Legal

Privacy Policy

Last updated: July 2026

1. What we collect

  • Account data: email, name, avatar, plan status.
  • Store data: store name, slug, catalog, orders, wallet balances, broadcasts.
  • Bot tokens: encrypted at rest with pgcrypto; never returned to the client.
  • Customer data (your tenants): Telegram user ID, username, first/last name, orders, and wallet activity, collected on your behalf.
  • Operational data: IP address, user agent, and request logs for security and abuse prevention.

2. How we use it

To operate the service, authenticate you, run your Telegram bot, process manual payments, send transactional emails, prevent abuse, and improve the product.

3. Sharing

We share data only with sub-processors required to run the service (Supabase for hosting/DB, Cloudflare for edge compute, Stripe when you enable card checkout, Resend for email). We do not sell personal data.

4. Data controller / processor

For merchant accounts, Telemerce is the controller. For your customers’ data collected through your Telegram bot, you are the controller and Telemerce is the processor acting on your instructions.

5. Retention

We retain account and store data while your account is active. Deleted stores are purged within 30 days. Logs are retained up to 90 days for security purposes.

6. Your rights

You can access, export, correct, or delete your data by writing to privacy@telemerce.site. Depending on your jurisdiction (GDPR, CCPA), you may have additional rights including objection and portability.

7. Security

Row-Level Security isolates tenants. Bot tokens are encrypted. Passwords are hashed by Supabase Auth. All traffic is served over HTTPS.

8. Children

Telemerce is not directed to children under 13 (or 16 in the EEA/UK).

9. Contact

privacy@telemerce.site