Privacy Policy
Last updated: 25 September 2026
ExceliaBOT answers your customers' messages on WhatsApp, Messenger and Instagram with an AI assistant, sends WhatsApp campaigns and follow-ups, and turns your online store's orders into WhatsApp updates. This policy explains what data we handle, why, who we share it with, how long we keep it, and the choices you have. We have written it in plain language rather than legalese.
1. Who we are
ExceliaBOT is operated by Excelia Marketing ("Excelia", "we", "us"). You can reach us at [email protected] for any privacy question, request, or complaint.
2. Data we collect
2.1 Account data (from you, our client)
- Business name, country and contact phone number.
- Name, email address and role of each account owner and team member, and the language you chose for the dashboard and for our emails.
- Your password, stored only as a bcrypt hash — we never store or see the password itself. If you switch on two-step verification, the authenticator secret is stored encrypted and the backup codes as hashes.
- A record of your acceptance of our Terms: the version accepted, the time, and the IP address it came from.
- Sign-in records: the email address typed, the outcome, the IP address, the country and the browser, kept for 90 days to lock accounts after repeated failures and to investigate abuse. A password-reset request records the IP address it came from.
- If you switch on browser notifications, the push subscription your browser issues, so we can deliver them.
2.2 Enquiries and signups from our website
If you submit the contact form or sign up, we store the name, business name, phone number, email address and message you provide, so we can create the account, confirm your email address, reply and qualify the request.
2.3 Integration credentials
To act on your behalf we store the identifiers and access tokens of the channels you connect: your WhatsApp Business account and phone number, your Facebook Pages and Instagram accounts, and your Shopify store (an expiring access token and its refresh token, renewed automatically). Every token and secret is encrypted at rest with AES-256-GCM before it touches our database.
2.4 Conversation data (your customers)
When someone messages your WhatsApp number, your Facebook Page or your Instagram account, we receive and store:
- Their identifier on that channel — a WhatsApp number, or, when the person has chosen to hide their number, the business-scoped id WhatsApp provides instead; a page-scoped id on Messenger and Instagram — and the profile name the platform provides.
- The content of their messages and of the replies sent back — by the assistant, by your team from the dashboard, or by your team from the WhatsApp app on the phone, which WhatsApp echoes to us so the thread is complete.
- Timestamps, the platforms' message identifiers (used to avoid processing the same message twice) and delivery status.
- Photos your customers send (up to 5 MB each) and pictures your team sends out. They are stored with the message and shown only to your signed-in team, never through a public link. Other attachments — documents, audio, video — are not stored: when you open one, we fetch it from Meta at that moment, for as long as Meta keeps it.
- Any information you have configured the assistant to collect as a "goal" — for example a name, phone number, address, or order details. You choose these fields; we do not decide what is asked.
2.5 Campaign audiences, templates and opt-outs
- The contact lists you upload for campaigns: the name, phone number and any other columns in your file. Lists you build from your store's events (people who left a checkout or placed an order) are stored the same way.
- The message templates you create, including any header image, which we keep so the dashboard can preview it and each send can reuse it.
- For each campaign recipient, the text that was sent and the delivery outcome WhatsApp reports.
- A marketing opt-out list: the numbers that asked to stop receiving your campaigns. We keep it even if you delete the list it came from, so the request keeps being honoured.
2.6 Store orders and Shopify
If you connect your store, we receive its orders so that WhatsApp updates can be sent: the order number, the customer's name and phone number, the items, the total, the payment method and each status change. Any platform can send them to us by webhook.
If you install the ExceliaBOT app from the Shopify App Store, we also receive from Shopify, within the access scopes shown to you at installation:
- Your store's name, domain, contact email, currency and the plan you chose for the app.
- Orders: the customer's name, phone number, email address and shipping address, the items, totals, payment and fulfilment status — and the tags and notes we write back when a customer confirms or cancels an order from WhatsApp.
- Checkouts your customers left: their email address, phone number and name, the items and total, the recovery link, and whether they agreed to marketing at checkout.
- Your products (name, description, price, image link, availability, type and tags), only if you switch on "Use products from the connected store" so the assistant can recommend them.
2.7 Product catalog
If you enable the catalog feature, we fetch product data (name, description, price, image, link) from the product feed URL or Meta Commerce catalog that you connect — or from your Shopify store, as above — so the assistant can recommend items.
2.8 Usage and technical logs
- Per-reply metering: which AI model ran and how many tokens it consumed. This is how plan limits are enforced and how you are billed.
- System events (for example a failed webhook signature or an exhausted quota) for security, troubleshooting and audit.
- A record of each email we send you — the address, the subject, and whether it was delivered or bounced — so we stop writing to an address that no longer exists.
- IP addresses, transiently, for rate limiting on public forms and sign-in; our web server's access logs are kept for 14 days.
2.9 Apps you connect
If you connect an AI assistant such as Claude to your account, we store the grant (as a hashed token), the time, IP address and language of your consent, and a log of every action taken through it.
3. Why we use it
| Purpose | Data involved |
|---|---|
| Generate and deliver AI replies to your customers | Conversation history, your instructions, catalog, goal fields |
| Send the campaigns, follow-ups and order messages you set up, and honour opt-outs | Audience lists, templates, store orders and checkouts, the opt-out list |
| Route incoming messages and orders to the right account and prevent duplicates | Channel identifiers, message and order identifiers |
| Enforce plan limits and bill you correctly | Reply and message counters; the plan Shopify reports for your store |
| Show you conversations, leads, orders and analytics in the dashboard | Messages, media, goal completions, orders |
| Secure the platform and investigate abuse | System logs, sign-in records, IP addresses |
| Respond to your enquiries, send you account emails and provide support | Contact and account data, email delivery records |
| Tell account owners about the platform — news, tips and offers, each with an unsubscribe link | The owner's name, email address, business name and the stage the account is at (signed up, connected, paying) |
| Understand how our website is used and measure our advertising | Website visits (section 6) |
Where a law such as the GDPR applies, our legal bases are: performing our contract with you; our legitimate interests in keeping the platform secure and understanding how it is used; our legal obligations; and your consent, where we rely on it — for example for advertising cookies on our website, which you can withdraw at any time.
We do not sell your data, and we do not use your conversations, your lists or your customers' data to train our own models or to market to your customers.
4. Who we share it with
We share data only with the providers needed to run the service, and only what each one needs:
| Provider | What it receives | Why |
|---|---|---|
| Google (Gemini API) | Your instructions, recent conversation history, the incoming message, and your catalog and goal configuration | To generate each reply. Google processes this under its own API terms and does not use it to train its models. |
| Meta Platforms (WhatsApp Cloud API, Messenger, Instagram) | The reply or campaign content and the recipient's identifier. If you switch on conversion tracking, also a "lead" or "purchase" event for your ad account's dataset, carrying the customer's phone number as a SHA-256 hash (or their page-scoped id) and the ad click id | To deliver messages; Meta is also the source of the inbound ones. The conversion events let Meta attribute your ads — you can switch them off at any time. |
| Shopify | Through its API, the tags, notes and cancellations we write to your orders; and, for billing, nothing from us — we read from Shopify the plan, price, status and period of your app subscription | To keep your store in step with what customers decide on WhatsApp, and to apply the plan you chose. Shopify bills you under its own terms; we never see your payment details. |
| AI assistants you connect (Anthropic — Claude) | Only what you ask the assistant for in a given chat: the conversations, leads, campaigns, reports or instructions it reads, and the text of what you tell it to send or change | Optional. You connect the assistant yourself from Security → Connected apps; it acts with your own permissions, asks before changing anything, and can be disconnected there at any time. What the assistant receives is processed by its provider under your agreement with them. |
| Our hosting provider | All platform data, at rest on the server, and its encrypted backups | To host the application and database. |
| Our email delivery provider | Your name, email address, and the subject and content of each account email | To deliver invoices, reports, alerts and sign-in emails. |
| Our email marketing provider | The account owner's name, email address, business name and account stage | To send account owners news, tips and offers about the platform. Every such email carries an unsubscribe link; unsubscribing is honoured at once and nothing further is sent. |
| Analytics and advertising providers (on the public website only) | Your visit to our marketing pages — see section 6 | To measure our advertising. Nothing from your dashboard or your customers' data goes to them. |
These providers operate internationally, so data may be processed outside your country. We may also disclose data where the law requires it, or to establish or defend legal claims.
5. How long we keep it
- Conversations, messages and stored photos are retained for as long as your account is active, so that the assistant has context and you keep your history.
- Leads captured by goals are retained until you delete them; you can delete individual leads or export them at any time.
- Campaign lists are retained until you delete them. The opt-out list is kept for as long as the account exists, because it records people's wish not to be contacted.
- Store orders and checkouts are retained while the account is active and the store is connected. Checkouts we pull from Shopify cover the last 90 days.
- When you uninstall the Shopify app, order messages stop at once and the store's token becomes unusable. Forty-eight hours later Shopify asks us to forget the store, and we do: the store record and its products are deleted, the personal fields of that store's orders and checkouts are blanked, and lists built from the store are emptied. When Shopify forwards a customer's deletion request, we do the same for that customer's orders, checkouts, list entries and follow-ups. When Shopify forwards a customer's data request, we email the account owner what we hold about that customer straight away, well within the 30 days Shopify allows, so you can answer them.
- Sign-in records are deleted after 90 days and web server logs after 14 days. System event logs and email delivery records are kept for as long as they remain useful for security, support and audit.
- When an account is closed, it is first archived — so it can be restored if the closure was a mistake — and then deleted, at the latest 90 days after closure or sooner if you ask. Deletion removes its conversations, messages, photos, leads, lists, orders, credentials and usage records.
- Backups. We take an encrypted backup every night and keep daily copies for 30 days and monthly copies for 12 months, so data you delete can remain in a backup for up to 12 months. Backups are used only to recover from a failure, never to restore data you asked us to delete.
- Website enquiries are kept until we have dealt with them and are then removed.
- Connected-app grants (the access you give an AI assistant such as Claude) are stored as hashed tokens, expire by themselves within 90 days of last use, end immediately when you disconnect the app or change your password, and every action taken through them is logged.
If you want your data, or one customer's data, deleted sooner, ask us and we will act on it.
6. Cookies and analytics
On our public website (the marketing pages, not the dashboard) we use Google Analytics and Google Ads, the Meta Pixel, the LinkedIn Insight Tag and the ChatGPT Ads pixel from OpenAI, to measure our advertising, count conversions when a form is submitted, and show our ads to people who visited us. Each of these sets its own cookies and receives your IP address, the page you visited and information about your browser, under its own privacy policy. We also count page views ourselves, storing only a one-way hash of your address and browser (never the address itself), your country, device type and the page or campaign that brought you.
You can opt out by blocking or deleting cookies in your browser, by using the advertising controls Google, Meta and LinkedIn offer in your accounts with them, or with a tracker blocker; the site works the same without them.
In the dashboard there are no advertising or analytics trackers. Your browser's local storage holds your sign-in token, your language choice and, briefly, a pending store-link request; our network provider may set strictly necessary cookies for security.
7. How we protect it
- Access tokens and API keys are encrypted with AES-256-GCM before storage; nobody can read them from a database dump alone. Shopify tokens expire and are refreshed automatically.
- Passwords are hashed with bcrypt and are never recoverable; two-step verification is available to every account.
- All traffic to the platform runs over HTTPS, and backups are encrypted before they leave the server.
- Each account is strictly isolated: every request is scoped to its own account, and one client can never read another's data.
- Incoming webhooks — from WhatsApp, Messenger, Instagram and Shopify — are signature-verified so forged messages and orders are rejected.
- Access is role-based: team members only see what their role allows, and a deactivated user loses access immediately rather than at token expiry. Our own staff access data only as far as support requires.
- Repeated failed sign-ins lock the account.
No system is perfectly secure, but if a breach ever affects your data we will tell you promptly and explain what happened.
8. Your rights
You can ask us to:
- Access the personal data we hold about you, or receive a copy.
- Correct anything inaccurate — most account details are editable in the dashboard.
- Delete your data, one customer's data, or your entire account.
- Export your leads and conversations — the dashboard does this to Excel on demand.
- Object to or restrict a particular use of your data.
Email [email protected] and we will respond within 30 days. If you are a customer who messaged or bought from a business using ExceliaBOT, contact that business first — we will forward your request to them if you reach us instead.
9. Your responsibilities as our client
You are the controller of your customers' data. That means you are responsible for having a lawful basis to message them — including for every list you upload — for honouring their requests and opt-outs, and for what you instruct the assistant to collect. Send cart reminders only to customers who agreed to marketing (the default in our audience rules). Please do not configure goals that gather more than you genuinely need, never collect payment card details, passwords, or health information through the assistant, and if your customers send you sensitive documents, handle them lawfully and delete them when they are no longer needed.
10. Children
ExceliaBOT is a business tool and is not directed at children under 18. We do not knowingly collect their data; if you believe we have, contact us and we will remove it.
11. Changes to this policy
We may update this policy as the platform evolves. We will change the date at the top and, for material changes, notify account owners by email or in the dashboard before they take effect.
12. Contact
Questions, requests or complaints:
Email: [email protected]
WhatsApp: +20 103 370 7172
