Privacy Policy
This policy explains what data WhatCart collects, why, how we use and protect it, and the rights you have. It covers whatcart.net, the merchant app at app.whatcart.net and its mobile apps.
Effective and last updated: 25 September 2026
1. Who we are
WhatCart is software that helps merchants manage orders, stock, shipping and customer conversations on WhatsApp. WhatCart is operated by BitTechs in Egypt (“WhatCart”, “we”, “us”).
For privacy and data requests: privacy@whatcart.net. For general questions: hello@whatcart.net. We are contacted by email only.
2. Our role
- Merchant account data: we are the controller. We decide why and how it is processed.
- Buyer data (the merchant’s customers): we process it as a service provider and processor on behalf of the merchant and on their instructions. The buyer’s relationship is with the merchant they buy from, and the merchant is responsible for telling their customers how their data is used.
3. Data we collect
Merchant account data:
- Name, email and password (stored only as a hash, never in plain text), and passkey public keys if you use passkeys.
- Business phone number and store settings (name, logo, currency and similar).
- Team members the merchant invites and their permissions.
- Device sessions, IP addresses and device type, for security and sign-in.
Store operations data the merchant enters or receives through the service:
- Products, prices, stock and product images.
- Orders, buyer names, phone numbers and delivery addresses, including a GPS location or maps link if the buyer chooses to send one.
- Order history, payment records (such as transfers, transfer proofs and cash on delivery), returns, and courier shipment data.
WhatsApp data through the WhatsApp Business Platform (Cloud API), after the merchant connects their number with Meta Embedded Signup:
- WhatsApp Business Account (WABA) ID, phone number ID and number details (display name, quality rating, messaging limit).
- The business integration token issued by Meta, stored encrypted.
- Content and media of messages exchanged between the merchant and their buyers: images, voice notes, documents, locations and contacts.
- Message status (sent, delivered, read, failed) and message templates.
- Catalog and product data synced with Meta.
- Each buyer’s marketing opt-in or opt-out status.
Payment providers (Paymob, and Stripe Connect when enabled): transaction references, status and amount. WhatCart never receives or stores full card numbers; card details are entered with the payment provider directly.
Couriers: tracking numbers and shipment status updates received by webhook or from files the merchant uploads.
Technical data: server logs, security events (such as failed sign-ins), and an audit log of sensitive actions in the store.
4. How we use data
- To provide and run the service: products, orders, stock, shipments and payments.
- To send order and shipping messages to buyers on WhatsApp on the merchant’s behalf, and receive their replies.
- To sync the merchant’s catalog with Meta.
- To protect accounts and prevent fraud and abuse.
- To give support when the merchant asks.
- To send service emails, such as email verification, password reset, team invitations and alerts.
- To comply with the law and respond to binding official requests.
What we do not do:
- We do not sell or rent personal data.
- We do not use data for advertising or share it with ad networks.
- We do not use WhatsApp data to train AI models, or to profile people beyond what is needed to provide the service.
5. Meta and WhatsApp
To deliver WhatsApp messages and catalogs, we exchange data with Meta Platforms through the WhatsApp Business Platform. Meta’s processing is subject to its own terms and policies, including the WhatsApp Business Policy https://www.whatsapp.com/legal/business-policy and the Meta Privacy Policy https://www.facebook.com/privacy/policy
We use data received from the Meta Platform only to provide the service to the merchant who connected it. We do not use it for any other purpose or pass it to other merchants.
A merchant can disconnect WhatsApp at any time in Settings → Channels. Disconnecting revokes our access to their account and wipes the stored integration token. If the merchant removes WhatCart in their Meta settings, we disconnect automatically when Meta notifies us.
8. Retention
- Merchant account and store data: while the account is active, then for up to 12 months after deletion for legal and security purposes, unless the law requires us to keep certain records longer.
- WhatsApp media (images, voice notes, documents): deleted automatically after the retention period the merchant sets in Settings, 12 months by default. This does not apply to product images or files the merchant keeps as transfer proof.
- Audit log: 12 months.
- Server logs: up to 12 months, for operations and security.
- Backups: kept for up to 12 months; deleted data leaves the backups as they cycle out.
Full data deletion instructions: https://whatcart.net/data-deletion
9. Security
- Encryption in transit (HTTPS/TLS) for all connections.
- Meta tokens and other secrets encrypted at rest.
- Each store’s data isolated from other stores.
- Role-based permissions for team members, and step-up verification before sensitive actions such as connecting or disconnecting WhatsApp.
- Audit logging of sensitive actions.
No system is perfectly secure, but we work continuously to protect data, and we notify affected people and authorities of a breach as the law requires.
10. Your rights
Under applicable data protection laws, including the EU/UK GDPR, Egypt’s Personal Data Protection Law No. 151 of 2020, and US state privacy laws such as the CCPA/CPRA where they apply, you have the right to:
- Access your data and get a copy.
- Correct inaccurate data.
- Delete your data.
- Object to or restrict processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting processing done before.
To exercise these rights, email privacy@whatcart.net. We respond within 30 days and may ask you to confirm your identity first.
If you are a buyer, contact the merchant you bought from first: they are responsible for your data, and we help them carry out your request. You can also email us directly.
11. Children
WhatCart is for businesses and is not directed to anyone under 18. We do not knowingly collect their data.
12. Changes to this policy
We post any update on this page and change the “last updated” date. For material changes, we tell merchants by email or in the app before they take effect.
13. Contact
Privacy and data requests: privacy@whatcart.net. General questions: hello@whatcart.net. WhatCart, operated by BitTechs, Egypt.