01 Overview & Roles
Welcome to CustomerFlow (referred to herein as "CustomerFlow", "we", "us", or "our"). CustomerFlow is a multi-tenant conversational e-commerce software-as-a-service (SaaS) platform that enables online merchants to automate customer service, answer product inquiries, and process orders on WhatsApp using artificial intelligence.
Under data protection frameworks including the European General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Indian Digital Personal Data Protection Act, 2023 (DPDPA):
- CustomerFlow as a Data Controller: We act as a Data Controller for our registered merchants' account information, billing details, platform login credentials, and usage analytics collected directly on our website.
- CustomerFlow as a Data Processor / Service Provider: We act as a Data Processor on behalf of our merchants regarding the personal information of their end-customers ("Shoppers") received via WhatsApp messages, orders, phone numbers, and delivery addresses. The merchant remains the Data Controller for their end-customers' data.
02 Information We Collect
To deliver our automated WhatsApp customer assistance, order reconciliation, and team inbox features, we collect the following categories of information:
A. Merchant Account Information (Collected from You)
- Identity & Contact: Full name, business email address, account password (hashed using bcrypt), business name, contact phone number.
- Store Configurations: Store name, catalogue products (names, descriptions, pricing, inventory stock, images), UPI IDs, QR code URLs, delivery charges, and FAQ knowledge bases.
- WhatsApp Integration Credentials: Meta WhatsApp Business Account (WABA) ID, Phone Number ID, App ID, and authorized Cloud API system access tokens.
- Billing & Subscription Details: Billing address, GST/Tax identification numbers, payment transaction IDs, and active subscription plan records (processed securely via PCI-DSS certified payment gateways).
B. End-Customer Data (Processed on Merchant's Behalf via WhatsApp)
- Contact Identifiers: WhatsApp phone number (in E.164 format) and WhatsApp profile display name.
- Message Content: Inbound and outbound message text, voice notes, product queries, images (such as payment receipts or product inquiry screenshots), and shared location pins for delivery purposes.
- Order & Transaction Details: Products requested, order totals, shipping address details provided in chat, and payment transaction references.
C. Automated Technical & Diagnostic Logs
- Web server access logs, IP addresses, browser user-agent, device metadata, webhook delivery receipt timestamps, API request latency (in milliseconds), and AI token consumption metrics.
03 How We Use Information
We strictly process collected information for legitimate business purposes and fulfilling our contractual commitments:
- Generating Accurate WhatsApp Customer Responses: Parsing incoming shopper messages and matching them against the merchant's real-time product catalogue and FAQs to formulate instant, natural replies.
- Payment & Order Orchestration: Providing merchants' UPI payment QR codes, confirming order placements, generating order tracking summaries, and syncing order status with WooCommerce/Shopify stores.
- Team Live Chat & Human Takeover: Rendering the live chat dashboard so human support staff can review conversations, override the AI, and chat directly with shoppers in real time.
- Webhook Monitoring & Outage Protection: Logging Meta webhook deliveries to guarantee no messages are lost during peak traffic or network timeouts.
- Security & Fraud Prevention: Detecting spam abuse, enforcing rate limits, and securing tenant boundaries.
04 Artificial Intelligence & LLM Disclosures
Automated Processing Transparency: When an end-customer sends a message to your connected WhatsApp number, our backend analyzes the query, retrieves relevant catalogue data, and constructs a contextual prompt sent to the configured AI model.
Guardrails & Human Fallback: Our AI agents operate under strict system instructions:
- The AI will never invent product prices or fabricate delivery policies not verified in your store settings.
- If a shopper asks a complex inquiry or expresses dissatisfaction, the AI marks the conversation as
ai_doubtand automatically hands off the chat to human support staff in your live chat inbox. - Store owners can toggle any conversation between AI Mode and Human Mode at any time with a single click.
05 Meta WhatsApp Cloud API Compliance
CustomerFlow operates strictly in compliance with the Meta WhatsApp Business Terms of Service, WhatsApp Business Policy, and WhatsApp Commerce Policy:
- 24-Hour Customer Care Window: When a shopper initiates a conversation, CustomerFlow processes and responds within Meta's standard 24-hour service messaging window without requiring pre-approved message templates.
- Opt-In Obligation: Merchants using CustomerFlow to send outbound notification messages outside the 24-hour window must obtain prior explicit opt-in consent from recipients in accordance with Meta guidelines.
- Spam & Prohibited Content: CustomerFlow does not support or permit unsolicited spam broadcasting, phishing, or the sale of items prohibited by WhatsApp Commerce Policy (including weapons, illegal narcotics, adult services, and counterfeit currency).
06 Third-Party Sub-Processors
We partner with select, vetted third-party service providers to host infrastructure and process messages under strict data protection agreements:
| Sub-Processor | Service Provided | Location | Data Security Standard |
|---|---|---|---|
| Meta Platforms, Inc. | WhatsApp Cloud API & Webhook routing | USA / Global | SOC 2, ISO 27001, Meta Business Terms |
| Google Cloud Platform | Gemini Flash LLM inference & cloud compute | USA / Global | ISO 27001, SOC 2, HIPAA, Zero-Data Retention |
| OpenAI, LLC | GPT-4o-mini inference (optional AI provider) | USA | SOC 2 Type II, Enterprise Non-Training API |
| Hosting & Cloud Database | Encrypted MySQL database, WebSockets (Reverb) | India / Singapore / USA | AES-256 at rest, TLS 1.3 in transit, automated backups |
07 Multi-Tenant Architecture & Data Security
CustomerFlow was architected from day one as a secure, multi-tenant platform. We employ robust administrative, physical, and technical safeguards:
- Strict Logical Siloing: Every database table query (conversations, messages, orders, customers, and knowledge items) enforces mandatory multi-tenant scoping constrained by
shop_id. Under no circumstances can one store access another store's conversations or customers. - Encryption in Transit: All HTTP traffic and Meta webhooks are enforced over TLS 1.3 with SHA-256 certificates.
- Credential Protection: Meta system tokens, OpenAI keys, and Gemini API keys are encrypted in the database at rest and masked in UI views.
- Role-Based Access Control (RBAC): Support staff members only have access to their assigned store dashboard without super-administrator permissions.
08 Data Retention & Purging
We retain personal data only for as long as necessary to provide platform services or comply with legal obligations:
- Merchant Account Data: Retained for the lifetime of your active subscription. Upon account closure, merchant data is scheduled for permanent deletion within 30 days.
- WhatsApp Chat Logs: Kept to allow merchants to review customer order history and handle disputes. Merchants can trigger manual conversation deletions or request complete data erasure at any time.
- AI API Logs & Webhook Diagnostics: Diagnostic records (latency, status codes, token usage) are automatically purged on a rolling 30-day retention schedule to conserve storage and minimize data footprints.
09 International Data Transfers
Because CustomerFlow utilizes global cloud infrastructure and AI APIs (such as Google Cloud and Meta), your information may be processed on servers located outside your country of residence.
When data is transferred internationally from the European Economic Area (EEA), the United Kingdom, or Switzerland, we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, and verify that our sub-processors adhere to the EU-U.S. Data Privacy Framework.
10 Merchant Privacy Rights (GDPR / CCPA / DPDPA)
As an account holder, you possess comprehensive rights regarding your personal data:
- Right of Access: Request a copy of the personal data we maintain about your account.
- Right to Rectification: Update or correct inaccurate profile details in your Account Settings.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your account and all associated store data.
- Right to Restrict Processing: Pause processing of your data during active disputes.
- Right to Data Portability: Export your product catalogue, customer directory, and order logs in standard formats (JSON/CSV).
To exercise any of these rights, email us directly at privacy@customerflow.net. We respond to all verified requests within 30 days.
11 End-Customer Rights (Shoppers & Consumers)
Because merchants act as the Data Controllers for their shoppers' information, end-customers seeking to access, correct, or delete their conversation records should primarily direct their requests to the merchant from whom they made inquiries. CustomerFlow assists merchants with automated tools to fulfill consumer data requests promptly.
12 Cookies & Tracking Technologies
CustomerFlow uses essential, strictly necessary cookies to maintain user authentication sessions and CSRF security tokens across our dashboard. We do not use intrusive third-party cross-site advertising cookies or sell user behavioral data to data brokers.
13 Children's Privacy
CustomerFlow is a business-to-business (B2B) platform intended solely for individuals aged 18 and older. We do not knowingly collect or solicit personal information from children under the age of 16. If we discover that a minor has provided personal information, we will delete it immediately.
14 Policy Updates & Notifications
We may update this Privacy Policy periodically to reflect changes in our platform features, WhatsApp API policies, or applicable laws. When material changes occur, we will notify merchants via an email notification or a prominent banner in the dashboard at least 14 days before changes take effect.
15 Contact Us & Grievance Redressal
If you have questions, feedback, or concerns regarding this Privacy Policy or our data handling practices, please contact our dedicated Data Protection & Grievance Office:
CustomerFlow Data Protection Office
📧 Email: privacy@customerflow.net
💬 Support & Legal Desk: support@customerflow.net
🌐 Platform Website: https://customerflow.net
⏱️ Response Timeframe: Within 48 business hours