Legal

Privacy Policy

bolnepage lets Nepali businesses put an AI assistant on their Facebook, Instagram, WhatsApp, and Viber channels to answer customers around the clock. Doing that means handling real messages from real people, so this page says plainly what we collect, who we send it to, how long we keep it, and how to get it deleted.

  • Who we are
  • What we collect
  • What we access on Facebook, Instagram, and WhatsApp
  • How we use it
  • How AI processing works
  • Who we share it with
  • How long we keep it
  • Your rights
  • How to delete your data
  • How we protect it
  • Where your data is processed
  • Children's privacy
  • Your responsibilities as a business
  • Changes to this policy

Who we are

bolnepage is operated by VardanSoft Pvt. Ltd., registered in Nepal. We are the data controller for the account information of business owners who sign up, and the data processor acting on a business's instructions for the customer messages their assistant handles.

Two different people appear in this policy. The business owner is our customer — they sign up, connect their channels, and pay us. Their customer is the person who messages that business on Facebook, Instagram, WhatsApp, or Viber. We handle the second group's messages only so the first group can answer them.

What we collect

We collect only what the assistant needs to do its job:

  • Account information: your name, email address, and the identifier issued by our sign-in provider. We never see or store your password.
  • Business profile: the business name, description, offerings, tone, opening rules, products and prices you enter, and any facts you or your assistant save as knowledge.
  • Channel connections: the page, account, or phone number you connect, along with the access tokens Meta, Slack, or Viber issue us. Tokens are encrypted before they are stored and are never shown back to you or to anyone else.
  • Customer conversations: the messages, comments, images, audio, video, and documents your customers send to your connected channels, plus their public display name and profile photo as the platform provides them, and the replies your assistant sends.
  • Commerce records: customer details saved on a conversation, orders, and payment references created through your assistant.
  • Usage and diagnostics: how much of your monthly allowance each reply consumed, an activity log of what your assistant did, and error reports when something breaks.
  • Cookies: a session cookie that keeps you signed in, and nothing else. We do not run advertising or cross-site tracking cookies.

What we access on Facebook, Instagram, and WhatsApp

When you connect a channel, Meta asks you to grant specific permissions. We request the narrowest set that makes the assistant work, and we use each one only for the purpose named here:

  • pages_messaging — to read messages customers send your Facebook Page and to send your assistant's replies.
  • pages_manage_metadata — to subscribe your Page to message and comment notifications, so the assistant knows a customer is waiting.
  • pages_read_engagement and pages_manage_engagement — to read the post and comment a customer is replying to, and to post your assistant's public reply.
  • instagram_business_basic — to identify the Instagram professional account you connected.
  • instagram_business_manage_messages — to read and reply to Instagram direct messages.
  • instagram_business_manage_comments — to read and reply to comments and mentions on your Instagram posts.
  • WhatsApp Business messaging — to receive messages sent to your connected WhatsApp number and send your assistant's replies within WhatsApp's messaging rules.
  • We never post to your feed, never message anyone who has not messaged you first, never advertise on your behalf, and never use your data or your customers' data to build advertising audiences.

How we use it

  • To generate replies. Your business profile, saved knowledge, catalog, and the recent messages in a conversation are sent to Google's Gemini model, which produces the reply text. This is the core of the service and it is described in more detail below.
  • To run the features you switch on: saving a customer's details, taking orders and issuing payment links, scheduling follow-ups, and escalating to you when the assistant is unsure.
  • To show you your inbox, activity log, and results, and to let you take over a conversation.
  • To meter your monthly allowance and bill you, and to tell you when you are running low.
  • To send you service email: escalations that need you, renewal reminders, and security notices.
  • To keep the platform working and secure — diagnosing errors and preventing abuse.
  • We do not sell your data, we do not share it with advertisers, and we do not use your customers' messages to train our own models.

How AI processing works

Your assistant is powered by Google's Gemini models through the Google Gemini API. To produce a reply, we send Google the business profile and instructions you wrote, the relevant saved knowledge and catalog entries, and the recent turns of that one conversation — including any image, audio, video, or document the customer sent, if you have switched that on for that media type.

Google processes this to return the reply and does not use data submitted through the paid Gemini API to train its models. We do not use your conversations to train any model of our own.

An AI assistant can be wrong. You choose per channel whether replies send automatically or wait for your approval, you can take over any conversation at any time, and you should review anything that matters commercially or legally before it reaches a customer.

Who we share it with

We share data only with the providers that make the service run. Each one receives only what its job needs, and none of them may use it for their own purposes:

  • Google (Gemini API) — generates assistant replies and knowledge search.
  • Google Cloud Platform — hosting, file storage for the media your customers send, and job scheduling.
  • Meta Platforms — Facebook, Instagram, and WhatsApp message delivery.
  • Slack — internal team notifications, when you connect it.
  • Rakuten Viber — Viber message delivery, when you connect it.
  • Khalti — payment processing for subscriptions and orders. Khalti handles your card and wallet details directly; we never see or store them.
  • Fonepay — payment processing for subscriptions paid by QR or mobile banking. Your bank credentials are entered in your own banking app; we never see or store them.
  • Sentry — error diagnostics.
  • We may also disclose data where the law of Nepal requires it, or to establish or defend a legal claim.

How long we keep it

  • Conversations and their messages stay until you delete them or close your account. You can delete any single conversation, or clear its messages, from your inbox at any time.
  • Saved customer details, knowledge, and catalog entries stay until you delete them.
  • Orders and payment references are kept for as long as tax and accounting law requires us to keep business records. They deliberately outlive the conversation they came from — deleting a chat does not erase a sale.
  • Escalation links expire 24 hours after they are created.
  • Access tokens are deleted as soon as you disconnect a channel.
  • Account and workspace data is deleted when you delete the workspace or ask us to close your account.

Your rights

You can access, correct, export, or delete your data. Most of it you can act on yourself from the dashboard: edit your profile and knowledge, export leads to CSV, delete conversations, or delete a whole workspace from its Settings tab. For anything else, email us and we will act within 30 days.

How to delete your data

There are three ways to have your data removed, and all of them work:

  • From the dashboard: open the workspace, go to Settings, and delete the workspace. This removes its conversations and everything saved on them, knowledge, catalog, and channel connections.
  • From Facebook: open Settings › Apps and Websites on Facebook, remove bolnepage, and choose to delete your data. Facebook sends us the request automatically, we delete the Facebook and Instagram data connected by that account, and we return a confirmation code with a link showing you exactly what was removed.
  • By email: write to support@bolnepage.com from your account address and ask us to delete your data. We will confirm within 30 days.
  • Removing our app on Facebook without requesting deletion simply disconnects the channel — your business records stay so you can reconnect later.

How we protect it

  • Channel access tokens and platform secrets are encrypted before they are written to the database.
  • All traffic runs over HTTPS, and every incoming webhook is signature-verified so we only act on messages that genuinely came from the platform they claim.
  • Access to production data is limited to the people who need it to run the service.
  • No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authorities without undue delay.

Where your data is processed

bolnepage is operated from Nepal, and our providers process data on servers outside Nepal — principally Google Cloud regions and the messaging platforms' own infrastructure. By using the service you agree to your data being processed in those locations under the safeguards those providers offer.

Children's privacy

bolnepage is a business tool and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child's data has reached us, write to us and we will delete it.

Your responsibilities as a business

You decide what your assistant says and what you do with the customer data it captures. You are responsible for telling your own customers that an AI assistant may answer them, for honouring their requests about their own data, and for not asking your assistant to collect sensitive information — health details, government ID numbers, card numbers — through chat.

Changes to this policy

We will update this page when the service changes. If a change materially affects how we handle your data, we will email you before it takes effect rather than relying on you to notice.

Contact us

Questions about this policy, or a request about your data? Write to us and a person will answer:

support@bolnepage.com

VardanSoft Pvt. Ltd., Kathmandu, Nepal

Last updated: 4 August 2026

bolnepage logobolnepage

Nepal's first AI staff for customer chats. It answers, follows up and keeps every name and number — and knows when to hand the chat to you. Built for Nepal, priced for Nepal.

Payment partners

KhaltiCheckout by Fonepay

Platform

FeaturesHow it worksPricingFAQHelpPartner program

Company

Privacy PolicyTerms of Service9841307947 on WhatsAppsupport@bolnepage.combolnepage on Facebook

© 2026 bolnepage. All rights reserved.

bolnepage
FeaturesHow it worksPricingFAQ
FeaturesHow it worksPricingFAQ