We are committed to protecting your data and your clients' data. This policy explains exactly what we collect, why, and how.
The company behind this platform
WhatsApp Commerce ("we", "our", "the platform") is a multi-tenant SaaS platform that enables businesses to automate their WhatsApp ordering workflows. We provide a dashboard, automation tools powered by n8n, and a REST API connecting to Meta's WhatsApp Business API.
This Privacy Policy applies to:
Data controller: WhatsApp Commerce operates as both a data controller (for business client account data) and a data processor (for end customer order data processed on behalf of business clients).
What information enters our system and from where
We do not collect: payment card numbers, government IDs, biometric data, or precise location data beyond city/country provided voluntarily during registration.
The specific purposes for each category of data
Where data lives and how it is protected
All data is stored on an Oracle Cloud Infrastructure virtual machine. We use Docker containers for service isolation, PostgreSQL for persistent data, and Redis for ephemeral session caching.
Breach notification: In the event of a data breach affecting personal data, we will notify affected business clients within 72 hours of becoming aware, in accordance with GDPR Article 33.
External services we integrate with and why
Required to send and receive WhatsApp messages. Meta's own Privacy Policy governs their handling of message metadata.
Used for subscription billing. Stripe receives the business client's email and billing details. We never see or store payment card numbers. Governed by Stripe's Privacy Policy.
Our hosting provider. All data at rest resides on Oracle Cloud servers. Governed by Oracle's Privacy Policy.
Our automation engine runs entirely on our own servers. No data leaves our infrastructure through n8n.
We do not use: Google Analytics, Facebook Pixel, advertising networks, or any third-party tracking scripts.
Specific rules for data flowing through WhatsApp
As a platform built on the WhatsApp Business API, we operate under Meta's Business Tools Terms and WhatsApp's Business Policy.
How long we keep different types of data
After account deletion, all personal data is permanently removed from active databases within 30 days.
What you can ask us to do with your data
Under GDPR and applicable Moroccan data protection law, you have the right to:
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
How we maintain your login session
We use browser sessionStorage (not cookies) to store your JWT authentication token:
We use a dark mode preference stored in localStorage (darkMode) containing only a true/false value — no personal information.
We do not use tracking cookies, advertising cookies, or any third-party cookies.
Age restrictions on our platform
Our platform is intended for business use only. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has registered for an account, please contact us and we will delete the account and all associated data.
How we handle updates to this policy
When we update this Privacy Policy:
Get in touch about any privacy matter
You also have the right to lodge a complaint with your national data protection authority.