1. Overview & Scope
Eazweb operates the Aura Commerce conversational commerce infrastructure. Our platform empowers independent merchants to connect their social channels (including Instagram Professional Accounts and WhatsApp Business) to automate customer product inquiries, deliver AI-powered shopping recommendations, and provide instant checkout experiences.
This policy applies to all visitors of our website, merchants utilizing our automation tools, and consumers ("Shoppers") interacting with merchants via automated Instagram direct messages, comments, or web storefronts.
We strictly abide by the Meta Platform Terms, Developer Policies, the Information Technology Act, 2000 (India), and international data protection standards. We never sell, monetize, or exploit personal information or Meta user data.
2. Information We Collect
Depending on whether you are a Merchant or an end-consumer Shopper, we collect the following categories of data:
A. From Merchants
- Account Information: Name, business name, email address, contact number, and login credentials.
- Social Connection Data: Instagram Professional Account IDs, Facebook Page IDs, and OAuth tokens required to receive webhooks and dispatch replies on your behalf.
- Product Catalog: Products, variants, descriptions, pricing, media assets, and inventory counts.
B. From Shoppers (End Users)
- Conversational Inquiries: Messages, questions, and public comments sent by shoppers to connected merchant accounts (e.g. "What sizes are available?", "PRICE").
- Checkout Details: Customer name, delivery address, postal code, verified mobile number (authenticated via one-time password), and email for order fulfillment.
- Transaction History: Items purchased, order amounts, and payment status (note: payment card numbers and UPI PINs are processed directly by PCI-DSS certified payment gateways and are never stored on our servers).
3. Meta Platform Data Handling
Our services integrate directly with Meta APIs (Instagram Graph API, Instagram Messaging API, and Webhooks). In compliance with Meta Developer Policies:
| Data Element | Source | Purpose & Processing | Storage Duration |
|---|---|---|---|
| Instagram Scoped ID (IGSID) | Instagram Graph API | Identifies the messaging thread to route automated replies back to the user. | Retained only during the active conversational lifecycle. |
| Public Comments | Instagram Webhooks | Analyzed in real time to trigger automated private replies (e.g., product links when a user comments "PRICE"). | Processed ephemerally; comment text is not permanently archived once reply is sent. |
| Direct Messages | Instagram Webhooks | Processed by our AI shopping assistant to understand shopping intent and display product cards. | Maintained in conversation history for multi-turn dialogue continuity. |
| Merchant Access Tokens | Instagram Login OAuth | Used exclusively to authorize API requests for the merchant's own storefront. | Encrypted at rest using AES-256-GCM. Stored until merchant disconnects. |
We do not use Meta Platform Data for profiling, advertising networks, data brokers, or any secondary purpose unrelated to the direct fulfillment of merchant customer support and commerce transactions.
4. How We Use Information
We use collected data solely for the following legitimate business purposes:
- Automated Conversational Replies: Enabling immediate, accurate answers to customer inquiries about product availability, sizing, and pricing.
- Comment-to-DM Fulfillment: Dispatched private replies with catalog links when users comment on merchant posts.
- Order Processing & Verification: Generating checkout sessions, verifying customer phone numbers via OTP, calculating shipping rates, and transmitting orders to merchants.
- Security & Fraud Prevention: Verifying requests using HMAC SHA-256 signatures from Meta webhooks to ensure message integrity and prevent spoofing.
- Platform Reliability: Diagnosing server errors, monitoring API rate limits, and improving agent accuracy.
5. Data Sharing & Third Parties
We do not sell personal data. We only share information with trusted third parties under strict confidentiality agreements:
- Connected Merchants: When a shopper initiates a purchase, their name, shipping address, and order selections are shared with the merchant fulfilling the order.
- Meta Platforms, Inc.: Data is exchanged via the official Meta Graph API to send direct messages and receive webhook events.
- Payment Processors: Licensed payment gateways (e.g. Razorpay, Stripe) receive billing details necessary to authorize payments securely.
- Infrastructure Providers: Cloud hosting (Cloudflare, PostgreSQL) adhering to SOC-2 and ISO 27001 data protection standards.
- Legal Compliance: If required by applicable court orders, law enforcement requests, or statutory obligations.
6. Data Security & Storage
We deploy robust enterprise-grade safeguards to protect user data:
- Encryption at Rest: All sensitive merchant credentials, Meta access tokens, and phone verification secrets are encrypted using industry-standard AES-256-GCM encryption.
- Encryption in Transit: All communications between shoppers, merchants, Meta APIs, and our servers are encrypted via Transport Layer Security (TLS 1.3).
- Webhook Signature Verification: Every incoming payload from Meta is verified against our app secret using SHA-256 HMAC cryptographic signatures before processing.
- Row-Level Data Isolation: Merchant data, product catalogs, and conversation logs are isolated in dedicated database schemas.
7. Data Retention Policy
We retain personal data only for as long as necessary to fulfill the purposes described in this policy:
- Ephemeral Webhooks: Webhook payloads from Instagram comments are processed within seconds and discarded immediately following delivery.
- Chat Session Memory: Conversational context is maintained for 30 days to assist returning shoppers, after which session memory is archived or pruned.
- Order & Billing Records: Completed order details are retained for accounting and compliance purposes as required under Indian commercial and tax statutes.
- Merchant Account Disconnection: If a merchant disconnects their Instagram account or deletes their account, all associated tokens and webhook subscriptions are revoked within 24 hours.
8. Your Rights & Choices
Depending on your jurisdiction, you have the following rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we maintain about you.
- Right to Rectification: You may request corrections to any inaccurate or incomplete details.
- Right to Erasure (Deletion): You have the right to request deletion of your data from our systems at any time.
- Revoke App Permissions: Instagram users can revoke Aura Commerce's access at any time directly through their Instagram App Settings.
9. User Data Deletion Instructions
In compliance with Meta Platform Developer Policies, users can request the deletion of their data through either of the following methods:
For detailed instructions and tracking confirmation codes, visit our dedicated Data Deletion Page.
10. Children's Privacy
Our services are not intended for individuals under the age of 13 (or under 18 in jurisdictions where parental consent is required for commerce transactions). We do not knowingly collect personal data from minors. If we discover that a child has provided us with personal information, we immediately remove such records from our databases.
11. Grievance Officer & Contact Details
If you have any questions, concerns, or grievances regarding this Privacy Policy or our data processing practices, you may contact our designated Grievance Officer:
Operating Entity: Eazweb (Proprietorship)
Government Registration: Udyam Registration (Ministry of MSME, Govt. of India)
Platform: Aura Commerce
Privacy Email: privacy@eazweb.in
General Support: support@eazweb.in
Jurisdiction: India