Boss BuddyAI

Privacy Policy

Effective date: 14 July 2026 · Last updated: 14 July 2026

Boss Buddy AI ("Boss Buddy", "we", "us") is a marketing tool for physical-store merchants in Hong Kong and Malaysia. This policy explains what data we collect, how we use it, and the choices you have — including how data from connected social accounts (Facebook, Instagram, Threads, TikTok) and connected WhatsApp Business accounts is handled.

Operator: JJ Marketing Enterprise (Malaysia, SSM Reg. No. 202003300443 / RA0064019-X), No 15, Amanria Residence, Jalan Amaria 2, Batu 14, Puchong, 47100 Puchong, Selangor, Malaysia. Contact: [email protected].

1. Who this policy covers

This policy applies to merchants who use the Boss Buddy dashboard, their staff users, and end-customers who interact with merchant share/reward pages. It also covers the social accounts a merchant chooses to connect.

2. Data we collect

CategoryWhatWhy
AccountBusiness name, login phone number, password (hashed), region, the referring account manager.Create and secure the merchant account.
Brand & contentPhotos you upload, captions, posters and content you generate.Produce marketing posters and captions you ask for.
Connected social accountsFor accounts you connect: the platform account ID (Facebook Page ID, Instagram Business account ID, Threads user ID), account name, and an access token issued by the platform.Publish the posts you choose to your own accounts, and read engagement metrics for those posts.
Connected TikTok accountFor a TikTok account you connect via TikTok's Login Kit: a TikTok user identifier (open ID), your display name and profile picture, and an access/refresh token issued by TikTok (scope user.info.basic). Plus the video file and caption you choose to publish (scopes video.upload, video.publish).Show you which TikTok account is connected, and publish the videos you create to your own TikTok account via the Content Posting API (Direct Post).
Published posts & insightsThe post IDs/permalinks we create on your behalf, and metrics (reach, impressions, likes, comments) for those posts.Show you how your published content performed.
Connected WhatsApp Business accountFor a WhatsApp number you connect via Meta's Embedded Signup: the WhatsApp Business Account (WABA) ID, phone number ID, display name and an access token. Plus messages to and from that number — your customers' WhatsApp phone numbers, message text and media, and delivery status.Provide a shared inbox, automated replies and customer messaging on your behalf through the WhatsApp Cloud API.
BillingSubscription plan, billing status. Card and bank payments are processed by Stripe and Billplz — we do not store card numbers.Run subscriptions and credits.
End-customer (light)For reward flows: a hashed phone and device signal, share/redeem events. No heavy account.Share attribution and reward redemption.
Operation (light ERP)For merchants using Boss Buddy for Operation: the operational records you enter — products, recipes and costs, inventory and stock movements, orders, deliveries and invoices, purchases and suppliers, production and quality records, returns, finance (receivables, payables, P&L), staff/HR records, and business documents you upload (e.g. company registration, certificates).To run the inventory, operations, finance, and reporting features you use.

3. How we use Meta Platform data (Facebook, Instagram, Threads, WhatsApp)

When you connect a Facebook Page, Instagram Business account or Threads account, you authorize Boss Buddy to act on your behalf only for the actions you trigger:

When you connect a WhatsApp Business account via Meta's Embedded Signup, you authorize Boss Buddy to send and receive WhatsApp messages on your behalf through the WhatsApp Cloud API:

We store the access token securely and use Platform data (including WhatsApp messages and phone numbers) solely for the above. We do not sell Platform data, do not use it for advertising to others, and do not share it except with the infrastructure providers listed below to operate the service. You can disconnect any account at any time, which stops all access.

4. How we use TikTok data (Login Kit & Content Posting API)

When you connect a TikTok account, you authorize Boss Buddy to act on your behalf only for the actions you trigger, using TikTok's Login Kit and Content Posting API:

We store the TikTok access token securely and use TikTok data solely for the above. We do not sell TikTok data, do not use it for advertising to others, and do not share it except with the infrastructure providers listed below to operate the service. Our use of TikTok data complies with the TikTok Developer Terms and their limited-use requirements. You can disconnect your TikTok account at any time, which revokes our access and stops all publishing.

5. Service providers we share with

ProviderPurpose
Meta Platforms (Facebook, Instagram, Threads; WhatsApp Cloud API)Publishing & insights for social accounts you connect; sending/receiving messages for the WhatsApp Business number you connect.
TikTok (TikTok for Developers — Login Kit & Content Posting API)Connecting your TikTok account and publishing the videos you create to your own TikTok account.
Stripe; BillplzPayment processing (subscriptions / FPX top-ups).
Cloudflare R2Image storage.
Vercel; NeonApp hosting and database.
Google (Gemini API)AI generation of captions/images from the content you provide.

These providers process data only to deliver the service and under their own terms.

6. Retention

We keep account and content data while your account is active. Social access tokens are kept until they expire or you disconnect. If you delete your account or request deletion, we remove your data as described in our Data Deletion page, except where we must keep limited records for legal or accounting reasons.

7. Your rights & deletion

You can access, correct, export, or delete your data. To disconnect a social account, use "解綁 / Disconnect" in the dashboard. To delete your account and associated data, follow the steps on our Data Deletion Instructions page or email us.

8. Security

Passwords are hashed; access tokens are stored server-side and transmitted over HTTPS. Access is restricted to operating the service.

9. Children

Boss Buddy is a business tool not directed to children. We do not knowingly collect data from anyone under 18.

10. Changes

We may update this policy; the effective date above reflects the latest version.

11. Contact

JJ Marketing Enterprise (Malaysia) · SSM 202003300443 (RA0064019-X) · [email protected] · No 15, Amanria Residence, Jalan Amaria 2, Batu 14, Puchong, 47100 Puchong, Selangor, Malaysia

隐私政策(中文摘要)

Boss Buddy AI 是面向香港与马来西亚实体商家的营销工具。我们收集:商家账号信息(店名、登录电话、加密密码)、你上传的照片与生成的内容、你主动绑定的社交账号(Facebook 专页 / Instagram 商业号 / Threads)的账号 ID、名称与平台授权令牌、以及我们代你发布的帖子及其互动数据。若你使用运营版 Operation,我们还会保存你录入的运营数据(产品/配方与成本、库存与进出、订单/配送/发票、采购与供货商、生产与质检、退货、财务应收应付与损益、员工/HR,以及你上传的营业注册/证书等文件),仅用于运营你所用的库存、经营与报表功能。

社交账号数据只用于你触发的操作:把你做的海报+文案发到你自己的账号、并把这些帖子的 reach/互动拉回你的看板。我们不出售、不用于对他人投放广告,除运营所需的基础设施服务商外不对外共享。你可随时在后台「解綁」停止一切访问。付款由 Stripe / Billplz 处理,我们不存卡号。删除账号与数据见 数据删除页。联系:[email protected]

若你通过 Meta 官方 Embedded Signup 绑定 WhatsApp 商业账号:我们会通过 WhatsApp Cloud API 代你收发消息 —— 收件箱接收顾客消息、发送你的回复(人工/关键字或 AI 自动回复/你主动发起的群发)。为此我们处理你的 WABA 与号码信息、顾客的 WhatsApp 号码、消息内容与送达状态,仅用于上述用途,不出售、不对他人投放广告。可随时在后台解除连接停止访问。

若你绑定 TikTok 账号(通过 TikTok Login Kit 与 Content Posting API):我们仅在你触发的操作范围内代你执行 —— 凭 user.info.basic 取得你的 TikTok 基本账号信息(open ID、显示名、头像),用于显示你绑定的是哪个账号;凭 video.upload / video.publish 把你创建的视频与文案发布到你自己的 TikTok 主页(Direct Post)。授权令牌安全存储,TikTok 数据仅用于上述用途,不出售、不对他人投放广告,并遵守 TikTok Developer Terms。可随时解绑,解绑即撤销访问、停止一切发布。