Privacy Policy
Last updated: 28 July 2026
1. Who this covers
This policy covers: (a) merchants and staff who create Wasl Cart accounts on https://app.waslcart.online; (b) shoppers and other end users whose data merchants or connected stores send to Wasl Cart so we can provide verification, messaging, and related features.
2. Roles and responsibility
For store customer data (phone numbers, order details, WhatsApp message content metadata, consent flags, and similar fields), the merchant typically determines the purposes of processing. Wasl Cart processes that data on the merchant’s instructions to operate the SaaS platform. Merchants must have a lawful basis to collect and share customer data with us and must honor opt-outs (including WhatsApp STOP replies where applicable).
3. Data we process
Depending on how you use the product, we may process:
- Account data: name, email, password (stored hashed), shop/account name, staff memberships, and policy acceptance records (terms/privacy version and acceptance time).
- Store connection data: platform (Shopify or WooCommerce), store URL/name, API credentials (secrets hashed or encrypted where applicable), and webhook-related secrets.
- Order and customer data: identifiers, names, emails, phone numbers (E.164), order totals/currency, payment method labels (e.g. COD), risk signals, OTP verification status, tracking/courier fields merchants provide, and related metadata.
- Abandoned checkout data: phone, email, cart snapshot, marketing consent flags, and recovery status when merchants sync this data.
- Messaging data: destination phone, template identifiers, delivery/read statuses, provider message IDs, credit ledger entries, inbox conversations/notes. One-time passwords (OTPs) are stored as irreversible hashes; plaintext OTP codes are not retained in message payload records.
- Billing data: plan/subscription records, invoices, Shopify App Billing charge references when used, and manual payment proofs (for example bank transfer, JazzCash, or EasyPaisa proof uploads) for WooCommerce / manual billing.
- Dedicated WhatsApp requests: business details submitted for number setup, status, and related fees.
- Support: in-app support tickets (subject, description, category, priority) and admin audit logs (with secret fields stripped where implemented).
We do not sell personal data.
4. How we use data
We use data to provide and secure Wasl Cart: COD/order verification via WhatsApp OTP, automations and campaigns (subject to merchant configuration and consent flags), inbox replies, billing and credit accounting, support, abuse prevention, and product operations. We do not operate a separate email marketing list in the application; marketing-style outreach on WhatsApp is controlled by merchant features and consent/opt-out settings.
5. WhatsApp / Meta
When Cloud API messaging is enabled, messages are sent through WhatsApp Business capabilities provided by Meta Platforms. Meta’s terms and privacy policies apply to delivery on WhatsApp. Meta may process message content and related metadata as an independent provider. Template and phone-number approval decisions are controlled by Meta; Wasl Cart does not guarantee Meta approval.
6. Sharing and processors
We share data with processors needed to run the service, including:
- Third-party web hosting and related infrastructure providers.
- Meta / WhatsApp Cloud API for message delivery and webhooks (webhook requests are verified with HMAC signatures when configured).
- Shopify, when you install and use the Wasl Cart Shopify app (including Shopify App Billing for eligible charges).
- Your own WooCommerce/WordPress store when you connect a plugin and sync orders or events.
Wasl Cart does not currently integrate Stripe or PayPal as payment processors. Manual payment proofs are reviewed by Wasl Cart operators; bank/JazzCash/EasyPaisa rails are described for merchant payment instructions, not as embedded payment gateways inside Wasl Cart.
We may disclose information if required by law or to protect rights, safety, and the integrity of the service.
7. Cookies
The marketing site at waslcart.online does not set analytics or advertising cookies. The SaaS application at app.waslcart.online uses essential cookies for session authentication and CSRF protection (Laravel session and XSRF-TOKEN cookies). See our Cookie Policy.
8. Retention
Default operational retention guidance: 365 days (account default; subject to legal and billing retention). Billing, invoice, payment-proof, and audit records may be kept longer where required for disputes, tax, or compliance. After account deletion requests are completed, we remove or anonymize merchant operational data as described in our Data Deletion instructions, subject to those retained categories.
9. Security
We use HTTPS in production, hashed passwords, hashed OTP codes, hashed or encrypted store secrets where applicable, account-scoped access controls, and signed webhooks for WhatsApp. No method of transmission or storage is completely secure. Merchants remain responsible for protecting their login credentials and store API secrets shown in the dashboard.
10. Your choices and deletion
Merchants can update account profile data in the dashboard, open Help tickets, and request account/data deletion from Account & Privacy settings (password re-authentication required) or by emailing us. Processing timeframes are described on the Data Deletion page (target: 30 days) . Shoppers should contact the merchant store first for order-related privacy requests; we support merchants and, where appropriate, process deletion requests that identify Meta or Wasl Cart-held data.
11. Contact
Privacy questions: support@waslcart.com
Internal note for operators: this policy should be reviewed by a qualified legal professional before public launch. It describes the product as implemented and is not a substitute for legal advice.