Legal
Privacy Policy
Effective date: July 13, 2026
WarpCart ("WarpCart," "we," "us," or "our") is an AI-powered WhatsApp commerce platform that helps businesses run storefronts, catalogs, carts, payments, and order tracking on WhatsApp. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use our website, vendor dashboard, APIs, and related services (collectively, the "Service").
1. Who this policy covers
This policy applies to:
- Vendors and staff — people who create or manage a WarpCart tenant, store, catalog, payments, WhatsApp connection, or subscription.
- Shoppers— end customers who browse, chat, order, or pay through a vendor's WhatsApp storefront or related shop experience powered by WarpCart.
- Website visitors — people who visit our marketing site or sign-in pages.
If you are a shopper interacting with a vendor on WhatsApp, that vendor is typically the merchant of record for your purchase. WarpCart processes shopper data to operate the messaging, commerce, payment, and AI features the vendor enables.
2. Information we collect
2.1 Account and vendor information
When you sign up or manage a store, we may collect:
- Name, email address, and password (stored as a secure hash)
- Phone number and verification status (including SMS OTP challenges)
- Profile image (including when you sign in with Google)
- Store details such as store name, description, logo, branding colors, business mode, default currency, and locale preferences
- Membership and role information within a tenant
- Subscription and plan usage information
2.2 Authentication and session data
- Session tokens and cookies used to keep you signed in
- OAuth account identifiers and tokens when you connect Google (access/refresh tokens as provided by the identity provider)
- Email magic-link / OTP verification records
- Active tenant selection for multi-store vendors
2.3 Shopper and commerce data
To run WhatsApp commerce for a vendor, we may process:
- WhatsApp phone number (E.164) and display name
- Conversation messages and metadata exchanged through the storefront
- Cart contents, orders, line items, prices, currency, and order status
- Delivery or fulfillment address when provided during checkout
- Payment status and related transaction references
2.4 Payments and settlements
WarpCart integrates with Safaricom M-Pesa (Daraja) for customer payments and vendor payouts. Depending on the flow, we may process:
- Payment amounts, currency, status, checkout request IDs, and receipt numbers
- Provider webhook payloads needed to confirm or reconcile transactions
- Vendor wallet balances and settlement destinations (for example phone number, Pochi la Biashara, Paybill, or Till details)
Card numbers and M-Pesa PINs are handled by the payment provider; WarpCart does not ask you to store M-Pesa PINs in our application.
2.5 WhatsApp and messaging infrastructure
- WhatsApp Business connection details needed to send and receive messages (including encrypted provider credentials where applicable)
- Message content routed through Vonage and, where configured, Twilio templates
- Meta/WhatsApp Business onboarding information collected during hosted signup
2.6 AI assistant and knowledge base
- Documents and FAQs you upload (including PDF and Word files), plus derived text chunks and embeddings used for retrieval
- AI session messages and model metadata generated while assisting vendors or shoppers
Message and document content may be sent to OpenAI and/or Azure OpenAI to generate replies and embeddings.
2.7 Technical and operational data
- IP address and user agent when recorded in audit or operational logs
- Product images, store logos, and other uploaded files
- Usage metering related to your plan
- Basic UI preferences stored locally in your browser (for example sidebar state)
3. How we use information
We use personal information to:
- Provide, operate, and improve the Service
- Create and manage vendor accounts, tenants, stores, and staff access
- Authenticate users and verify email or phone ownership
- Sync catalogs, carts, checkouts, orders, and customer conversations on WhatsApp
- Process M-Pesa payments, reconcile webhooks, and handle vendor wallet withdrawals
- Power AI assistance, recommendations, and knowledge-base answers
- Send transactional emails and SMS (OTP codes, security notices, service messages)
- Monitor reliability, prevent fraud and abuse, and maintain audit trails
- Comply with legal obligations and enforce our terms
We do not sell personal information. We do not currently use third-party advertising pixels or behavioral ad networks on the Service.
4. Legal bases
Where applicable privacy laws require a legal basis, we rely on:
- Contract — to provide the Service you or your organization requested
- Legitimate interests — to secure, improve, and operate the platform in ways that do not override your rights
- Consent — where required (for example certain marketing messages or optional integrations)
- Legal obligation — when we must retain or disclose information to meet applicable law
7. Data retention
We retain personal information for as long as needed to provide the Service, meet contractual and legal obligations, resolve disputes, and enforce our agreements. Examples:
- Account and store records while your tenant remains active
- Orders, payment references, and wallet history for accounting and dispute handling
- OTP challenges until expiry or consumption, then according to our cleanup practices
- Conversation and AI message logs needed to operate and support the storefront
- Uploaded knowledge documents until you delete them or close the related account
When data is no longer required, we delete or anonymize it, subject to backups and legal holds.
8. Security
We implement technical and organizational measures designed to protect personal data, including password hashing, encrypted storage of certain provider secrets, authenticated APIs, tenant scoping, and access controls. No method of transmission or storage is 100% secure. If you believe your account or a storefront has been compromised, contact us promptly.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority.
Vendors can update much of their profile and store data in the dashboard. Shoppers should start with the vendor they purchased from, and may also contact WarpCart using the details below. We may need to verify your identity before fulfilling a request.
10. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.
11. International transfers
WarpCart and our processors may process data in Kenya and other countries where our infrastructure or subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers.
12. Vendors and their customers
Vendors are responsible for providing their own customer-facing notices where required, honoring applicable messaging and marketing consent rules on WhatsApp, and using shopper data only for legitimate commerce purposes. WarpCart processes shopper data on behalf of vendors to deliver messaging, catalog, checkout, payment, and AI features.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be communicated through the Service or by email where appropriate.
14. Contact us
For privacy questions, requests, or complaints, contact:
- Email: privacy@warpcart.app
- Product: WarpCart
This policy is provided for transparency about how WarpCart works. It is not legal advice. Have counsel review it before relying on it for regulatory compliance.
