Legal

Privacy Policy

Last updated · May 2026

This is a template provided for convenience and does not constitute legal advice. Have it reviewed by qualified counsel before publishing.

This Privacy Policy explains how Konfirm, Inc. (“Konfirm”, “we”, “us”) collects, uses, and protects personal data when you use our website and our order-confirmation platform. Konfirm helps ecommerce merchants confirm cash-on-delivery and other orders over WhatsApp. We act as a data controller for our own account holders and as a data processor for the customer data merchants send through the platform.

Who this policy covers

This policy applies to two groups:

  • Merchants — the businesses that sign up for and administer a Konfirm account.
  • End customers — the shoppers a merchant messages through the platform. For this data, the merchant is the controller and Konfirm is the processor acting on their instructions. See our Data Processing Addendum.

Information we collect

Account & billing data

When a merchant signs up we collect a name, work email, company name, and authentication details. Billing is handled by our payment processor; we receive limited transaction metadata but never store full card numbers.

Order & messaging data

To confirm orders we process data the merchant connects from their store and WhatsApp numbers: order details, line items, customer names and phone numbers, message content, delivery and read receipts, and reply classifications.

Usage & technical data

We collect log data, device and browser information, IP addresses, and product analytics to operate, secure, and improve the service.

How we use information

  • To provide, maintain, and secure the platform.
  • To send order confirmations and classify replies on the merchant's behalf.
  • To enforce sending limits, suppression lists, and opt-out handling.
  • To provide support and respond to your messages.
  • To detect, prevent, and investigate abuse or security incidents.
  • To comply with legal obligations and enforce our agreements.

We do not sell personal data, and we do not use end-customer message content to train general-purpose AI models. Reply-classification models operate within the bounds described in our WhatsApp Use Policy.

Multi-tenant data isolation

Konfirm is multi-tenant. Each merchant's data is logically isolated and access is scoped to that merchant's organization at every layer of the application. One merchant cannot access another merchant's orders, contacts, conversations, or numbers.

Sharing & sub-processors

We share data with vetted sub-processors that help us run the service — cloud hosting, messaging infrastructure, payment processing, email delivery, and analytics. Each is bound by contractual confidentiality and data-protection obligations. A current list of sub-processors is available on request.

We may also disclose data when required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where required).

International transfers

Where data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or an equivalent lawful transfer mechanism.

Data retention

We retain account data for as long as an account is active and for a reasonable period afterward to meet legal, accounting, and audit-log requirements. Merchants can request deletion of end-customer data, subject to retention we are legally required to keep.

Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. End customers should direct such requests to the merchant who messaged them; we will assist the merchant in fulfilling them.

Security

We use encryption in transit, access controls, audit logging, and least-privilege practices to protect data. No system is perfectly secure, but we work continuously to reduce risk and respond promptly to incidents.

Children

The platform is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated through the product or by email, and the “last updated” date above will change.

Contact us

Questions about this policy or your data? Email us at support@konfirm.app or use our contact page.