YOUR INFORMATION
Privacy, in plain language.
This notice explains how Bayyo handles information for store conversations and workspace accounts.
Updated 12 September 2026 · Controlled pilot
Who this notice covers
Bayyo provides this conversation workspace. The business you message controls its customer relationship and how it uses your messages. Bayyo processes those messages to provide the workspace and its assistant. The business may have its own privacy notice for purchases and other services.
For questions about information held here, use our data request form or contact the store through the same account you used to message it. The form routes requests to the relevant workspace owner; it is not a shared inbox for other stores.
Information we handle
- Messages, channel identifiers, message identifiers, timestamps, staff replies and conversation status.
- Details you choose to provide, such as your name, phone number, delivery address, product selections and order or after-sales requests.
- Workspace account name, email, Supabase authentication identity, membership and encrypted sign-in session records. Legacy accounts retain their password hash until verified migration.
- Store product data, policies and knowledge added by the workspace owner; encrypted connection credentials.
- Privacy requests and limited security and operational records, including request metadata and a hashed IP identifier for rate limiting.
We do not collect card numbers. Workspace subscriptions can be paid externally through InstaPay. We store the chosen plan, amount, transaction reference, uploaded receipt, and review decision to verify payment and manage access. Receipts are encrypted in storage and accessible only to workspace owners and platform administrators; they are not sent to the AI assistant. When a store enables Shopify ordering, a customer-approved order can be created for cash on delivery. Automatic refunds, exchanges and carrier bookings are outside this release.
Why we use it
We use this information to receive and answer messages, keep context, prepare customer-approved cash-on-delivery orders and collect after-sales requests for staff, operate accounts, enforce workspace permissions, diagnose delivery problems and handle privacy requests. When AI replies are enabled, relevant messages, recent conversation history, collected customer details and store information are sent to OpenAI to generate a response.
AI replies can be wrong. Ask for the store’s team when you need a person. We do not use your conversations to train a model of our own or sell them to advertisers.
Who receives information
Authorized users of the relevant workspace can view its conversations. Service providers process information to run the service: Vercel hosts the application, Supabase stores application data, OpenAI generates enabled AI replies, and Meta delivers connected-channel messages. Shopify supplies live catalog, inventory, discount and delivery data when connected. After your explicit confirmation, your selected products, name, phone number and delivery address are sent to that store’s Shopify account to create an unpaid, unfulfilled COD order. Resend delivers account verification, recovery and invitation emails through Supabase Auth when email service is enabled.
These providers may process data outside your country under their own service terms and settings. Deleting a record here does not automatically delete a copy already held by Meta, OpenAI, the store or another provider.
Meta privacy · OpenAI privacy · Supabase privacy · Vercel privacy
Retention and deletion
Conversation history shown to the assistant is limited, but related operational records may remain in the database. This preview does not yet apply a blanket automatic expiry to all customer records. Data is retained until it is removed by an authorized owner or a verified deletion request is fulfilled.
Verified conversation erasure removes the conversation, captured contact and delivery details, and linked requests and processing records from Bayyo’s active database. We keep a minimal request receipt and a keyed, non-readable identifier with an erasure timestamp to prevent older message deliveries from recreating deleted records. New messages sent after deletion can create a new conversation.
Provider backups and records held separately by the store follow their respective retention processes. Workspace or account removal and requests that require retention review are handled separately; a form submission is not a confirmation that data has been deleted.
Security and cookies
Saved connection secrets are encrypted, Supabase manages verified account authentication, and legacy account passwords are hashed, and workspace access requires authorization. The console uses an essential sign-in cookie. These public privacy pages contain no advertising pixels or session-replay scripts. Hosting providers may retain technical request logs.
Your choices
Use the data request form to ask about access, correction, deletion, or workspace/account removal. We verify requests before changing another person’s records. You do not need a Bayyo account to submit a request. Do not include passwords, API keys, identity documents or payment details in the form.
Keep the private status link shown after submission. Updates appear there; this preview does not send automatic email confirmations. You can also follow up directly with the store.
لو عايز تسأل عن بياناتك أو تطلب حذفها، استخدم نموذج طلبات البيانات أو كلّم المتجر من نفس الحساب. تقديم الطلب مش معناه إن البيانات اتحذفت؛ لازم نتأكد من الهوية الأول.
Operator and support
Alaa Nosser
nosseralaa7@gmail.com