selfshop.com.bd ("we", "us", "our") operates a business-to-business (B2B) online platform providing services primarily to companies, merchants, retailers, distributors and other business entities in Bangladesh and internationally.
This policy explains how we collect, use, disclose, store and protect personal information in the course of our B2B activities, for individuals who act on behalf of business customers, prospects, suppliers, partners, website visitors and other business contacts ("you").
We handle personal information in line with the Digital Security Act 2018, the Information and Communication Technology Act 2006 (as amended), and relevant Bangladesh regulations. If you're located outside Bangladesh, additional laws — such as the GDPR for EU residents — may apply in specific cases.
Information we collect
A. Information you provide directly
- Business contact details — name, job title, company name, department, business email and phone, business address
- Account and registration information — username, password, company registration details, TIN/VAT number where required
- Payment-related information, handled by secure third-party payment processors
- Communications — messages, support tickets, emails, chat records, meeting notes
- Uploaded business documents — trade license, partnership deed, authorization letters, if required for verification
- Anything else you voluntarily share when requesting demos, quotes or support
B. Information collected automatically
- Device and network information — IP address, browser type and version, operating system, device identifiers
- Usage data — pages visited, access times, features used, referral source, session duration
- Cookies and similar technologies — see Section 9
C. Information from third parties
- Public business directories and company registries
- Payment gateway providers, for transaction confirmation only
- Business partners or referrers, with your consent or on a legitimate-interest basis
How we use your information
- Create, administer and manage business accounts and subscriptions
- Provide, maintain, improve and personalize our B2B services
- Process orders, invoices, payments and deliveries
- Communicate about your account, orders, support and service changes
- Verify business identity and prevent fraud
- Send service notices, legal notices and transactional emails
- Share product updates, feature announcements and webinar invitations — you can opt out of marketing
- Respond to inquiries and support requests
- Analyze platform usage to improve the user experience
- Comply with legal obligations, resolve disputes and enforce agreements
- Support internal accounting, auditing, reporting and security
Legal basis for processing
Where applicable, we rely on one of the following grounds:
This covers your business agreement or subscription with us; B2B contact management, service delivery, fraud prevention and direct marketing of similar services; compliance with law; and cases where we specifically ask for your consent, such as marketing newsletters.
Sharing of information
We share personal information only in these limited circumstances:
- With service providers who assist us — hosting, cloud storage, email, payment processors, analytics, support tools — all bound by strict confidentiality
- With logistics and delivery partners, to fulfill orders
- With banks and payment gateways, for transaction processing
- To comply with law enforcement, court orders, regulatory authorities or legal process
- In connection with a merger, acquisition, asset sale or reorganization
- With your explicit consent or direction
Data storage & international transfers
Your data is primarily stored on secure servers located in Bangladesh and select cloud regions. Where data is transferred outside Bangladesh, we put appropriate safeguards in place before that transfer happens.
Data retention
We keep personal information only as long as necessary for the purposes in this policy, or as required by law. After the relevant period, data is securely deleted or anonymized.
| Data category | Retention period |
|---|---|
| Active business account data | Duration of relationship + 2–5 years |
| Marketing data | Until you unsubscribe or opt out |
| Logs & security data | 6–24 months |
Security
We apply commercially reasonable technical, administrative and physical measures to protect personal information from unauthorized access, loss, misuse or alteration. No method of transmission over the internet or electronic storage, however, is 100% secure.
Your rights
Depending on applicable law, you may have the right to:
To exercise these rights, contact [email protected]. We aim to respond within 30 days.
Cookies & analytics
We use cookies and similar technologies for essential functionality, performance, analytics and, where enabled, marketing. You can manage preferences through our cookie banner or your browser settings.
Product analytics and session replay
We use PostHog's European cloud service to understand how people use the SelfShop website, reseller app and supplier app — including pages viewed, feature usage, account recovery steps, subscription journeys and app lifecycle activity.
Before sign-in, this activity is tied to a random device or browser identifier. After sign-in, it may be linked to an internal account identifier so journeys work across SelfShop products. We do not send names, phone numbers, email addresses, passwords, one-time passwords, addresses, payment references, search text or support-message content to PostHog.
Children's privacy
Our services are not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. The revised version will be posted on this page with an updated "Last updated" date — we encourage you to check back periodically.
This is a general reference document for a B2B platform and is not legal advice. Have it reviewed by a qualified Bangladeshi lawyer familiar with digital commerce and data protection requirements.



