SOONComing soon to the Shopify App Store. Join the waitlist.
ChatFirmShopify
Privacy Policy

Privacy Policy

Last updated: October 2026

1. Who we are and our role

ChatFirm (“ChatFirm,” “we,” “us”) provides a Shopify app that helps merchants in Pakistan confirm Cash on Delivery (COD) orders, verify delivery addresses, book couriers and keep customers informed over WhatsApp.

This policy covers two groups of people: Merchants (the businesses that install ChatFirm) and Customers (the people who place orders or start a checkout on a Merchant's store).

For Merchant information, ChatFirm is the data controller. For Customer information, the Merchant is the data controller and ChatFirm is a data processor acting only on the Merchant's instructions, under our Data Processing Addendum. If you are a Customer and want to see, correct or erase your data, please contact the store you ordered from first; you can also contact us (section 11) and we will help the store respond.

2. What we collect

A. Merchant information

Your Shopify store address and name, the account details Shopify shares when you install the app, the phone numbers you enter for admin alerts, the WhatsApp number you connect, your Leopards Courier API credentials, your settings and message templates, and your plan and billing status. Payments are handled by Shopify; we never see card details.

B. Customer information received from your Shopify store

For each order: the customer's name, phone number and delivery address, the order number, items, total, payment method and payment status. We request access to name, phone and address only. We do not collect or store customer email addresses.

C. Abandoned checkouts (only for customers who opted in)

If you turn on Abandoned Checkout Recovery, we receive checkout events from Shopify. We keep a checkout (name, phone, cart summary, link back to the cart) only if the customer ticked Shopify's marketing opt-in at checkout. For anyone who did not opt in, nothing is stored and no reminder is sent.

D. WhatsApp replies and payment proof

Messages are sent from the Merchant's own WhatsApp number. We keep what we need to run the order: the customer's short replies (YES, NO, ADVANCE, STOP), an address correction or cancellation reason they type, and, for bank-transfer orders, the payment screenshot they send. ChatFirm itself does not keep whole conversations, but the WhatsApp gateway we use (OpenWA) keeps a copy of the messages it carries, including customers' replies, and deletes them automatically after 30 days.

E. Courier information

Consignment numbers, tracking links and delivery status codes returned by the courier.

F. Website waitlist

If you join the waitlist on our website we keep the name, email address and store URL you give us, only to tell you when ChatFirm opens. You can ask us to delete them at any time (section 11).

G. Technical records

Event logs of what the system did (for example “order received”, “courier booked”) and an access log recording when customer data is viewed or exported in the dashboard (counts only, not the data itself).

3. How we use it

  • Sending the WhatsApp messages the Merchant has switched on: order confirmation, address verification, payment-proof handling, courier and delivery updates, review requests and (for opted-in customers) abandoned-checkout reminders.
  • Booking parcels with the Merchant's courier and updating the Shopify order.
  • Alerting the Merchant's admins about orders and problems.
  • Providing support, keeping the service secure and meeting our legal and accounting obligations.

We do not sell customer data, we do not use it for advertising or for our own marketing, and we do not build profiles across merchants. We make no automated decision that has a legal or similarly significant effect on a customer.

4. WhatsApp: what you should know

ChatFirm sends and receives WhatsApp messages through OpenWA, an open-source, unofficial WhatsApp Web integration connected to the Merchant's own WhatsApp account. It is not Meta's official WhatsApp Business API. Meta's terms and policies for WhatsApp apply to that account, and using an unofficial integration carries a risk that WhatsApp may restrict the account. Merchants are responsible for using it in line with WhatsApp's rules and applicable law. We are working on support for the official WhatsApp Business API.

5. AI address checking

When a customer replies to an address-verification message with free text, we send only that text to an AI language model (Groq, United States) to judge whether it is a complete delivery address. No name, phone number or order number is sent with it. The provider does not use it to train models, and ChatFirm uses the provider's zero-data-retention setting so the text is not kept after the answer is returned.

6. Who else handles the data

We use the service providers (subprocessors) below, under agreements that require them to protect the data. The current list is also on our Subprocessors page, and merchants are told before we add one.

Shopify Inc.

Platform on which ChatFirm is installed. Delivers order and checkout events to ChatFirm and receives the changes ChatFirm makes (for example order tags and notes).

Location: Canada / United States (Shopify's infrastructure)

Supabase Inc.

Database and file storage for ChatFirm: merchant settings, orders, abandoned checkouts, privacy-request records, logs and payment screenshots. Data is encrypted at rest and in transit.

Location: Sydney, Australia (AWS ap-southeast-2)

Groq, Inc.

AI language model that judges whether a customer's free-text address reply is a complete delivery address.

Location: United States

Railway Corp.

Hosts the shared OpenWA service, an open-source, unofficial WhatsApp Web integration through which messages are sent and received on the Merchant's own WhatsApp account.

Location: As configured for ChatFirm's Railway project (confirmed in the subprocessor register before launch)

Vercel Inc.

Hosts the ChatFirm web application and receives the order and checkout events sent by Shopify.

Location: United States (ChatFirm's functions run in Sydney, Australia)

ngrok Inc.

A tunnel that carries ChatFirm's internal requests to its workflow engine until the engine moves to its own server.

Location: United States

Server hosting provider (ChatFirm application and workflow automation)

Runs the ChatFirm web application and the workflow engine (n8n) that carries out the automations.

Location: Named here when production hosting goes live; this page is updated and merchants are notified before any new subprocessor handles customer data

Your courier (currently Leopards Courier) receives the customer details needed to deliver a parcel; the courier is the Merchant's own service provider. We may also disclose information where the law requires it.

7. How long we keep it

These limits are enforced automatically every day.

DataKept forThen
Orders (customer name, phone, delivery address, replies)12 months from the order datePersonal details are removed. The order's stage, totals and dates remain so billing counts and order history stay accurate.
Message copies held by the WhatsApp gateway (OpenWA), including customers' replies30 daysDeleted automatically by the gateway. A customer erasure request removes the customer's details from ChatFirm immediately; their messages in the gateway age out within these 30 days.
Raw copy of the Shopify order30 daysCut down to the product lines (product, quantity, price); everything else is deleted.
Abandoned checkouts (only customers who opted in to marketing)30 daysDeleted.
Technical logs90 daysDeleted.
Payment screenshots12 monthsDeleted from storage.
Customer data exports prepared for a Shopify data request30 daysDeleted.
Access log (who viewed or exported customer data)12 monthsDeleted.
WhatsApp STOP opt-outsKept while the store is a ChatFirm customerStored only as a one-way keyed hash, never the phone number, so a customer who opted out is never messaged again. Deleted with the store's data when the store is erased.
Website waitlist (name, email, store URL)Until ChatFirm opens to you or you ask us to delete itDeleted on request.
Billing history and the merchant record (no customer personal data)As required for accountingKept after a store is erased.

If a Merchant uninstalls ChatFirm, Shopify tells us 48 hours later and we erase the store's data (orders, checkouts, settings, connections, logs, screenshots and the WhatsApp session). Only the minimal billing record remains.

8. Shopify privacy requests and your rights

ChatFirm handles Shopify's three mandatory privacy requests automatically:

  • customers/data_request: we prepare the customer's stored data for the Merchant, who gives it to the customer (within 30 days).
  • customers/redact: we remove the customer's personal details from orders and delete their checkouts, screenshots and matching log entries (within 30 days of Shopify sending the request).
  • shop/redact: we erase the store's data 48 hours after the app is uninstalled.

Depending on where you live you may have the right to access, correct, restrict or erase your personal data, to object to processing, and to complain to a data-protection authority. Contact the store first, or write to us (section 11).

9. Security

  • All traffic to and from ChatFirm is encrypted with TLS. Stored data is encrypted at rest by our database provider.
  • Shopify access tokens and courier credentials are additionally encrypted by ChatFirm before they are stored.
  • Payment screenshots are stored privately and shown only through short-lived links.
  • Only authorised ChatFirm personnel can reach production data; accounts use strong passwords and multi-factor authentication, and customer-data access is logged.
  • Production and test data are kept separate, and we have a written incident-response plan. If a breach affects your data we will tell affected Merchants without undue delay and in any case within 72 hours of confirming it.

No system is perfectly secure; if you believe your data has been exposed, contact us at once.

10. Cookies, children and changes

The ChatFirm dashboard sets one essential first-party cookie to keep you signed in. This website does not use advertising or analytics cookies. ChatFirm is a business tool and is not directed at children. If we change this policy in a way that matters, we will update the date above and tell Merchants.

11. Contact

Questions, requests or complaints about privacy:

ChatFirm Privacy
General support: support@chatfirm.tech
Based in: Lahore & Karachi, Pakistan