PistioAI E-Commerce AI Support LogoPistioAI
Back to Home
🔒Legal Document

Privacy Policy

Last updated: July 31, 2026 · Effective immediately upon publication

This Privacy Policy explains how Pistio AI (“we”, “us”, or “our”), operated by Dolsky Solution (Pistio Technologies), Bhopal, Madhya Pradesh, India, collects, uses, stores, and discloses your information when you access or use our platform at pistioai.com and app.pistioai.com.

1Information We Collect

We collect the following categories of information to provide and improve our services:

  • Account Information: Name, business name, email address, phone number, and password when you register for a Pistio AI merchant account.
  • Integration Credentials: API keys, access tokens, and configuration data for third-party integrations (e.g., Shopify, WhatsApp Business API, Meta). These are encrypted at rest using AES-256.
  • Customer Conversation Data: Messages, attachments, and metadata exchanged through connected channels (WhatsApp, Instagram, Email, etc.) on behalf of your customers. This data is processed to generate AI-driven responses.
  • Billing Information: Subscription plan, billing cycle, and payment references. Payment processing is handled directly by our payment partner; we do not store full card numbers.
  • Usage & Analytics Data: Log files, IP addresses, browser type, device identifiers, pages visited, and feature usage — collected automatically to monitor platform health and improve user experience.
  • WhatsApp Contact Registry: Phone numbers and opt-in/opt-out consent records for WhatsApp marketing communications, stored in compliance with Meta's Business Messaging Policy.

2How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Pistio AI platform and its features.
  • Process and deliver AI-generated responses to your customers across connected channels.
  • Authenticate users and manage merchant accounts securely.
  • Send transactional emails (e.g., account verification, password reset, billing receipts).
  • Enforce our Terms of Service and prevent fraud or abuse.
  • Analyse platform usage to identify bugs, improve features, and ensure uptime.
  • Comply with applicable Indian and international data protection laws.
No Selling of Data:We do not sell, rent, or trade your personal information or your customers' conversation data to third parties for marketing purposes.

3Legal Basis for Processing (GDPR / India IT Act)

We process your personal data under the following legal bases:

Contractual Necessity
Processing required to fulfil the service agreement between you and Pistio AI.
Legitimate Interest
Platform security, fraud prevention, and service improvement.
Consent
For optional communications and WhatsApp marketing messages (opt-in required).
Legal Obligation
Compliance with Indian Information Technology Act, 2000 and applicable rules.

4Data Sharing & Third-Party Processors

We share data only with trusted service providers under strict data processing agreements:

ProcessorPurposeData Shared
Meta Platforms (WhatsApp / Instagram)Message delivery via Meta Cloud APIPhone numbers, template messages
OpenAI / Google AIAI response generationAnonymized conversation context
PostgreSQL Cloud DatabaseData persistenceAll structured application data (encrypted)
Email / SMTP ProviderTransactional emailsRecipient email, message content
Shopify / E-commerce APIsOrder data retrieval for AI contextOrder IDs, customer names, status

5Data Retention

We retain your data for as long as your merchant account is active or as required to fulfil the purposes described in this policy. Specifically:

  • Account data: Retained for the duration of the subscription and deleted within 90 days of account closure upon written request.
  • Conversation logs: Retained for up to 12 months for service quality and AI training purposes, then purged.
  • Billing records: Retained for 7 years in compliance with Indian GST and tax regulations.
  • Server logs: Retained for up to 30 days for security monitoring.

6Data Security

We implement industry-standard security measures to protect your information:

🔐
AES-256 Encryption
All credentials and API keys encrypted at rest.
🔒
TLS 1.3 in Transit
All communications encrypted in transport.
🛡️
Role-Based Access
Staff access limited to permitted resources.
🔑
Bcrypt Passwords
Passwords hashed using bcrypt with salt.

7Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right to access the personal data we hold about you.
  • Right to correct inaccurate or incomplete information.
  • Right to request deletion of your data (subject to legal retention requirements).
  • Right to withdraw consent for optional processing at any time.
  • Right to data portability — request an export of your account data.
  • Right to lodge a complaint with the relevant data protection authority.

To exercise any of the above rights, email us at support@pistioai.com with subject line “Data Rights Request”. We will respond within 30 days.

8Meta & WhatsApp Platform Data & Data Deletion Instructions

In accordance with Meta Developer Platform Terms & Policies, we process Meta Platform Data (including WhatsApp Business Account tokens, registered template content, incoming customer chat payloads, and delivery report webhooks) strictly to provide messaging features for merchants.

No Unauthorized Data Transfer: We do not sell, rent, or transfer Meta Platform Data to third-party ad networks, data brokers, or information resellers.
Meta User Data Deletion Instructions: If you disconnect your Meta/WhatsApp integration or request account closure, all associated Meta access tokens, webhook subscription logs, and customer chat history will be permanently deleted from our servers within 30 days.
Manual Erasure Request: To request immediate deletion of your Meta Platform Data, please submit a request to support@pistioai.com with the subject line “Meta Data Deletion Request”, or use the Disconnect Integration & Purge Data option inside your account dashboard.

9Cookies & Local Storage Policy (GDPR & DPDP Compliant)

We use cookies and local storage tokens to ensure platform security, maintain authenticated sessions, and measure platform performance:

1. Strictly Necessary CookiesAlways Active

Essential for user login, session management, CSRF protection, and billing status verification. Cannot be disabled.

2. Analytics & Performance Cookies

Anonymized metric collection to diagnose load times, feature adoption, and improve platform uptime and reliability.

3. Marketing & Personalization Cookies

Used to deliver relevant product updates, onboarding tutorials, and personalized support assistance.

You can adjust or revoke your cookie choices at any time via the Cookie Consent Banner or by clearing your browser cookies and local storage.

10Children's Privacy

Pistio AI is a B2B platform intended solely for businesses and individuals aged 18 and above. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, contact us immediately at support@pistioai.com.

11Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and notify you by email or in-platform notification. Continued use of the platform after notification constitutes acceptance of the revised policy.

Contact Our Privacy Team

For any questions, requests, or concerns regarding this Privacy Policy or your personal data:

🏢Pistio Technologies Private Limited (Dolsky Solution), Bhopal, Madhya Pradesh — 462001, India