Orderkind Privacy Policy

Effective date: 7 October 2026

Who operates Orderkind

Orderkind is operated by Tiavola, a registered company in Egypt. Contact info@tiavola.com about the service, this policy or personal-data requests. This policy covers Orderkind’s Shopify and WhatsApp integration and supplements the merchant’s own privacy policy. For merchant account administration Tiavola determines the use of account information. For buyer messaging workflows, Orderkind processes information on the merchant’s behalf; the merchant determines the messaging purposes.

Information processed

We process store domains and installation/session details; Shopify and Meta access credentials; WhatsApp business-account and phone-number identifiers; template and language settings; buyer phone numbers and customer/order identifiers; order, shipment, tracking and COD decision context; checkout identifiers, names, product context, totals and recovery links; message identifiers, delivery/read/failure status and retry records. Consent records include a protected identifier derived from the store and phone number, agreed purpose, grant or withdrawal, source, time, notice version and supporting evidence reference. We also process support correspondence and technical logs.

Purposes and messaging choices

We use data to connect merchant accounts, send enabled order/COD and checkout messages, process COD replies, stop recovery after conversion, handle delivery failures, display analytics and provide support. The cart consent block offers separate optional choices for order messages and checkout reminders. A number entered at checkout, or an SMS/email subscription, is not by itself WhatsApp permission. Automated sends and retries require recorded permission for the relevant purpose. Buyers may send STOP or إيقاف on WhatsApp or ask the merchant to stop messages. START does not restore permission; a new affirmative choice is required. Direct or accelerated checkout may bypass the cart block; messages are blocked without other recorded permission. Merchants may record consent obtained elsewhere with its actual time, purpose and evidence reference.

Service providers and transfers

Shopify provides commerce and integration services. Meta/WhatsApp receives messaging information needed to deliver messages. Heroku/Salesforce hosts the app and production PostgreSQL database in Europe. Neon/Databricks provides the development PostgreSQL database in eu-west-2. These providers may process information internationally, including for support, under their applicable service and privacy terms. We do not sell buyer information. We may disclose information where required by applicable law.

Retention and deletion

Operational messaging records, integration settings and credentials remain while the merchant uses the service, unless removed through a verified deletion request or store-removal process. Consent and withdrawal evidence remains until the relevant deletion or store-removal process. On uninstall, the integration and queued retries are removed and recovery scheduling stops. Shopify store-redaction requests erase the store’s live service records. Verified customer deletion removes their messaging, recovery, retry, COD and consent records; a protected suppression marker is retained to prevent old consent from being reused. Deleted live records may remain in provider backups until those backups expire under the provider’s applicable retention, and are not used for active messaging. Records independently held by Shopify, Meta or the merchant are subject to their own policies.

Your requests

Buyers may contact the sending merchant about access, correction, deletion and communication choices. Merchants and buyers may also email info@tiavola.com. We verify requests proportionately and coordinate with the merchant where required. We handle verified requests within applicable legal deadlines, including Shopify’s 30-day deadline for its compliance requests. Do not send passwords, tokens or payment-card details. See the Orderkind Data Deletion Instructions for the request process.

Security and changes

Connections to Orderkind use HTTPS. Merchant privacy tools require Shopify admin authentication; Shopify and Meta webhook signatures are checked before processing. Access credentials are used for authorized integration operations. This policy may change as the service changes; the effective date will be updated.

Privacy policy · Terms · Data deletion instructions