Privacy Policy
Last updated: September 21, 2026
Merchants who install Byvano through Shopify: Subscription charges for stores that installed Byvano through Shopify are processed only through Shopify Admin billing (Shopify App Pricing). Stripe is used exclusively for WooCommerce and direct byvano.com web sign-ups — never for Shopify-installed merchants.
Byvano ("we," "us," or "our"), operated by Seztech Inc., provides a shoppable video platform for eCommerce merchants. This Privacy Policy explains how we collect, use, and protect information when you use byvano.com and our Shopify application.
1. Information we collect
Account information: name, email address, company or store name, and authentication credentials when you register or install our app.
Store data: Shopify store domain, product catalog data (for tagging), and OAuth tokens required to operate the app (scoped to read_products).
Content you provide: imported or uploaded videos, widget configuration, product tags, and connected social account metadata.
Scheduled content: if you use the Byvano social scheduler, we store the posts you create — captions, hashtags, first comments, links, uploaded or selected media, the accounts you chose to publish to, the time you scheduled, and the result of each publish attempt (including the network's post ID, permalink, and any error it returned).
Performance data: for posts published through Byvano, and for the connected account as a whole, we retrieve performance figures from the network on your behalf — reach, views, reactions, comments, shares, saves, link clicks, follower counts and follower growth, and the aggregated, anonymous audience breakdowns the network provides (age band, gender, country, city). These breakdowns are statistical aggregates supplied by the network; they never identify an individual follower, and we never receive a list of who follows you.
Usage & analytics: widget views, video plays, product tag clicks, session identifiers, and technical logs (IP address, user agent, referrer) where needed for analytics and security.
2. How we use information
- Provide, maintain, and improve the Byvano service
- Display shoppable video widgets on your storefront
- Publish the posts you schedule to the social accounts you connected, at the times you chose, and retry or report a failure
- Show you how your published content performed, in your Byvano analytics dashboard and in the CSV exports you request
- Process subscriptions and billing (Shopify App Pricing or Stripe for non-Shopify plans)
- Send transactional emails (verification, password reset, billing notices)
- Respond to support requests and comply with legal obligations
We do not use your content, your connected accounts, or your performance data to train machine-learning models, to build advertising profiles, or for any purpose other than operating the features you asked for. Where Byvano offers optional AI caption assistance, only the text you explicitly submit to that feature is sent to the AI provider — never your analytics or audience data.
3. Shopify merchant & customer data
When installed on Shopify, we process store and product data according to Shopify's API terms. We do not sell merchant or buyer personal data. End-customer PII is limited; our widgets primarily collect aggregated interaction events. Shopify mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) are supported.
4. Data retention & deletion
Data is retained while your account is active. Uninstalling the Shopify app triggers store disconnection; you may request deletion via Settings or by emailing contact@byvano.com. After shop/redact, we delete store-linked configuration per our GDPR procedures.
5. Security
We use HTTPS/TLS for data in transit, access controls, and industry-standard practices to protect stored data. No method of transmission over the Internet is 100% secure; we work to minimize risk.
6. How we share & disclose data
We do not sell, rent, or trade your personal information or Google user data, and we do not share it with advertisers or data brokers. We disclose data only in the limited circumstances below, and only as needed to operate Byvano:
- Service providers (subprocessors) that host and operate our platform on our behalf — our cloud hosting and database provider (where your account, store, video, and analytics data is stored) and our transactional email provider. They may process data only to provide services to us and are bound by confidentiality obligations.
- Payment processors — Shopify (Shopify App Pricing) for Shopify-installed merchants, and Stripe for WooCommerce/web sign-ups — to process subscriptions. Google user data is never shared with them.
- Your own storefront visitors see only the video content and product tags you choose to publish through your widgets.
- Legal & safety — when required by law, regulation, or legal process, or to protect the rights, property, or safety of Byvano, our users, or the public.
- Business transfers — if Byvano is involved in a merger, acquisition, or sale of assets, data may be transferred under the same protections described in this policy.
Each third party named above (Shopify, Stripe, and our infrastructure and email providers) maintains its own privacy policy governing its services.
7. Google user data (YouTube API Services)
Byvano uses YouTube API Services. If you connect a YouTube account, Google shows you exactly which permissions we are asking for, and we use them only for the purposes described in this section.
a) Importing your videos (https://www.googleapis.com/auth/youtube.readonly, together with https://www.googleapis.com/auth/userinfo.profile). We read your own YouTube videos and their metadata (titles, thumbnails, and video IDs) so you can import them and turn them into shoppable widgets on your store, and your Google account name and profile picture so the connected account can be shown in your dashboard. Imported YouTube videos play on your store through YouTube's own embedded player; Byvano does not download or re-host them.
b) Uploading the videos you create with us (https://www.googleapis.com/auth/youtube.upload, together with youtube.readonly). If you connect a YouTube channel for uploads, Byvano does only the following:
- Identifies the channel you authorised — its channel ID, name, handle, and profile image — so it can show that channel under Scheduler → Accounts.
- Uploads a video only when you have scheduled it, only at the time you chose, and only to the channel you selected, with the title, description, tags, category, visibility (public, unlisted, or private) and "made for kids" setting you set in the composer. Those values are sent unchanged, with two exceptions shown to you in the composer: the characters < and > are removed, because YouTube does not accept them, and the first line of your caption is used as the title when you leave the title empty.
- Checks your channel's most recent uploads only when an upload was interrupted, to confirm whether YouTube already received that video so it is never uploaded twice. The titles read for this check are not stored.
- Reads the view, like, and comment counts of the videos we uploaded for you, only to show them in your analytics dashboard.
We never delete or edit your existing YouTube videos, never change the visibility of a video after it has been uploaded, and never comment, like, or subscribe on your behalf.
What we store: the channel details listed above; the OAuth access and refresh tokens Google issues, which are encrypted at rest (AES-256-GCM) and never shown in the Byvano dashboard, in API responses, or in exports; and, for each video we upload, the YouTube video ID, its link, the time it was uploaded, and any error YouTube returned. View, like, and comment counts are held in a short-lived cache (about ten minutes) and are not otherwise stored.
With whom we share Google user data: we do not sell or transfer it to third parties except the service providers (subprocessors) described in Section 6 that host and operate Byvano on our behalf, and except as required by law. We do not use Google user data for advertising, and we do not share it with data brokers. Our YouTube features do not place any additional cookies; Section 11 describes the cookies and browser storage byvano.com uses.
Revoking access and deleting data. You can revoke our access to your Google account at any time from the Google security settings page. Once access is revoked, we can no longer read from or upload to your channel, and any upload still waiting for that channel fails with a request to reconnect. Disconnecting the channel in Byvano under Scheduler → Accounts deletes the stored channel details and upload tokens immediately; a YouTube account connected for video import is managed separately on the Connect page. To have the remaining records deleted — imported videos and the record of videos we uploaded — use our data deletion page or email contact@byvano.com, and we will delete them within 7 days. Videos already on YouTube stay on your channel until you remove them in YouTube Studio.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
8. Instagram / Facebook / Meta Platform data
Byvano connects to Meta in two ways, and which one applies depends on what you asked Byvano to do.
a) Importing your videos. If you connect an Instagram professional (Business or Creator) account, Byvano uses Instagram Business Login to read your own Instagram media and its metadata (captions, thumbnails, permalinks, and media IDs) so you can import your Reels and turn them into shoppable widgets on your store.
b) Scheduling and publishing on your behalf. If you use the Byvano social scheduler, you are additionally authorising Byvano to create content on your Facebook Page or Instagram professional account at the times you schedule, and to read back how that content performed. This is the material change from earlier versions of this policy, which described a read-only integration. Concretely, Byvano:
- Lists the destinations you can publish to — the Facebook Pages you administer and the Instagram professional account you authorise — so you can choose which ones to connect (
pages_show_list,business_management,instagram_business_basic) - Publishes the posts, Reels and Stories you create in Byvano, only at the time you scheduled and only to the accounts you selected (
pages_manage_posts,instagram_business_content_publish) - Reads engagement and insights for your account and for the posts you published, to draw your analytics dashboard (
pages_read_engagement,read_insights,instagram_business_manage_insights) - Reads Page settings where a publishing action requires it (
pages_manage_metadata)
Byvano publishes only content you created or approved inside Byvano. It never posts on your behalf without a post you scheduled, never edits or deletes content it did not create, never posts to an account you did not select, and never acts on any account after you disconnect it. If you grant a permission Byvano does not currently need, it simply goes unused.
Comments and messages. Where the Meta use case Byvano is registered under also grants comment or message permissions, Byvano does not read, store, or reply to your direct messages. Any comment data is limited to the aggregate counts shown against your own posts in analytics.
With whom we share Instagram/Meta data: we do not sell or transfer it to third parties except the service providers (subprocessors) described in Section 6 that host and operate Byvano on our behalf, and except as required by law. We do not use it for advertising, and we do not share it with data brokers. Access tokens for your connected accounts are encrypted at rest (AES-256-GCM) and are never exposed in the Byvano dashboard, in API responses, or in exports.
Retention and revocation. Performance figures are cached briefly to avoid re-querying Meta on every page view, and post records are kept for as long as your account is active so your history stays intact. You can revoke Byvano's access at any time — on Instagram under Settings → Apps and websites, on Facebook under Settings & privacy → Settings → Business integrations, or by disconnecting the account in Byvano under Scheduler → Accounts, which deletes the stored token immediately. Revoking access stops all future publishing. To have imported and published-post data deleted as well, use our data deletion page or email contact@byvano.com.
Our use and transfer of information received from the Meta, Facebook, and Instagram APIs adheres to the Meta Platform Terms and Developer Policies.
9. TikTok data
If you connect a TikTok account, Byvano uses TikTok Login Kit and requests exactly two scopes:
user.info.basic— to identify which TikTok account you connected and show it in your dashboard (open ID, avatar, display name). Nothing else is derived from it.video.list— to list your own public TikTok videos and their metadata (captions, thumbnails, video IDs, cover images) so you can choose which ones to embed on your store as shoppable video.
Byvano never posts to TikTok. We do not request video.publish orvideo.upload, and we have not enabled TikTok's Content Posting API. The integration is read-only and exists so your existing TikTok content can keep selling on your own product pages.
We access this data only at your request, and store it on our infrastructure solely to render the widgets you configure. Access tokens are stored encrypted. We do not use TikTok data for advertising, we do not sell or transfer it to data brokers, and we share it only with the service providers (subprocessors) described in Section 6 that host and operate Byvano on our behalf, or where required by law.
You can disconnect TikTok from your Byvano dashboard at any time, which deletes the stored tokens and stops any further access. You can also revoke Byvano's access from your TikTok account settings. Imported video records are deleted on disconnection or on account deletion as described in Section 4. Our use of TikTok data is also subject to the TikTok Terms of Service and the TikTok Privacy Policy.
10. LinkedIn data
If you connect a LinkedIn account, Byvano uses LinkedIn's Community Management API and requests exactly three scopes:
rw_organization_admin— to list the LinkedIn Pages and Showcase Pages you administer, so you can choose which ones to connect, and to read those Pages' own analytics.w_organization_social— to publish the posts you create and schedule in Byvano, only at the time you scheduled and only to the Pages you selected.r_organization_social— to read back the posts published for those Pages and their engagement figures (reactions, comments and impression counts) to draw your analytics dashboard.
Byvano publishes as a Page, never to your personal LinkedIn profile. We do not requestw_member_social or any member-profile scope, so Byvano cannot post, comment or react as you personally, and it cannot read your personal feed, your connections, your messages, or anyone else's profile.
Byvano publishes only content you created or approved inside Byvano. It never posts without a post you scheduled, never edits or deletes content it did not create, never posts to a Page you did not select, and never acts on any Page after you disconnect it.
We access this data only at your request, and store the identifiers of the Pages you connected, the posts Byvano published, and their engagement counts. Access tokens are stored encrypted at rest (AES-256-GCM) and are never exposed in the Byvano dashboard, in API responses, or in exports. We do not use LinkedIn data for advertising, we do not sell or transfer it to data brokers, and we share it only with the service providers (subprocessors) described in Section 6 that host and operate Byvano on our behalf, or where required by law.
You can disconnect LinkedIn from your Byvano dashboard at any time under Scheduler → Accounts, which deletes the stored tokens immediately and stops any further access. You can also revoke Byvano's access from LinkedIn under Settings & Privacy → Data privacy → Other applications → Permitted services. Stored post and analytics records are deleted on disconnection or on account deletion as described in Section 4. Our use of LinkedIn data is also subject to the LinkedIn Marketing API Terms and the LinkedIn Privacy Policy.
11. Cookies and browser storage
byvano.com and our widgets use a small number of first-party browser storage items, each needed to run the service:
- Sign-in cookie — an HTTP-only session cookie that keeps you signed in to your dashboard.
- Local storage in your browser — the dashboard keeps a copy of your sign-in token for browsers that block the cookie, and remembers small interface choices such as whether you finished the getting-started tutorial.
- Storefront widget — the shoppable video widget keeps a random session identifier in the shopper's browser session storage, which is cleared when the tab closes, to count views, video plays, and product tag clicks. It contains no personal information.
We do not use advertising cookies, do not allow third parties to serve advertisements through byvano.com or our widgets, and do not load third-party tracking pixels.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your data. Contact contact@byvano.com or use in-app account export where available.
13. Contact
Seztech Inc.
6600 Chase Oaks Blvd, Ste 150, Plano, TX 75023, USA
Email: contact@byvano.com