Privacy Policy
সংক্ষেপে
সংক্ষেপে আপনার তথ্যের মালিক আপনি। আমরা শুধু সেবা চালাতে যা দরকার তাই নিই, বিক্রি করি না, আর যেকোনো সময় আপনি ডেটা রপ্তানি বা মুছে ফেলার অনুরোধ করতে পারেন।
1. Who we are
Stakenix ("Stakenix", "we", "us") is a software-as-a-service platform operated from Dhaka, Bangladesh. We provide business software modules — social post scheduling and social media automation, school management, doctor chamber management, restaurant point of sale, supershop point of sale, AI chatbot for Messenger, WhatsApp and websites, Meta Ads automation, web hosting and domain registration — delivered on a per-customer subdomain in the form {name}.stakenix.com. We also provide website design and development services, and sell one-time digital products: ready-made website templates (source code) and ebooks. Our public website additionally hosts a blog and newsletter.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the choices and rights you have. It applies to our public website, our signup and billing flows, and the Stakenix application dashboard.
Legal operator : Stakenix — Trade Licence No. TRAD/DNCC/005635/2026
Registered address : ৫/ক, নিচতলা, পিসি কালচার হাউজিং সোসাইটি, রিং রোড, শ্যামলী, ঢাকা-১২০৭, বাংলাদেশ
Privacy contact : support@stakenix.com · +880 1910-001189
2. Controller and processor roles
Our role depends on whose data is involved, and this distinction matters for your rights:
- We are the controller for data about you as a Stakenix account holder — your signup details, billing records, support conversations and how you use the dashboard.
- We are a processor for the data you put into your workspace about your own students, patients, staff, customers and orders. You remain the controller of that data. We handle it only to deliver the service and on your instructions, and we do not use it for our own purposes.
If you are an individual whose data was entered into a Stakenix workspace by a school, clinic, shop or restaurant, please contact that organisation first — they decide what is collected and how long it is kept. We will support them in responding to you.
3. Data we collect
3.1 Data you give us
| Category | Examples | Why we need it | |---|---|---| | Account identity | Name, business name, email address, mobile number, chosen subdomain, password (hashed) | To create and secure your account and workspace | | Billing | Plan and module selection, invoice history, transaction references and the payment method type returned by our gateway | To charge subscriptions and issue invoices | | Support | Messages, call notes, screenshots and attachments you send us | To answer questions and resolve faults | | Workspace content | Whatever you enter into your chosen modules — students, attendance, results, fees, patients, appointments, prescriptions, products, sales, tables, posts and media | To deliver the module you subscribed to |
3.2 Data we collect automatically
| Category | Examples | Why we need it | |---|---|---| | Device and connection | IP address, browser and operating system, device type, language and time zone | Security, abuse prevention, and rendering the interface correctly | | Usage | Pages and features opened, timestamps, error traces, request identifiers | Diagnosing faults, capacity planning, improving the product | | Server logs | Request URL, status code, response time, referrer | Operations, security investigation and fraud detection | | Cookies | Session and preference cookies — see the Cookie Policy | Keeping you signed in and remembering settings |
3.3 Data from connected platforms
If you connect a Facebook Page, Instagram professional account or Google service to Stakenix, we receive only the data those platforms release for the permissions you approve — for example the page or account name and identifier, an access token, and the publishing status of posts we send on your behalf. We never receive your password for those platforms, and you can disconnect at any time. Section 10 sets out exactly how we use platform data.
We do not collect payment card numbers. Card, bKash, Nagad and Rocket credentials are entered on SSLCommerz's hosted page and never touch Stakenix systems. We store only the result of the transaction and a reference number.
4. How we use data
- To provide the service — creating your workspace, issuing an SSL certificate for your subdomain, running the modules you subscribed to, and storing your data.
- To bill you — starting trials, taking subscription payments through SSLCommerz, issuing invoices and recovering unpaid amounts.
- To support you — answering questions in Bangla or English by phone, WhatsApp and email, and reproducing faults you report.
- To keep the platform safe — detecting abuse, spam, fraud, credential stuffing and denial-of-service attempts, and enforcing our Acceptable Use Policy.
- To improve the product — measuring which features are used, in aggregate, and finding where the interface fails people.
- To communicate with you — service notices, maintenance windows, security advisories, billing reminders and, if you opt in, product news. Service and billing notices are not marketing and cannot be unsubscribed from while your account is active.
- To meet legal obligations — tax and VAT records, responding to lawful requests, and defending legal claims.
We do not sell personal data, we do not rent contact lists, and we do not use the content of your workspace to train machine learning models.
5. Legal bases
Where the EU or UK GDPR applies to a visitor or customer, we rely on these bases:
- Contract — creating your account, running your workspace, billing and support.
- Legitimate interests — security, abuse prevention, aggregate product analytics and protecting our legal position, balanced against your rights.
- Consent — optional cookies, marketing email, and connecting third-party platforms. You can withdraw consent at any time without affecting the lawfulness of past processing.
- Legal obligation — accounting, tax and lawful disclosure requirements under Bangladesh law.
For customers in Bangladesh we process data on the basis of your agreement to these terms and our legitimate interest in operating the service, consistent with applicable Bangladeshi law.
6. Who we share data with
We share personal data only with the categories of recipient below, and only to the extent needed. Every processor is bound by contract to confidentiality and to security measures no weaker than ours.
| Recipient | Purpose | Data involved | |---|---|---| | SSLCommerz | Payment processing for subscriptions | Name, email, mobile, amount, invoice reference | | Hosting and infrastructure providers | Running servers, storage and backups | All data, encrypted in transit and at rest | | Email and messaging providers | Transactional email, OTP and support replies | Name, email, mobile, message content | | Meta Platforms | Publishing posts you scheduled to your Facebook Page or Instagram professional account | The post content, media and schedule you created | | Domain registries and registrars | Registering domains you order | Registrant contact details required by the registry | | Professional advisers and authorities | Accounting, audit, legal advice, lawful requests | Only what is strictly required |
If Stakenix is involved in a merger, acquisition or asset sale, personal data may transfer to the successor. We will give notice before your data becomes subject to a different privacy policy, and the successor will be bound by commitments no less protective than these.
7. International transfers
Our primary infrastructure is chosen to keep customer data close to Bangladesh. Some processors — email delivery, error monitoring and the platforms you connect — may process data outside Bangladesh. Where personal data protected by the EU or UK GDPR leaves that jurisdiction, we rely on Standard Contractual Clauses or another approved transfer mechanism, and we assess whether additional technical measures such as encryption are needed. You may request details of the safeguards that apply to a specific transfer.
8. How long we keep data
| Data | Retention | |---|---| | Active workspace content | For as long as your subscription is active | | Workspace content after cancellation | 30 days, so you can export or reactivate, then permanently deleted | | Expired trials never converted | 30 days after the trial ends, then permanently deleted | | Invoices, tax and accounting records | Retained as long as Bangladeshi tax and company law requires, currently a minimum of 5 years | | Security and server logs | Up to 12 months, then deleted or aggregated beyond identification | | Support conversations | 24 months from the last message | | Backups | Rolling window of up to 30 days, after which copies age out automatically |
9. Your rights
Subject to applicable law, you may ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix data that is wrong or incomplete. Most fields you can edit yourself in the dashboard.
- Delete — erase your data, subject to records we must keep by law. See section 11.
- Export — receive your workspace data in a structured, machine-readable format. There is no lock-in and no fee.
- Restrict or object — limit processing based on legitimate interests, or object to it.
- Withdraw consent — for cookies, marketing or a connected platform, at any time.
- Complain — to us first at support@stakenix.com, and to your local supervisory authority if you remain unsatisfied.
Email support@stakenix.com from the address on your account, or from another address with enough detail for us to verify you. We respond within 30 days. We will tell you if we need longer and why. We do not charge for reasonable requests and we will never penalise you for making one.
10. Connected platforms: Meta, Google and social networks
10.1 Facebook and Instagram
The social post scheduler publishes content to Facebook Pages and Instagram professional accounts that you explicitly connect. When you connect an account:
- We request only the permissions needed to list your pages and publish or schedule content. We do not request permissions we do not use.
- We store the page or account identifier, its display name, and an access token, encrypted at rest.
- We use platform data solely to provide the scheduling feature to you. We do not sell it, transfer it to data brokers, use it for advertising or profiling, or combine it with data from other customers.
- We do not read your private messages, and we do not post anything you have not scheduled or approved.
- You can disconnect an account at any time from the dashboard. On disconnection we revoke and delete the stored token; scheduled posts that depend on it stop.
- We honour deletion and deauthorisation callbacks from Meta. If you remove the Stakenix app from your Facebook or Instagram settings, we treat it as an instruction to delete the platform data we hold for that connection.
Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies. Where those terms are stricter than this policy, those terms govern platform data.
10.2 WhatsApp Business and Messenger (AI chatbot)
The AI chatbot module answers messages sent to the Facebook Page or WhatsApp Business number that you connect through Meta's official APIs. For this feature we process the content of those customer conversations, sender identifiers and timestamps — as your processor, solely to generate replies, take orders and hand over to a human when configured. Conversation content is not used to train models shared with other customers, is not sold, and is deleted with the connection or on your instruction. Where the WhatsApp Business Platform terms apply, they govern that data.
10.3 Meta ad accounts (Ads automation)
The Meta Ads automation module connects to the ad account you authorise via Meta's Marketing API. We read campaign performance data (spend, results, audience metrics) to generate suggestions, and we apply changes — budget, status, targeting — only after you or your authorised plan approves them. We never move money: ad spend is billed by Meta to your own payment method. Disconnecting the ad account revokes the token and stops all analysis immediately.
10.4 Other connected social platforms
The social media automation module can publish to TikTok, YouTube, LinkedIn, Pinterest, X (Twitter) and Threads accounts that you explicitly connect through each platform's official API. For every such connection the same rules apply as in 10.1: minimum scopes, encrypted tokens, publish-only use, no sale or transfer of platform data, disconnect at any time from the dashboard, and compliance with each platform's developer policies.
10.5 Google API services
If you sign in with Google or connect a Google service, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve the feature you requested.
- We do not transfer Google user data to third parties except as necessary to provide that feature, for security, or to comply with law.
- We do not use Google user data for advertising, and we do not sell it.
- No human reads Google user data unless you give explicit permission for a specific support case, it is necessary for security, or the law requires it.
- We request the narrowest scopes that make the feature work, and you can revoke access at any time from your Google Account permissions page.
11. Data deletion instructions
How to delete your data From the dashboard. Open Settings → Account → Delete account. Confirm, and your workspace is scheduled for permanent deletion after a 30-day grace period during which you can still export or reverse the request.
By email. Write to support@stakenix.com from the address on your account with the subject Data deletion request and your subdomain. We acknowledge within 3 working days and complete deletion within 30 days.
For a connected Facebook or Instagram account. Remove Stakenix from Facebook Settings → Apps and Websites, or disconnect the account in the Stakenix dashboard. Either action deletes the access token and platform data held for that connection. You may also email us the request above.
For a connected WhatsApp number, ad account, or TikTok / YouTube / LinkedIn / Pinterest / X / Threads account. Disconnect it in Settings → Connections, or revoke Stakenix from that platform's own app-permissions page. Either action revokes and deletes the stored token, and the associated platform data (including chatbot conversation history for that channel) is deleted within 30 days.
When deletion completes we remove your workspace database, uploaded files, media and access tokens from live systems, and the corresponding copies age out of backups within the rolling backup window of up to 30 days. We retain only what law requires — principally invoices and tax records — plus a minimal record that the deletion happened, so we can prove we honoured your request.
12. Children
Stakenix is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. The school module necessarily holds data about pupils who are minors; in that case the school is the controller, is responsible for obtaining any consent required from parents or guardians, and instructs us on retention. If you believe a child has created an account with us directly, contact support@stakenix.com and we will remove it.
13. Security
We encrypt data in transit with TLS, encrypt sensitive fields and access tokens at rest, enforce role-based access on a least-privilege basis, and take automated daily backups. The full description of our controls is in the Data Security Policy. No system is perfectly secure; if a breach affects your data we notify you as described in that policy.
14. Automated decisions
We do not make decisions about you by automated means alone that produce legal effects. Automated systems do flag suspected abuse, spam or fraud for review, but a person decides before we suspend or terminate an account, except where an immediate block is needed to stop active harm.
15. Changes to this policy
We may update this policy as the service changes or the law changes. We revise the "Last updated" date at the top and, for material changes, notify account holders by email or dashboard notice at least 14 days before the change takes effect. Continuing to use Stakenix after that date means you accept the updated policy. Superseded versions are available on request.
16. Contact us
Questions, requests or complaints about privacy: support@stakenix.com, +880 1910-001189, or by post to the registered address in section 1. We answer in Bangla or English.
