ExceliaBOT ← Back to site

Privacy Policy

Last updated: 25 September 2026

ExceliaBOT answers your customers' messages on WhatsApp, Messenger and Instagram with an AI assistant, sends WhatsApp campaigns and follow-ups, and turns your online store's orders into WhatsApp updates. This policy explains what data we handle, why, who we share it with, how long we keep it, and the choices you have. We have written it in plain language rather than legalese.

Two different roles. For your own account details, we are the data controller. For the conversations your customers have with you, the contact lists you upload and the orders and checkouts of your store, you are the controller and we act as your processor — we handle that data only to run the service for you, on your instructions. If you are one of those customers, please contact the business you messaged or bought from; they decide how your data is used, and we will forward any request you send us to them.

1. Who we are

ExceliaBOT is operated by Excelia Marketing ("Excelia", "we", "us"). You can reach us at [email protected] for any privacy question, request, or complaint.

2. Data we collect

2.1 Account data (from you, our client)

2.2 Enquiries and signups from our website

If you submit the contact form or sign up, we store the name, business name, phone number, email address and message you provide, so we can create the account, confirm your email address, reply and qualify the request.

2.3 Integration credentials

To act on your behalf we store the identifiers and access tokens of the channels you connect: your WhatsApp Business account and phone number, your Facebook Pages and Instagram accounts, and your Shopify store (an expiring access token and its refresh token, renewed automatically). Every token and secret is encrypted at rest with AES-256-GCM before it touches our database.

2.4 Conversation data (your customers)

When someone messages your WhatsApp number, your Facebook Page or your Instagram account, we receive and store:

2.5 Campaign audiences, templates and opt-outs

2.6 Store orders and Shopify

If you connect your store, we receive its orders so that WhatsApp updates can be sent: the order number, the customer's name and phone number, the items, the total, the payment method and each status change. Any platform can send them to us by webhook.

If you install the ExceliaBOT app from the Shopify App Store, we also receive from Shopify, within the access scopes shown to you at installation:

2.7 Product catalog

If you enable the catalog feature, we fetch product data (name, description, price, image, link) from the product feed URL or Meta Commerce catalog that you connect — or from your Shopify store, as above — so the assistant can recommend items.

2.8 Usage and technical logs

2.9 Apps you connect

If you connect an AI assistant such as Claude to your account, we store the grant (as a hashed token), the time, IP address and language of your consent, and a log of every action taken through it.

3. Why we use it

PurposeData involved
Generate and deliver AI replies to your customersConversation history, your instructions, catalog, goal fields
Send the campaigns, follow-ups and order messages you set up, and honour opt-outsAudience lists, templates, store orders and checkouts, the opt-out list
Route incoming messages and orders to the right account and prevent duplicatesChannel identifiers, message and order identifiers
Enforce plan limits and bill you correctlyReply and message counters; the plan Shopify reports for your store
Show you conversations, leads, orders and analytics in the dashboardMessages, media, goal completions, orders
Secure the platform and investigate abuseSystem logs, sign-in records, IP addresses
Respond to your enquiries, send you account emails and provide supportContact and account data, email delivery records
Tell account owners about the platform — news, tips and offers, each with an unsubscribe linkThe owner's name, email address, business name and the stage the account is at (signed up, connected, paying)
Understand how our website is used and measure our advertisingWebsite visits (section 6)

Where a law such as the GDPR applies, our legal bases are: performing our contract with you; our legitimate interests in keeping the platform secure and understanding how it is used; our legal obligations; and your consent, where we rely on it — for example for advertising cookies on our website, which you can withdraw at any time.

We do not sell your data, and we do not use your conversations, your lists or your customers' data to train our own models or to market to your customers.

4. Who we share it with

We share data only with the providers needed to run the service, and only what each one needs:

ProviderWhat it receivesWhy
Google (Gemini API) Your instructions, recent conversation history, the incoming message, and your catalog and goal configuration To generate each reply. Google processes this under its own API terms and does not use it to train its models.
Meta Platforms (WhatsApp Cloud API, Messenger, Instagram) The reply or campaign content and the recipient's identifier. If you switch on conversion tracking, also a "lead" or "purchase" event for your ad account's dataset, carrying the customer's phone number as a SHA-256 hash (or their page-scoped id) and the ad click id To deliver messages; Meta is also the source of the inbound ones. The conversion events let Meta attribute your ads — you can switch them off at any time.
Shopify Through its API, the tags, notes and cancellations we write to your orders; and, for billing, nothing from us — we read from Shopify the plan, price, status and period of your app subscription To keep your store in step with what customers decide on WhatsApp, and to apply the plan you chose. Shopify bills you under its own terms; we never see your payment details.
AI assistants you connect (Anthropic — Claude) Only what you ask the assistant for in a given chat: the conversations, leads, campaigns, reports or instructions it reads, and the text of what you tell it to send or change Optional. You connect the assistant yourself from Security → Connected apps; it acts with your own permissions, asks before changing anything, and can be disconnected there at any time. What the assistant receives is processed by its provider under your agreement with them.
Our hosting provider All platform data, at rest on the server, and its encrypted backups To host the application and database.
Our email delivery provider Your name, email address, and the subject and content of each account email To deliver invoices, reports, alerts and sign-in emails.
Our email marketing provider The account owner's name, email address, business name and account stage To send account owners news, tips and offers about the platform. Every such email carries an unsubscribe link; unsubscribing is honoured at once and nothing further is sent.
Analytics and advertising providers (on the public website only) Your visit to our marketing pages — see section 6 To measure our advertising. Nothing from your dashboard or your customers' data goes to them.

These providers operate internationally, so data may be processed outside your country. We may also disclose data where the law requires it, or to establish or defend legal claims.

Your WhatsApp account stays yours. You connect your own WhatsApp Business account and your own billing with Meta. Meta's conversation charges are billed to you directly, not through us.

5. How long we keep it

If you want your data, or one customer's data, deleted sooner, ask us and we will act on it.

6. Cookies and analytics

On our public website (the marketing pages, not the dashboard) we use Google Analytics and Google Ads, the Meta Pixel, the LinkedIn Insight Tag and the ChatGPT Ads pixel from OpenAI, to measure our advertising, count conversions when a form is submitted, and show our ads to people who visited us. Each of these sets its own cookies and receives your IP address, the page you visited and information about your browser, under its own privacy policy. We also count page views ourselves, storing only a one-way hash of your address and browser (never the address itself), your country, device type and the page or campaign that brought you.

You can opt out by blocking or deleting cookies in your browser, by using the advertising controls Google, Meta and LinkedIn offer in your accounts with them, or with a tracker blocker; the site works the same without them.

In the dashboard there are no advertising or analytics trackers. Your browser's local storage holds your sign-in token, your language choice and, briefly, a pending store-link request; our network provider may set strictly necessary cookies for security.

7. How we protect it

No system is perfectly secure, but if a breach ever affects your data we will tell you promptly and explain what happened.

8. Your rights

You can ask us to:

Email [email protected] and we will respond within 30 days. If you are a customer who messaged or bought from a business using ExceliaBOT, contact that business first — we will forward your request to them if you reach us instead.

9. Your responsibilities as our client

You are the controller of your customers' data. That means you are responsible for having a lawful basis to message them — including for every list you upload — for honouring their requests and opt-outs, and for what you instruct the assistant to collect. Send cart reminders only to customers who agreed to marketing (the default in our audience rules). Please do not configure goals that gather more than you genuinely need, never collect payment card details, passwords, or health information through the assistant, and if your customers send you sensitive documents, handle them lawfully and delete them when they are no longer needed.

10. Children

ExceliaBOT is a business tool and is not directed at children under 18. We do not knowingly collect their data; if you believe we have, contact us and we will remove it.

11. Changes to this policy

We may update this policy as the platform evolves. We will change the date at the top and, for material changes, notify account owners by email or in the dashboard before they take effect.

12. Contact

Questions, requests or complaints:
Email: [email protected]
WhatsApp: +20 103 370 7172