WhatsApp Pilot
Privacy Policy
WhatsApp Pilot is a Shopify app by E-SAFQA. It helps merchants add a floating WhatsApp button to their storefront, send transactional Order Confirmation messages, and recover abandoned checkouts with merchant-configured WhatsApp reminders.
Last updated: 26 August 2026
Who this policy covers
This policy describes how the app processes information about merchants (the store) and about the merchant’s customers when the merchant installs and uses WhatsApp Pilot.
Shopify authorization
The app uses Shopify authorization (OAuth / session tokens) to install the app, identify the shop, and keep the merchant signed in inside Shopify Admin.
What the app does
- Floating widget. Merchants save a WhatsApp contact number and button settings so shoppers can start a chat from the storefront.
- Order Confirmation. When enabled by the merchant, the app uses new-order events to send a merchant-configured WhatsApp confirmation. This is a transactional message about an order the customer already placed. The app uses that order data to choose a recipient phone number and to personalize the message with order, name, and shipping details the merchant includes.
- Abandoned Cart Recovery. Abandoned Cart Recovery is available on Pro. WhatsApp must be connected. Recovery messages are sent only when the same phone number used at checkout has already granted WhatsApp marketing consent. Ineligible customers are skipped. Eligible recovery messages may include an optional merchant-configured recovery discount.
Shopify data we access
The app requests:
read_themes— theme / app embed status for the floating widgetread_orders— new-order events for Order Confirmation and to stop recovery after a matching order is completedread_customers— customer phone information may be used to determine a recovery recipient. WhatsApp marketing-consent status is read to decide whether a recovery message is eligible to sendwrite_discounts/read_discounts— the app can create and verify unique, merchant-configured recovery discounts
Name, phone, and address used for Order Confirmation may also come from the Shopify order event. The app does not use customer lists or segments to run bulk campaigns.
Protected customer fields the app may use:
- Name — personalize messages (for example, first name)
- Phone — deliver WhatsApp messages and determine the recovery recipient
- Address — personalize order messages when the merchant’s template includes shipping or billing details
The app does not request customer Email for Order Confirmation or checkout recovery.
Why we process this data
- App functionality — run the floating widget, receive order and checkout events, choose a message recipient, send merchant-configured WhatsApp messages, and create or verify merchant-configured recovery discounts
- Personalization — replace message variables such as name, order number, totals, and shipping or address details
Abandoned Cart Recovery messages are merchant-configured reminders and may be treated as marketing messages. They are sent only when the same phone number used at checkout has already granted WhatsApp marketing consent. Ineligible customers are skipped. We do not use customer data for our own advertising. The Shopify protected customer data purpose for marketing or advertising remains in place for this product.
Merchant settings we store
- Widget appearance, visibility, and greeting text
- WhatsApp contact details entered by the merchant for click-to-chat
- Automation flow drafts (message templates, timing, language, optional recovery discount settings)
- Merchant send preferences (for example, opting in to order messages)
Customer data we store
We do not keep the raw Shopify webhook body. We keep only what is needed to send, support, and measure messages:
- Shopify order or checkout identifiers
- Recipient phone, stored encrypted, with a masked display value
- Rendered message text (may include name or address if the merchant’s template uses those variables)
- Short-link records whose destination URLs are stored encrypted
- Encrypted recovery discount codes and hashed values used to verify redemption
- Dispatch and internal message records used to prevent duplicates
Analytics events do not store the full phone number, the full message text, the raw recovery checkout URL, or the discount code.
Consent
Order Confirmation is a transactional message about an order the customer placed. Abandoned Cart Recovery is available on Pro when WhatsApp is connected. Recovery messages are sent only when the same phone number used at checkout has already granted WhatsApp marketing consent. Ineligible customers are skipped. The app does not sell customer data and does not treat customer data as a “sale” or similar sharing under applicable privacy laws.
Retention, security, and deletion
- Customer-linked operational and message records are kept for 90 days, then deleted.
- Data is transmitted over HTTPS and stored in an encrypted database. Recipient phone numbers, recovery destinations, and discount codes are encrypted by the app before storage.
- Shopify compliance webhooks are supported: customer data request, customer redact, and shop redact. Uninstall also deletes shop-owned app data.
- Merchants can also email mosa.alhelo@gmail.com to request deletion or a copy of app-owned customer data. After Shopify sends a customer data request, the authenticated merchant can download that shop’s export from Support inside WhatsApp Pilot.
Sharing
The app does not sell merchant or customer data. Data is processed by hosting, database, and messaging infrastructure needed to run the app and deliver merchant-configured WhatsApp messages. We do not use customer data for our own advertising.
This policy is provided so merchants and Shopify can understand how WhatsApp Pilot handles data. It is not legal advice.