WWAWCD for Shopify

Privacy Policy

What the WAWCD Shopify app collects, why, and how you stay in control. Last updated: August 2026.

What we collect

  • Store details: your shop domain, store name, email, currency and timezone.
  • Order event data received from Shopify webhooks (order number, totals, line-item titles, customer first name and phone number) — used only to send the transactional messages you configure.
  • Message activity in the WAWCD Shopify application database: recipient number, order reference, rendered message, template, provider reference, send status and error. Customer-identifying fields are redacted after 90 days; the non-identifying delivery result can remain for merchant reporting.
  • Opt-out history: the normalized phone number, source and timestamps needed to enforce a recipient's stop request. Legacy permission records from earlier app versions may remain until their normal deletion or a verified Shopify redaction request.
  • Templates and automation settings you create in the app.

What we never do

  • We do not sell or share customer data with third parties for advertising.
  • We do not use Shopify customer data for marketing or unrelated broadcasts.
  • Merchants are responsible for obtaining every permission required by law and WhatsApp before enabling an automation. WAWCD does not independently verify that permission from Shopify order attributes.
  • Every automated QR message contains an encrypted self-service opt-out link. WhatsApp replies are not currently imported automatically, so merchants must also monitor the linked account and promptly honor any stop request before another update is sent.

Processors

  • WAWCD Cloud — manages the QR-linked session and receives the recipient number and configured message content needed to deliver each message.
  • Shopify — source of store and order data and the host of the embedded app experience.
  • Vercel — application hosting and request processing.
  • Neon — encrypted application database hosting.

Retention

  • Webhook and delayed-job payloads are cleared as soon as processing succeeds or finally fails.
  • Customer-identifying message activity is retained for no more than 90 days.
  • Active opt-out phone numbers are retained while the app is installed so a stop request cannot be lost; they are erased for a verified customer-redaction or shop-redaction request.
  • Completed privacy-request identifiers and requested order IDs are cleared immediately.
  • Terminal job receipts and webhook deduplication records are removed after 30 days.
  • Protected-data access records contain only keyed hashes, actions and timestamps—never names, phone numbers, email addresses or message bodies—and are removed after 12 months.

GDPR & data removal

We process Shopify's mandatory privacy webhooks. A customer data request is recorded for our team to prepare the data held by this app and provide it to the merchant within Shopify's 30-day deadline. When a customer-redaction request arrives, matching phone numbers, opt-out and legacy audit records, message contents, order references, and pending local sends are removed or redacted. When Shopify sends a shop-redaction request after uninstall, the linked WAWCD Cloud session is closed before the shop's local app records are deleted.

Customers can request access, deletion, or messaging opt-out through their merchant or by emailing us. We verify and handle direct requests manually. A customer-level local redaction does not itself erase records retained independently by a delivery processor; those requests require separate coordination with the relevant processor.

Contact

Privacy questions: support@wawcd.com