Merchant Data Processing Terms
Last updated 2026-07-21.
This is CodWatchdog's actual data-processing commitment to installing merchants, written to be accurate today. It is not a substitute for a lawyer-reviewed Terms of Service; it will be reviewed before it is the final terms a merchant accepts.
Roles
The installing merchant is the data controller for their customers' personal data. CodWatchdog acts as a data processor, processing personal data only on the merchant's instructions (via the app's configured behavior) and only for the purpose stated below.
What is processed
- Order phone number (read_customer_phone / order.phone), used solely to send WhatsApp order-status messages (confirm / cancel, delivery-health alerts) through the merchant's own connected WhatsApp Business Account.
- No other customer field (name, email, address) is requested or processed.
Purpose limitation
Phone data is used only for the WhatsApp order-messaging purpose above. It is never used for marketing, sold, shared with data brokers, or used to train AI or ML models.
Sub-processors
- Meta Platforms, Inc. (WhatsApp Cloud API): message delivery.
- Neon, Inc.: Postgres database hosting, encrypted at rest and in transit.
- Vercel Inc.: application hosting and deployment.
- Shopify: the platform CodWatchdog is distributed through and authenticates against.
Merchant rights
- A merchant can request deletion of their store's data at any time by uninstalling the app, which triggers Shopify's shop/redact deletion flow.
- A merchant can request an export or explanation of what is stored by contacting the founder at support@codwatchdog.com.
Owner
Muhammad Hassaan Javed, founder and sole operator.