Last updated: July 12, 2026
ChatFleet is a customer-conversation and order-management platform for online businesses. Each business (a “workspace”) uses ChatFleet to manage its own Facebook, Instagram and WhatsApp conversations, orders, deliveries and advertising measurement. Every workspace’s data is fully isolated from every other workspace.
Account data — name, email, phone number and role of workspace staff (admins, managers, moderators).
Conversation data — messages, photos, voice notes and attachments exchanged between a workspace and its customers on connected channels (Messenger, Instagram, WhatsApp), including customer names and profile photos those platforms provide.
Order & delivery data — order text, customer name, phone number, delivery address, amounts, product details, courier tracking status and delivery outcomes.
Usage & device data — sign-in events, feature usage, and technical logs needed to keep the service secure and reliable. The mobile app additionally stores unsent orders on the device so a bad network never loses an order.
Solely to operate the service for the workspace that owns the data: routing and answering conversations, creating and tracking orders, dispatching couriers, detecting fraudulent orders, measuring the workspace’s own advertising, and producing reports. We never sell personal data, never use it for our own advertising, and never build cross-workspace profiles.
When a workspace connects Facebook, Instagram or WhatsApp (including via Meta’s official WhatsApp Embedded Signup), we receive and process Platform Data under Meta’s Platform Terms. Access tokens are stored AES-256 encrypted, are never exposed to the browser, and are used only to operate the inbox and messaging for that workspace. WhatsApp connections use Meta’s official Cloud API — we do not use unofficial clients.
If a workspace enables it, order-funnel events (order placed, delivered, returned, etc.) are reported to Meta to measure that business’s own ads. Personal identifiers in these events (phone, name, email) are SHA-256 hashed before sending; only ad-click identifiers Meta itself issued are sent as-is. This feature is off by default and controlled per workspace.
We share the minimum data required with providers a workspace has enabled:
• Courier partners (e.g. Pathao, Steadfast, RedX, Carrybee) — recipient name, phone, address and COD amount, to deliver parcels and return live tracking.
• SMS gateways — customer phone numbers, to send order-confirmation or OTP messages the workspace has configured.
• AI providers (e.g. OpenAI, Anthropic, Google, Groq) — the relevant message text only, when a workspace enables AI-assisted replies; these APIs do not train on the data.
• Payment processors (Stripe; bKash for manual billing) — subscription billing details. We never store full card numbers.
• Hosting — our infrastructure runs in secured data centers; data is encrypted in transit (TLS) and sensitive values at rest.
Encryption in transit (HTTPS/TLS) everywhere; AES-256-GCM encryption at rest for tokens, API keys and credentials; role-based access control; per-workspace isolation; webhook signature verification; audit logging of administrative actions; and automatic encrypted backups.
Workspace data is retained while the subscription is active. When a workspace is deleted, its conversations, orders, media and credentials are removed from the live systems, with residual copies expiring from backups on a rolling schedule.
Workspace owners can export or delete their data from Settings or by contacting support. End customers can have their data removed through our Data Deletion process — including automatically when they remove the app from their Facebook settings. Where GDPR or similar laws apply, you may exercise access, rectification, erasure and portability rights through the same channels.
We use only essential cookies (session/authentication). No third-party advertising or tracking cookies are set by the dashboard.
ChatFleet is a business tool and is not directed at children under 16. We do not knowingly collect children’s data.
We will post any material changes to this policy here and update the date above. Questions or requests: contact your workspace administrator or our support team.
See also our Terms & Conditions.