Legal

Privacy Policy

Effective date: July 13, 2026

WarpCart ("WarpCart," "we," "us," or "our") is an AI-powered WhatsApp commerce platform that helps businesses run storefronts, catalogs, carts, payments, and order tracking on WhatsApp. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use our website, vendor dashboard, APIs, and related services (collectively, the "Service").

1. Who this policy covers

This policy applies to:

  • Vendors and staff — people who create or manage a WarpCart tenant, store, catalog, payments, WhatsApp connection, or subscription.
  • Shoppers— end customers who browse, chat, order, or pay through a vendor's WhatsApp storefront or related shop experience powered by WarpCart.
  • Website visitors — people who visit our marketing site or sign-in pages.

If you are a shopper interacting with a vendor on WhatsApp, that vendor is typically the merchant of record for your purchase. WarpCart processes shopper data to operate the messaging, commerce, payment, and AI features the vendor enables.

2. Information we collect

2.1 Account and vendor information

When you sign up or manage a store, we may collect:

  • Name, email address, and password (stored as a secure hash)
  • Phone number and verification status (including SMS OTP challenges)
  • Profile image (including when you sign in with Google)
  • Store details such as store name, description, logo, branding colors, business mode, default currency, and locale preferences
  • Membership and role information within a tenant
  • Subscription and plan usage information

2.2 Authentication and session data

  • Session tokens and cookies used to keep you signed in
  • OAuth account identifiers and tokens when you connect Google (access/refresh tokens as provided by the identity provider)
  • Email magic-link / OTP verification records
  • Active tenant selection for multi-store vendors

2.3 Shopper and commerce data

To run WhatsApp commerce for a vendor, we may process:

  • WhatsApp phone number (E.164) and display name
  • Conversation messages and metadata exchanged through the storefront
  • Cart contents, orders, line items, prices, currency, and order status
  • Delivery or fulfillment address when provided during checkout
  • Payment status and related transaction references

2.4 Payments and settlements

WarpCart integrates with Safaricom M-Pesa (Daraja) for customer payments and vendor payouts. Depending on the flow, we may process:

  • Payment amounts, currency, status, checkout request IDs, and receipt numbers
  • Provider webhook payloads needed to confirm or reconcile transactions
  • Vendor wallet balances and settlement destinations (for example phone number, Pochi la Biashara, Paybill, or Till details)

Card numbers and M-Pesa PINs are handled by the payment provider; WarpCart does not ask you to store M-Pesa PINs in our application.

2.5 WhatsApp and messaging infrastructure

  • WhatsApp Business connection details needed to send and receive messages (including encrypted provider credentials where applicable)
  • Message content routed through Vonage and, where configured, Twilio templates
  • Meta/WhatsApp Business onboarding information collected during hosted signup

2.6 AI assistant and knowledge base

  • Documents and FAQs you upload (including PDF and Word files), plus derived text chunks and embeddings used for retrieval
  • AI session messages and model metadata generated while assisting vendors or shoppers

Message and document content may be sent to OpenAI and/or Azure OpenAI to generate replies and embeddings.

2.7 Technical and operational data

  • IP address and user agent when recorded in audit or operational logs
  • Product images, store logos, and other uploaded files
  • Usage metering related to your plan
  • Basic UI preferences stored locally in your browser (for example sidebar state)

3. How we use information

We use personal information to:

  • Provide, operate, and improve the Service
  • Create and manage vendor accounts, tenants, stores, and staff access
  • Authenticate users and verify email or phone ownership
  • Sync catalogs, carts, checkouts, orders, and customer conversations on WhatsApp
  • Process M-Pesa payments, reconcile webhooks, and handle vendor wallet withdrawals
  • Power AI assistance, recommendations, and knowledge-base answers
  • Send transactional emails and SMS (OTP codes, security notices, service messages)
  • Monitor reliability, prevent fraud and abuse, and maintain audit trails
  • Comply with legal obligations and enforce our terms

We do not sell personal information. We do not currently use third-party advertising pixels or behavioral ad networks on the Service.

5. How we share information

We share information only as needed to run the Service, including with:

  • Vonage — WhatsApp messaging, SMS OTPs, and related channel provisioning
  • Meta — WhatsApp Business account linking and messaging compliance via the WhatsApp channel
  • Twilio — optional WhatsApp template messaging where configured
  • Safaricom / M-Pesa Daraja — payment initiation, confirmation, and payouts
  • OpenAI / Azure OpenAI — AI chat and embedding generation
  • Google — if you choose Google sign-in
  • Email/SMTP providers — transactional email delivery
  • Infrastructure providers — hosting, databases, and Redis caching used to operate WarpCart
  • Vendors— shopper chat, order, and payment data belonging to that vendor's storefront
  • Professional advisors or authorities — when required by law or to protect rights, safety, and security

Service providers are instructed to process personal data only for specified purposes and in accordance with applicable agreements and law.

6. Cookies and similar technologies

We use cookies and similar technologies for essential operation of the Service:

  • Authentication cookies — to maintain your signed-in session (NextAuth JWT session, typically up to 30 days)
  • Tenant preference cookie — to remember the active store for vendors with multiple memberships
  • Local storage — for non-essential UI preferences such as sidebar collapsed state

These technologies are primarily required for security and core functionality. You can control cookies through your browser settings, but disabling essential cookies may prevent sign-in or multi-store switching from working correctly.

7. Data retention

We retain personal information for as long as needed to provide the Service, meet contractual and legal obligations, resolve disputes, and enforce our agreements. Examples:

  • Account and store records while your tenant remains active
  • Orders, payment references, and wallet history for accounting and dispute handling
  • OTP challenges until expiry or consumption, then according to our cleanup practices
  • Conversation and AI message logs needed to operate and support the storefront
  • Uploaded knowledge documents until you delete them or close the related account

When data is no longer required, we delete or anonymize it, subject to backups and legal holds.

8. Security

We implement technical and organizational measures designed to protect personal data, including password hashing, encrypted storage of certain provider secrets, authenticated APIs, tenant scoping, and access controls. No method of transmission or storage is 100% secure. If you believe your account or a storefront has been compromised, contact us promptly.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority.

Vendors can update much of their profile and store data in the dashboard. Shoppers should start with the vendor they purchased from, and may also contact WarpCart using the details below. We may need to verify your identity before fulfilling a request.

10. Children

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.

11. International transfers

WarpCart and our processors may process data in Kenya and other countries where our infrastructure or subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers.

12. Vendors and their customers

Vendors are responsible for providing their own customer-facing notices where required, honoring applicable messaging and marketing consent rules on WhatsApp, and using shopper data only for legitimate commerce purposes. WarpCart processes shopper data on behalf of vendors to deliver messaging, catalog, checkout, payment, and AI features.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be communicated through the Service or by email where appropriate.

14. Contact us

For privacy questions, requests, or complaints, contact:

This policy is provided for transparency about how WarpCart works. It is not legal advice. Have counsel review it before relying on it for regulatory compliance.