Privacy Policy
Last updated 2026-07-21.
This is a working policy for a solo pre-launch founder, written to be accurate to how CodWatchdog operates today. It is not a substitute for a lawyer-reviewed policy; it will be reviewed before any EU or UK merchant is expected to install the app.
What CodWatchdog is
A Shopify app that sends WhatsApp order-status messages (delivery confirmation and cancellation, account-health alerts) for merchants running cash-on-delivery stores, using the official Meta WhatsApp Cloud API.
What we collect
- Order phone number, read from Shopify via the read_customer_phone API scope, for the sole purpose of sending WhatsApp order-status messages through the merchant's own WhatsApp Business Account.
- We do not collect name, email, or address.
- We do not use cookies, trackers, or analytics on customer-facing messages.
Why we collect it
Solely to deliver the messaging functionality merchants install the app for. See the merchant terms for the full processor / controller relationship.
How long we keep it
Consent records are kept until revoked or the shop uninstalls. Operational records are purged on a rolling window (30 to 90 days). Everything tied to a shop is deleted when the merchant uninstalls the app.
How it is protected
Stored in a managed Postgres database with encryption at rest and TLS in transit. Access is limited to the founder; no other staff or shared credentials exist.
Your choices
- Merchants: uninstalling the app triggers deletion of your store's data.
- Customers: WhatsApp messages include an opt-out path. Opting out is recorded and enforced before any future send.
Contact
Questions about this policy or a request to see, export, or delete your data: email support@codwatchdog.com.