Privacy Policy.
Last Updated: August 16, 2026
This Privacy Policy explains how Qbexel (“Qbexel,” “we,” “our,” or “us”) collects, uses, stores, shares, and protects information when businesses use our software, APIs, integrations, and services, including KomoChat, Automate, and EasTrack (together, the “Services”).
This Policy is written for business customers, merchants, website owners, page administrators, and authorized users who access or connect platforms to our Services. By using our Services or connecting third-party platforms (such as Meta platforms including Facebook Pages, Instagram, WhatsApp Business via Embedded Signup/Login, websites via Shopify, WooCommerce, TikTok, Google Analytics), you agree to the practices described below.
01. Who We Are
Qbexel provides integrated e-commerce and business software that helps merchants connect front-end sales channels (websites, social inboxes, and messaging apps) with back-end ERP, logistics, and financial infrastructure.
KomoChat
AI conversational sales, comment automation, and WhatsApp Cloud API agent with Embedded Signup & Co-existence support.
Automate (ERP)
Full-lifecycle E-Commerce ERP managing multi-channel orders (Shopify, WooCommerce, FB, IG, WhatsApp, TikTok), courier APIs, live tracking, inventory, double-entry cashbooks, CRM, and customer retargeting.
EasTrack
First-party server-side conversion tracking SaaS platform dispatching events directly to Meta CAPI, GA4, TikTok, and Webhooks.
02. Scope of This Policy & Core System Architecture
This Privacy Policy applies when:
- A business signs up for, authorizes, or uses Qbexel Services;
- A merchant connects e-commerce platforms (Shopify, WooCommerce, custom websites) or Meta platforms (Facebook Pages, Instagram Accounts, WhatsApp Business Accounts via WhatsApp Embedded Signup / Login);
- A merchant operates Automate ERP, where message and order ingestion from Facebook, Instagram, and WhatsApp serves as a mandatory, default foundational order bridge to capture customer transactions for courier booking and accounting;
- A merchant operates WhatsApp in Co-existence Mode (simultaneous WhatsApp Business mobile app and WhatsApp Cloud API);
- A website visitor interacts with a merchant website configured with EasTrack first-party server-side tracking (via custom CNAME domains);
- Customer direct messages, public comments, post reactions, webhooks, or order fulfillment records are ingested and processed through our Services;
- Any customer interacts with a Qbexel-powered merchant inbox, post comment thread, WhatsApp conversation, or automated sales channel.
03. Information We Collect
Depending on the specific modules enabled by the merchant, we collect and process the following categories of information:
3.1 Business Client Account Data
When a business registers for Qbexel:
- Business name, administrator name, contact email address, phone number, and physical office address;
- Account login credentials, billing/subscription records, product catalogs, pricing rules, inventory warehouses, API keys (`authKey`), and pixel credentials (Meta Pixel ID/Token, GA4 Measurement ID/Secret, TikTok Pixel ID/Token).
3.2 Multi-Channel E-Commerce & Social Data (Shopify, WooCommerce, Meta & TikTok)
When a business connects e-commerce stores and social channels:
- Storefront & Web Orders: Order items, SKUs, customer details, checkout values, and payment status synced from Shopify, WooCommerce, or custom storefront APIs.
- Direct Inquiries & Messages: Text messages, conversation threads, timestamps, voice notes, and shared media sent to the merchant's Facebook Page Inbox or Instagram Direct Inbox.
- Public Engagement Data: Public posts, user comments on merchant posts/reels, post reactions, comment IDs, and parent post context needed to automate public comment replies and initiate private messenger follow-ups.
- Social Profile Metadata: Publicly available customer identifiers permitted by Meta APIs, such as Page-Scoped IDs (PSID), Instagram-Scoped IDs (IGSID), user profile display names, and language preferences.
3.3 WhatsApp Business Platform, Embedded Signup & Co-existence Data
When a merchant connects WhatsApp Business via WhatsApp Embedded Signup / Login or enables WhatsApp Co-existence:
- Embedded Signup Account Data: WhatsApp Business Account (WABA) ID, verified business name, WhatsApp Phone Number ID, display phone number, messaging tier limits, and authorized system user access tokens provisioned via Meta's embedded onboarding dialog.
- Conversational Messages & Media: Incoming and outgoing WhatsApp messages, timestamps, interactive button replies, list message choices, voice notes, and media files exchanged between the customer and the merchant's WhatsApp number.
- WhatsApp Co-existence Webhook Ingestion: When Co-existence is active, messages sent by human agents from the physical WhatsApp Business mobile app and messages handled through the WhatsApp Cloud API are synchronized via real-time webhooks. This ensures KomoChat and Automate maintain an accurate, unified conversation history and capture confirmed orders regardless of whether the order was finalized in the mobile app or via automated API workflows.
- Consent & Opt-In / Opt-Out Records: Customer phone numbers, timestamped opt-in records, and opt-out commands (e.g. “STOP”) to comply with WhatsApp Business Messaging Policies.
3.4 Customer Order & Delivery Information (PII)
When an order is created or confirmed (via website checkout, chat inbox, comment thread, or WhatsApp chat), Automate extracts and stores essential fulfillment data:
- Customer Identifiers: Full Name and Primary Contact Phone Number;
- Shipping & Delivery Details: Full delivery address, district/city, postal zone, and landmark instructions required by couriers;
- Order Specifics: Item names, SKUs, sizes/colors, quantities, agreed price, delivery fee, payment mode (Cash on Delivery / Advance), and special order notes.
3.5 CRM, Customer Purchase History & Retargeting Data
Within Automate's CRM module:
- Customer lifetime value (LTV), total orders completed, return/cancellation rates, delivery reliability score, and product category affinities.
- This data allows merchants to send relevant, permissioned follow-ups, notify past buyers about new catalog arrivals, launch retargeting broadcasts, and provide tailored repeat-purchase promotions.
3.6 EasTrack Server-Side Event & Conversion Data
When a merchant installs EasTrack on their online storefront (via their first-party custom domain like `track.merchant.com`), our Fastify collector receives:
- Standard & Custom Web Events: Event names (`PageView`, `AddToCart`, `Purchase`), monetary value, and currency code.
- Cryptographically Hashed PII: Contact phone numbers and email addresses are immediately converted to one-way SHA-256 hashes (`phoneHash`, `emailHash`) prior to storage and API dispatch. Raw plaintext phone numbers and emails are never retained in tracking logs.
- Platform Attribution Identifiers: First-party click/browser IDs (`_fbc`, `_fbp`, `ttclid`, `ttp`, `gclid`, `gaClientId`), client IP, and browser User-Agent.
3.7 Mandatory Webhook Listeners & Order Extraction Conduit
For merchants utilizing Automate ERP, social channel connectivity (Facebook, Instagram, WhatsApp) is an essential default integration. Even when automated AI customer replies are disabled, secure webhook listeners remain continuously active to read incoming messages and extract confirmed order details (Name, Phone, Address, SKU) to feed Automate's shipping booking, inventory reservation, and accounting ledger engines.
04. How We Use Information
We process collected data exclusively to provide, maintain, and enhance our Services on behalf of our merchant clients:
- Operating Automate ERP to manage multi-channel order lifecycles (Shopify, WooCommerce, FB, IG, WhatsApp, TikTok);
- Executing automated courier API bookings (Pathao, Steadfast, RedX, Paperfly) and real-time parcel tracking;
- Maintaining double-entry accounting ledgers, cashbooks, expense journals, and SKU-level profit & loss calculations;
- Managing inventory warehouses, preventing overselling, and reserving stock variants;
- Powering Automate CRM to calculate customer reliability and facilitate permissioned customer retargeting with newer products;
- Delivering automated and agent-assisted conversational sales across Facebook, Instagram, and WhatsApp;
- Managing WhatsApp Business Cloud API communication and WhatsApp Co-existence message synchronization;
- Dispatching 100% accurate, ad-blocker resilient conversion events server-side to Meta Conversions API (CAPI), Google Analytics 4 (GA4), and TikTok Events API;
- Detecting fraudulent order attempts, repeated fake delivery requests, or abuse.
05. How Automate ERP & KomoChat Work Together
Automate is an enterprise ERP system that serves as the central operations engine, while KomoChat serves as the intelligent conversational and messaging bridge.
5.1 Default & Mandatory Order Ingestion for Automate
For merchants running Automate ERP, reading messages and events across Facebook, Instagram, and WhatsApp is a mandatory, core functionality. It guarantees that whenever a customer confirms an order in chat or via website webhooks, the order is automatically parsed and sent straight into Automate for fulfillment, courier dispatch, and financial ledger logging.
5.2 Merchant Control: Full AI vs. Webhook-Only Mode
Merchants have complete flexibility over how their conversations are handled:
- Full AI Assistant Mode: KomoChat actively converses with customers, answers product queries, handles objections, and automatically books orders.
- Webhook-Only / ERP Order Extraction Mode: Merchants can turn off automated AI customer replies and comment replies completely. In this mode, human agents chat with customers (via web inboxes or the WhatsApp Business mobile app), and the system operates strictly in the background—using secure webhook listeners to parse confirmed customer order details (Name, Phone, Address, Items) and pass them to Automate for instant shipping and accounting management.
5.3 CRM & Customer Retargeting with New Products
Automate compiles customer transaction history, purchasing patterns, and delivery success metrics. Merchants can leverage these insights to retarget previous customers with newer product collections, stock availability updates, or promotional messages across WhatsApp and social channels in compliance with platform messaging rules.
06. How EasTrack Operates (Server-Side Tracking Architecture)
EasTrack is a first-party server-side tracking SaaS platform designed to deliver reliable conversion event telemetry while maximizing visitor privacy and data accuracy:
6.1 First-Party Domain Collection & CNAME Isolation
EasTrack serves tracking libraries directly from the merchant's own registered first-party CNAME subdomain (e.g. `track.merchant.com`). Events are received by our Fastify collector behind an automated on-demand TLS proxy. Because tracking operates on the merchant's own first-party context, it bypasses third-party browser cookie restrictions (Safari ITP, ad-blockers) without injecting invasive third-party scripts.
6.2 One-Way SHA-256 Hashing of Personal Data
When contact identifiers (email, phone number) are supplied with conversion events (such as `Purchase`), our collector immediately normalizes and hashes them using irreversible cryptographic SHA-256 hashing algorithms before storing event logs or sending payloads to marketing APIs. Raw contact information is never written to event logs.
6.3 Multi-Destination Routing Engine
Events buffered in PostgreSQL and Redis BullMQ queues are processed by an isolated Worker Routing Engine, which executes custom rules to dispatch server-to-server payloads to:
- Meta Conversions API (CAPI): Direct server-to-server event dispatch to Graph API v19.0+;
- Google Analytics 4 (GA4): Server-side Measurement Protocol ingestion;
- TikTok Events API: Conversion API v1.3 dispatch;
- Custom Webhooks: Secure HTTPS POST forwarding to merchant-defined endpoints.
07. Meta Platform & WhatsApp Developer Policy Compliance
Qbexel complies strictly with Meta Platform Terms, Meta Developer Policies, and WhatsApp Business Messaging Policies. In accordance with these standards:
- No Sale of Platform Data: We never sell, rent, trade, or transfer Meta/WhatsApp platform data, user IDs, message logs, tracking events, or customer PII to third-party data brokers, advertising networks, or unauthorized entities.
- No Cross-Merchant Data Aggregation: Meta platform, WhatsApp messages, and EasTrack tracking data retrieved for one merchant is strictly isolated and never used to train global advertising profiles or shared with competitor businesses.
- WhatsApp Policy Compliance: We enforce WhatsApp's 24-hour customer service window, require approved message templates for outbound notifications, and honor all customer opt-out requests instantly.
- Strict Functional Use: We request only the Meta and WhatsApp permissions necessary to deliver the features requested by the merchant (e.g., direct messaging, reading post comments, publishing comment replies, WhatsApp Cloud API management, Meta CAPI event delivery, processing webhooks).
- No Surveillance: We do not use Meta platform or WhatsApp data for surveillance, credit eligibility scoring, or discriminatory practices.
08. User Data Deletion Instructions (Meta & WhatsApp Compliance)
In compliance with Meta's Platform Data Deletion requirements and global data protection standards, users and merchant administrators have the right to request the deletion of all data associated with their Facebook, Instagram, WhatsApp Business, or EasTrack tracking accounts stored by Qbexel.
Option A: Automatic Removal via Meta Account Settings
If you connected your Facebook Page, Instagram account, or WhatsApp Business Account to Qbexel, you can revoke access and trigger automated data deletion at any time:
- Go to your Facebook Profile or Business Settings > Settings & Privacy > Settings.
- Navigate to Apps and Websites or Business Integrations.
- Locate Qbexel / KomoChat in the active applications list.
- Click Remove.
- Our automated Data Deletion Callback endpoint will receive Meta's notification, revoke API access tokens immediately, disconnect WABA webhook subscriptions, and schedule all associated caches for purging.
Option B: Manual Data Erasure Request
End customers, WhatsApp users, website visitors, or page administrators may submit a direct deletion request at any time:
Send an email to support@qbexel.com with the subject line “Data Deletion Request”. Please provide your Page/WABA Name, Facebook User ID, WhatsApp Phone Number, or Account Email. Our security team will confirm your identity and permanently delete all relevant messages, EasTrack event logs, contact information, and conversation history within 30 days, providing you with a confirmation code. You can also visit our dedicated Data Deletion Instructions Page.
09. How We Share Information
We do not sell personal data. We share information only with authorized entities strictly required for service delivery:
9.1 With the Merchant Client
The business customer who owns the connected page, shop, WhatsApp Business number, or tracking domain controls the conversation data, order logs, tracking events, and customer records processed through their account.
9.2 With Advertising & Analytics Platforms (Meta, Google, TikTok)
Under EasTrack server-side routing rules configured by the merchant, conversion events and SHA-256 hashed identifiers are securely forwarded via official APIs (Meta CAPI, GA4 Measurement Protocol, TikTok Events API) exclusively for ad optimization and attribution analytics.
9.3 With Courier & Logistics Partners
Customer shipping information (Name, Phone Number, Delivery Address, Item details) is transmitted to integrated courier partners (Pathao, Steadfast, RedX, Paperfly) exclusively to create delivery consignments and generate tracking numbers.
9.4 With Infrastructure & Service Providers
We use cloud infrastructure, secure database hosting, and AI compute providers who process data under strict data protection and confidentiality agreements.
9.5 Legal & Regulatory Requirements
We may disclose information if required by court order, law enforcement, or applicable legal process to prevent fraud or protect the safety of users.
10. Data Retention & Purging Policy
We retain message context, WhatsApp conversations, customer orders, EasTrack event logs, and accounting records for as long as the merchant maintains an active account with Qbexel. Raw EasTrack event logs in PostgreSQL are cycled or aggregated after 90 days. When a merchant disconnects an integration or deletes their subscription, API access tokens are instantly revoked, and stored data is purged within 30 days, except where statutory financial accounting rules require retention of invoice records.
11. Data Security Safeguards
We implement industry-standard organizational and technical safeguards to protect all data, including:
- End-to-end encryption in transit (HTTPS / TLS 1.3) with automated on-demand SSL certificates via Caddy;
- One-way SHA-256 cryptographic hashing for customer contact identifiers before storage and dispatch;
- AES-256 encryption at rest for sensitive API access tokens, WhatsApp system user tokens, and customer credentials;
- Role-based access controls (RBAC), Redis BullMQ queue isolation, host header verification against registered CNAMEs to prevent cross-domain spoofing.
12. Merchant Responsibilities
Merchants using Qbexel, Automate, KomoChat, and EasTrack are responsible for maintaining a transparent Privacy Policy and Cookie Consent Banner on their storefronts, obtaining customer opt-in for WhatsApp and promotional retargeting messages in accordance with applicable laws, and ensuring lawful processing of customer delivery addresses.
13. Contact Us
For questions regarding this Privacy Policy, WhatsApp integrations, Meta Data Deletion, or data protection practices, please contact our Data Protection Officer:
Office AddressQbexel · rd 1, nikunja 2, khilkhet, Dhaka
Email Support & Privacysupport@qbexel.com
Phone Line+8801982780739