Privacy Policy

Last updated: August 24, 2026

1. Who we are

Zapinger helps Shopify merchants recover abandoned carts via WhatsApp, through Meta's WhatsApp Business Platform. Questions about this policy: zapinger.info@gmail.com.

2. Who this applies to

Two groups: merchants using our dashboard ("you"), and your customers, whose data passes through Zapinger to send recovery messages ("your customers"). For your customers' data, you're the controller under GDPR and Zapinger is the processor, acting only on your instructions. For your own account data, Zapinger is the controller. To stop WhatsApp messages, use WhatsApp's own controls on that chat — tap Block, or choose to stop marketing messages from that business (WhatsApp enforces this directly) — or contact the store that messaged you. Zapinger isn't directed at anyone under 18, and we don't knowingly collect data from children.

3. What we collect

From you, the merchant:

  • Account details — name and email, via Clerk, our login provider
  • Your Shopify store domain and details, via Shopify's OAuth connection (separate from login)
  • Meta/WhatsApp API credentials you provide during setup, encrypted before storage
  • Billing details, handled entirely through Shopify — we never see your card

From your Shopify store, on your behalf:

  • Customer name, phone, cart contents, and cart value, via Shopify's abandoned-checkout webhooks
  • Customer email, only when needed to look up an order and no phone number was included
  • Delivery status and cost category (sent, delivered, read, replied, opted out, billing) per attempt
  • Product titles, descriptions, prices, costs, inventory and image alt text — read on the Pro plan so we can tell you where your store is losing money. On that plan we can also write back two things, and only after you approve them: a product's search description and its image alt text. We never change your prices, and any change we make can be undone for 7 days.

4. How we use it

  • To detect abandoned carts and send the WhatsApp recovery messages you've configured
  • To automatically pick which approved message template and offer best fits a cart (see §5 — AI processing)
  • To show you the dashboard, funnel, and recovery analytics inside Zapinger
  • To contact you about your account, billing, or changes to our service
  • To detect, investigate, and fix errors in the service

5. AI processing

To pick a message template and offer, Zapinger sends a limited set of cart details (customer first name, cart items, cart value, shop name, checkout link) to an AI provider — see §6. It makes no decision with a legal or similarly significant effect on your customer, and you can ask us to disable it for your store anytime. If unavailable, Zapinger falls back to rule-based selection automatically.

6. Who we share data with

We don't sell data or share it for behavioral advertising. We share it only with the providers that run Zapinger, each acting as a sub-processor under our instruction:

  • Shopify — source of your store and customer data, and processes your subscription billing
  • Meta / WhatsApp Business Platform — delivers the messages, governed by Meta's own privacy terms
  • Clerk — handles your account login and authentication
  • Groq — AI template selection, described in §5
  • Render — hosts our backend application
  • TiDB Cloud (PingCAP) — hosts our database, in Singapore
  • Cloudflare — hosts and delivers our website
  • Sentry — error monitoring, hosted in the European Union. It records technical fault details only (page path, request method, error stack) and is configured not to store IP addresses or any customer personal data

These are global services, so data may be processed in India, Singapore, the United States, the European Union, and other countries they operate in — using Zapinger means consenting to this transfer. We may also disclose data if required by law, or to protect Zapinger's, our merchants', or their customers' rights, safety, or property.

7. How long we keep it

Customer name, phone, checkout link, and AI-generated message are deleted 90 days after cart abandonment — automatically, even if you've left Zapinger. Recovery totals (cart value, recovered or not, and when) are kept afterward for your historical dashboard; they no longer identify a specific customer. Raw Shopify webhook data is deleted after 30 days. Uninstalling deletes your account, carts, and logs within about 48 hours (Shopify's shop/redact process). We also honor customers/data_request (respond within 30 days) and customers/redact (immediate deletion once requested via Shopify Admin).

8. Your rights

Access, correct, export, or delete your merchant account data anytime from Settings, or by emailing us. Shoppers can ask the merchant who messaged them to access or delete their data — actioned from their Shopify Admin, reaching Zapinger automatically — or stop further messages using WhatsApp's own controls on that chat, which WhatsApp enforces directly. Depending on where you live, you may have additional rights under laws like GDPR or CCPA, including objecting to processing or complaining to your local data authority.

9. Security

Data is encrypted in transit (HTTPS/TLS). Shopify access tokens, WhatsApp/Meta credentials, and webhook secrets are AES-256 encrypted at rest before storage — never plain text. Production access is limited to the people who need it. If we become aware of a breach affecting your data, we'll notify you without undue delay. No system is 100% secure, and we can't guarantee absolute protection against every possible breach.

10. Cookies and local storage

No advertising or analytics cookies — only strictly necessary ones from Clerk, our login provider, to keep you signed in.

Zapinger also caches your most recently loaded dashboard data — which can include customer names and phone numbers — in your browser's local storage, so pages appear instantly instead of reloading each time. That copy never leaves your device, refreshes at most every 24 hours, and is erased when you sign out.

11. Changes to this policy

If we make material changes, we'll update the date above and notify merchants. Minor edits (typos, clarifications) may be made without notice.