Privacy Policy
Last updated: July 17, 2026
1. Who we are
Goगोदाम (“we”, “us”, “the Service”) provides AI-powered sales automation for businesses: a unified inbox and AI sales agent across WhatsApp, Instagram, Facebook Messenger, Gmail, and web chat, together with lead management, inventory, orders, delivery, and billing tools. This policy explains what data we collect, why we collect it, which third-party permissions we request, and how you can control or delete your data.
Our customers are businesses (“merchants”). When a merchant’s customers (“end customers”) message that business, we process those messages on the merchant’s behalf.
2. Information we collect
Account information. When you create an account we collect your name, email address, password (stored as a salted hash — we never store plain-text passwords), and optionally a phone number and avatar. Team members you invite provide the same details, plus a role (owner, admin, agent, or viewer).
Business information.Your business name, type, address (district and municipality), contact phone number, working hours, timezone, and your AI assistant’s configuration (persona name, instructions, language).
End-customer conversation data. When end customers contact your connected channels we receive and store, on your behalf: their name, phone number, email address, and platform identifiers (WhatsApp ID, Instagram ID, Facebook Messenger ID); the content of their messages, including text, images, and other media; and AI-generated conversation summaries, lead status, tags, and notes your team adds.
Catalog, order, and delivery data.Products, variants, stock levels, and prices you manage in the Service; order details including the end customer’s delivery address and phone number; and shipment tracking events.
Payment and billing data.Your subscription plan, payment history, and gateway transaction references. If you connect your own eSewa or Khalti merchant account so the AI can send payment links, we store those credentials encrypted; only the last few characters are ever displayed back to you. We never see or store end customers’ card or wallet credentials — payments happen directly on the gateway’s pages.
Usage and technical data. AI reply counts against your plan limit, feature usage, and standard technical logs (timestamps, request metadata) needed to operate and secure the Service.
3. Third-party permissions we request
The Service only works by connecting to messaging platforms on your behalf. You grant these permissions explicitly during channel setup, and you can disconnect any channel at any time from Settings.
Meta (Facebook, Instagram, WhatsApp). When you connect a Facebook Page we request permission to: list and manage messaging for your Pages, access the Instagram business account linked to a Page (including sending and receiving Instagram Direct messages), and access your WhatsApp Business Account (sending and receiving WhatsApp messages, and syncing your product catalog). We store the resulting page-scoped access tokens encrypted at rest and use them solely to send and receive messages and sync catalog data for your business.
Google (Gmail and Calendar). When you connect Google we request: read, send, and label access to your Gmail mailbox (gmail.modify) so customer emails appear in your inbox and the AI can reply on your behalf; access to your Google Calendar so the AI can check availability and book appointments; and your email address to identify the connected account. OAuth tokens are stored encrypted at rest.
Goगोदाम’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, and do not allow humans to read it except with your explicit permission, for security purposes, or to comply with law.
4. How we use information
- To operate the unified inbox: receiving, displaying, and sending messages across your connected channels.
- To generate AI replies, conversation summaries, lead classification, and escalation decisions. Conversation content is processed by our AI model providers (currently Anthropic and Google) solely to generate these outputs; we do not permit them to use your data to train their models.
- To manage your catalog, orders, and deliveries, including booking couriers and generating payment links when you ask the Service to.
- To bill your subscription and enforce plan limits.
- To secure the Service, prevent abuse, and comply with legal obligations.
We do not sell personal data, and we do not use your data or your end customers’ data for third-party advertising.
5. Who we share data with
- Meta Platforms — to deliver messages on WhatsApp, Instagram, and Facebook Messenger, and to sync product catalogs.
- Google — to send and receive Gmail messages and manage calendar events you authorize.
- AI model providers (Anthropic, Google) — conversation content needed to generate AI responses and summaries.
- Payment gateways (eSewa, Khalti) — transaction details needed to process subscription payments and the payment links you send.
- Courier partners (NCM) — recipient name, phone, and delivery address needed to fulfil shipments you book.
- Infrastructure providers — hosting and database services that store data under contractual confidentiality.
Each provider receives only the data required for its function. We may also disclose data where required by law.
6. Security
All traffic is encrypted in transit (TLS). Third-party access tokens and merchant payment credentials are encrypted at rest. Passwords are stored as salted hashes. Every record is scoped to your business — team members of one business can never access another business’s data, and role-based permissions restrict what each team member can do.
7. Data retention and deletion
We retain your data while your account is active. Disconnecting a channel revokes and deletes its stored access tokens. Deleting your business account removes your business data, conversations, and connected-account credentials from our systems, except records we must keep for legal or accounting purposes (such as payment records). You can also revoke our access directly from your Google account permissions or Facebook Business settings at any time.
8. Your rights
You may access, correct, export, or delete your personal data, and object to or restrict certain processing. Merchants are responsible for honoring end customers’ privacy requests for conversation data held on their behalf; we provide the tools (deleting leads and conversations) to do so, and we will assist where required.
9. Changes and contact
We will update this policy as the Service evolves and revise the date at the top. Material changes will be announced in the dashboard. Questions or requests: contact us at privacy@gogodaam.com.