Legal
Privacy Policy
Last updated: June 25, 2026
Wappsello is a Shopify app that lets merchants send WhatsApp messages to their own customers using the merchant's own WhatsApp Business Account. This policy explains what data we collect, how we use it, who we share it with, and how you can ask us to delete it.
1. Who we are
Wappsello is operated by AI Saturn. Throughout this policy, “we”, “us”, and “our” refer to AI Saturn as the data controller for the data described below. Our app is distributed exclusively through the Shopify App Store and runs as an embedded admin experience inside a merchant's Shopify dashboard.
2. Data we collect
2.1 Merchant account data (from Shopify)
When a merchant installs Wappsello, Shopify provides us with:
- Shop domain (e.g. your-shop.myshopify.com) and shop ID
- Shop owner name, email, billing address, primary currency, and time zone
- OAuth access tokens scoped to the permissions you granted at install
- Theme metadata needed to detect whether the storefront widget is enabled
2.2 Customer & order data (from Shopify webhooks and the Admin API)
To send relevant WhatsApp campaigns we read order, checkout, and customer records from the merchant's store:
- Customer first name, last name, email, and phone number
- Order number, line items, totals, currency, payment status, fulfillment status
- Abandoned checkout records (recovery URL, line items, totals)
- Tracking URLs from order fulfillments
- The shop's configured order status URL used to deep-link customers back to their order
We persist a customer's phone number alongside each outbound message we coordinate, so the merchant can see what was sent to whom and audit the campaign. We do not store the customer's email, address, or full order body beyond what is needed to render the message and attribute back to the order.
2.3 WhatsApp Business Account data (from Meta)
When a merchant connects their WhatsApp number via Meta's Embedded Signup, Meta returns:
- The merchant's WhatsApp Business Account (WABA) ID and verified phone number ID
- A long-lived access token for that WABA, scoped to send messages and read message status
- Template names, categories, languages, and approval status
- Webhook events for message delivery, read receipts, and replies (sent → delivered → read)
Access tokens are encrypted at rest using AES-256-GCM with a key held outside the database. Tokens never leave the server; the merchant's browser never sees them.
2.4 Storefront widget data
For merchants who enable the storefront chat / share widget, our client-side JavaScript collects:
- Anonymous view and click events to count widget engagement
- A random session ID stored in localStorage to deduplicate views from the same browser session
- The current page URL so we can suppress the widget on excluded pages
We do not set tracking cookies. We respect the storefront's customer-privacy consent flag (window.Shopify.customerPrivacy) — if analytics processing is not allowed, no events are sent.
3. How we use your data
We use the data above to:
- Send WhatsApp messages on behalf of the merchant — abandoned cart recovery, order confirmations, fulfillment updates, and post-purchase follow-ups using merchant-approved templates
- Render the storefront chat / share widget and the merchant's admin dashboard
- Generate short links so the merchant can attribute revenue back to specific WhatsApp campaigns
- Show campaign performance, delivery status, conversion counts, and aggregate analytics in the merchant admin
- Authenticate API and webhook requests via HMAC, OAuth, and Meta's webhook signature verification
- Communicate with merchants about service issues, security incidents, or important product changes
We do not sell or rent any data. We do not use customer data to train machine-learning models. We do not use customer data for our own marketing.
4. Who we share data with
We share data only with the following processors, each strictly to operate the service:
- Shopify Inc. — the platform we are embedded in; data flows back and forth via the Shopify Admin API and webhooks
- Meta Platforms (WhatsApp Business Platform) — outbound messages, template approval, and delivery webhooks are routed through Meta's WhatsApp Cloud API. Meta bills the merchant directly per conversation; we are not a billing intermediary
- Our hosting provider — virtual servers and managed PostgreSQL inside the EU/US that store the data described above
- Error monitoring and logs — operational logs that may incidentally contain shop domain, request IDs, and (in rare error cases) a redacted customer phone number for diagnosis
We may disclose data when required by law, valid legal process, or to defend our legal rights, after notifying the affected merchant where lawful.
5. Data retention
- While installed: we retain merchant configuration, encrypted WABA tokens, and a rolling history of outbound messages and campaign attribution so the admin dashboard works
- On uninstall: Shopify fires the app/uninstalled webhook. We cascade-delete every row keyed to that shop within minutes — configuration, templates, campaign runs, conversions, short links, analytics rollups, the WhatsApp account record, and OAuth sessions
- After uninstall (48-hour mark): Shopify fires shop/redact. We run the same cascade defensively as a second safety net
- Customer redact: Shopify fires customers/redact when a customer exercises their right to deletion. We replace the matching phone number on every campaign run row with the literal [REDACTED] — the audit row stays so the merchant can prove what was sent, but the personal identifier is gone
6. Your rights
Depending on your jurisdiction (GDPR for the EU/UK, CCPA for California, and similar laws elsewhere) you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data
- Object to or restrict certain processing
- Receive your data in a portable, machine-readable format
- Lodge a complaint with your local data-protection authority
Merchants can exercise these rights by contacting us at the address in section 11. Customers of a Shopify store should contact the merchant directly — the merchant is the data controller for their own customer relationships, and we act as a processor for them.
7. Deletion & GDPR webhooks
We implement Shopify's three mandatory GDPR webhooks:
- customers/data_request — when a customer asks for their data, we log the request and forward the obligation to the merchant; the merchant is the data controller for their customers
- customers/redact — we scrub the customer's phone number from every campaign-run row that targeted them
- shop/redact — we run a full cascade delete on all data keyed to the shop, including OAuth sessions
8. Security
- All data in transit is encrypted with TLS 1.2+
- Meta access tokens are encrypted at rest with AES-256-GCM using a key held outside the database
- Shopify webhook payloads are verified with HMAC-SHA256 before any database write
- Meta webhook payloads are verified against the configured app secret before processing
- Database access is restricted to the application service account; no shared admin credentials
No system is perfectly secure. If we become aware of a material breach affecting your data we will notify you without undue delay and report to regulators as required by law.
9. Children's privacy
Wappsello is a business-to-business product for Shopify merchants. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data through our service, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we make material changes we will revise the “Last updated” date at the top of this page. Continued use of the app after an update constitutes acceptance of the revised policy.
11. Contact
For any privacy-related question, request, or complaint, contact us at harun.ketenci@admosphere.com.tr. We aim to respond to all requests within 30 days.