Privacy policy
Last updated
Who we are
ecomprops is a multi-tenant commerce platform for Bangladesh sellers. This policy covers the marketing site (ecomprops.com), merchant accounts on the dashboard, and shopper data that merchants store in the product.
For shopper data inside a merchant's shop, the merchant is the controller. ecomprops acts as a processor on their behalf. For marketing leads and merchant account data, ecomprops is the controller.
Questions: privacy@ecomprops.com.
Data we collect
From merchants and prospects: account email, full name, password hash (never plaintext), membership and role in a shop, refresh-session metadata (hashed token, optional IP and user agent), and marketing lead fields from contact or demo forms (name, phone, optional email, business details, message, locale, and attribution).
From shoppers, as processor for a merchant: customer name, email, phone, notes, tags, marketing consent flags, delivery addresses, and order details including buyer contact, shipping address, notes, amounts, and status.
Operational records: append-only audit log entries (who did what to which record), short-lived Redis keys for rate limits and caches when Redis is enabled, and media files such as product images that merchants upload.
On this marketing site only: locale preference, first-touch attribution, and (if you choose) analytics consent. Cloudflare Turnstile tokens are checked for bot protection and are not kept in our database.
Why we use it
To create and secure merchant accounts, run shops (orders, customers, staff access, storefronts), reply to sales and support requests, prevent abuse, improve the marketing site when analytics is enabled and consented, and meet legal duties.
We do not sell personal data.
Legal basis in plain words
Contract: we need account and shop data to provide the service you sign up for.
Legitimate interests: security, fraud and abuse prevention, product reliability, and answering sales inquiries.
Consent: non-essential marketing analytics on this site, and any marketing flags a merchant records for their shoppers.
Legal obligation: where Bangladesh law requires us to keep or disclose records.
Data inventory
Merchant users (email, name, password hash): account auth in Postgres (Cloud SQL). Visible to the user and platform operators. Kept while the account is active. Passwords use argon2id.
Memberships and roles: authorisation for a shop. Tenant-scoped with row-level security. Visible to that shop's staff with the right permissions.
Refresh tokens: session refresh. Stored as hashes with optional IP and user agent. Expire or revoke (default about 30 days).
Customers and addresses: merchant CRM. Tenant-scoped with RLS. Staff with customer permissions can view; staff with privacy permission can export or anonymise.
Orders: buyer contact, shipping address, notes, money, status. Tenant-scoped with RLS. Staff with order permissions.
Audit log: actor, action, entity ids, metadata. Tenant-scoped, append-only. Staff with audit read permission.
Marketing leads: platform-global (not tenant RLS). Platform operators only. No public self-serve erase API yet; email privacy@ecomprops.com to request deletion.
Locale cookie (ecomprops_locale): language preference on the marketing host, about one year.
Attribution cookie (ecp_attr) and session last-touch: UTMs for register and lead forms, 90 days for the cookie, marketing host only.
Consent cookie (ecp_consent): analytics choice on the marketing host, about 180 days.
Media objects: product images and logos in object storage. Kept while the merchant keeps them.
Analytics events: only if analytics is configured and you accept cookies. Sent to Google Analytics and/or Plausible.
Third-party processors
Vercel hosts the marketing site, dashboard, and storefronts.
Google Cloud runs the API (Cloud Run) and primary database (Cloud SQL). Production also targets managed Redis (Memorystore) and object storage (Cloud Storage). Local and some setups may use a Redis URL compatible with Upstash when Redis is enabled.
Cloudflare Turnstile checks bots on lead forms and checkout.
Google Analytics and/or Plausible receive marketing-site analytics only after you accept non-essential cookies, and only when those services are configured.
Outbound email for leads and similar notices is sent through our configured mailer to an operations inbox when set. We do not sell your contact details to advertisers.
Where data lives
Primary application data is stored in managed Postgres in Google Cloud (asia-southeast1 / Singapore region in our hosting plan). Frontend apps are served from Vercel's edge network. Marketing cookies stay on the marketing origin and are not shared with shop subdomains.
Retention
Merchant account and shop data stay while the account or shop is active, unless we agree a shorter period or law requires longer.
Refresh tokens expire or are revoked. Customer records can be anonymised by merchant staff with privacy permission. Marketing leads are kept until removed after a valid request or our own cleanup. Analytics retention follows the analytics provider's settings.
Deletion and export
Merchants can ask us to close an account or delete marketing-lead details by emailing privacy@ecomprops.com. We will confirm identity and act within a reasonable time.
For shopper data inside a shop, ask the merchant first. Merchant staff with the privacy permission can export a customer package or anonymise that customer in the product.
There is no public self-serve portal for every data type yet; email remains the path for platform-level requests.
Contact for privacy questions
Email privacy@ecomprops.com. You can also use the contact options on this site.
Changes
We may update this policy as the product grows. The "Last updated" date at the top will change when we do. Material changes will be called out on this page.
