Privacy Policy
Last updated 14 September 2026
Buyziz is a commerce platform that lets a merchant run an online store and answer their customers across their own storefront, Facebook Messenger and Instagram. This policy explains what personal information we handle, why, who we share it with, and what you can ask us to do about it.
Two different groups of people appear in this policy, and the distinction matters throughout. A merchant is someone who signs up to run a store. A customer is someone who shops at, or sends a message to, one of those stores. For a merchant's own account we are the controller of that data. For their customers' data, the merchant decides what is collected and why — we process it on their behalf, as their service provider.
1. What we collect
From merchants. Your name and email address, a password (stored only as a one-way hash, never in a readable form), and — if you sign in with GitHub — your GitHub account id, username and avatar. If you enable two-factor authentication we store the secret needed to verify your codes. During onboarding we may collect business verification details such as an owner name, phone number, address and an identity document, which exist solely to confirm that a store is run by a real, reachable business.
From customers of a store. Whatever that store's checkout and conversations require: typically a name, phone number, delivery address, order contents and payment status. Where a customer messages a store through Messenger or Instagram, we receive the message, the sender's platform-scoped id, and the account it was sent to.
Automatically. IP address, device and browser information, pages viewed and actions taken. We use this to keep the service running, to detect fraud and abuse, and to understand which features are used. On buyziz.com and in the dashboard, an analytics cookie lets us see how visitors find us and whether a visit leads to opening a shop; it does not record anything you type.
What we do not collect. We do not store full card numbers or banking credentials. Payments are completed by a payment provider; we keep only the outcome and a reference. Credentials a merchant gives us for a third-party service — a payment gateway, a courier, an email sender, a connected Meta account — are encrypted before storage and are never displayed back, in full, by any part of the product.
2. Facebook and Instagram
A merchant can connect a Facebook Page or an Instagram professional account so that messages sent to it reach their Buyziz inbox. Connecting is explicit: the merchant signs in with Meta and grants permission, and can disconnect at any time.
- What we receive. The account's id and name, an access token, and the content of messages sent to that account — the message text, any attachments, and the sender's platform-scoped id. We do not receive a customer's Facebook or Instagram password, friend list, or anything about their activity away from that conversation.
- What we do with it. We deliver the message to the merchant, keep the conversation history so the thread makes sense, and — where the merchant has enabled it — let an automated assistant help answer questions about products, stock and orders.
- Tokens. The access token that lets us read and reply on the merchant's behalf is encrypted at rest and used only for that purpose.
- Disconnecting. When a merchant disconnects an account we stop receiving its messages and tell Meta to stop sending them. Conversation history already held is deleted on request — see section 7.
We use this data only to provide the messaging feature. We do not sell it, and we do not use it for advertising.
3. How we use information
- To create and secure accounts, and to sign people in.
- To run stores: publishing products, taking orders, and arranging delivery.
- To deliver and answer messages on the channels a merchant has connected.
- To send messages people expect — order confirmations, delivery updates, password resets, security alerts — by email and, where a merchant has enabled it, SMS.
- To detect and prevent fraud, abuse and unauthorised access.
- To measure and improve the product, and to provide support when asked.
- To meet legal, tax and accounting obligations.
We do not sell personal information, and we do not share it with advertisers for their own purposes.
4. Who we share it with
We share personal information only with services that help us run Buyziz:
- Cloudflare — hosting, storage and databases. Buyziz runs on Cloudflare's network.
- Meta — for Messenger and Instagram messaging, where a merchant has connected an account.
- Payment providers — to take and verify payments. They handle card and wallet details directly; we receive the result.
- Delivery partners — the courier a merchant chooses receives the recipient's name, phone number and address so the parcel can be delivered.
- Email and SMS providers — to deliver the messages described above.
- Analytics providers — to understand product usage. This is limited to how the product is used and does not include the contents of customer conversations.
We may also disclose information where the law requires it, or where it is necessary to protect our rights, our users, or the public. If Buyziz is ever involved in a merger or sale, information may transfer as part of that transaction, and this policy will continue to apply until it is replaced.
A store's data belongs to that store. Each store's business data is kept in its own database, separate from every other store on the platform. One merchant cannot see another merchant's customers or orders.
5. How we protect it
- Traffic is encrypted in transit.
- Passwords are stored as one-way hashes. Third-party credentials and access tokens are encrypted before they are stored, and are decrypted only at the moment they are used.
- Access inside the product is limited by role — a merchant decides what each member of their team can see and do.
- Each store's data is physically separated from every other store's.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your information we will tell you and the relevant authorities where the law requires it.
6. How long we keep it
We keep information for as long as an account is open and for as long afterwards as we need it to meet legal, tax and accounting obligations, resolve disputes and enforce our agreements. Order records are generally kept longer than conversation history, because they are financial records. When information is no longer needed it is deleted or anonymised.
7. Your choices and rights
You can ask us to:
- show you the personal information we hold about you;
- correct it if it is wrong;
- delete it;
- stop using it for a particular purpose.
Merchants can do much of this directly in their dashboard: edit their profile, disconnect a channel, remove a team member, or close their store.
If you are a customer of a store, the merchant decides what is collected about you, so please contact them first — they can delete your details from their store. You can also write to us at hello@buyziz.com and we will help, or pass the request on.
To delete data we hold from Facebook or Instagram, a merchant can disconnect the account in their dashboard, or email hello@buyziz.com asking us to delete the conversation history for a connected account. We will confirm when it is done.
8. Children
Buyziz is not intended for children, and we do not knowingly collect information from anyone under 13. If you believe a child has given us information, write to hello@buyziz.com and we will delete it.
9. Where your information is held
Buyziz runs on a global network, so information may be processed in countries other than your own. Wherever it is processed, it is protected as described in this policy.
10. Changes to this policy
We may update this policy as the product changes. The date at the top shows when it was last revised. If a change materially affects how we use your information, we will tell account holders directly rather than relying on this page alone.
11. Contact us
Questions, requests or complaints about privacy: hello@buyziz.com. We aim to reply within a few working days.