Privacy Policy. This page is ready

Privacy Policy

WaSphere

Last updated: 22 June 2026


WaSphere (“WaSphere”, “we”, “us”) provides a self-hosted WhatsApp automation app for Shopify stores. We send transactional and marketing WhatsApp messages on your behalf — order confirmations, fulfillment and cancellation updates, abandoned-checkout reminders, auto-replies, and bulk broadcasts you initiate. This policy explains what data we access, why, and how we protect it. It applies to the WaSphere Shopify app and the WhatsApp connection it manages.

Data we access and process

We access only the data needed to deliver the messages you configure. Specifically:

  • Order data from your store (order number, status, line items, totals, fulfillment and tracking details) to build order-related messages.
  • Customer contact details for the recipients of those messages — name, phone number, and, where relevant to the message, shipping/billing address.
  • Your message templates, automation settings, and the delivery records (which message was sent to which recipient, and whether it was delivered).
  • Store metadata Shopify provides on install (shop domain, plan, and the access scopes you grant).

We do notread, store, or have access to your personal WhatsApp conversations. The WhatsApp connection is used to send the automated messages you configure and to receive replies that drive your auto-reply rules — nothing more. We do not scrape contacts, message history, or chats unrelated to your store’s automations.

How WhatsApp connects

WaSphere connects to WhatsApp as a linked deviceon your own WhatsApp account — the same mechanism as WhatsApp Web. You scan a QR code to link; you can unlink at any time from your phone (WhatsApp → Linked Devices) or by disconnecting inside the app. Because WaSphere is self-hosted, the connection and its session credentials live on the infrastructure operating your WaSphere instance, not on a shared third-party server.

WaSphere is an independent product and is not affiliated with, endorsed by, or sponsored by WhatsApp or Meta. The connection uses an unofficial WhatsApp interface rather than the official WhatsApp Business API. See our Terms of Service for the implications of that approach.

How we use the data

  • To compose and send the WhatsApp messages your automations and bulk campaigns define.
  • To record delivery status and usage so you can see analytics and we can enforce plan limits.
  • To operate, secure, troubleshoot, and improve the app.
  • To respond to your support requests.

We process customer personal data as your processor — you are the data controller for your customers’ information, and you are responsible for having a lawful basis (such as opt-in consent) to message them.

We do not sell your data

We never sell, rent, or trade your data or your customers’ data. We do not use it for advertising or share it with third parties except the limited service providers required to run the app (for example, hosting and the WhatsApp transport), and only to the extent needed to deliver the service.

Data retention

We keep order and recipient data only as long as needed to send the related messages and to show you delivery history and analytics. Message and delivery records are retained for your reporting and then aged out. When you uninstall the app or disconnect, we stop processing your store’s data and remove the WhatsApp session credentials.

GDPR and Shopify data requests

We honour Shopify’s mandatory privacy webhooks so your customers’ rights are respected automatically:

  • customers/data_request — when a customer asks what data you hold, we surface the WaSphere data tied to that customer.
  • customers/redact — when a customer requests erasure, we delete that customer's contact details and message records.
  • shop/redact — when you uninstall, we erase your store's data after Shopify's retention window.

If you are in the EU/UK or another region with data-protection rights, you (and your customers, through you) may request access, correction, or deletion of personal data. Email support@wasphere.com and we will action verified requests.

Security

Data in transit is encrypted with TLS. WhatsApp session credentials are stored as access-restricted secrets, never in source control. Because WaSphere is self-hosted, the operator of your instance also controls the hosting environment and is responsible for its security configuration.

Children

WaSphere is a business tool and is not directed to children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy as the app evolves. We will revise the “Last updated” date above, and material changes will be communicated through the app.

Contact

For privacy questions or data requests, contact us at support@wasphere.com.


Questions about this document? Email us at support@wasphere.com, or message us on WhatsApp at +92 332 7685715 or +44 7476 885240.

See also our Privacy Policy and Terms of Service.