Privacy policy

Last updated · 2026-09-20

AutoWtsp answers your customers' WhatsApp messages on your behalf. That means we handle two kinds of personal data: yours, as the merchant who signed up, and your customers', who never signed up with us at all. This page says exactly what we hold, why, who else sees it, and how to get rid of it.

Who we are

AutoWtsp is operated from Morocco and provides the WhatsApp assistant described on this site. For your customers' data we act as a processor on your instructions: you are the merchant, it is your shop, and the customer is yours. For your own account data we act as the controller.

Questions about anything on this page go to privacy@autowtsp.com.

What we collect from you

Your name, email address, password (stored only as an Argon2 hash — we cannot read it), your shop name and WhatsApp number, and the settings you choose: language, tone, delivery zones and fees, business hours, and how much autonomy you give the Agent.

Whatever you teach the Agent: products, prices, stock, FAQs, policies, and any document you upload.

If you connect Shopify, WooCommerce or YouCan, we store an access credential for that shop, encrypted. It is never displayed back to you, not even masked, and the only repair for a lost one is to reconnect.

What we collect from your customers

The messages they send to your WhatsApp number and the replies sent back, their phone number, the name WhatsApp reports, and anything they tell the Agent in the course of ordering — typically a delivery address and a city.

We also keep a short summary of each conversation and a small set of remembered facts, so the Agent stops asking someone their city every time they write. That is the whole purpose of it.

We do not buy, sell, rent or share customer data with anyone for advertising, and we do not build profiles of your customers for any purpose outside your own shop.

Why we are allowed to hold it

Your account data: to provide the service you asked for, and to bill you if and when billing exists.

Your customers' data: on your instructions, to answer them and record their order. You are responsible for having a lawful basis for the conversation itself — in practice, a customer who messages your shop has started one.

Who else sees it

Google (Gemini), which generates replies and computes the search index over your knowledge. The question, the relevant part of your own knowledge and the recent turns of the conversation are sent for each generated answer. Answers already known are served from our own cache and reach no model at all.

Meta (WhatsApp), which carries the messages. This is unavoidable — it is the channel.

Our hosting and database providers, which store the data at rest.

Resend, which delivers the emails we send you: password resets, address verification, and nothing to your customers. It receives your email address and the message.

The shop platform you connect — Shopify, WooCommerce or YouCan — which we read your catalogue from and whose credential we hold for that purpose. Nothing about your customers is sent to it.

Sentry, our error-monitoring provider, when something crashes. What it receives is the type of error, the code path it happened in, and the identifiers that let us find the same event in our own logs — the request, workspace and user ids. What it does not receive is the request itself: no message bodies, no headers, no cookies, no email addresses, no customer text, and no local variables from the code that failed. Those are removed before the report is sent, and there are tests that hold us to it.

That is the complete list. No analytics broker, no advertising network, no data reseller.

Where it lives, and for how long

Data is stored on managed infrastructure in the European Union. Transfers happen because the processors above operate globally; they are covered by those providers' standard contractual terms.

Conversations, orders and the answer ledger are kept while your account is open, because they are your commercial records. Cached answers expire after seven days. Delete your account and we delete the workspace and everything under it within 30 days, except records we are separately required to keep.

Your rights, and your customers'

Access, correction, deletion, objection and portability — for you, by writing to privacy@autowtsp.com; for your customers, through you, and we will act on any instruction you give us about their data.

Deletion is a request, not a button — write to privacy@autowtsp.com from the address on the account and we act within 30 days. There is one procedure and it removes the workspace and everything under it: conversations, messages, customers, orders, products, knowledge, the answer cache, the evaluation ledger, store credentials and the usage counter. Crash reports already sent to Sentry are not part of it; they carry a workspace id and no content, and they expire on that provider's own retention.

Export is the same: ask from the address on the account and we send you a machine-readable copy of everything under your workspace — conversations, customers, orders, products, knowledge and settings — within 30 days. There is no self-serve export screen yet; the export is produced by us, from a documented procedure, and we would rather say so than put a button here that does not exist.

Deleting a single customer anonymises them in place rather than erasing their orders, because an order is a financial record and destroying it would falsify your own books.

Under Moroccan law 09-08 you may also complain to the CNDP.

How your WhatsApp number is connected

By default your shop is connected by scanning a code from your phone, the same way WhatsApp Web is. This uses WhatsApp's multi-device protocol through an unofficial client, not a product Meta offers or supports. WhatsApp's terms allow it to restrict or ban a number it believes is using an unofficial client, and merchants using such clients have had numbers banned. We keep the connection conservative — no bulk sending, no marking messages read on your behalf, no unsolicited outreach — but we cannot rule the risk out, and a banned number is a loss to your business that we cannot undo.

By connecting a number this way you accept that risk knowingly. If your business cannot tolerate it, ask us about connecting through the official WhatsApp Business Platform instead, which Meta supports and which requires a business verification with them.

Your device credentials and the message keys for the connection are encrypted at rest with a key held separately from the database. Disconnecting from the dashboard removes the device from your phone's linked devices and deletes those credentials.

Security

Passwords are hashed with Argon2. Third-party shop credentials are encrypted at rest with a key we hold separately. Every request is scoped to one workspace at the database layer, so one merchant's query cannot reach another's rows. To stop password guessing and email flooding we count requests per network address; the address is kept only as a one-way digest and discarded within a day.

We do not claim to be unbreachable. If we are breached and your data is affected, we will tell you what happened and what was taken.

Cookies

A session cookie so you stay signed in; a cookie remembering which language you chose; a cookie remembering whether you prefer the light or dark theme; and, only if you open the invitation-only product demo, a cookie holding your demo pass for that visit. Nothing else. There is no advertising or cross-site tracking on this site.

Changes

If we change this policy in a way that affects what we do with your data, we will tell you before it takes effect rather than after. The date at the top is the date of the current version.