SellPilot
Sign in
Legal

Privacy Policy

Last updated: September 27, 2026

SellPilot ("SellPilot", "we", "us") is an AI sales assistant that helps online businesses answer customer messages on Facebook Messenger, Instagram and WhatsApp, and manage orders. This policy explains what data we collect when you use SellPilot at app.sellpilot-mvp.online, how we use it, and the choices you have.

1. Who this policy covers

This policy applies to:

  • Business users: people who create a SellPilot account and connect their business's messaging channels.
  • Customers of those businesses: people who message a business on Facebook, Instagram or WhatsApp. The business decides to use SellPilot to answer those messages; for this data we act on the business's behalf.

2. Data we collect

Account data. Your name, email address, password (stored only as a secure hash), or your Google account name and email if you sign in with Google; the business name, logo and settings you enter; and team members you invite.

Data from Meta platforms (Facebook, Instagram, WhatsApp). When you connect a channel with Facebook Login for Business, you choose which assets to share. For those assets only, we receive and store:

  • the Facebook Page, Instagram professional account or WhatsApp Business number you selected: its ID, name or username and profile picture;
  • the access tokens Meta issues so SellPilot can act for that asset;
  • messages sent to and from the connected asset, and the sender's ID, name or username and profile picture as provided by Meta, so the conversation can be shown in your inbox and answered.

We use these permissions only to list and connect the assets you choose, receive new messages through webhooks, and send the replies you or the AI assistant write. We do not read posts, followers or other content you did not connect, and we do not use Meta data for advertising.

Business data. Products, orders, customers, invoices, notes and tags you create in SellPilot.

Payment data. Subscription payments are processed by SSLCommerz. We receive the payment status and transaction reference, not your full card details.

Technical data. Log data such as IP address, browser type and the time of requests, used to keep the service secure and working.

3. How we use data

  • to provide the service: show conversations, generate and send replies, and manage orders;
  • to generate AI reply suggestions and automatic replies, using the conversation, your product catalog and your business settings;
  • to send account emails such as verification, password reset and billing notices;
  • to secure the service, prevent abuse and fix problems;
  • to meet legal obligations.

We do not sell personal data.

4. Service providers we share data with

We share data only with providers that help us run SellPilot, and only as needed:

  • Meta Platforms: to receive and send messages on the channels you connect.
  • OpenAI: conversation text and relevant business information are sent to generate AI replies. Under OpenAI's API terms, this data is not used to train their models.
  • Neon: our PostgreSQL database host.
  • Amazon Web Services (Singapore region): file storage (S3) and email delivery (SES).
  • Google: sign-in with Google, if you choose it.
  • SSLCommerz: payment processing.

We may also disclose data if required by law or to protect the rights and safety of our users.

5. Data retention

We keep account data, business data and conversations while your account is active. When you remove a connected channel, its Meta access token is deleted immediately. When you ask us to delete your account or a channel's conversations, we delete that data within 30 days, except records such as invoices that we must keep by law.

6. Deleting your data

You can disconnect or permanently remove any channel in Connect Channels, and ask us to delete your account and all related data. See our Data Deletion instructions. Customers of a business can ask that business, or contact us directly, to delete their messages.

7. Security

Data is encrypted in transit (HTTPS). Access tokens and passwords are stored securely and only accessible to the systems that need them. Access to production data is limited to authorized staff.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to its processing. Contact us to make a request.

9. Children

SellPilot is a business tool and is not intended for anyone under 18.

10. Changes

We may update this policy. We will change the "Last updated" date and, for significant changes, notify account owners by email.

11. Contact

Questions or requests: sales@sellpilot-mvp.online.