissions you grant during OAuth, including
pages_messaging, instagram_manage_messages,
pages_show_list, and related scopes. We use this
data only to surface customer conversations to
your inbox and to send your replies back to customers.
We do not sell, rent, or share Meta Platform Data with any third party for advertising or any purpose other than operating the EcomWiz Customer Service service on your behalf. We do not use Meta Platform Data to train artificial intelligence or machine-learning models beyond per-tenant draft suggestions that are not shared across tenants.
5. How We Share Information
We share information only as follows:
- Service providers: Infrastructure (Railway, AWS), email delivery, error monitoring, and AI inference providers — under contracts that restrict them to processing data on our behalf.
- Legal requirements: When required by law, subpoena, or to protect the rights, property, or safety of EcomWizzard, our users, or the public.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to you.
We do not sell personal information.
6. Data Retention
We retain account and conversation data for as long as your account is active. When you disconnect a channel, we stop receiving new data from that channel immediately. When you close your account or request deletion (see Data Deletion), we delete or anonymize associated personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, tax records).
7. Security
We use industry-standard practices to protect your data, including encryption in transit (TLS 1.2+), encryption at rest for sensitive credentials (AES-256-GCM), access controls, and regular security reviews. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Object to or restrict certain processing.
- Receive a portable copy of your data.
To exercise any of these rights, email us at barak@refael.net. We will respond within 30 days.
9. Children's Privacy
EcomWiz Customer Service is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. International Transfers
EcomWizzard operates infrastructure in the European Union and United States. By using our service, you consent to the transfer of your information to these regions, which may have different data protection laws than your country.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the new policy on this page and update the "Last updated" date. Material changes will be communicated to active account holders by email.
12. Contact Us
Questions about this Privacy Policy? Email barak@refael.net.