ChatVendor
API Live

Privacy Policy

Last Updated: August 2026

1. Overview & Roles Under GDPR

ChatVendor ("we", "our", or "us") provides conversational commerce infrastructure connecting merchant businesses ("Merchants") with WhatsApp via Meta’s Cloud API.

Under the EU General Data Protection Regulation (GDPR):

  • Merchant: Acts as the Data Controller for their customer interactions and order fulfillments.
  • ChatVendor: Acts as the Data Processor hosting database instances and executing messaging workflows.
  • Meta Platforms, Inc.: Acts as a technical sub-processor providing the WhatsApp messaging channel under certified Data Privacy Frameworks and Standard Contractual Clauses (SCCs).

2. Information We Process

A. Merchant Credentials: Authorized WhatsApp Business Account (WABA) IDs, Phone Number IDs, display names, and OAuth access tokens required to route API requests.

B. Messaging & Cart Payloads: Customer WhatsApp phone numbers, active cart item selections, delivery preferences, and order timestamps.

C. System Logs: Timestamped API delivery statuses and webhook receipt records.

3. Data Residency & Infrastructure Security

Merchant and customer relational data is stored on managed libSQL/Turso database instances utilizing AES-256 encryption at rest and TLS 1.3 encryption in transit. Database instances are hosted within secure European Union cloud zones to satisfy data residency requirements.

4. Customer Data Subject Rights (Articles 15 & 17)

We provide automated and programmatic mechanisms for end-customers to exercise their rights:

• Right of Access (Data Export): Customers may request a complete report of their active cart items and historical order receipts directly via WhatsApp messaging commands.

• Right to Erasure (Deletion & Anonymization): Customers may trigger immediate erasure of their active carts. Historical order ledgers are scrubbed of all identifying personal data (phone number, shipping details) while retaining non-identifying financial totals strictly to satisfy statutory tax and invoice record-keeping exemptions under GDPR Article 17(3)(b).

5. Merchant Offboarding & Data Purging

When a Merchant resets or offboards their store via the ChatVendor dashboard, all associated access tokens, webhooks, catalogs, carts, and customer transaction records are permanently deleted via cascading foreign key routines.

6. Contact & Data Inquiries

For privacy questions, compliance verifications, or manual data requests, contact our compliance desk:

Platform: ChatVendor

Privacy & Compliance Desk: support@chatvendor.app