ကိုယ်ရေးအချက်အလက် မူဝါဒ
ZayFlow (zayflow.net, zayflow.app) က Facebook Messenger၊ Telegram နဲ့ TikTok ကနေ ရောင်းတဲ့ ဆိုင်တွေအတွက် အော်ဒါစီမံခန့်ခွဲမှု ဝန်ဆောင်မှုပါ။ ZayFlow ကို JP Mandalar Global LLC က ဆောင်ရွက်ပါတယ်။ ဒီစာမျက်နှာက ကျွန်တော်တို့ ဘာအချက်အလက် သိမ်းလဲ၊ ဘာကြောင့် သိမ်းလဲ၊ ဘယ်သူ မြင်ရလဲ၊ ဘယ်လို ဖျက်လို့ရလဲ ဆိုတာ ရှင်းပြထားပါတယ်။
၁။ ဘာအချက်အလက်တွေ သိမ်းလဲ
- အကောင့် — email၊ အမည်၊ ဖုန်းနံပါတ် (ထည့်ရင်)၊ password ကို hash လုပ်ထားတာ (မူရင်း password ကို ဘယ်တော့မှ မသိမ်းပါ)။ Google နဲ့ ဝင်ရင် Google က ပေးတဲ့ အကောင့် ID နဲ့ email။
- ဆိုင်အချက်အလက် — ပစ္စည်း၊ ဈေး၊ လက်ကျန်၊ အော်ဒါ၊ ပို့ဆောင်ရေး၊ COD ငွေစာရင်း၊ ဆိုင်ဆက်တင် (ပို့ခ၊ ငွေလွှဲ account)။
- Facebook Page — ဆိုင်ရှင် ချိတ်ပေးတဲ့ Page ရဲ့ ID၊ အမည်နဲ့ access token။ Token ကို encrypt လုပ်ပြီး သိမ်းပါတယ်၊ browser ဆီ ဘယ်တော့မှ မပို့ပါ။
- Messenger စာများ — ချိတ်ထားတဲ့ Page ဆီ ဝယ်သူပို့တဲ့ စာသား၊ ဝယ်သူရဲ့ Messenger ID၊ ဆိုင်က ပြန်တဲ့ စာ၊ ဝယ်သူရဲ့ ပြသနာမည်နဲ့ ပရိုဖိုင်ပုံ link။
- Telegram — ဆိုင်ရှင် ထည့်တဲ့ Bot token (encrypt လုပ်ပြီး သိမ်း)၊ Bot ဆီ (သို့) Telegram Business နဲ့ ချိတ်ထားရင် ဆိုင်ရှင်အကောင့်ဆီ ဝယ်သူပို့တဲ့ စာသား၊ ဝယ်သူရဲ့ Telegram chat ID နဲ့ ပြသနာမည်။ ဆိုင်ရှင် Telegram အကောင့် ID ကိုလည်း ချိတ်ဆက်မှု အတည်ပြုဖို့ သိမ်းပါတယ်။
- TikTok — ဆိုင်ရှင် ခွင့်ပြုတဲ့ TikTok Business အကောင့်ရဲ့ ID၊ username နဲ့ access/refresh token (encrypt လုပ်ပြီး သိမ်း)၊ ဝယ်သူ ပို့တဲ့ DM စာသား၊ ဝယ်သူရဲ့ TikTok username နဲ့ conversation ID။ ပုံ/ဗီဒီယိုတွေကို မဒေါင်းပါ။
- ဝယ်သူ အချက်အလက် — အော်ဒါအတွက် ဆိုင်က ထည့်တဲ့ အမည်၊ ဖုန်း၊ လိပ်စာ။
- လုံခြုံရေး မှတ်တမ်း — ဝင်ရောက်မှု အောင်/မအောင်၊ IP လိပ်စာ၊ browser အမျိုးအစား — အကောင့်ကို ကာကွယ်ဖို့အတွက်ပါ။
၂။ ဘာကြောင့် သိမ်းလဲ
ဆိုင်က ဝယ်သူစာကို ဖတ်၊ ပြန်ဖြေ၊ အော်ဒါဖွင့်၊ လက်ကျန်ထိန်း၊ ပို့ဆောင်မှုနဲ့ COD ငွေကို စီမံနိုင်ဖို့ — ဒါပဲပါ။ ကြော်ငြာအတွက် မသုံးပါ၊ AI model လေ့ကျင့်ဖို့ မသုံးပါ၊ တတိယပါတီကို မရောင်းပါ။
၃။ AI အသုံးပြုမှု
ZayFlow ရဲ့ AI ကို Google ရဲ့ Gemini API (အခပေး ဝန်ဆောင်မှု) နဲ့ လုပ်ပါတယ်။ AI ဆီ ပို့တာ နှစ်မျိုးပဲ ရှိပါတယ် — (၁) ဆိုင်ဝန်ထမ်းက "AI" ခလုတ် နှိပ်တဲ့အခါ သက်ဆိုင်ရာ conversation၊ ပစ္စည်းစာရင်း၊ ဆိုင်ဆက်တင်နဲ့ အဲ့ဝယ်သူရဲ့ အော်ဒါ၊ (၂) ဆိုင်က "AI အော်ဒါမူကြမ်း" ကို ဖွင့်ထားရင် ဝယ်သူက ဖုန်းနံပါတ်ပါတဲ့ စာ ပို့တဲ့အခါ အဲ့ conversation နဲ့ ပစ္စည်းစာရင်း။ Google က အခပေး API ကနေ ရတဲ့ စာတွေကို သူ့ product တိုးတက်ဖို့ မသုံးပါ၊ အလွဲသုံးမှု စောင့်ကြည့်ဖို့ ကာလတိုသာ သိမ်းနိုင်ပါတယ်။ AI က ကိုယ်တိုင် စာမပို့၊ အော်ဒါကို မူကြမ်းအဖြစ်ပဲ ထားပြီး လက်ကျန် မနှုတ်ပါ — အတည်ပြုတာ၊ ပို့တာကို လူကပဲ လုပ်ပါတယ်။ AI ဝန်ဆောင်မှုပေးသူကို ပြောင်းရင် ဒီစာမျက်နှာမှာ ပြင်ရေးပါမယ်။
၄။ ဘယ်သူ မြင်ရလဲ
ဆိုင်တစ်ဆိုင်ရဲ့ အချက်အလက်ကို အဲ့ဆိုင်ရဲ့ ပိုင်ရှင်နဲ့ ပိုင်ရှင်က ထည့်ထားတဲ့ ဝန်ထမ်းတွေသာ မြင်ရပါတယ်။ ZayFlow ရဲ့ နည်းပညာအဖွဲ့က ပြဿနာ ဖြေရှင်းဖို့ လိုအပ်မှသာ ဝင်ကြည့်ပါတယ်။
၅။ ဘယ်မှာ သိမ်းလဲ
Cloudflare ရဲ့ ကမ္ဘာလုံးဆိုင်ရာ ကွန်ရက်ပေါ်မှာ (Workers နဲ့ D1 database) သိမ်းပါတယ်။ ဆက်သွယ်မှုအားလုံး HTTPS နဲ့ encrypt လုပ်ထားပါတယ်။
၆။ Facebook/Meta နဲ့ ဆက်စပ်မှု
Page ချိတ်တဲ့အခါ Facebook Login ကို သုံးပါတယ်၊ Facebook password ကို ZayFlow မှာ ဘယ်တော့မှ မရိုက်ရပါ။ ZayFlow က Page ရဲ့ Messenger စာတွေကို Meta ရဲ့ Platform Terms နဲ့အညီ လက်ခံ/ပြန်ပို့ပါတယ်။ ဆိုင်ရှင်က "ဖြုတ်ရန်" နှိပ်ရင် Page token ကို ချက်ချင်း ဖျက်ပြီး Meta ဆီ စာမပို့တော့ဖို့ အကြောင်းကြားပါတယ်။
၆ (က)။ Telegram နဲ့ TikTok
Telegram မှာ ဆိုင်ရှင်က @BotFather နဲ့ ကိုယ်ပိုင် Bot လုပ်ပြီး token ထည့်ပါတယ်။ TikTok မှာ TikTok ရဲ့ ခွင့်ပြုစာမျက်နှာကနေ ဝင်ပြီး ခွင့်ပြုပါတယ် — TikTok password ကို ZayFlow မှာ မရိုက်ရပါ။ ZayFlow က ဝယ်သူ စာပို့ပြီးမှသာ ပြန်ဖြေပါတယ်၊ ဝယ်သူကို အရင်ဦးဆုံး စာမပို့ပါ၊ အစုလိုက် ကြော်ငြာစာ မပို့ပါ။ "ဖြုတ်ရန်" နှိပ်ရင် token တွေကို ချက်ချင်း ဖျက်ပါတယ်။
၇။ အချက်အလက် ဖျက်ခြင်း
- Page / Bot / TikTok ဖြုတ်ခြင်း — ချန်နယ်များ → ဖြုတ်ရန်။ Token ချက်ချင်း ပျက်ပါတယ်။
- အကောင့်နဲ့ ဆိုင်ဒေတာ အကုန် ဖျက်ခြင်း — ဆိုင်ပိုင်ရှင်က hello@zayflow.app ကို အကောင့် email ကနေ စာပို့ပါ။ ၇ ရက်အတွင်း ဆိုင်၊ အော်ဒါ၊ စာ၊ ဝယ်သူ အချက်အလက် အားလုံးကို ဖျက်ပြီး အတည်ပြုစာ ပြန်ပို့ပါမယ်။
- Facebook ကနေ ဖြုတ်ခြင်း — Facebook Settings → Business Integrations မှာ ZayFlow ကို ဖယ်ရှားလို့လည်း ရပါတယ်။ အဲ့အခါ ZayFlow က အဲ့ Page ဆီ ဝင်ခွင့် ချက်ချင်း ဆုံးရှုံးပါတယ်။
၈။ ပြောင်းလဲမှုများ
ဒီမူဝါဒ ပြောင်းရင် ဒီစာမျက်နှာမှာ ရက်စွဲနဲ့ အပ်ဒိတ်လုပ်ပြီး၊ အရေးကြီးတဲ့ ပြောင်းလဲမှုဆိုရင် ဆိုင်ပိုင်ရှင်တွေကို email နဲ့ အကြောင်းကြားပါမယ်။
Privacy Policy (English summary)
ZayFlow (zayflow.net, zayflow.app) is an order-management service for shops that sell through Facebook Messenger, Telegram and TikTok, operated by JP Mandalar Global LLC (“we”). We store account details (email, name, optional phone, a password hash or a Google account id), shop data (products, orders, deliveries, COD records, settings), the Facebook Page id, name and an encrypted Page access token for Pages the shop owner connects, messages sent to those Pages together with the sender's Messenger id, display name and profile picture URL, for Telegram the shop's bot token (encrypted), messages customers send to that bot or, if the owner connects it through Telegram Business, to the owner's account, with the customer's chat id and display name, for TikTok the encrypted access and refresh tokens of the Business Account the owner authorises and the direct messages it receives with the customer's username and conversation id, customer details entered for orders, and security logs (sign-in attempts, IP address, browser).
We use this data only to provide the service to the shop. We do not sell it, use it for advertising, or use it to train AI models. AI features run on Google's paid Gemini API. Data goes to it in two cases only: when a staff member presses an AI button (the conversation, the catalog, shop settings and that customer's orders), and, if the shop has turned on AI draft orders, when a customer sends a message containing a phone number (that conversation and the catalog). Google does not use paid API data to improve its products and may keep it briefly for abuse monitoring. The AI never sends messages; orders it prepares stay drafts that take no stock until a person confirms them. If we change AI provider, this page will say so.
Only the shop's owner and the staff the owner adds can see the shop's data. Data is stored on Cloudflare's network (Workers and D1) and transmitted over HTTPS. Page access is obtained through Facebook Login; disconnecting a Page deletes its token immediately and unsubscribes it from webhooks. Removing ZayFlow under Facebook Settings → Business Integrations has the same effect. We only reply to customers who wrote first and never send bulk or promotional messages. Disconnecting a Telegram bot or TikTok account deletes its tokens immediately.
Data deletion: a shop owner can request deletion of all account and shop data by emailing hello@zayflow.app from the account's email address; we delete everything within 7 days and confirm by email.