Soukbot

Privacy Policy

Last updated: 10 August 2026

This Privacy Policy explains how Soukbot ("we", "us") collects, uses, and protects information when you use the Soukbot marketplace, its WhatsApp messaging features, and its social publishing features for Facebook, Instagram, TikTok and YouTube.

1. Information we collect

  • Account & seller data: name, email, phone number, and business details you provide.
  • WhatsApp Business data: when a seller connects a WhatsApp Business Account, we process the WhatsApp Business Account ID, phone number ID, message templates, and the content and metadata of messages exchanged between sellers and their customers to deliver the messaging service.
  • Customer messages: messages customers send to a seller's WhatsApp number, including text and media, and delivery and read status.
  • Connected social account data: when you choose to connect a Facebook Page, Instagram account, TikTok account or YouTube channel, we store the identifiers and display names of that account (for example the Page ID, Instagram account ID, TikTok Open ID and display name, or YouTube channel ID and title) together with the access and refresh tokens that the platform issues to us, so that we can publish on your behalf without asking you to log in again.
  • Content you publish: the captions, images and videos you submit through Soukbot for publication, and the identifiers the platform returns for each published post or video.
  • Publication statistics: aggregate performance figures the platform reports for content published through Soukbot — for example views, likes, comments, shares, reach and impressions.
  • Technical data: log data needed to operate and secure the service.

2. How we use information

  • To send and receive WhatsApp messages between sellers and their customers (order updates, support, notifications, approved marketing templates).
  • To create and manage WhatsApp message templates on a seller's WhatsApp Business Account at the seller's request.
  • To publish the content you submit to the Facebook Pages, Instagram accounts, TikTok accounts and YouTube channels you have connected — only at your request, and only to the channels you select for that publication.
  • To show you which account is connected (we read basic profile information such as the account name for this purpose only) and to report how content published through Soukbot performed.
  • To provide marketplace functionality, billing, and customer support.
  • We do not sell personal data. We do not use the content of WhatsApp messages for advertising, and we do not use data obtained from social platform APIs for advertising or to build advertising profiles.

3. Facebook and Instagram

When you connect a Facebook Page or an Instagram professional account, Soukbot uses Meta's Graph API to publish the posts, Reels and Stories you submit, to read the statistics of that content, and — if you enable it — to read and reply to comments and messages on your behalf. We store the Page and Instagram account identifiers and the page access token.

You can disconnect at any time from Soukbot, or remove Soukbot's access directly in your Facebook settings under Business integrations.

4. TikTok

When you connect a TikTok account, Soukbot requests only the permissions it needs to operate the feature you asked for:

  • user.info.basic — to read your basic profile so we can show you which account is connected.
  • video.publish and video.upload — to post the videos you submit through Soukbot to your account, at your request.
  • video.list — to read the view, like, comment and share counts of videos published through Soukbot, so we can report their performance to you.

To publish a video, TikTok retrieves the video file from a Soukbot-controlled URL. We do not read your private videos, we do not post without an explicit request from you, and we do not use TikTok data for advertising or share it with third parties. You can revoke Soukbot's access at any time in the TikTok app under Settings and privacy → Security and permissions → Manage app permissions, and you may ask us to delete the stored connection — see our Data Deletion Instructions.

5. YouTube

Soukbot's YouTube publishing feature uses YouTube API Services. By connecting a YouTube channel to Soukbot you also agree to be bound by the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy.

With your authorisation we request only the scopes the feature needs:

  • youtube.upload — to upload the videos you submit through Soukbot to your channel, at your request.
  • youtube.readonly — to read your channel identifier and title so we can show you which channel is connected, and to read back the videos published through Soukbot.
  • yt-analytics.readonly — to read the performance statistics (such as views, watch time and audience retention) of videos published through Soukbot, so we can report them to you.

We store your channel identifier, channel title and the OAuth refresh token Google issues to us. We do not request write access to your channel beyond uploading the videos you submit, and we never delete or modify content we did not publish for you. The tokens are protected as described in section 7, "How we protect your data".

Limited use. Data obtained through YouTube API Services is used solely to provide and improve the publishing and reporting features you have requested. We do not transfer it to third parties except as needed to provide the service, we do not use it for advertising, and we do not allow humans to read it except with your consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.

You can revoke Soukbot's access to your YouTube data at any time through the Google security settings page at myaccount.google.com/permissions.

6. Third-party processors

To deliver the service we rely on:

  • Meta Platforms, Inc. — WhatsApp Business Platform / Cloud API, and the Graph API for Facebook Page and Instagram publishing.
  • TikTok (TikTok Pte. Ltd. / TikTok Inc., depending on your region) — Login Kit and the Content Posting API for TikTok publishing.
  • Google LLC — YouTube Data API for YouTube publishing.
  • Twilio Inc. — messaging connectivity for certain WhatsApp numbers.
  • Amazon Web Services, Inc. — cloud infrastructure and storage of application data and media.

These providers process data only as needed to deliver the service on our behalf.

7. How we protect your data

We apply the following safeguards to all personal data we hold, and specifically to the sensitive data described in this policy — WhatsApp message content, and the OAuth access and refresh tokens for connected Facebook, Instagram, TikTok and YouTube accounts:

  • Encryption in transit. All traffic between you and Soukbot, and every call we make to the WhatsApp Business Platform, the Meta Graph API, the TikTok API and Google and YouTube API Services, is transmitted over HTTPS using TLS. We do not transmit credentials or user data over unencrypted connections.
  • Encryption at rest. Application data and uploaded media are stored on Amazon Web Services infrastructure with encryption at rest enabled, in access-controlled storage.
  • Access control and isolation. Soukbot enforces record-level access rules: each seller can access only their own connected accounts, tokens, conversations and content. Sellers cannot read another seller's data. Administrative access is restricted to a small number of authorised personnel who need it to operate and support the service, and is granted on a least-privilege basis.
  • Credential handling. OAuth access and refresh tokens are stored in access-restricted fields, are never displayed to other users, are never written to application logs, and are never shared with third parties. They are used solely to perform the actions you have requested on the account you connected.
  • Revocation and deletion. When you disconnect an account, or delete your Soukbot account, the stored tokens for that connection are deleted, which ends our ability to access the platform on your behalf. You may additionally revoke our access directly with the platform at any time.
  • Monitoring and logging. We keep operational logs to detect errors, abuse and unauthorised access. Logs are retained only as long as needed for security and troubleshooting and exclude credentials.
  • Secure development. Access to our production systems requires authentication, changes are reviewed before deployment, and we keep our platform and dependencies up to date with security fixes.
  • Incident response. We maintain procedures to investigate and contain suspected security incidents, and we will notify affected users and the relevant supervisory authorities where required by applicable law.
  • No AI/ML model training. We do not use data obtained from Google or YouTube API Services, from the Meta or TikTok APIs, or the content of WhatsApp messages, to develop, train, retrain or improve generalised artificial intelligence or machine-learning models.

No method of transmission or storage is completely secure, but we work to protect your data using the measures above and review them as the service evolves.

8. Data retention

We retain account and message data for as long as the account is active or as needed to provide the service and meet legal obligations. Access and refresh tokens for a connected Facebook, Instagram, TikTok or YouTube account are deleted as soon as you disconnect that account or delete your Soukbot account. You may request deletion at any time — see our Data Deletion Instructions.

9. Your rights

You may request access to, correction of, or deletion of your personal data, and you may withdraw consent for WhatsApp messaging at any time. You may disconnect any social account from Soukbot at any time, and you may additionally revoke our access directly with the platform — Facebook (Business integrations), TikTok (Manage app permissions) or Google (myaccount.google.com/permissions).

10. Who is responsible for your data

Soukbot is operated by two affiliated companies, and which one is responsible for your personal data depends on where you are:

  • In Algeria — Soukbot is operated by Soukbot EURL, a company registered in Algeria. Soukbot EURL is the data controller for the personal data of users, sellers and customers in Algeria.
  • Outside Algeria — Soukbot is operated by Inkstand Inc., a corporation registered in Ontario, Canada, which is the data controller for the personal data of users outside Algeria and which owns and develops the Soukbot platform.

Both companies apply the protections described in section 7 and may share data between them only as needed to operate the service for you.

11. Contact

Soukbot EURL (Algeria)
Boulevard Mohamed Boudiaf, Blida 09000, Algeria
+213 982 301 857

Inkstand Inc. (Canada)
3162 Tilbury Lane, London, ON N6P 0C1, Canada
+1 519 697 0663

For any privacy request — access, correction, deletion, or a question about this policy — contact info@soukbot.com and we will route it to the responsible entity.