Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains how Destesi ("Destesi", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you use our websites, applications, and services, including the Destesi product suite and the Destesi Connect integration platform (collectively, the "Services"). By using the Services, you agree to the practices described here.
1. Information we collect
We collect the following categories of information:
- Account information — name, email address, workspace details, and authentication data you provide when you create an account.
- Usage data — log data, device and browser information, and information about how you interact with the Services.
- Connection data — when you connect a third-party application, we receive and store the access credentials (such as OAuth tokens) you authorize, along with the data from that application necessary to provide the features you request.
- Content — the data, files, and messages you create, upload, or process through the Services.
2. How we use your information
We use the information we collect to:
- Provide, maintain, and improve the Services;
- Authenticate you and secure your account;
- Provide support — authorized Destesi personnel may access your workspace to investigate and resolve issues, for a limited time, with the reason recorded. Access of this kind is shown to you in your account activity.
- Execute the integrations and actions you authorize with connected third-party apps;
- Communicate with you about the Services, including security and service notices;
- Detect, prevent, and address fraud, abuse, and security issues;
- Comply with legal obligations.
3. Third-party connections
The Services let you connect third-party accounts (for example, Slack, GitHub, HubSpot, Intercom, Zoom, and others). When you authorize a connection, we access and process data from that accountonly to the extent you authorize and solely to provide the requested functionality. We do not sell this data, and we do not use it for advertising. You can revoke any connection at any time from within the Services or from the third-party provider, after which we cease accessing that account and delete the associated credentials in accordance with Section 7.
3.1 Meta Platform data (Facebook, Instagram, Threads, Meta Ads)
When you connect a Meta account, we receive and store only what is needed to operate the feature you authorized:
- Access credentials — the OAuth access token issued for your account, its expiry, and the list of permissions (scopes) you granted. We never receive or store your Meta password.
- Account identity — the account identifier, username or account name, account type, and profile picture URL, used solely to show you which account is connected and to address API calls to the right account.
- Content you act on — the media and text you choose to publish through Destesi, and the data a feature you invoked returned (for example, campaign metrics you asked to see).
We use Meta Platform data only to provide the functionality you requested. We do not sell it, we do not use it for advertising or profiling, we do not transfer it to data brokers, and we do not use it to train machine learning models. We do not request or store Meta data beyond the permissions you granted, and we retain it only while the connection is active — seeData Deletion Instructions to remove it. For a per-permission breakdown of one such connection, see the Instagram integration page.
3.2 E-commerce platform data (Shopify)
When you connect a Shopify store, we call that store's Admin API on your behalf and process:
- Access credentials — the access token Shopify issues for your store, the granted scopes, and your store's domain. We never receive or store your Shopify password.
- Catalog data — products, variants, prices, images, inventory levels, and locations, so the items you already sell on Shopify can be sold through the channels Destesi supports.
- Order and customer data — your recent orders and, for each, the buyer's name, email address, phone number, and shipping and billing address. We use them to show you the status of an order, to quote shipping and create carrier labels, and to let your assistant answer that buyer's questions about their own order on your behalf.
We process Shopify protected customer dataonly for those purposes. We do not sell it, we do not use it for advertising or profiling, we do not transfer it to data brokers, and we do not use it to train machine learning models. Assistant features are powered by AI service providers that process this data on our behalf, under contractual terms that forbid using it to train their models. We honour Shopify's compliance requests: a customer data request, a customer redaction request, or a shop redaction request relayed by Shopify is actioned within 30 days, and uninstalling the app deletes the stored credentials for that store.
4. How we share information
We do not sell your personal information. We may share information:
- With service providers who process data on our behalf under appropriate confidentiality and security obligations;
- With third-party services you connect, as directed by your use of the Services;
- For legal reasons, when required to comply with law or to protect the rights, safety, and security of Destesi and others;
- In a business transfer, such as a merger or acquisition, subject to this Privacy Policy.
5. Government and law enforcement requests
We may receive requests from public authorities, courts, or law enforcement seeking personal data, including data we access through third-party connections. We handle every such request under the following safeguards:
- Legality review — we review each request to confirm it is valid, properly issued, and legally binding before disclosing any data.
- Challenging unlawful requests — where a request is overbroad, improperly issued, or otherwise unlawful, we push back on, narrow, or challenge it through appropriate legal channels.
- Data minimization — we disclose only the minimum information necessary to comply with a valid request, and never more than the request legally compels.
- Documentation — we keep a record of the requests we receive, our responses, the legal reasoning applied, and the individuals involved in handling them.
Where we are legally permitted to do so, we will notify affected users before disclosing their data.
6. Security
We implement technical and organizational measures designed to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6.1 Encryption
All traffic between you, our Services, and the third-party providers you connect travels over TLS. Third-party credentials are additionally encrypted at the application layer with AES-256-GCM before they are written to storage, so a database copy alone does not yield a usable token. Our production database and its automated backups are encrypted at rest with a customer-managed key, and object storage encrypts its contents at rest by default.
6.2 Access control
Personal data is isolated per workspace, and every request is authorized against the workspace it names. Access to production systems is limited to the personnel who need it for their role, is granted individually rather than shared, and is revoked when the need ends. Staff accounts use strong, unique passwords held in a password manager, and access to our production infrastructure is federated through single sign-on. Requests that reach personal data are logged with the identity of the caller, the workspace, the operation, and the time, and those logs are retained for review.
6.3 Separation of environments and data loss prevention
Development and testing run against separate systems seeded with test data; production personal data is never copied into them. Production access follows least privilege, credentials are held in a managed secret store rather than in code or in configuration files, bulk export of personal data out of production is not a routine operation available to staff, and backups with point-in-time recovery protect against loss or corruption.
6.4 Security incident response
We maintain a documented incident response procedure. A suspected incident is triaged by severity, contained, and remediated, and the cause and the actions taken are recorded. Where a confirmed breach affects your personal data, we notify you without undue delay and within the timeframes applicable law requires, and we notify the relevant supervisory authority and any affected platform where we are obliged to do so. Report a suspected vulnerability or incident tohello@destesi.io.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Services, and no longer. Specifically:
- Connection credentials are deleted when you disconnect the account or uninstall the app from the provider.
- Data from a connected account is deleted within 30 days of the connection being removed, and sooner where the provider's own erasure request reaches us first.
- Workspace data, including the personal data of your customers, is purged from every product in the suite within 30 days of the workspace being deleted.
- Operational logs are retained for no more than 90 days.
We retain data beyond these periods only where the law requires it, and only for as long as that obligation lasts.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us athello@destesi.io. You may also revoke third-party connections at any time directly within the Services. For step-by-step instructions on deleting a connection, an account, or all of your data, seeData Deletion Instructions.
9. Cookies, advertising, and measurement
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Services are used. You can control cookies through your browser settings, though some features may not function properly without them.
9.1 Advertising and measurement technologies
On our public marketing website at destesi.io we use advertising measurement technologies provided by the advertising platforms we advertise on — currently theTikTok Pixel. These set cookies or similar identifiers in your browser and send TikTok information about your visit, such as the pages you viewed, your approximate location, device and browser characteristics, and whether you completed an action such as creating an account. We use this to measure whether our advertising works and to attribute sign-ups to the campaign that produced them.
Two limits apply. First, these technologies runonly on our marketing website — they are not loaded inside the product suite, so your activity within the Services is not sent to any advertising platform. Second, we never share your account content, your files, or any data from the third-party accounts you connect with advertising platforms; as stated in Section 3, connection data is never used for advertising.
TikTok processes the data it receives under its own privacy policy and as an independent controller of that data. You can limit this collection through your browser's cookie settings, through your device's tracking controls, or through the ad personalization settings in your TikTok account. Declining has no effect on your ability to use the Services.
10. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. International transfers
We may process and store information in countries other than your own. Where we transfer personal data across borders, we take steps to ensure appropriate safeguards are in place as required by applicable law.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice.
13. Contact
Questions about this Privacy Policy or our data practices? Contact us athello@destesi.io.