Privacy Policy
Last updated: August 30, 2026
1. Who We Are
Storely (operated at storelybd.com) is a multi-tenant e-commerce platform builder for Bangladeshi merchants. We provide tools to create and manage online stores, process orders, and connect with third-party services including Meta (Facebook & Instagram) advertising platforms.
2. Information We Collect
We collect the following types of information:
- Account information: Name, email address, phone number, and business details provided during registration.
- Store data: Products, orders, customer names, phone numbers, and delivery addresses entered by merchants.
- Meta integration data: When a merchant connects their Meta Ads account, we store an OAuth access token to read advertising insights (campaign spend, reach, purchases, ROAS) on behalf of that merchant. We do not store Meta user passwords.
- Usage data: Pages visited, features used, browser type, IP address, and session identifiers for analytics and fraud prevention.
- UTM parameters: Tracking parameters appended to URLs from ad campaigns to attribute orders to advertising sources.
3. How We Use Your Information
- To operate and improve the Storely platform
- To process and display order information to merchants
- To sync advertising campaign performance data from Meta APIs at the merchant's request
- To show merchants analytics about their store traffic, orders, and ad performance
- To detect and prevent fraudulent orders
- To send transactional emails (order confirmations, system alerts)
- To comply with legal obligations
4. Meta Platform Data
Storely integrates with the Meta Marketing API to allow merchants to view their Facebook and Instagram advertising performance inside their Storely dashboard. Specifically:
- Merchants must explicitly authorize Storely to access their Meta Ads account via Facebook Login (OAuth 2.0).
- We request the
ads_readandads_managementpermissions to read campaign insights (spend, impressions, clicks, purchases, ROAS). - Access tokens are encrypted and stored securely. They expire after 60 days and must be re-authorized by the merchant.
- We do not create, modify, or delete any ads on behalf of merchants — the integration is read-only for reporting purposes.
- Meta advertising data is only accessible to the merchant who owns that ad account and authorized Storely. It is never shared with other merchants or third parties.
- Merchants can disconnect their Meta account at any time from the Meta Ads settings page, which immediately revokes Storely's access to their data.
5. Data Sharing and Third Parties
We do not sell your personal data. We share data only in these circumstances:
- Courier services (Steadfast, Pathao, CarryBee): Delivery name, phone, and address are sent to the courier API when a shipment is booked.
- Payment processors (bKash, Nagad): Transaction references are exchanged for payment verification.
- Meta Platforms Inc.: We communicate with the Meta Graph API on the merchant's behalf using their authorized access token. Meta's own privacy policy applies to their data practices.
- Legal compliance: We may disclose information if required by law or to protect against fraud or security threats.
6. Data Retention
We retain merchant account data for as long as the account is active plus 30 days after deletion. Order data is retained for 2 years for accounting compliance. Meta access tokens are deleted immediately when a merchant disconnects their Meta account.
7. Data Deletion
Merchants can request deletion of their data and all associated store data by contacting us at support@storelybd.com. We will process deletion requests within 30 days.
If you have authorized Storely via Facebook Login and wish to delete the data we received through that authorization, you can:
- Disconnect from within Storely (Meta Ads → Disconnect), or
- Revoke access directly from your Facebook App Settings, or
- Email us at support@storelybd.com with your request.
8. Security
We use industry-standard security measures including HTTPS encryption, encrypted storage of access tokens, randomized filenames for uploaded files, magic-byte validation on uploads, and rate limiting on sensitive endpoints. However, no system is completely secure and we cannot guarantee absolute security.
9. Cookies
Storely uses session cookies to keep merchants logged into their admin panel and to temporarily store checkout data for storefront visitors. We do not use third-party advertising cookies on the admin panel. The storefront themes may load the Meta Pixel (configured by each merchant) which sets cookies per Meta's own policy.
10. Children's Privacy
Storely is a business platform not directed at children under 13. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this policy periodically. We will notify merchants of significant changes via email or a notice in the admin dashboard. Continued use of Storely after changes are posted constitutes acceptance of the updated policy.
12. Governing Law
This policy is governed by the laws of Bangladesh. Disputes shall be resolved in the courts of Dhaka, Bangladesh.
Contact Us
For privacy questions, data deletion requests, or concerns about our Meta integration:
support@storelybd.com
Storely · Dhaka, Bangladesh
storelybd.com