Legal

Privacy Policy

Last updated: September 16, 2026

1. Overview

Bosla ("Bosla", "we", "us") provides a bilingual customer communication and order-management platform for online sellers. This Privacy Policy explains what information we collect, how we use it, and the choices available to you when you use our website, dashboard, and connected integrations (the "Service").

We act as a data controller for information about the seller accounts and team members who use Bosla, and as a data processor for the end-customer messages and order data that sellers route through the platform. Sellers remain responsible for the lawful handling of their own customers' data.

2. Information we collect

We collect the following categories of information:

  • Account data — name, email, phone number, company details, role, and authentication data (including MFA) for seller team members.
  • Business profile — store name, store URL, support channels, brand voice, and team details provided during onboarding.
  • Channel & integration data — credentials and tokens for connected channels (WhatsApp, Instagram, Messenger, TikTok, Telegram) and stores (Shopify, Salla, Zid, custom API). These are encrypted at rest.
  • Conversation & order data — messages, attachments, contact details, and orders that flow through the unified inbox, including content processed by AI to generate replies.
  • Usage & device data — log data, IP address, browser/device information, and push notification tokens.

3. How we use information

We use information to:

  • Provide, operate, and secure the Service and your account.
  • Deliver and receive messages across connected channels and synchronize orders from connected stores.
  • Generate AI-assisted replies in the seller's configured brand voice, when AI is enabled on a conversation.
  • Send transactional notifications (e.g. order updates, delivery status).
  • Provide support, prevent abuse, and meet legal obligations.
  • Access your workspace to provide support, investigate abuse or security incidents, and comply with the law — see section 8.

4. AI processing

When AI auto-reply is enabled on a conversation, recent message history and the seller's business profile are sent to our AI model provider to generate a suggested or automated reply. We do not use your customers' message content to train third-party foundation models. AI can be disabled per conversation at any time.

5. Third-party services

We share data with infrastructure and integration providers strictly to operate the Service, including:

  • Meta Platforms (WhatsApp Cloud API, Instagram, Messenger) for messaging.
  • Store platforms (Shopify, Salla, Zid) for order and product sync.
  • Cloud hosting, object storage, email, and SMS providers.
  • AI model providers for reply generation.

Each provider processes data only as needed to deliver its function. We do not sell your personal data.

6. Data retention

We retain account and conversation data for as long as your account is active and as needed to provide the Service. When you disconnect a store or close your account, we delete or anonymize the associated personal data within 30 days, except where retention is required by law or for legitimate business records. For connected Shopify stores, we honor Shopify's data-protection webhooks: a customer data-erasure request (customers/redact) and a store-erasure request (shop/redact) delete the corresponding data, and a customer data-access request (customers/data_request) is fulfilled through the store owner.

7. Security

We protect data with encryption in transit and at rest, encrypted per-seller integration credentials, encrypted database backups, tenant-level data isolation, role-based access control, MFA, least-privilege staff access with access logging, and a security incident response process. We process the minimum personal data needed to provide the Service. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard safeguards.

8. Support access to your account

To resolve a problem you report, investigate abuse or a security incident, or meet a legal obligation, authorized Bosla staff can access your workspace — including your inbox, orders, customers, and settings — and can act inside it as a member of your team would.

  • Only staff with a platform operator role can do this. No other Bosla employee can enter a workspace.
  • We use it for support, troubleshooting, security, and legal compliance only — never to read your data for our own commercial purposes, and we never sell it.
  • Operator actions that change a workspace — plan and limit changes, suspension, password resets, workspace creation — are recorded in an internal audit log.
  • Staff with this access are bound by confidentiality obligations and least-privilege rules.
  • Where we need to make a change on your behalf that isn't part of resolving a request you raised, we ask you first.

If you'd prefer we not enter your workspace for a given issue, tell us at [email protected] and we'll work from screenshots and descriptions instead — though some problems can't be diagnosed that way.

9. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. End customers should direct requests to the seller they interacted with, who controls that data.

10. Children's privacy

The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you through the Service.

12. Contact us

For privacy questions or requests, contact us at [email protected].