Privacy Policy
Effective date: July 30, 2026
EcomKaptaan ("EcomKaptaan", "we", "us", "our"), available at https://ecomkaptaan.com, is an AI-powered ecommerce operations platform that helps online merchants manage customer conversations, orders, shipping, returns, and business reporting. This policy explains what data we collect, how we use it, and the choices you have.
1. Information we collect
- Account information — your name, email address, and password (stored as a secure hash) when you create an EcomKaptaan account.
- Store and integration data — when you connect your store or business tools (for example WooCommerce, courier services, WhatsApp Business, or Gmail), we sync the data needed to operate the service: products, orders, customers, shipments, and the API credentials or OAuth tokens for those connections.
- Customer conversation data — messages your customers send to your store through connected channels (WhatsApp, email, website chat), which the platform stores and answers on your behalf.
- Technical data — basic logs (timestamps, request metadata) needed to run and secure the service.
2. How we use information
- To provide the service: answering customer messages, managing orders, booking shipments, handling returns, detecting fraudulent orders, and generating business reports.
- To operate AI features: conversation content and related order/product context are processed by our AI language-model providers solely to generate replies and insights for your store.
- To secure the service and prevent abuse.
We do not sell your data or your customers' data to anyone.
3. Google user data (Google Ads)
If you choose to connect your Google Ads account, EcomKaptaan uses Google's OAuth with the https://www.googleapis.com/auth/adwords scope.
- What we do: we use this permission exclusively to read campaign performance data from your own Google Ads account — campaign names, statuses, budgets, impressions, clicks, spend, conversions, and ROAS — for the last 7 and 30 days. This data is displayed inside your EcomKaptaan dashboard so you can see ad performance alongside your orders and revenue.
- What we do not do: we do not create, modify, pause, enable, or delete any campaigns, ad groups, ads, or budgets. All access is strictly read-only.
- Storage: your OAuth refresh token is stored securely on our servers, is used only to fetch the read-only metrics described above, and is deleted when you disconnect the integration.
- No advertising: Google Ads data is never used to target advertising, build profiles unrelated to the service, or transferred to third parties except as necessary to provide the dashboard feature itself or as required by law.
EcomKaptaan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Ads at any time from the Integrations page inside EcomKaptaan, or revoke access from your Google account at myaccount.google.com/permissions.
4. Google user data (Gmail)
If you choose to connect your Gmail account, EcomKaptaan uses Google's OAuth with the following scopes: openid, email (to identify the connected address), https://www.googleapis.com/auth/gmail.send, and https://www.googleapis.com/auth/gmail.readonly.
- What we do: we use the
gmail.sendpermission to send customer-service emails (replies to customer inquiries, order confirmations, return updates) from your own email address, either when you click send or when your configured AI assistant replies on your behalf. We use thegmail.readonlypermission solely to detect and capture a customer's reply to one of those emails, so it appears in the same support conversation as the rest of that customer's messages (alongside WhatsApp, website chat, etc.) instead of being invisible to the platform. - What we do not do: we do not browse your mailbox, read messages unrelated to customer-service conversations, or modify, label, or delete anything in your inbox. We do not request the broader
gmail.modifyscope — message deduplication is done internally by tracking which message IDs we've already processed, not by changing anything in your mailbox. - Storage: your OAuth tokens are stored securely on our servers, are used only for the sending and reply-capture described above, and are deleted when you disconnect the integration.
- No advertising: Google user data is never used for advertising, profiling unrelated to the service, or transferred to third parties except as necessary to provide the features described above or as required by law.
EcomKaptaan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Gmail at any time from the Integrations page inside EcomKaptaan, or revoke access from your Google account at myaccount.google.com/permissions.
5. Sharing with service providers
We use trusted infrastructure providers to run the service: cloud hosting (Amazon Web Services, Vercel), managed databases, AI language-model providers (for generating replies and reports), and the third-party services you explicitly connect (couriers, messaging platforms, ecommerce platforms). Each receives only the data necessary to perform its function.
6. Data retention and deletion
We retain your data while your account is active. You may disconnect any integration at any time, and you may request deletion of your account and associated data by emailing us at the address below; we will complete verified deletion requests within 30 days.
7. Security
Data is encrypted in transit (HTTPS/TLS). Credentials and tokens are stored server-side and are never exposed to the browser. Access to production systems is restricted.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date at the top of this page.
9. Contact
Questions or requests: support@ecomkaptaan.com