Terms and privacy
Terms of service
CanalYar is a service that publishes products from your WooCommerce store to your Telegram, Bale and Rubika channels using its own bots. The service is operated by Milad Kardgar. By creating an account or using the WordPress plugin or the API, you accept these terms.
- Account: accounts are created with a mobile number. You are responsible for keeping each site's connection key private; anyone with the key can post on behalf of that site. If it leaks, create a new key in the panel.
- Channels: posts only go to channels whose ownership you proved with the verification code. Do not add channels that are not yours.
- Content: you are responsible for the text, images and files you send. Illegal content, spam, or anything that breaks the target messenger's rules is not allowed and may lead to suspension.
- Subscription and quota: new accounts get a free trial; after that, sending continues with a paid plan. The quota, channel limit and duration of each plan are as shown in the panel at purchase. Renewals are added to the end of the current subscription.
- Attribution: on some plans a short "Sent by CanalYar" line is added to posts; this is stated in the plan description.
- Availability: the service is provided as is. We aim to keep it available, but delivery also depends on the messengers themselves and may be delayed or fail.
- Changes: these terms may be updated; the current version is always on this page.
Privacy policy
What we store
- Account: your mobile number, plus name and email if you enter them; when the account was created and last signed in. One-time login codes are stored only as hashes, together with the requesting IP address to prevent abuse.
- Sites: site URL, connection key, the channels you added and their verification status.
- Payments: plan, amount, discount code and the gateway's reference number. Card details never reach us; only the payment gateway sees them.
- Support tickets: your messages and any files you attach.
- Request logs: for each send, the time, messenger, result, size and error message — for quota counting and troubleshooting.
- Site analytics: for each page view on this site, the time, page, referring site, campaign parameters, browser and IP address, plus a random cookie (cy_vid, one year) to count unique visitors. No third-party analytics service is used.
What we do not store
- Post text, images and files are only used to deliver the post to the messenger; uploaded images and files are deleted right after sending.
- The WordPress plugin never sends any data about your store's customers or orders.
Who it is shared with
- Telegram, Bale and Rubika: post text, images and files, to publish them in your channel.
- sms.ir: your mobile number, to send login codes and subscription reminders.
- Zarinpal: the amount and details needed to process a payment.
- If you connect an Instagram account, we store only the account ID, username and the access token Instagram issues. Your Instagram password never reaches us.
- The token is used only to publish the posts you send yourself from the panel, the plugin or the API. We do not read your account's posts, followers or messages.
- A post's image is made available to Instagram at a random URL for a few seconds and deleted right after publishing.
- Removing the channel in the panel, or removing CanalYar under Apps and websites in Instagram settings, deletes the token and account details immediately. Data deletion requests sent through Instagram are handled the same way.
Your data is not sold or shared for advertising. To see or delete your account data, send a ticket from "Support" in the panel.