Privacy Policy
Storedeko is a product of Openplanet Technologies Ltd, registered in Nigeria with the Corporate Affairs Commission under RC 1652204. This policy explains what personal data we handle, why, and what you can ask us to do about it.
Two kinds of people
Storedeko is used by merchants — businesses who sell through WhatsApp — to serve their own customers. Both appear in this policy, and the distinction matters: a merchant chooses to use Storedeko, while their customer is simply buying something. We hold customer data on the merchant's behalf, and the merchant decides how their business uses it.
What we collect from merchants
- Business name, your name, and email address, when you create an account.
- Your business logo, payment instructions and shop address, if you choose to add them.
- Bank account details — bank, account number and the account name your bank returns — so that payments reach you directly. We do not ask for your BVN.
- If you sell as a registered business, your CAC registration number, your tax identification number and a copy of your CAC certificate, where you give them to us. Sellers registering as individuals are not asked for any of these.
- Your product catalogue, prices and negotiation limits.
- A record of what each person on your team did in your account and when, and when each of them last signed in.
What we handle about customers
- Name and WhatsApp phone number.
- The content of WhatsApp conversations with the merchant, including photographs or files sent in that conversation — including conversations from before the merchant started using Storedeko, where the merchant uploads their own WhatsApp chat export so that their history moves with their number.
- Delivery address, where the merchant records one.
- An email address, where the merchant records one or the customer gives one.
- Any notes the merchant writes about a customer in their own words — these are free-form, and their contents are whatever the merchant chose to put there.
- Quotations, invoices, orders and payment status.
- A review a customer leaves after an order, and its rating. People often name themselves in a review, so we treat the text as personal data.
- A timeline of what happened with that customer — messages, quotes, invoices, payments and orders — so a merchant can see the history of one person in one place.
What we hold about a payment
We never receive a full card number, a card's security code, or a bank PIN, and we cannot. Paying happens on Paystack's own checkout page, never on ours, so those details do not pass through Storedeko at any point.
We should be precise about what we do receive, because it is more than a bare yes-or-no. When a payment succeeds, Paystack sends us a confirmation and we store it unchanged as the permanent record of that payment. Alongside the amount, the reference and whether it succeeded, that confirmation describes the instrument used: the first six and last four digits of the card, the card type, the issuing bank, the expiry month and year, and a token Paystack uses to recognise the same card again. It also carries back the customer's name and phone number, because we send those to Paystack so the payment is raised against the right person.
We keep that confirmation exactly as Paystack sent it, because an edited record of a payment is not evidence of anything. We do not use it for any purpose other than proving and reconciling the payment, and we do not share it.
What our AI and negotiation records hold
When the system drafts a reply, or handles haggling over a price, it writes down what it did. That record includes what it took the customer to be asking for, the reply it drafted, the price it was prepared to offer that customer, and whether the merchant's own rules allowed the reply to be sent. Drafts the rules rejected are kept as well — knowing what the system was stopped from saying is most of the reason for keeping any of it.
Where a customer haggles, we also record what they offered, what we quoted them, and how many rounds it took to get there.
These are conclusions about a person, drawn from that person's own messages, and we treat them as personal data rather than as system logs. They exist to serve that conversation and to let a merchant check what was said in their name. They are not used to build a profile of anyone across different merchants, they are not used to advertise, and they are not sold.
Technical and operational records
Some records exist to keep the service running rather than to run a shop, and they contain personal data too. Naming them is more useful than leaving them under a heading like "technical data".
- Messages as WhatsApp delivered them. When Meta delivers a message we store the delivery exactly as it arrived — including the sender's phone number, their WhatsApp profile name and the message text — before we have worked out which merchant it belongs to. This is what lets us replay a message that failed to process instead of losing it. A job that fails repeatedly is set aside for an engineer with its contents intact, for the same reason.
- An audit log of actions taken in a merchant's account: who did what, to which record, and when. It cannot be edited or deleted by anyone, including us. That is the property that makes it worth having.
- Server request logs recording the time, the method, the path, the response status, how long the request took, and a request id. They do not contain IP addresses, request contents, passwords or access tokens — the logging code can only emit a fixed list of fields, so there is nothing in it to leak. These are held by our hosting provider and are not linked to any customer record.
- One exception on addresses. When a webhook reaches us carrying an invalid signature, we log the network address it came from, because a burst of those is how we notice somebody probing the service. We do not record network addresses for ordinary, valid traffic.
Why we handle it
To operate the service a merchant has signed up for: to record conversations, produce quotations and invoices, take payments, create orders, and show a customer the status of what they bought. We do not sell personal data, and we do not use customer conversations to advertise to them.
Who else is involved
- Meta (WhatsApp) — carries the messages between a customer and a merchant.
- Paystack — processes payments and settles money to the merchant's bank.
- Railway — hosts the application and database.
- Cloudflare — stores documents and images, such as invoice PDFs.
Each handles data under its own terms. We share only what those services need to do their job.
Where data is stored
Our database and application servers are currently located in Amsterdam, in the European Union, and document storage is distributed across Cloudflare's network. This means personal data of Nigerian customers is processed outside Nigeria. We will say so plainly here if that changes.
How long we keep it, and what we can delete
We keep business records — invoices, payments and orders — for as long as the merchant's account is active, and afterwards where we are required to for accounting and legal reasons. Invoices are deliberately immutable once issued: an issued invoice cannot be silently edited, which is what makes it trustworthy as a record.
What an issued invoice freezes. When an invoice is issued it stores a copy of the customer's name, phone number and address as they stood at that moment. That copy cannot afterwards be changed or removed — not by the merchant, and not by us. It is the same immutability that makes the invoice trustworthy as a record, and it applies to the personal details printed on it just as it does to the amounts. The invoice PDF, and any receipt, carry them too.
We want to be straightforward about a current limitation. Conversation records are stored in an append-only form, and there is no self-service button today that erases them. If you ask us to delete personal data, we handle the request manually and will tell you what we have removed and what we are obliged to keep. We are building a proper self-service path, and this section will be updated when it exists.
What a deletion reaches. When we erase a customer's data we remove their name, phone number, email address and any notes held about them; the contents of their messages, including any history a merchant imported; their delivery address; the text of any review; and the detail on their activity timeline. The fact that an order or a message existed survives, without its contents.
And what it does not reach today. We would rather list these than let you assume a deletion is more complete than it is:
- The raw record of each message as WhatsApp delivered it, described above. It is stored before we know which merchant or customer it belongs to, which is exactly why our erasure process cannot currently find it again.
- The AI drafting and negotiation records described above.
- The payment confirmation from Paystack, and the personal details printed on an issued invoice or receipt, which we keep because Nigerian law requires a business to retain its accounting records.
- Photographs and files held in our document storage. The database record is cleared immediately; the stored file itself is removed by hand afterwards.
The last two are retentions we are required or obliged to make. The first two are gaps we intend to close, not positions we are defending — they are recorded as engineering work, and this page will change when that work lands. If you make a request, ask us and we will tell you exactly which of these applied to you.
Your rights
Under the Nigeria Data Protection Act 2023 you may ask us to confirm what personal data we hold about you, correct it if it is wrong, delete it, or stop using it in a particular way. Write to support@storedeko.com and we will respond within 30 days.
If the data concerns a purchase you made from a merchant, that merchant is the business you dealt with, and we may need to involve them to answer you properly.
Security
Passwords are stored hashed, never in readable form. Each merchant's data is isolated from every other merchant's at the database level. Payment confirmations are accepted only when cryptographically signed by Paystack, and inbound WhatsApp messages only when signed by Meta. A merchant's bank account number is never sent back out through the app — only its last four digits are ever shown, including to the merchant themselves — and a merchant's WhatsApp access credential is encrypted before it is stored, in a form the database itself refuses to accept in plain text. No system is perfectly secure, and we will not claim otherwise.
Children
Storedeko is for businesses and their customers, and is not directed at children under 18.
Changes
If this policy changes we will update the date above. Where a change materially affects how we handle personal data, we will tell merchants directly.
Contact
- Data controller
- Openplanet Technologies Ltd (RC 1652204)
- support@storedeko.com
- Website
- www.storedeko.com