Privacy Policy
Draft for review, not yet in effect. The version currently in effect is here.
This policy explains what information Abanro collects, why, how it is used and shared, and the choices you have. It covers abanro.com, the Abanro app at app.abanro.com, Abanro Export and Abanro's social-commerce tools.
Who we are
Abanro provides software for businesses. Abanro Export helps exporters manage buyers, follow up on WhatsApp and email, present products with Product Sheets and prepare export documents. Abanro's earlier tools help merchants receive and respond to Instagram messages and comments and run checkout from conversations. Those tools are still part of Abanro and are covered here too.
For privacy questions, email privacy@abanro.com.
Your data and your buyers' data
Abanro is used by businesses ("you" or "merchants"). The buyers, contacts and customers you add to Abanro, and the messages you send them, are your business information. You decide what goes into your workspace and who you contact. We process that information on your behalf to provide the service.
You are responsible for having the right to contact the people in your workspace and for honouring their choices. Abanro helps by leaving out buyers whose WhatsApp or email permission is turned off.
Information we collect
Account and sign-in
- Your phone number, used to verify your identity with a one-time code. Codes are delivered by Twilio Verify or Google Firebase Authentication.
- Where offered, the email address or account identifier from signing in with email, Google or Apple.
- Session records and security information such as IP address, approximate country, device and browser details, and the results of bot checks (Google reCAPTCHA). We use these to keep accounts secure and prevent abuse of sign-in and signup.
Workspace and business profile
- Workspace name, business profile details you enter (company name, logo, address, phone, WhatsApp, email, website, tax ID), currency, time zone and language.
- Team members and their roles, where you invite others to a workspace.
Buyers and contacts you add
- Company name, contact person, country, email, mobile and WhatsApp numbers, website, address, tags and notes.
- Whether each buyer has WhatsApp or email marketing permission turned on or off.
- The buyer's export orders, invoices and other records linked to them.
Catalogue, Product Sheets and export documents
- Products, categories, photos, specifications, prices, packaging, certificates and other files you upload.
- Product Sheets, including their content, settings, share links, QR codes and optional PIN.
- Quotes, export orders, invoices, packing lists, purchase orders, goods receipts, vendors, stock locations and stock movements, and other export documents you attach to an order.
People who open a Product Sheet
A Product Sheet can be opened by anyone with its link. When it is opened we count the view and record when the sheet was last viewed, and show those figures to the sheet's owner. If a sheet is protected by a PIN, we briefly use the visitor's IP address to limit repeated wrong PIN attempts.
Messages you send through Abanro
WhatsApp and email campaigns are described in the Google and WhatsApp sections below.
Billing
If you pay for a plan, payments are processed by Stripe. Abanro receives payment status and subscription details from Stripe but does not receive or store full card numbers.
Support and Export SOS
When you contact us or request Export SOS, we keep the messages and the case details you share, such as order, shipment or document information, so we can help.
Usage information
- The Abanro app records how features are used (for example, which pages are opened and when) so we can operate, secure and improve the service. The app also uses Google Analytics.
- The abanro.com marketing site does not use analytics or advertising cookies.
Google and Gmail
Abanro Export lets you send email campaigns from your own Gmail or Google Workspace account. This section explains exactly what we access when you connect a Google account for sending.
What we request
| Permission (scope) | What it allows | Why we need it |
|---|---|---|
https://www.googleapis.com/auth/gmail.send | Send email as you. | To send the campaign emails and follow-ups you write, from your address. |
openid and email | Confirm which Google account you connected and its email address. | To show which mailbox is connected and send from the right address. |
Abanro does not request permission to read, search, label, modify or delete your Gmail messages, contacts, calendar or files. We cannot see your inbox, and we do not read the replies you receive.
How we use and store Google data
- We store the connected email address, the sender name you choose, the Google account identifier, the permissions you granted, and the access and refresh tokens Google issues. Tokens are encrypted before they are stored.
- When an email is sent, we store the recipient address, subject and body you wrote, the send time and status, and the message and thread identifiers Gmail returns. We use these to show campaign results and to send follow-ups in the same thread.
- We use Google data only to send the emails you schedule and to show you what was sent. We do not use it for advertising, we do not sell it, and we do not use it to train or improve AI models.
Sharing
We do not share Google user data with third parties, except with the infrastructure providers that host Abanro (listed below) to run the service, when needed for security, or when required by law.
Disconnecting and deletion
- Disconnect a mailbox in Abanro under Email → Gmail accounts → Disconnect. Abanro revokes its access with Google and deletes the stored tokens.
- You can also remove Abanro at any time from your Google Account, under Security → Your connections to third-party apps and services (myaccount.google.com/connections).
- To delete the record of the connected mailbox and the emails sent through it, email privacy@abanro.com. See Data deletion and your rights.
Abanro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
WhatsApp and Meta
Connecting a number
- WhatsApp Cloud API. When you connect a WhatsApp Business number, we store its identifiers (phone number ID, WhatsApp Business Account ID, display number and verified name), connection and quality status, and the access token you provide. The token is encrypted before it is stored and is never shown again.
- Linked phone (where available). Some workspaces can link the WhatsApp app on a phone by scanning a QR code, like WhatsApp Web. The session information needed to keep the device linked is held by our messaging gateway until you unlink it.
Templates, campaigns and messages
- Message templates you write are stored in Abanro and submitted to WhatsApp for approval. We store their content and the approval status and history WhatsApp returns.
- For each campaign we store who it went to (name and WhatsApp number), which step was sent, and the delivery status WhatsApp reports (sent, delivered, read or failed).
- When a buyer replies to your number, WhatsApp sends us the incoming message. We store it so we can show it to you and stop a sequence for buyers who reply.
- Message fees for the WhatsApp Cloud API are charged by Meta to your WhatsApp Business account.
Disconnecting and deletion
- Disconnect a number in Abanro under WhatsApp setup → Disconnect. Abanro deletes the stored access token and stops sending from that number.
- For a Cloud API number you can also remove Abanro's access in Meta Business Settings. For a linked phone, open WhatsApp on the phone → Settings → Linked devices and log out.
- Disconnecting doesn't delete messages on WhatsApp itself. To delete Abanro's copies of templates, campaign records and messages, see Data deletion and your rights.
Abanro helps merchants receive and respond to Instagram messages and comments for their connected business accounts using official Meta APIs. When you connect Instagram, Abanro receives an access token through Meta OAuth. Abanro never asks for your Instagram password.
Abanro may store Instagram message and comment webhook payloads, customer Instagram identifiers, conversation state, and connection metadata needed to operate inbox and checkout flows. This data lets merchants view conversations, automate replies, and fulfill orders initiated through Instagram DMs or comments.
Merchants can delete Abanro-stored Instagram data, disconnect Instagram, or request account/workspace deletion from the Chat data controls area. Deleting in Abanro does not delete messages on Instagram.
AI features
Some Abanro social-commerce features use AI, for example to understand customer messages or match product photos. When you use those features, the relevant content is processed by Microsoft Azure OpenAI Service. Abanro Export does not currently use AI to process your workspace data. We will update this policy before launching AI features in Abanro Export. Google user data is never used for AI.
How we use information
- To provide the service: run your workspace, send the messages you schedule, publish your Product Sheets and produce your documents.
- To keep accounts and the service secure, including verifying sign-ins and preventing spam, fraud and abuse.
- To provide support and Export SOS assistance you ask for.
- To bill for paid plans.
- To understand how the service is used and improve it.
- To meet legal obligations and enforce our Terms of Service.
We do not sell personal information.
Who we share it with
We share information only as needed to run Abanro, with:
- Infrastructure and service providers that host or support Abanro on our behalf, currently including Microsoft Azure (hosting, storage and Azure OpenAI Service), Google (Firebase Authentication, reCAPTCHA and Google Analytics), Twilio (verification codes) and Stripe (payments).
- The platforms you connect. Messages and templates go to Meta (WhatsApp, Instagram) and emails go through Google (Gmail) because you ask us to send them.
- People you choose to share with, such as buyers who open a Product Sheet link you sent, or team members in your workspace.
- Authorities where the law requires it, or where needed to protect the rights, property or safety of our users, the public or Abanro.
How long we keep it
We keep workspace data for as long as your workspace is active, so it is there when you need it. When you delete a record, disconnect an integration or ask us to delete your account, we remove the data from the active service. Some records may be kept longer where we must do so by law, to resolve disputes or to prevent fraud and abuse.
Security
Abanro uses encrypted connections (HTTPS), encrypts integration tokens such as Google, WhatsApp and Instagram tokens before storing them, keeps each workspace's data separate, and limits staff access to what is needed to run and support the service. No system is perfectly secure, so we cannot guarantee absolute security.
Your choices and rights
- Edit or delete many records yourself in the app, and disconnect Google, WhatsApp and Instagram at any time.
- Ask us for a copy of your data, to correct it or to delete your account by emailing privacy@abanro.com.
- If you are a buyer or contact of a business that uses Abanro, please contact that business first. If you contact us, we will pass your request to them.
- Depending on where you live, you may have additional rights under local law, including the right to complain to a data protection authority.
Step-by-step instructions are on Data deletion and your rights.
International processing
Abanro and its service providers may process information in countries other than the one where you or your buyers are located. Where we do, we take steps to protect it as this policy describes.
Children
Abanro is a service for businesses and is not intended for use by children.
Changes to this policy
We will update this policy when our service or practices change. If a change is significant, we will tell account holders before it takes effect, by email, in the app or on this page.
Contact
Questions or requests about privacy: privacy@abanro.com.