Skip to content
DokaanDM
Privacy policy Data deletion
Sign in

Legal & privacy

Privacy policy

DokaanDM brings a shop’s messages, customers, and orders into one workspace. This policy explains what information we handle, why we use it, and how you can exercise your choices.

Effective and last updated: 9 October 2026

On this page

  1. 1. Who we are
  2. 2. Information we collect
  3. 3. How we use it
  4. 4. Facebook & Instagram
  5. 5. Customer matching & COD risk
  6. 6. Who can access it
  7. 7. Cookies & local storage
  8. 8. How long we keep it
  9. 9. Security & transfers
  10. 10. Your rights & choices
  11. 11. Children’s information
  12. 12. Changes & contact

1. Who we are and when this policy applies

Zeeri Labs, Dharan, Nepal operates DokaanDM (“we,” “us,” or “our”). This policy covers our website, web and mobile applications, connected Meta integrations, and communications with support.

We determine how information about our own users, website visitors, and support contacts is used to operate DokaanDM. A shop using DokaanDM decides how to use its customers’ messages and order records. For that information, we provide the service on the shop’s behalf and follow its authorized instructions, subject to applicable law. Where applicable, these roles are called a data controller and a data processor.

If you are a shop’s customer, its own privacy notice also applies. We can help route a request about your information to the shop responsible for it.

Operator
Zeeri Labs
Contact address
Dharan, Nepal
Privacy and support
[email protected]

2. Information we collect and where it comes from

  • Account and business details: your name, business name, email address, optional phone number, subscription plan, account status, and login records. We store a password hash rather than your readable DokaanDM password.
  • Connected account information: Facebook Page and Instagram professional-account identifiers, names or usernames, connection status, permissions, and access tokens needed for the integration.
  • Messages and conversations: message text, participant identifiers, timestamps, conversation status, and attachment links or metadata supplied through the connected platform. These come from Meta when an authorized shop connects its accounts, and from replies sent through DokaanDM.
  • Customers and orders: names, phone numbers, social-account identifiers or handles, delivery addresses, customer notes and tags, products, quantities, prices, payment type or reference, order status, returns, and follow-up reminders. Shops and their staff enter this information or create it while handling conversations.
  • Team and activity information: staff names and emails, invitations, roles and permissions, assignments, and records of account and workspace actions, including who sent a reply.
  • Technical and support information: IP addresses, browser or device information, request and error logs, security events, and the content and contact details you provide when asking for help.

DokaanDM records payment type and references for a shop’s orders; it does not process those customer payments or ask for payment-card credentials. Please do not put passwords, card details, government identification, or other unnecessary sensitive information in messages, notes, or support requests.

3. How and why we use information

We use information to create and secure accounts; connect authorized channels; receive and send messages; organize customers, products, orders, and reminders; apply team permissions and plan limits; calculate workspace reports; provide support; detect misuse; troubleshoot errors; and meet legal obligations.

Where applicable law requires a legal basis, we rely on providing the service under our agreement with you, legitimate interests in running and securing the service balanced against your rights, legal obligations, and consent where it is required. You can withdraw consent for a use that relies on consent, without affecting earlier lawful processing. A shop is responsible for its legal basis, notices, and any required customer consent for the information it puts into DokaanDM. Authorizing a Meta connection does not replace those responsibilities.

We do not sell personal information. We do not use private messages for targeted advertising or to train AI models. Customer histories are not shared between unrelated shops.

4. Facebook and Instagram integrations

Connections are authorized through Meta’s own login and permission screens. We do not receive your Facebook or Instagram password. We use the account information, credentials, and message data that Meta makes available under the permissions you grant to provide the connected inbox and related workspace features.

When you send a reply, its content and the identifiers needed to deliver it are sent to Meta and the intended recipient. Access depends on your permissions, account settings, and Meta’s API rules. Meta handles information independently under its Privacy Policy.

You can disconnect a channel in DokaanDM and revoke our access in Meta’s Business Integrations settings. Disconnecting stops use of the channel within DokaanDM but does not erase previously stored records. To request their removal, follow our data-deletion instructions.

5. Customer matching and cash-on-delivery risk

Within a single shop’s workspace, DokaanDM can match customer records across channels using a phone number supplied to that shop. This helps the shop see its own conversations and order history together.

Cash-on-delivery (COD) risk labels are calculated with fixed rules using that shop’s delivered and returned order counts and return rate. The calculation does not use machine learning or other shops’ customer histories. Labels are a decision aid: DokaanDM does not automatically refuse an order, and the shop remains responsible for its decision. You can ask the shop to correct inaccurate records or review a decision based on a label.

6. Who can access information

  • The relevant shop: its owner and authorized team members can access workspace information according to their permissions. Messages sent to the shop are available to the staff handling that workspace.
  • Service providers: hosting, database, security, communications, and support providers may process information as needed to supply their services to us, under appropriate restrictions.
  • Connected services: Meta and other services you choose to interact with receive information needed for that interaction. The marketing site and web app load fonts from Google, which receives the technical information needed to serve those requests.
  • Legal and safety recipients: we may disclose necessary information to comply with valid legal requirements, protect rights and safety, investigate abuse, or resolve a dispute.
  • A business successor: information may be transferred as part of a merger, acquisition, or transfer of the service, subject to applicable privacy protections and any required notice.

Information you send through an email app, Facebook, Instagram, or another external service is also subject to that service’s privacy practices.

7. Cookies and local storage

The web app uses an authentication cookie to maintain your signed-in session. Browser storage remembers preferences such as your theme, accent color, and selected business workspace. The landing site stores its theme preference. These are used for the service and interface, rather than advertising profiles.

The current landing site does not use advertising pixels or third-party analytics trackers. Its demo and COD calculator run in your browser; their input values are not submitted to our server. Hosting and font requests can still generate technical logs.

You can clear cookies and browser storage through your browser settings. Blocking authentication cookies may prevent sign-in, and clearing preferences resets them. External services, including Meta, apply their own cookie policies.

8. How long we keep information

We retain information for as long as needed for its purpose. Account and workspace records generally remain while the account or workspace is in use, unless a verified deletion request or another requirement calls for earlier removal. Disconnecting a channel, archiving an item, or disabling a staff member does not by itself delete historical records.

Retention decisions take account of the service requested, the shop’s instructions, whether the information is still needed, security and dispute needs, and legal recordkeeping obligations. Support and security records are kept only for as long as needed for those purposes. Expired session records are eligible for automatic cleanup; temporary webhook-processing records are configured to become eligible for cleanup after seven days. That temporary cleanup does not erase saved inbox messages.

After an approved deletion request, records covered by the request are deleted or anonymized unless a lawful exception applies. If backup copies exist, removal may follow their applicable rotation schedule; any retained copies remain subject to access restrictions. We will explain relevant exceptions or backup-related timing when responding to your request. See data deletion for the process.

9. Security and international processing

Our safeguards include password hashing, encryption of stored integration tokens, access controls, separation of business workspaces, and verification of incoming Meta notifications. No system can guarantee absolute security. Protect your login credentials, review your team’s access, and contact us if you suspect unauthorized use.

Zeeri Labs is based in Nepal. Depending on the hosting location and services involved, information may be processed outside Nepal or your country of residence, where privacy laws may differ. Where applicable law requires protections for an international transfer, we use the required safeguards. Contact us for information about the providers, processing locations, or safeguards relevant to your data.

10. Your rights and choices

Depending on the law that applies to you, you may have rights to access or receive a copy of your information, correct inaccurate information, request deletion, restrict processing, object to processing based on legitimate interests, withdraw consent, or request data portability. These rights may have legal limits. You may also raise a complaint with the competent privacy authority where applicable.

You can object to processing based on legitimate interests by emailing us. You do not need to close your account simply to ask a privacy question. To make a request, email [email protected]. We may verify your identity or authority using information proportionate to the request.

If the information belongs to a shop’s customer records, contact that shop first. You can also contact us with the shop name and enough detail to identify the record; we will help route and handle the request with the responsible shop. Staff requests are assessed separately from a request to delete an entire business workspace.

11. Children’s information

DokaanDM’s account service is intended for adult business users, not children. Customer messages may include information about younger people that a shop handles under its own responsibilities. If you believe a child has provided information inappropriately, contact the shop or us so the situation can be reviewed and appropriate action taken.

12. Changes to this policy and contact

We may update this policy when the service or our practices change. The date at the top identifies the latest version. For material changes, we will provide additional notice when required; if a new use requires consent, we will obtain it before that use.

For questions, concerns, or privacy requests, contact Zeeri Labs, Dharan, Nepal at [email protected].

Request data deletion
DokaanDM

Operated by Zeeri Labs · Dharan, Nepal
© 2026 DokaanDM. All rights reserved.

HomePrivacy policyData deletionContact support