Privacy Policy
Last updated: 15 August 2026
SSFlows is a software service operated by Phulkuri Media, Fulbari, Kurigram, Bangladesh. SSFlows helps small businesses reply to customer messages on their own Facebook Pages automatically.
This policy explains what information we collect, why we collect it, how we store it, and how you can have it deleted.
1. Who this policy covers
This policy applies to two groups of people:
- Clients — business owners who create an SSFlows account and connect their own Facebook Page.
- Customers — people who send a message to a Facebook Page that is connected to SSFlows.
2. Information we collect from clients
- Name, email address, phone number and business address provided at sign-up.
- Facebook Page ID, Page name and an access token for the Page the client connects.
- Business information the client enters, such as products, prices, opening hours and delivery charges.
3. Information we collect from customers
When a customer sends a message to a connected Facebook Page, we receive:
- The content of the message.
- A page-scoped user ID (PSID) supplied by Facebook.
- The customer's public profile name, where Facebook provides it.
- Any name, phone number or delivery address the customer chooses to type when placing an order.
We do not collect payment card details, government identity numbers or location data.
4. How we use this information
- To read an incoming message and generate a reply based only on the information the business owner has provided.
- To send that reply through the Facebook Page.
- To show the conversation history to the business owner in their dashboard, so they can take over a conversation manually at any time.
- To record orders placed through the conversation.
- To count message volume for billing.
We do not sell your data. We do not share it with advertisers. We do not use it to train advertising models or to build profiles across businesses.
5. Automated replies
Replies are generated using Google Gemini. Message text is sent to Google for the sole purpose of composing a reply and is not used by SSFlows for any other purpose. Prices and order totals are always calculated from the business owner's own database records, never generated by the language model.
6. Separation between clients
Each client can only see data belonging to their own Facebook Page. This separation is enforced at the database level through row-level security, not only in the interface.
7. Where data is stored
Data is stored in Supabase (PostgreSQL). Facebook access tokens are held in a restricted table that no client account can read. Connections to our servers use HTTPS.
8. How long we keep data
- Conversation history is kept while the client's account is active, so the business owner can refer back to it.
- If a client disconnects their Page, the stored access token is removed.
- If a client closes their account, associated data is deleted within 30 days.
9. Your rights
You may ask us to show you what data we hold about you, correct it, or delete it. Requests are handled within 30 days.
10. Children
SSFlows is intended for business use. We do not knowingly collect information from children under 13.
11. Changes to this policy
If we change this policy we will update the date at the top of this page. Significant changes will be communicated to clients by email.
12. Contact
Phulkuri Media
Taluk Shimulbari Mirpara, Fulbari, Kurigram 5680, Bangladesh
Email:
admin@ssflows.com