Privacy Policy
Last Updated: July 4, 2026 • Oryxa is a product of RR Computer
At Oryxa, we are committed to protecting your privacy. This Privacy Policy explains how Oryxa (referred to as "we," "us," or "our"), a specialized product of RR Computer, collects, uses, processes, and protects your information when you use our multi-tenant SaaS platform, websites, and integrations.
1. Information We Collect
To provide our AI auto-reply and sales agent features, we collect information from both merchants and end-customers:
- Merchant Account Data: Registration and authentication information, including name, email address, password hashes (managed securely via Firebase Auth), and billing details.
- Social Platform Access Tokens: When you connect a social platform (e.g., Facebook Messenger, Instagram, WhatsApp), we securely store the Page Access Tokens required to read messages and post replies.
- Conversation Logs: We store communication transcripts, including user messages, AI agent responses, product inquiries, cart statuses, and order details, to process auto-replies and show performance analytics.
2. How We Use and Process Data
We use the collected information for the following business operations:
- Providing the LangGraph & Gemini AI-driven automated chat sales services.
- Creating and managing product carts, checking stock availability, and creating merchant orders directly from conversation streams.
- Displaying performance metrics, response speed analytics, and message counts in the merchant dashboard.
- Ensuring security, debugging system issues, and preventing fraudulent usage.
3. Data Sharing and Third-Party API Integrations
We do not sell merchant or customer data. To deliver Oryxa's core functionality, data is processed through the following secure third-party systems:
- Meta APIs (Facebook & Instagram): We fetch messages and dispatch AI replies via the Meta Graph Send API.
- Google Gemini API: Message payloads are processed through Gemini LLM services to generate smart customer responses.
- Firebase Admin SDK: Used for secure auth session verification.
- Cloud Storage (Backblaze B2): To securely cache and serve product catalog and variant images.
4. Data Deletion and Deactivation
Merchants retain full control over their integrations. When you disconnect a Facebook Page or delete a channel from Oryxa:
- We automatically call Meta APIs to unsubscribe our webhook from your Page events.
- Associated social access tokens and credentials are deleted or deactivated within our database.
- Merchants may request a complete hard delete of their business workspace, product lists, and historical conversation histories by contacting support.
5. Contact Support
If you have questions about this policy, or if you need to request data deletion under GDPR/CCPA regulations, you can follow our Data Deletion Instructions or contact us at:
RR Computer - Software Division
Email: alamsarwar@hotmail.com
Address:
51, Mirpur Road
Room 517, Alpana Plaza, Level 5
Dhaka 1205
Bangladesh