Privacy Policy – Buylive.app:

1. Introduction

Welcome to Buylive.app, a software-as-a-service (SaaS) platform empowering sellers to create customized checkout pages for live shopping events. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our platform, in full compliance with the General Data Protection Regulation (GDPR) and other relevant privacy laws.

BuyLive does not host or broadcast live streams itself. Sellers stream on their own social platforms (such as Facebook, Instagram or TikTok); with the seller's authorization, BuyLive reads the comments on the seller's own live videos to capture orders and can send a commenter a private reply containing the seller's checkout link. Sections 13–15 describe the data involved for our mobile app, browser extension, and Meta platform integration.

2. Data Controller

Buylive.app is operated by Buylive OÜ, registered in Estonia. We are the data controller responsible for your personal data.

If you have questions about your data, you can contact us at:

Email: support @ buylive.fr
Postal Address: Buylive OÜ
Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia

3. What Data We Collect

We collect the following personal information:

From Sellers:
> Name, email address, and business information
> Billing information (for subscription payments)
> Store settings, products, and checkout page content

From Shoppers:
> Name, email address, and shipping/billing details
> Order and checkout information
> Payment method (processed securely via third-party gateways)
> Purchase history and preferences (if opted in)

We do not process or store sensitive data such as biometric, health, or government identification numbers.

4. How We Use Your Data

We use your data to:
> Provide and maintain our services
> Enable customized checkout page creation and sharing
> Process and fulfill orders
> Communicate updates, support, and notifications
> Ensure compliance with applicable laws and tax regulations
> Improve our platform experience and performance

5. Legal Basis for Processing

We process your data based on:
> Contractual necessity (to provide services)
> Legitimate interest (e.g., platform security, analytics)
> Consent (e.g., for marketing, cookies)
> Legal obligation (e.g., VAT compliance)

You may withdraw your consent at any time by contacting us.

6. Data Sharing & Third-Party Services

We only share personal data when necessary, and only with:
> Payment processors (e.g., Stripe, PayPal, Klarna – all PSD2/SCA compliant)
> Fulfillment & logistics providers (as instructed by the seller)
> Email/notification platforms (to send order updates)
> Analytics services (aggregated, non-identifiable)

We never sell or rent your personal data.

7. International Data Transfers

If your data is transferred outside the EU (e.g., to the U.S.), we ensure compliance via:
> Standard Contractual Clauses (SCCs)
> Data Processing Agreements with our vendors
> Additional security measures

8. Data Retention

We retain data only as long as needed to fulfill the purposes outlined above, including:
> Customer data for tax and legal purposes (up to 7 years)
> Marketing data until you unsubscribe
> Support interactions for quality assurance (max 12 months)

9. Your Rights Under GDPR

As an EU/EEA user, you have the right to:
> Access your data
> Correct inaccuracies
> Delete your data (“right to be forgotten”)
> Restrict or object to processing
> Request data portability

To exercise these rights, contact support @ buylive.fr

10. Cookies & Tracking

We use minimal cookies for:
> Session management
> Analytics (Google Analytics, etc.)
> Consent management (via GDPR-compliant banners)

You can manage cookies via your browser or opt-out using our cookie settings tool.

11. Children’s Privacy

Our platform is not intended for children under 16. We do not knowingly collect personal data from minors.

12. Updates to This Policy

We may update this Privacy Policy as necessary. You will be notified of significant changes via email or platform notification.

13. BuyLive Mobile App

This section applies specifically to the BuyLive mobile application for iOS and Android, which lets customers follow their orders and lets sellers manage customer conversations and send notifications.

Data the app collects:
> Your email address — used to authenticate you (one-time codes for customers, password sign-in for sellers) and to link your device to your orders.
> A device identifier (push token) — used solely to deliver push notifications when a seller updates an order, replies to your message, or sends a broadcast.
> Messages you send and receive in the in-app chat — stored to deliver them and display conversation history; visible only to you and the other party on the order.
> Photos you attach to a message — stored only as long as the conversation is active.

The app does NOT collect: location, contacts, financial information, browsing history, health data, or any advertising identifier. The app contains no analytics or tracking SDKs and shows no ads. Your data is never used for advertising and never sold.

Sharing: to deliver push notifications, the notification content and the push token are transmitted to Apple Push Notification service (iOS), Firebase Cloud Messaging (Android) and the Expo Push Service. These providers act as processors under our instructions.

Retention: account information is kept while your account is active; messages and attachments while the order is active and for up to 12 months after; push tokens until the device is unregistered or the token expires.

Deleting your app account and data: follow the steps on our Data Deletion Instructions page, or email help@buylive.app from the address you signed up with. Deletion is completed within 30 days.

14. BuyLive Companion Browser Extension

This section applies specifically to the BuyLive Companion browser extension for Chrome, Edge and Brave. It helps a BuyLive seller connect a signed-in TikTok “assistant” account to their own BuyLive account so BuyLive’s in-chat auto-reply can post from that assistant, shows a read-only status panel, and prints order labels to a local thermal printer.

Data the extension accesses:
> TikTok session cookies of the assistant account you choose (e.g. sessionid, ttwid, msToken). These authenticate the assistant so BuyLive can post in-chat replies on your live. They are read from your browser and sent only to your own BuyLive backend.
> Your BuyLive backend address, the optional assistant @handle label, and thermal-printer preferences (baud rate, QR/barcode toggles) — stored locally in the browser so your settings are remembered.

How the data is used:
> The assistant session is transmitted only to your own BuyLive backend (the same server your BuyLive workspace already uses) to arm and maintain in-chat auto-reply. Because TikTok rotates its tokens, the extension re-sends the session automatically when it changes so replies keep working.
> The status panel only reads information back from your own BuyLive backend.
> Label printing happens locally over Web Serial; label content is sent directly to your USB/serial printer and to no server.

The extension does NOT:
> Sell or rent your data, show ads, or contain any advertising identifier.
> Include analytics or third-party tracking SDKs.
> Send your TikTok session or any data to us or to any third party other than your own BuyLive backend.
> Read cookies for, or inject code into, websites unrelated to this workflow.

Where data is kept: the raw session cookie header stays in the extension’s background service-worker memory and is transmitted to your backend; the popup only ever displays masked values. Only the small, non-sensitive settings listed above are stored via the browser’s local extension storage.

Permissions and why:
> cookies — read the assistant account’s TikTok session cookies.
> host access to tiktok.com — read those cookies; host access to your BuyLive domain — send the session and read status.
> tabs & scripting — find your open BuyLive tab and deliver the request through it.
> alarms — refresh the session so it doesn’t go stale.
> storage — remember your settings.
> notifications — alert you if the assistant account logs out of TikTok.
An optional “all sites” permission is off by default and is requested one specific origin at a time, only if you run BuyLive on a custom domain, with your explicit approval.

Retention & control: the assistant session is used only to keep your auto-reply link live. You can click Unlink in the extension at any time to stop it being refreshed, sign the assistant account out of TikTok to invalidate the session, or remove the extension to delete its locally stored settings. Any session data held by your BuyLive backend is governed by the rest of this Privacy Policy.

Limited Use: BuyLive Companion’s use and transfer of information received from the browser adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used solely to provide the features described above and is never sold or used for advertising.

Contact: help@buylive.app

15. Facebook & Instagram (Meta) Platform Data

This section applies when a seller connects their own Facebook Page or Instagram professional account to BuyLive through Facebook Login, to capture orders during their own live videos.

Data we access from Meta:
> The list of Facebook Pages you manage, the Page name and ID, and a Page access token issued by Meta.
> The linked Instagram professional account (ID and username), where applicable.
> The status and metadata of live videos on your own Page or Instagram account.
> Comments posted on your own live videos — the commenter’s display name, their app-scoped identifier, the comment text and its timestamp.

How we use it: solely to provide the service to the seller who connected the account — detect buying-intent comments in real time during the seller’s live, turn them into order tickets and printable labels, and, when the seller enables it, send the commenter one private reply containing the seller’s checkout link. Meta Platform Data is never used for advertising or profiling, never combined with other data sources for other purposes, and never sold or rented.

Roles: for viewer comment data, the seller is the data controller and BuyLive acts as their processor. Our use of Meta Platform Data complies with the Meta Platform Terms and Developer Policies.

Storage & security: Page access tokens are stored encrypted at rest on our EU-hosted servers; comment data is isolated per seller workspace. Tokens are never exposed in logs or to the browser.

Sharing: Meta Platform Data is not shared with any third party. It is processed only on our own infrastructure to deliver the features above.

Retention: connection data and tokens are kept until you disconnect the Page or Instagram account in BuyLive (Integrations), remove the BuyLive app in your Facebook settings, or revoke the permissions — whichever comes first. Captured comment data follows the retention rules in section 8.

Deletion: removing the BuyLive app from your Facebook or Instagram account automatically triggers our registered Meta data-deletion callback, which erases the associated data and returns a confirmation code. You can also follow our Data Deletion Instructions or email help@buylive.app; deletion is completed within 30 days.

2026 © BuyLive - All Rights Reserved Trademark 019232190 - Privacy Policy | Contact | Terms of Services