Weystack

Draft — pending review by Novalitics’ counsel before publication

Privacy Policy

Effective date: [EFFECTIVE DATE]

The short version

  • Weystack brings a business’s WhatsApp, Instagram and Facebook Messenger chats into one inbox and helps turn them into orders.
  • If you are a vendor using Weystack, the customer data in your inbox is yours. We handle it on your behalf and only on your instructions.
  • If you are a customer who messaged a business that uses Weystack, that business decides how your data is used. You can contact them, or us, to use your rights.
  • We send the text of conversations to OpenAI so AI can sort chats and pull out order details. We name every company we share data with below.
  • Our servers and service providers are outside Nigeria. We protect your data when it leaves the country, as the Nigeria Data Protection Act 2023 requires.
  • Messages are deleted after 12 months. We never sell personal data.

1. Who we are

Weystack is operated by Novalitics (RC [RC NUMBER]), whose registered address is [REGISTERED ADDRESS], Nigeria. In this policy, “Novalitics”, “we”, “us” and “our” mean Novalitics.

This policy explains how we handle personal data when you use the Weystack web app, when you message a business that uses Weystack, and when you visit weystack.com. It is written to meet the Nigeria Data Protection Act 2023 (“NDPA”) and the regulations and guidance of the Nigeria Data Protection Commission (“NDPC”).

Our Data Protection Officer is [DATA PROTECTION OFFICER NAME]. You can reach them at [PRIVACY EMAIL].

2. Who is responsible for your data

Under the NDPA, responsibility depends on whose data it is:

  • Vendors and their staff. We are the data controller for your account details, sign-in information, billing records and how you use Weystack. We decide how that data is used, and this policy governs it.
  • Customers of vendors. When you message a business that uses Weystack, that business is the data controller for your name, phone number, address, messages and orders. We are its data processor: we store and organise that data for the business and only use it to provide our service to them. The business’s own privacy notice explains how it uses your data.
  • Our own limited purposes. Where we use data for our own purposes, such as keeping the service secure or producing aggregated figures about how Weystack is used, we are the controller for that use.

3. What we collect

From vendors and their staff

  • Name, business name, email address and phone number.
  • Sign-in details. Passwords are handled by our authentication provider in hashed form.
  • Bank account name, number and bank, if you add them. These are details you choose to share with your customers, and we include them in payment reminders you send.
  • Names, emails and roles of staff you invite.
  • Details of the Facebook Pages, Instagram accounts and WhatsApp numbers you connect, and the access tokens Meta issues so we can send and receive messages for them.
  • Plan and billing records.

About customers who message a vendor (received from Meta when the customer messages the vendor’s connected account)

  • Name or profile name, phone number, and Instagram or Facebook identifiers.
  • The contents of messages sent and received, with dates and times.
  • Images sent in chat, such as bank-transfer screenshots and product photos. Voice notes, videos, documents and stickers are not stored; the conversation only shows that an attachment was sent.
  • Delivery addresses, order items, amounts and payment status.
  • AI results about the conversation, such as a label (for example “ready to buy”) and suggested order details.

Technical data

  • IP address, browser and device type, pages requested, and error reports, collected when you use the app or this website.
  • The app uses cookies and similar storage that are strictly necessary to keep you signed in. This website does not use advertising cookies.

4. How we use data and our lawful bases

The NDPA only allows personal data to be processed where there is a lawful basis. These are the purposes we use data for and the basis we rely on for each.

Purposes of processing and lawful bases
PurposeLawful basis
Running your account and providing the servicePerformance of our contract with you (the vendor)
Receiving, storing and showing your customers’ messages in your inboxProcessed on your instructions as your processor; you rely on your own lawful basis, usually performance of a contract with your customer or legitimate interests
AI classification of conversations and extraction of order detailsProcessed on your instructions as your processor, as part of the service you signed up for
Sending transactional email (sign-in links, alerts, receipts)Performance of our contract with you
Keeping the service secure, preventing fraud and fixing errorsOur legitimate interests in running a safe and reliable service
Improving Weystack using aggregated or pseudonymised usage figuresOur legitimate interests; we do not use message contents for this
Keeping financial and tax recordsCompliance with a legal obligation
Optional product news or marketing to vendorsYour consent, which you can withdraw at any time

Where we rely on legitimate interests, we have weighed them against your rights and freedoms. Where we rely on consent, you can withdraw it at any time without affecting anything we did before you withdrew it.

5. How we use AI

Weystack uses AI models provided by OpenAI to read incoming conversations, label them (for example as an enquiry or a likely order), and suggest order details such as items, quantities and delivery address.

To do this, the text of the messages in a conversation thread is sent to OpenAI. That text can include a customer’s name, phone number, delivery address and anything else they wrote. OpenAI processes it as our sub-processor under contract. OpenAI states that data sent through its API is not used to train its models by default, and may be kept for a limited period to detect abuse.

AI results are suggestions. The vendor reviews and can change any label or order detail, and nothing the AI produces is used to make decisions about a customer that have legal or similarly significant effects. The AI is instructed to leave a field empty rather than guess, but it can still make mistakes, so vendors should check details before relying on them.

6. Who we share data with

We do not sell personal data, and we do not share it for advertising. We share it only with:

  • The vendor and the staff they authorise, for customer data in their inbox.
  • Sub-processors that help us run Weystack, listed below. Each is bound by a contract that limits what it can do with the data and requires it to protect the data.
  • Authorities, where the law requires it, or where it is necessary to protect someone’s safety or defend legal claims.
  • A buyer or successor if Novalitics’s business is sold or merged, on terms that keep this policy’s protections in place.
Sub-processors
Sub-processorWhat they do for usData involved
OpenAIAI classification of conversations and extraction of order detailsThe text of messages in a conversation thread, which can include customers’ names, phone numbers and delivery addresses
Meta PlatformsSending and receiving WhatsApp, Instagram and Messenger messagesMessage contents, images, customer phone numbers and social profile identifiers
SupabaseDatabase hosting and account sign-inAll account, conversation and order data held in our database
Cloudflare R2Storage of images received in conversationsImages such as bank-transfer screenshots and product photos
RenderHosting of the Weystack APIAll data passing through the service
VercelHosting of the Weystack web app and this websiteTechnical data such as IP addresses and request logs
ResendSending transactional emailVendor and staff names, email addresses and email contents
SentryError monitoringTechnical diagnostics, which can incidentally include account identifiers or fragments of data involved in an error

We will update this list before we add or replace a sub-processor that handles customer data, so vendors have the chance to object.

7. Transfers outside Nigeria

Our sub-processors store and process data outside Nigeria, in [DATA HOSTING REGIONS]. The NDPA only permits this where the destination provides an adequate level of protection or another lawful transfer basis applies.

We rely on the safeguards the NDPA and the NDPC recognise, including binding contractual terms with each sub-processor that require them to protect personal data to a standard at least equal to the NDPA. You can ask us for more information about these safeguards at [PRIVACY EMAIL].

8. How long we keep data

We keep data only for as long as it is needed. Different data is kept for different periods:

Retention periods
DataHow longThen
Message text and images your customers send in chat12 months from the last message in the conversationPermanently deleted, including the stored image files
Conversation records (channel, dates, AI label)24 monthsPseudonymised: the customer’s name and phone number are removed; the remaining figures are kept for your dashboard
Orders, line items and payments, including proof-of-payment images you attach to a paymentFor as long as your account is open, then [STATUTORY RETENTION PERIOD] after it closesDeleted
Notification delivery logs12 monthsPermanently deleted
Channel access tokens (Facebook Page, Instagram, WhatsApp)Until you disconnect the channel or Meta tells us you removed WeystackDeleted immediately
Your vendor account after you close itUp to 30 days, except records we must keep by law (above)Deleted with everything linked to it

The same image can have two retention periods. A bank-transfer screenshot a customer sends in chat is message content and is deleted after 12 months. If the vendor attaches that screenshot to a payment record as proof, the copy on the payment record is a financial record and is kept for as long as the other payment records.

Backups. Our database provider keeps backups so we can recover from failures. Deleted data stays in these backups for up to [BACKUP PURGE WINDOW] after deletion, and is then gone. Backups are encrypted and are not used for anything other than recovery.

Nigerian law requires some financial and tax records to be kept for a minimum period, even after an account closes. Where that applies, we keep only what the law requires and delete it when the period ends.

9. How we protect data

  • Data is encrypted in transit using TLS, and our hosting providers encrypt stored data.
  • Channel access tokens from Meta are encrypted separately in our database and deleted as soon as a channel is disconnected.
  • Images are kept in private storage and shown only through short-lived signed links.
  • Access is restricted by role. Vendors control which staff can see and act on conversations, and each vendor’s data is kept separate from every other vendor’s.
  • Only a small number of Novalitics personnel can access production systems, and only when needed to run or support the service.

No system is completely secure. If you think your account has been compromised, contact us straight away at [PRIVACY EMAIL].

10. If something goes wrong

If a personal data breach is likely to put people’s rights and freedoms at risk, we will notify the NDPC within 72 hours of becoming aware of it, as the NDPA requires.

Where the breach affects customer data we process for a vendor, we will tell the vendor without undue delay and give them the information they need to meet their own obligations. Where a breach is likely to put individuals at high risk, we or the vendor will also tell the people affected, in plain language, with steps they can take to protect themselves.

11. Your rights

Under the NDPA you have the right to:

  • Be informed about how your data is used, which is what this policy does.
  • Access the personal data we hold about you and get a copy.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: have your data deleted where there is no good reason to keep it.
  • Restriction: ask us to limit how your data is used, for example while a complaint is looked into.
  • Portability: receive your data in a structured, commonly used, machine-readable format, or have it sent to another organisation.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time, where we rely on consent.
  • Not be subject to decisions based solely on automated processing that have legal or similarly significant effects on you.
  • Complain to the Nigeria Data Protection Commission at ndpc.gov.ng. We would appreciate the chance to put things right first, but you do not have to contact us before complaining.

How to use your rights. Vendors and staff can email [PRIVACY EMAIL]. If you are a customer of a business that uses Weystack, the quickest route is to contact that business, because it controls your data. You can also email us with the business’s name and the phone number or social account you messaged from. We will pass your request to the business and help it respond, or respond ourselves where we are the controller.

We may need to confirm your identity before acting on a request. We will respond without undue delay and within the time the NDPA allows. Using your rights is free unless a request is clearly unfounded or excessive.

To delete data connected through Facebook or Instagram, see our data deletion instructions.

12. Children

Weystack is a business tool for people aged 18 or over. We do not knowingly collect data about children for our own purposes. If you believe a child’s data has been shared with us, contact us and we will work with the relevant business to deal with it.

13. Changes to this policy

We will update this policy when our practices or the law change, and show the new effective date at the top. If a change materially affects how we use personal data, we will tell vendors by email or in the app before it takes effect.

14. Contact us

Novalitics, [REGISTERED ADDRESS], Nigeria.
Data Protection Officer: [DATA PROTECTION OFFICER NAME]
Email: [PRIVACY EMAIL]