This policy explains what data TwingBot collects, why it is collected, how it is used, how long it is kept, and how users can request deletion or correction. The full policy is on this page; the summary below reproduces its main sections.
Connected channel data: Facebook Page, Instagram, WhatsApp or other channel IDs, names, images, access tokens, webhook subscription state and channel settings.
Conversation data: customer messages, comments, attachments, images, voice/audio metadata, message timestamps, delivery/read status, handoff status and assigned agent activity.
AI and automation data: bot settings, persona prompts, reply rules, language settings, automation flows, AI reply logs, AI failure events and credit usage records.
Product and order data: product names, images, stock, variants, prices, customer order details, delivery address, phone number, courier status, fraud-check results and order events.
Billing and credit data: credit balance, credit ledger, top-up records, purchase history, transaction references and invoice metadata.
Device and security data: login sessions, browser/device details, IP-derived approximate location, masked IP, hashed IP and last active time.
How we use information
To provide the dashboard, inbox, channel management, order management and product management features.
To send automated replies, AI-generated replies, private replies to comments and handoff notifications based on user settings.
To detect orders, create order drafts, submit confirmed orders and update courier status.
To calculate credits, stop AI features when credits are insufficient and restore AI features when credits are loaded.
To protect the platform from abuse, duplicate free-credit claims, blocked-account re-registration, spam and suspicious activity.
To maintain security, debug issues, improve performance and keep a reliable audit trail.
Meta platform data
When a user connects Meta channels, TwingBot may receive Page, Instagram, message, comment, webhook and profile data permitted by the user's granted permissions. Meta data is used only to provide connected channel functionality such as inbox sync, automation, AI replies, private comment replies, order detection, analytics and page management. If a connected page is removed from TwingBot, we unsubscribe the page from our Meta webhook subscription so new webhook events stop arriving for that page.
AI processing
If AI features are enabled, customer text, image or voice content may be processed to understand intent, answer product questions, detect orders and draft replies. AI replies follow the user's configured persona, language, reply rules, channel settings, automation settings and available product/order data. AI features can be disabled by the user from the AI bot settings.
Third-party services
Meta/Facebook/Instagram/WhatsApp APIs for channel login, webhooks, messages, comments and page management.
AI model providers for AI replies, understanding images or voice, and order detection when AI features are enabled.
Courier providers such as Steadfast, Pathao, RedX, CarryBee or similar services when the user connects courier credentials and submits orders or checks delivery/fraud status.
Cloud/image storage providers when users upload or attach files/images.
Payment or billing providers when users buy subscriptions or credits.
Data retention
Workspace data is kept while the account is active and needed to provide the service.
Fraud-check cache may be retained temporarily to avoid repeated courier checks for the same phone number.
Logs, billing records and anonymized order/accounting records may be retained where needed for security, accounting, dispute handling or legal obligations.
Starter-credit claim hashes may be retained to prevent repeated free-credit abuse.
Blocked identity hashes may be retained so a blocked user cannot delete the account and immediately register again with the same identity.
Account deletion and Meta data deletion
Users can request account deletion from the Security settings page. After confirmation, cleanup is processed through a background queue. Deletion cleanup removes connected pages, unsubscribes Meta webhooks, stops automations, removes sessions, inbox data, products, settings and AI data, and anonymizes records that must be retained.
Security
TwingBot uses access controls, authenticated API routes, encrypted/secret field handling where appropriate, masked IP display, session management and worker queues for sensitive background operations. Courier credentials, tokens and connected channel credentials should only be provided by the account owner or an authorized team member. No system can guarantee absolute security, but we work to reduce unnecessary data exposure and keep sensitive workflows server-side.