1. Who we are and when this policy applies
Zeeri Labs, Dharan, Nepal operates DokaanDM (“we,” “us,” or “our”). This policy covers our website, web and mobile applications, connected Meta integrations, and communications with support.
We determine how information about our own users, website visitors, and support contacts is used to operate DokaanDM. A shop using DokaanDM decides how to use its customers’ messages and order records. For that information, we provide the service on the shop’s behalf and follow its authorized instructions, subject to applicable law. Where applicable, these roles are called a data controller and a data processor.
If you are a shop’s customer, its own privacy notice also applies. We can help route a request about your information to the shop responsible for it.
- Operator
- Zeeri Labs
- Contact address
- Dharan, Nepal
- Privacy and support
- [email protected]
2. Information we collect and where it comes from
- Account and business details: your name, business name, email address, optional phone number, subscription plan, account status, and login records. We store a password hash rather than your readable DokaanDM password.
- Connected account information: Facebook Page and Instagram professional-account identifiers, names or usernames, connection status, permissions, and access tokens needed for the integration.
- Messages and conversations: message text, participant identifiers, timestamps, conversation status, and attachment links or metadata supplied through the connected platform. These come from Meta when an authorized shop connects its accounts, and from replies sent through DokaanDM.
- Customers and orders: names, phone numbers, social-account identifiers or handles, delivery addresses, customer notes and tags, products, quantities, prices, payment type or reference, order status, returns, and follow-up reminders. Shops and their staff enter this information or create it while handling conversations.
- Team and activity information: staff names and emails, invitations, roles and permissions, assignments, and records of account and workspace actions, including who sent a reply.
- Technical and support information: IP addresses, browser or device information, request and error logs, security events, and the content and contact details you provide when asking for help.
DokaanDM records payment type and references for a shop’s orders; it does not process those customer payments or ask for payment-card credentials. Please do not put passwords, card details, government identification, or other unnecessary sensitive information in messages, notes, or support requests.
3. How and why we use information
We use information to create and secure accounts; connect authorized channels; receive and send messages; organize customers, products, orders, and reminders; apply team permissions and plan limits; calculate workspace reports; provide support; detect misuse; troubleshoot errors; and meet legal obligations.
Where applicable law requires a legal basis, we rely on providing the service under our agreement with you, legitimate interests in running and securing the service balanced against your rights, legal obligations, and consent where it is required. You can withdraw consent for a use that relies on consent, without affecting earlier lawful processing. A shop is responsible for its legal basis, notices, and any required customer consent for the information it puts into DokaanDM. Authorizing a Meta connection does not replace those responsibilities.
We do not sell personal information. We do not use private messages for targeted advertising or to train AI models. Customer histories are not shared between unrelated shops.
4. Facebook and Instagram integrations
Connections are authorized through Meta’s own login and permission screens. We do not receive your Facebook or Instagram password. We use the account information, credentials, and message data that Meta makes available under the permissions you grant to provide the connected inbox and related workspace features.
When you send a reply, its content and the identifiers needed to deliver it are sent to Meta and the intended recipient. Access depends on your permissions, account settings, and Meta’s API rules. Meta handles information independently under its Privacy Policy.
You can disconnect a channel in DokaanDM and revoke our access in Meta’s Business Integrations settings. Disconnecting stops use of the channel within DokaanDM but does not erase previously stored records. To request their removal, follow our data-deletion instructions.
5. Customer matching and cash-on-delivery risk
Within a single shop’s workspace, DokaanDM can match customer records across channels using a phone number supplied to that shop. This helps the shop see its own conversations and order history together.
Cash-on-delivery (COD) risk labels are calculated with fixed rules using that shop’s delivered and returned order counts and return rate. The calculation does not use machine learning or other shops’ customer histories. Labels are a decision aid: DokaanDM does not automatically refuse an order, and the shop remains responsible for its decision. You can ask the shop to correct inaccurate records or review a decision based on a label.
7. Cookies and local storage
The web app uses an authentication cookie to maintain your signed-in session. Browser storage remembers preferences such as your theme, accent color, and selected business workspace. The landing site stores its theme preference. These are used for the service and interface, rather than advertising profiles.
The current landing site does not use advertising pixels or third-party analytics trackers. Its demo and COD calculator run in your browser; their input values are not submitted to our server. Hosting and font requests can still generate technical logs.
You can clear cookies and browser storage through your browser settings. Blocking authentication cookies may prevent sign-in, and clearing preferences resets them. External services, including Meta, apply their own cookie policies.
8. How long we keep information
We retain information for as long as needed for its purpose. Account and workspace records generally remain while the account or workspace is in use, unless a verified deletion request or another requirement calls for earlier removal. Disconnecting a channel, archiving an item, or disabling a staff member does not by itself delete historical records.
Retention decisions take account of the service requested, the shop’s instructions, whether the information is still needed, security and dispute needs, and legal recordkeeping obligations. Support and security records are kept only for as long as needed for those purposes. Expired session records are eligible for automatic cleanup; temporary webhook-processing records are configured to become eligible for cleanup after seven days. That temporary cleanup does not erase saved inbox messages.
After an approved deletion request, records covered by the request are deleted or anonymized unless a lawful exception applies. If backup copies exist, removal may follow their applicable rotation schedule; any retained copies remain subject to access restrictions. We will explain relevant exceptions or backup-related timing when responding to your request. See data deletion for the process.
9. Security and international processing
Our safeguards include password hashing, encryption of stored integration tokens, access controls, separation of business workspaces, and verification of incoming Meta notifications. No system can guarantee absolute security. Protect your login credentials, review your team’s access, and contact us if you suspect unauthorized use.
Zeeri Labs is based in Nepal. Depending on the hosting location and services involved, information may be processed outside Nepal or your country of residence, where privacy laws may differ. Where applicable law requires protections for an international transfer, we use the required safeguards. Contact us for information about the providers, processing locations, or safeguards relevant to your data.
10. Your rights and choices
Depending on the law that applies to you, you may have rights to access or receive a copy of your information, correct inaccurate information, request deletion, restrict processing, object to processing based on legitimate interests, withdraw consent, or request data portability. These rights may have legal limits. You may also raise a complaint with the competent privacy authority where applicable.
You can object to processing based on legitimate interests by emailing us. You do not need to close your account simply to ask a privacy question. To make a request, email [email protected]. We may verify your identity or authority using information proportionate to the request.
If the information belongs to a shop’s customer records, contact that shop first. You can also contact us with the shop name and enough detail to identify the record; we will help route and handle the request with the responsible shop. Staff requests are assessed separately from a request to delete an entire business workspace.
11. Children’s information
DokaanDM’s account service is intended for adult business users, not children. Customer messages may include information about younger people that a shop handles under its own responsibilities. If you believe a child has provided information inappropriately, contact the shop or us so the situation can be reviewed and appropriate action taken.
12. Changes to this policy and contact
We may update this policy when the service or our practices change. The date at the top identifies the latest version. For material changes, we will provide additional notice when required; if a new use requires consent, we will obtain it before that use.
For questions, concerns, or privacy requests, contact Zeeri Labs, Dharan, Nepal at [email protected].