سياسة الخصوصيّة
كيف يجمع Smart Ecom بيانات صفحات فيسبوك المربوطة ويستخدمها ويحميها.
مَن نحن
Smart Ecom (smartecomdz.com) خدمة تساعد أصحاب المتاجر على إدارة تعليقات ورسائل صفحات فيسبوك آليًّا: ردّ ذكيّ باللهجة، إشراف على التعليقات، والتقاط طلبات الدفع عند الاستلام (COD). لا نعمل إلا على الصفحات التي يربطها صاحبها بنفسه ويمنحنا صلاحيّة إدارتها.
البيانات التي نصل إليها
- معلومات الصفحة العامّة (الاسم، المُعرّف، صورة الصفحة) بعد أن يربطها صاحبها.
- التعليقات العامّة على منشورات الصفحة (نصّها، كاتبها العامّ، وقتها) لإدارتها والردّ عليها.
- الرسائل الواردة إلى صندوق الصفحة، لتوليد ردّ ومساعدة صاحب المتجر.
- بيانات الطلب التي يكتبها العميل طوعًا في المحادثة (الاسم، الهاتف، العنوان) لإتمام الطلب.
لا نطلب ولا نخزّن كلمات مرور المستخدمين النهائيّين، ولا بيانات بطاقات بنكيّة.
كيف نستخدمها
- توليد ردود آليّة على التعليقات والرسائل نيابةً عن صاحب المتجر.
- إخفاء التعليقات المسيئة أو المزعجة حسب إعدادات صاحب المتجر.
- تنظيم الطلبات في لوحة تحكّم صاحب المتجر (وجدول Google Sheet إن ربطه).
لا نبيع بياناتك ولا نشاركها لأغراض إعلانيّة لأطراف ثالثة.
بيانات منصّة Meta والصلاحيّات المستخدمة
نتكامل مع منصّة Meta عبر واجهة Facebook Graph API و Messenger Platform، ونطلب فقط صلاحيّات الصفحة اللازمة لوظيفة الخدمة:
- public_profile — لتسجيل دخول صاحب المتجر عبر Facebook Login for Business والتعرّف على حسابه أثناء ربط الصفحة.
- pages_show_list — لعرض قائمة الصفحات التي يديرها صاحب المتجر كي يختار الصفحة التي يريد ربطها بالخدمة.
- business_management — للوصول إلى الصفحات المملوكة داخل حافظة أعمال (Business portfolio)، ولاكتشاف منشورات الصفحة الإعلانية التي يعلّق عليها العملاء كي لا تفوتنا تعليقاتهم.
- pages_manage_metadata — لاشتراك الصفحة في تنبيهات Meta الفوريّة (
feedوmessages) حتى يصل تعليق العميل أو رسالته لحظةَ وصولها بدل انتظار فحص دوريّ. - pages_read_engagement — لقراءة منشورات الصفحة والتعليقات العامّة عليها كي نعرضها لصاحب المتجر ونولّد ردودًا مناسبة للسياق.
- pages_read_user_content — لقراءة نصّ تعليق العميل نفسه (كاتبه ووقته) حتى يمكن تصنيفه والردّ عليه أو إخفاؤه.
- pages_manage_engagement — لنشر ردود صاحب المتجر على تعليقات العملاء، ولإخفاء التعليقات المسيئة أو المزعجة حسب إعداداته.
- pages_messaging — لاستقبال رسائل العملاء الواردة إلى صندوق الصفحة وإرسال الردود الآليّة ضمن سياسة المراسلة لدى Meta.
- instagram_business_basic — لربط حساب إنستغرام احترافي مباشرةً وعرض هويته ومحتواه الأساسي لصاحب المتجر.
- instagram_business_manage_messages — لاستقبال رسائل العملاء المرسلة إلى حساب إنستغرام الاحترافي وعرضها والردّ عليها ضمن سياسة Meta.
- instagram_business_manage_comments — لقراءة تعليقات منشورات وريلز إنستغرام والردّ عليها أو إخفائها حسب إعدادات صاحب المتجر.
نستخدم هذه البيانات حصرًا لتشغيل الميزات أعلاه على الصفحة المربوطة، لا لأيّ غرض آخر، ولا نطلب أيّ صلاحيّة لا تظهر وظيفتها في الخدمة.
المشاركة مع أطراف ثالثة
نعتمد على مزوّدين تقنيّين لتشغيل الخدمة فقط: منصّة Meta (مصدر التعليقات والرسائل)، استضافة قاعدة البيانات والخوادم، ومزوّد نماذج الذكاء الاصطناعيّ لتوليد الردود. يعالج كلٌّ منهم البيانات نيابةً عنّا وفق اتفاقيّات معالجة، لا لأغراضهم الخاصّة.
ملفّات تعريف الارتباط والتحليلات
نستخدم ملفّات تعريف ارتباط ضروريّة فقط لتشغيل الخدمة — لا للإعلانات ولا للبيع:
- كوكيز الجلسة والمصادقة لإبقائك مسجَّلاً بأمان في لوحة التحكّم.
active_tenantلتذكّر المتجر المُختار عند إدارتك أكثر من متجر.se-localeلتذكّر لغة الواجهة.
نستعين بـ Vercel Analytics لقياس أداء الصفحات بشكل مُجمَّع ومجهول، دون ملفّات تتبُّع إعلانيّة ودون بيع لأيّ بيانات.
مكان معالجة البيانات
تُعالَج بياناتك وتُخزَّن على بنية Supabase التحتيّة داخل الاتحاد الأوروبيّ (منطقة أوروبا)، إضافةً إلى مزوّدي الاستضافة ونماذج الذكاء الاصطناعيّ الذين يعالجون البيانات نيابةً عنّا فقط.
المُعالِجون من الباطن
هؤلاء وحدهم يعالجون بياناتك نيابةً عنّا، ولكلٍّ منهم غرض واحد معلَن:
- Supabase Inc. — قاعدة البيانات والمصادقة (منطقة الاتحاد الأوروبيّ): تخزين الحساب والتعليقات والرسائل وتوكن الصفحة.
- Vercel Inc. — استضافة لوحة التحكّم؛ تمرّ البيانات عبرها أثناء عرضها على صاحب المتجر.
- Contabo GmbH (ألمانيا) — الخادم الذي يستقبل إشعارات فيسبوك ويُرسل الردود عبر Meta Graph API.
- Google LLC — Gemini API: يُرسَل نصّ تعليق الزبون أو رسالته لتوليد ردّ صاحب المتجر ولتصنيف التعليق (استفسار / شكوى / إساءة) حتى يقرّر النظام الردّ أو الإخفاء. وتُرسَل كذلك صورة إيصال الدفع (BaridiMob/CCP) الذي يرفعه صاحب المتجر لقراءة المبلغ والمرجع. لا يُستعمل شيء من ذلك للإعلانات ولا لبناء ملفّات شخصيّة، ولا نبيع أيّ بيانات.
- Google LLC — Sheets & Drive: إذا ربط صاحب المتجر جدول Google، نكتب فيه بيانات الطلب كاملةً — اسم الزبون ورقم هاتفه وولايته وبلديته وعنوانه والمنتج والكميّة والمبلغ. الجدول ملك صاحب المتجر ويبقى تحت حسابه، ونكتب فيه نيابةً عنه فقط.
- Telegram Messenger LLP — تنبيهات تشغيليّة لفريقنا (أعطال، حدود استهلاك، تسجيل متجر جديد). يصلها عنوان التنبيه واسم المتجر؛ لا يصلها اسم زبون المتجر ولا هاتفه ولا عنوانه ولا نصّ محادثته.
الاحتفاظ والحذف
نحتفظ بالبيانات ما دامت الصفحة مربوطة والخدمة عاملة. يمكن لصاحب المتجر فصل الصفحة في أيّ وقت من لوحة التحكّم (الإعدادات ← الاتصال) فنحذف فورًا كلّ البيانات المخزّنة المرتبطة بها، كما يمكنه حذف حسابه بالكامل من (الإعدادات ← بياناتي).
لطلب حذف بياناتك:
- راسِلنا على yoravia.smilix@gmail.com بعنوان «Data Deletion Request» مع اسم الصفحة أو رابط التعليق/المحادثة، أو
- أزِل تطبيقنا من إعدادات فيسبوك (Settings & Privacy → Settings → Business Integrations) فتصلنا إشارة الحذف وتُنفَّذ آليًّا، أو
- إن كنت صاحب المتجر، افصل الصفحة أو احذف حسابك مباشرةً من لوحة التحكّم.
ننفّذ الحذف خلال 30 يومًا كحدّ أقصى. راجع صفحة حذف البيانات لمتابعة حالة طلبك.
التواصل
لأيّ سؤال حول الخصوصيّة: yoravia.smilix@gmail.com.
Privacy Policy
How Smart Ecom collects, uses, and protects data from connected Facebook Pages and Instagram professional accounts.
Who we are
Smart Ecom (smartecomdz.com) helps merchants manage their Facebook Page and Instagram comments and messages automatically: AI replies in local dialect, comment moderation, and cash-on-delivery (COD) order capture. We act only on Pages that the Page owner explicitly connects and grants us permission to manage.
Data we access
- Public Page information (name, ID, picture) after the owner connects the Page.
- Public comments on the Page's posts (text, public author, timestamp) to moderate and reply.
- Messages sent to the Page inbox, to generate replies and assist the merchant.
- Order details a customer voluntarily provides in chat (name, phone, address) to complete the order.
We never request or store end-user passwords or any payment-card data.
How we use it
- Generate automated replies to comments and messages on behalf of the merchant.
- Hide abusive or spam comments according to the merchant's settings.
- Organize orders in the merchant's dashboard (and a linked Google Sheet, if enabled).
We do not sell your data or share it for third-party advertising.
Meta Platform data and permissions used
We integrate with the Meta Platform through Facebook Login for Business and Instagram Login, and request only the permissions required for the visible service features:
- public_profile — to sign the merchant in through Facebook Login for Business and identify their account while they connect a Page.
- pages_show_list — to list the Pages the merchant manages so they can choose which one to connect to the service.
- business_management — to reach Pages held inside a Business portfolio, and to discover the Page's ad posts that customers comment on so those comments are not missed.
- pages_manage_metadata — to subscribe the Page to Meta's realtime webhooks (
feedandmessages) so a customer's comment or message reaches the merchant as it arrives, instead of waiting for a periodic poll. - pages_read_engagement — to read the Page's posts and their public comments so we can display them to the merchant and generate context-aware replies.
- pages_read_user_content — to read the content of the customer's own comment (its text, author and time) so it can be classified and then replied to or hidden.
- pages_manage_engagement — to publish the merchant's replies to customer comments and to hide abusive or spam comments per the merchant's settings.
- pages_messaging — to receive customer messages sent to the Page inbox and send automated replies within Meta's messaging policy.
- instagram_business_basic — to connect an Instagram professional account directly and show its basic identity and media to the merchant.
- instagram_business_manage_messages — to receive and display customer messages sent to the connected Instagram professional account and reply within Meta's policy.
- instagram_business_manage_comments — to read, reply to, and hide comments on the connected Instagram account's posts and Reels according to the merchant's settings.
We use this data solely to operate the features above on the connected Page — for no other purpose — and we do not request any permission whose function is not visible in the service.
Third-party sharing
We rely on technical providers solely to operate the service: Meta (source of comments and messages), database and server hosting, and an AI model provider to generate replies. Each processes data on our behalf under data-processing terms, not for their own purposes.
Cookies & analytics
We use only cookies that are necessary to run the service — never for advertising or resale:
- Session & authentication cookies to keep you securely signed in to the dashboard.
active_tenantto remember the selected store when you manage more than one.se-localeto remember the interface language.
We use Vercel Analytics to measure page performance in aggregate and anonymously — no advertising trackers and no data resale.
Data residency
Your data is processed and stored on Supabase infrastructure within the European Union (EU region), alongside hosting and AI-model providers that process data solely on our behalf.
Sub-processors
These are the only providers that process your data on our behalf, each for one stated purpose:
- Supabase Inc. — database and authentication (EU region): stores the account, comments, messages and the Page access token.
- Vercel Inc. — hosting for the dashboard; data passes through it in transit while a merchant views it.
- Contabo GmbH (Germany) — the server that receives Facebook webhooks and sends replies through the Meta Graph API.
- Google LLC — Gemini API: the text of a customer's comment or message is sent to generate the merchant's reply and to classify the comment (enquiry / complaint / abuse) so the system can decide whether to reply or hide it. A payment-receipt image (BaridiMob/CCP) uploaded by the merchant is also sent, to read its amount and reference. None of it is used for advertising or profiling, and no data is sold.
- Google LLC — Sheets & Drive: if the merchant links a Google Sheet, we write the full order into it — the customer's name, phone, wilaya, commune and address, plus product, quantity and amount. The spreadsheet belongs to the merchant and stays in their own Google account; we only write to it on their behalf.
- Telegram Messenger LLP — operational alerts to our team (failures, usage limits, a new store signing up). It receives the alert title and the store name; no end-customer name, phone, address or message text.
Retention and deletion
We retain data while the Page is connected and the service is active. A merchant can disconnect a Page at any time from the dashboard (Settings → Connection), after which we immediately delete the stored data associated with it, and can also delete their entire account from (Settings → My data).
To request deletion of your data:
- Email yoravia.smilix@gmail.com with the subject "Data Deletion Request" and the Page name or a link to your comment/conversation, or
- Remove our app from your Facebook settings (Settings & Privacy → Settings → Business Integrations) — we receive the signal and process it automatically, or
- If you are the merchant, disconnect the Page or delete your account directly from the dashboard.
We complete deletion within 30 days. See the Data Deletion page to track your request.
Contact
For any privacy question: yoravia.smilix@gmail.com.