1. Introduction
Conversora (“we,” “our,” or “us”), operating at https://conversora.io, provides a multi-tenant commerce management system (CMS), AI-assisted operations platform, and omnichannel messaging infrastructure for independent merchants.
This Privacy Policy explains how we collect, use, process, protect, and delete personal data when you use our platform, storefronts, and connected third-party integrations, including the Meta Platform (Facebook Messenger and Instagram Graph APIs).
2. Data We Collect
We collect information in the following categories to provide and secure our services:
Merchant Account Data
Name, business email address, store domain, billing identifiers, organization membership (via Clerk authentication), and store settings.
Storefront Customer Data
Customer contact information, shipping address, order details, and payment transaction metadata processed through connected gateways (Stripe, Razorpay).
Meta Platform Data
Connected Facebook Page ID/name, Instagram Business Account ID/username, user-scoped IDs, customer direct messages, comments, and avatar references.
Operational Logs
IP address, browser user-agent, timestamped API interaction logs, webhook delivery receipts, and error telemetry for security and reliability.
3. Meta Platform Data Usage & Permissions
Conversora accesses Meta Platform data strictly via official Meta Graph API v26 endpoints in accordance with the Meta Developer Policies and Platform Terms:
- instagram_manage_messages & pages_messaging:Used solely to receive customer direct messages into the merchant’s unified Conversora inbox and allow merchants to reply directly to customer inquiries.
- instagram_basic, pages_read_engagement & pages_show_list: Used to display connected account names, usernames, and profile picture previews in the store admin dashboard.
- instagram_content_publish: Used to enable merchants to schedule and publish product announcements and marketing posts directly to their Instagram accounts.
- instagram_manage_comments: Used to display post comments in the inbox engagement workspace and allow merchant replies.
Strict Non-Disclosure: We do not sell, rent, trade, broker, or transfer Meta User Data to data brokers, ad networks, or any unauthorized third parties.
4. Data Security & Storage
We implement enterprise-grade security practices to safeguard all platform data:
- Encryption in Transit: All HTTP traffic is encrypted using TLS 1.3.
- Encryption at Rest: OAuth access tokens and sensitive credentials are encrypted using AES-256-GCM before database insertion.
- Tenant Isolation: Every database query is strictly scoped by verified store and organization boundaries (`Store.id`).
- Zero Credential Exposure: Access tokens are never transmitted to client bundles or logged in application monitors.
5. User Data Deletion Instructions
In accordance with Meta Platform rules and international data protection laws (GDPR / CCPA), users have the right to request deletion of their personal data and platform interactions.
How to Delete Your Data from Facebook / Instagram:
- Go to your Facebook or Instagram profile’s Settings & Privacy.
- Navigate to Settings $\rightarrow$ Apps and Websites.
- Find Conversora in the list of active apps and click Remove.
- Click View Removed Apps and Websites, select Conversora, and click Send Request to automatically trigger a data deletion request.
Direct Deletion Requests:
You may also request complete data removal by emailing our Data Protection team at privacy@conversora.io with your store slug or Instagram username. All associated messages, identity profiles, and token records will be permanently purged within 30 days.
6. Contact Information
If you have any questions, inquiries, or privacy requests regarding this policy, contact our compliance team: