Sigma Solutions (“us”, “we”, or “our”) owns and operates SmartComm, a Software-as-a-Service (SaaS) platform (the “Service”). Your privacy is important to us. Sigma Solutions is committed to respecting your privacy while you use SmartComm.
This Privacy Policy defines the requirements to ensure compliance with applicable data privacy laws and regulations governing Sigma Solutions’ collection, use, and transmission of Personal Data in connection with SmartComm.
We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Definitions
- Service: Service means SmartComm, the SaaS platform.
- Personal Data: Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
- Usage Data: Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Cookies: Usage Cookies are small files stored on your device (computer or mobile device).
- Data Controller: Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed. For the purpose of this Privacy Policy, Sigma Solutions is the Data Controller of Personal Data relating to its own account holders. Where Personal Data relates to a merchant’s own customers and is obtained through a store the merchant has connected to the Service, the merchant is the Data Controller and Sigma Solutions acts solely as a Data Processor, processing that data on the merchant’s documented instructions.
- Data Processors (or Service Providers): Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to operate the Service.
- Data Subject (or User): Data Subject is any living individual who is using our Service and is the subject of Personal Data.
Types of Data Collected
Personal Data
While using the Service, we may ask you to provide certain personally identifiable information that can be used to contact or identify you (“Personal Data”), including but not limited to: Email address, First name, Last name, Phone number. We may use the Personal Data of our own account holders to contact them with newsletters, marketing, or promotional materials, and other information that may be of interest to them. They may opt out at any time by following the instructions provided in any communication. This does not apply to Personal Data relating to a merchant’s own customers obtained through a connected store, which is never used for marketing, advertising, or promotional purposes.
Usage Data
We may also collect information that your browser sends whenever you access or use the Service, including date and time of visit, pages visited, time spent on pages, device identifiers, and other diagnostic data. When you access the Service via a mobile device, this Usage Data may include device type, unique device ID, IP address, mobile operating system, browser type, and other diagnostic information.
Use of Data
- To provide and maintain the Service
- To notify you about changes to the Service
- To allow you to participate in interactive features of the Service when you choose to do so
- To provide customer support
- To analyze and improve the Service
- To monitor the usage of the Service
- To detect, prevent, and resolve technical issues
- To provide information about other related services offered by Sigma Solutions, unless you opt out
Retention of Data
Sigma Solutions will retain Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements. Usage Data is retained for shorter periods unless required for security, functionality improvements, or legal compliance.
Disclosure of Data
- Business Transactions: Personal Data may be transferred in connection with a merger, acquisition, or asset sale.
- Law Enforcement: Data may be disclosed when required by law or valid government request.
- Legal Requirements: Data may be disclosed to comply with legal obligations, protect rights, prevent misuse, ensure safety, or address liability.
Security of Data
We use commercially acceptable measures to protect Personal Data, but no transmission or storage method is completely secure.
Changes in Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page and may be notified via email or within the Service.
Data Deletion Policy
Users may request partial or complete deletion of their Personal Data when legally permissible by sending an email to mohammad.mostafizur@sigmasolutions.com.bd. Once the request is evaluated and approved, we will delete the data of the user. We will take all necessary actions to perform the complete or partial deletion of the data when requested within two months (60 calendar days). Once the deletion is complete, we will send the concerned user a confirmation through email. We always work to complete the request of deletion in advance of the deadline.
Meta Platform Integrations
SmartComm allows users to optionally connect their Facebook Pages, Instagram Professional Accounts, and WhatsApp Business Accounts to the Service in order to manage messaging, comments, and customer communication within the CRM. Connection to Meta services is entirely optional and requires explicit authorization via Meta’s secure login and OAuth flow. No Meta data is accessed until a user grants this permission.
Types of Meta Data Accessed
- Public profile information, including name, profile picture, and account/Page ID
- Messages sent and received via Facebook Messenger, Instagram Direct, and WhatsApp Business
- Comments and replies on connected Facebook Pages and Instagram accounts
- Publicly available information associated with a customer's comment or message, such as the post ID, post title, post content, and related metadata
- Conversation metadata such as timestamps, attachments, and delivery/read status
- Webhook events related to messages, comments, and delivery statuses
Purpose of Meta Data Usage
- Display messages, comments, and conversations within the user’s CRM inbox
- Allow users to reply to messages, mentions, and comments from within SmartComm
- Associate messaging data with customer profiles in the CRM
User Consent and Opt-Out
Users must explicitly authorize the connection of their Meta accounts to SmartComm. Users may revoke access at any time. Once access is revoked, access tokens are deleted and SmartComm stops processing any data related to the disconnected Meta account. Access can be revoked via the SmartComm interface, through Meta, or by contacting us at mohammad.mostafizur@sigmasolutions.com.bd. Revoking access will stop future syncing of Meta data; any previously stored Meta data will be retained or deleted in accordance with SmartComm’s Data Deletion Policy.
Retention and Deletion of Meta Data
Meta-derived data is retained only as long as necessary for the purposes described above. Users may request deletion of their Meta platform data at any time by contacting mohammad.mostafizur@sigmasolutions.com.bd. Deletion requests will be processed in accordance with the existing Data Deletion Policy, typically within 60 calendar days, and a confirmation will be sent once deletion is complete.
Data Sharing and Prohibited Uses
SmartComm does not sell, rent, license, transfer, or otherwise share Meta platform data with any third parties. Meta platform data is used solely within SmartComm for CRM functionality and is not used for profiling outside of CRM purposes, advertising, discriminatory purposes, or surveillance.
Compliance with Meta Policies
SmartComm operates in accordance with Meta Platform Terms, Developer Policies, and applicable data protection regulations. By connecting a Meta account, users acknowledge that Meta may process their data in accordance with its own policies.
Store Integrations
SmartComm allows users to optionally connect their online store, including Shopify, to the Service in order to manage orders, delivery, and inventory within the platform. Connection is entirely optional and requires explicit authorisation through the store platform’s secure OAuth flow. No store data is accessed until a merchant grants this permission.
Roles of the Parties
For data relating to a merchant’s own customers, the merchant is the Data Controller and Sigma Solutions acts solely as a Data Processor, processing that data on the merchant’s documented instructions. This section prevails over any contrary statement elsewhere in this Privacy Policy in respect of such data.
Types of Store Data Accessed
- Store information, including shop name, currency, and inventory locations
- Products, product variants, and inventory quantities
- Orders, including line items, totals, financial status, and fulfilment status
- Customer name, email address, phone number, and delivery address associated with an order
- Order history retained for the merchant’s records
Purpose of Store Data Usage
- Display a merchant’s store orders inside SmartComm’s order manager
- Enable the merchant’s agents to contact the buyer to confirm a cash-on-delivery order before dispatch
- Submit the delivery details required to complete a shipment to the courier the merchant has chosen, such as Pathao or Steadfast
- Reflect the store’s inventory counts and product details inside SmartComm so that the merchant’s staff work from current information
- Return the outcome of an order to the merchant’s store, including fulfilment, tracking, payment, cancellation, and return records, so that the merchant’s own records stay current
- Keep inventory counts consistent between SmartComm and the merchant’s store
Store data is never used for marketing, advertising, profiling outside these purposes, automated decision-making, or surveillance.
User Consent and Opt-Out
Merchants must explicitly authorise the connection. Access may be withdrawn at any time by uninstalling the application from the store’s admin, or by contacting mohammad.mostafizur@sigmasolutions.com.bd. On withdrawal, stored access credentials are deleted and SmartComm stops processing data from the disconnected store.
Retention and Deletion of Store Data
Store data is retained only for as long as necessary for the purposes described above, and in accordance with the Data Deletion Policy set out in this Privacy Policy. A request may also reach us through a connected store on a buyer’s behalf, and is handled under the same process. Requests received through a connected store platform, whether for access or for erasure, are actioned within 30 calendar days, which is shorter than the general period set out above.
Data Sharing and Prohibited Uses
Sigma Solutions does not sell, rent, license, transfer, or otherwise share store data with any third parties. It is disclosed only to the courier the merchant has selected, and only the delivery details that courier requires in order to complete the shipment.
Security of Store Data
Each merchant’s data is held in a separate database on a separate deployment. All traffic is carried over TLS, and store access credentials are encrypted at rest.
Compliance with Store Platform Policies
SmartComm operates in accordance with the Shopify API Terms of Service, the Shopify Partner Program Agreement, and Shopify’s requirements for protected customer data.