WhatsApp Business Platform

Privacy Policy

Privacy Policy

Last updated: 29 June 2026

1. Introduction

DevFlow Pty Ltd (“DevFlow”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal, customer, order, business, and technical information shared with us.

This Privacy Policy explains how information is collected, used, stored, and protected when you use our application and platform, including integrations with Meta Platforms, WhatsApp Business, Meta Business Manager, Shopify, and other supported business systems.

By using the App or connecting any third-party account, you agree to the practices described in this Privacy Policy.

2. Scope of This Policy

This Privacy Policy applies to information processed through our platform and integrations, including:

  • WhatsApp Business and Meta Business integrations.

  • Shopify store integrations.

  • Business messaging and chatbot features.

  • Ecommerce data synchronization.

  • Customer audience and segment management.

  • Webhooks, logs, and integration activity.

This policy applies to business users, merchants, administrators, and, where applicable, end customers whose information is processed through a connected business account or store.

3. What Information We Collect

We only collect and process information that is necessary to provide, secure, support, and improve our services.

3.1 Business and Account Information

When you connect a Meta, WhatsApp Business, Shopify, or other supported business account, we may access or store:

  • Business name.

  • Business account details.

  • Connected platform account identifiers.

  • Store domain or shop URL.

  • Business phone number(s).

  • Messaging configuration details.

  • Integration settings.

  • Permissions and access scopes granted to the App.

  • Connection status and installation history.

This information allows us to correctly link, configure, and manage your business messaging and ecommerce integrations.

3.2 Meta and WhatsApp Business Information

When you connect your Meta or WhatsApp Business account, we may access or process:

  • WhatsApp Business account details.

  • Business Manager account information.

  • WhatsApp phone number details.

  • Approved message templates.

  • Messaging configuration settings.

  • Message delivery status and webhook events.

3.3 Messaging Information

When using WhatsApp messaging features through our App, we may process:

  • Messages sent and received by your WhatsApp Business account.

  • Message timestamps.

  • Message delivery, read, failed, and status events.

  • Recipient phone numbers.

  • Approved message templates.

  • Campaign information.

  • Chatbot conversation context needed to provide replies.

We only process messages related to business communication initiated, configured, or authorised by you or your organisation.

3.4 Shopify Store Information

When you connect a Shopify store, we may access and process information from that store based on the permissions granted during installation.

This may include:

  • Store domain and Shopify shop details.

  • Product information.

  • Product variant information.

  • Product pricing and compare-at pricing.

  • Inventory availability.

  • Discount and coupon information.

  • Order information.

  • Order line items.

  • Customer information associated with orders, carts, checkouts, or customer records.

  • Cart and checkout information where made available by Shopify.

  • Webhook events for products, discounts, orders, customers, carts, checkouts, app uninstall events, and app scope updates.

This information is used to connect your Shopify store to our platform, support chatbot responses, synchronize ecommerce data, and enable business messaging workflows.

3.5 Shopify Access Scopes

Our Shopify integration may request the following access scopes:

  • read_products — to read product and product variant information so the chatbot and platform can answer product-related questions and synchronize product data.

  • read_inventory — to read inventory or availability information where required.

  • read_orders — to read order, checkout, cart, and order-related information for customer support, order status, ecommerce synchronization, and automation workflows.

  • write_orders — to update order notes, tags, metafields, or related order information where required for merchant-approved workflows, such as recording that a WhatsApp message was sent.

  • read_customers — to read customer contact details and related information for audience, segmentation, order support, and merchant-approved communication workflows.

  • read_discounts — to read discount and promotion information.

  • write_discounts — to create or update discounts where enabled by the merchant for approved campaigns or automation workflows.

We request only the Shopify permissions that are required for the features used by the merchant.

3.6 Customer, Audience, and Segment Information

When a business uses our audience, segment, ecommerce, or messaging features, we may process customer information such as:

  • Name.

  • Email address.

  • Phone number.

  • Customer identifiers from connected platforms.

  • Order history or order references.

  • Tags, audience membership, or segment membership.

  • Communication preferences where available.

  • Messaging history related to business communication.

This information is used to help businesses manage customer communication, customer support, ecommerce updates, and approved messaging campaigns.

3.7 Ecommerce Information

When ecommerce integrations are connected, we may process:

  • Products and product variants.

  • Product pricing.

  • Product inventory.

  • Product status and availability.

  • Discounts, promotions, and coupon codes.

  • Orders and order line items.

  • Carts and cart line items.

  • Checkouts and checkout line items.

  • Customer details associated with ecommerce records.

  • Store webhook events.

  • Raw integration payloads required for audit, debugging, or synchronization.

3.8 Technical Information

For security, reliability, auditing, and troubleshooting, we may collect:

  • System logs.

  • API usage data.

  • Webhook event data.

  • Error reports.

  • IP addresses used for security, fraud prevention, and abuse detection.

  • Authentication events.

  • Integration connection and disconnection events.

4. How We Use Your Information

We use information to provide and support the services requested by you or your organisation.

This includes:

  • Enabling WhatsApp Business messaging.

  • Sending and receiving WhatsApp messages on your behalf.

  • Managing and configuring business messaging setups.

  • Connecting Shopify stores and other supported ecommerce systems.

  • Synchronizing products, discounts, orders, customers, carts, and checkouts.

  • Allowing chatbots to answer product, order, policy, and customer support questions.

  • Creating or updating discounts where authorised.

  • Updating order notes, tags, or related order information where authorised.

  • Managing customer audiences and segments.

  • Supporting order status, abandoned cart, checkout, marketing, and customer service workflows where configured by the merchant.

  • Providing customer support and troubleshooting.

  • Monitoring system performance and security.

  • Detecting abuse, fraud, or unauthorised access.

  • Complying with Meta, WhatsApp, Shopify, and applicable platform policies.

  • Complying with legal and regulatory obligations.

We do not sell, rent, or trade personal, customer, order, or business data.

We do not use connected store or messaging data for advertising by DevFlow.

5. Use of Meta and WhatsApp Services

Our App connects to Meta and WhatsApp Business services to:

  • Manage WhatsApp Business accounts.

  • Send and receive WhatsApp messages.

  • Access business-level settings and permissions.

  • Verify business ownership and access rights.

  • Process message delivery and status events.

  • Manage approved WhatsApp templates and campaigns.

All access is limited to what is required for the App to function correctly.

6. Use of Shopify Services

Our App connects to Shopify stores to:

  • Read store product, inventory, order, customer, discount, cart, and checkout information where authorised.

  • Synchronize ecommerce information into the merchant’s DevFlow account.

  • Help chatbots answer product and order-related questions.

  • Support customer communication and WhatsApp messaging workflows.

  • Create or update discounts where authorised by the merchant.

  • Update order notes, tags, or related order fields where authorised by the merchant.

  • Receive Shopify webhook events to keep ecommerce records up to date.

The merchant can disconnect the Shopify integration at any time. When the App is uninstalled or disconnected, we will stop using the Shopify access token and mark the integration as inactive.

7. Webhooks and Automated Events

Our platform may receive webhook events from connected services such as Meta, WhatsApp, Shopify, and other supported providers.

Webhook events may include:

  • Message status updates.

  • Product created, updated, or deleted events.

  • Discount created, updated, or deleted events.

  • Order created or updated events.

  • Customer created or updated events.

  • Cart created or updated events.

  • Checkout created, updated, or deleted events.

  • App uninstall or permission update events.

We use webhook events to keep data synchronized, trigger merchant-configured workflows, and maintain accurate integration status.

8. Data Sharing

We do not sell, rent, or trade your personal, customer, order, or business data.

Your data may be shared only:

  • With Meta Platforms, Inc. and WhatsApp, as required to provide messaging functionality.

  • With Shopify, as required to provide Shopify integration functionality.

  • With trusted service providers such as hosting, infrastructure, database, monitoring, and communication providers under appropriate confidentiality and security obligations.

  • With connected platforms or services that you authorise.

  • When required by law, regulation, court order, or legal process.

  • To protect the rights, safety, and security of DevFlow, our users, customers, or the public.

9. Service Providers and Infrastructure

We may use trusted third-party service providers to host, process, store, secure, and deliver the App and related services.

These providers may process information only as needed to provide services to DevFlow and are required to protect the information appropriately.

10. Data Storage and Retention

We store information securely using appropriate technical and organisational safeguards.

Data is retained only for as long as necessary to:

  • Provide the service.

  • Maintain connected integrations.

  • Support audits, logs, troubleshooting, and security monitoring.

  • Comply with applicable laws and platform requirements.

  • Maintain accurate business records.

  • Support merchant-configured communication and ecommerce workflows.

Message data, logs, ecommerce records, webhook payloads, and customer records may be retained while the merchant account or integration remains active, unless deletion is requested or a shorter retention period is required.

You may request deletion of your data at any time, subject to any legal, security, audit, or compliance obligations that require retention.

11. Data Security

We take data security seriously and implement appropriate safeguards, including:

  • Secure authentication and access controls.

  • Encrypted connections.

  • Secure handling of integration access tokens and secrets.

  • Limited internal access to customer and business data.

  • Monitoring for unauthorised access or misuse.

  • Logging and audit controls.

  • Use of secure hosting and infrastructure providers.

  • Separation of tenant data where applicable.

Access tokens, secrets, and integration credentials are stored securely and are not intentionally exposed to browsers, public users, or unauthorised parties.

12. Customer Data and Merchant Responsibility

Merchants are responsible for ensuring they have the necessary rights, permissions, notices, and legal basis to use customer information with our platform.

This includes responsibility for:

  • Obtaining required customer consent where applicable.

  • Sending messages only where legally permitted.

  • Complying with marketing, electronic communication, privacy, and data protection laws.

  • Respecting opt-out and unsubscribe requests.

  • Using WhatsApp, Meta, Shopify, and other connected platforms in accordance with their terms and policies.

DevFlow provides tools and integrations, but the merchant remains responsible for how they configure and use those tools for their own customers.

13. Your Rights

Depending on applicable law, you may have the right to:

  • Request access to your data.

  • Request correction of inaccurate information.

  • Request deletion of your data.

  • Request restriction or objection to certain processing.

  • Request export of certain data.

  • Disconnect the App from Meta, WhatsApp Business, Shopify, or another connected service.

  • Withdraw consent where processing is based on consent.

You can manage certain permissions directly through the relevant platform, such as Meta Business Manager, WhatsApp Business settings, Shopify admin, or your DevFlow account.

You may also contact us for assistance.

14. Data Deletion Requests

You may request data deletion by:

  • Removing or disconnecting the App from your connected platform account.

  • Uninstalling the Shopify app from your Shopify store.

  • Removing the App from your Meta Business account.

  • Contacting us at info@devflowltd.com.

Once verified, we will delete or anonymise your data unless we are legally required or permitted to retain it.

For Shopify stores, we may process required privacy or deletion requests received through Shopify’s required data request and redaction mechanisms where applicable.

15. App Uninstall and Disconnection

If you uninstall or disconnect an integration:

  • We will mark the integration as inactive.

  • We will stop using the access token or credentials for that integration.

  • We may retain historical logs or business records where needed for security, troubleshooting, legal, audit, or compliance purposes.

  • You may request deletion of retained data, subject to applicable legal or operational requirements.

16. International Transfers

Our services and service providers may process information in countries other than your country of residence or business operation.

Where applicable, we take reasonable steps to ensure that personal information remains protected in accordance with this Privacy Policy and applicable data protection laws.

17. Children’s Privacy

Our App is intended for business use and is not directed at children.

We do not knowingly collect personal information from children through the App. If you believe that a child’s information has been provided to us, please contact us so that we can take appropriate action.

18. Compliance

Our App is designed to support compliance with:

  • Meta Platform Terms and Developer Policies.

  • WhatsApp Business Platform Policies.

  • Shopify requirements and applicable Shopify API policies.

  • Applicable data protection laws, including POPIA and GDPR where applicable.

  • Applicable electronic communication and marketing laws where relevant.

Merchants are responsible for ensuring their own use of the platform complies with laws and platform rules that apply to their business and customers.

19. Changes to This Policy

We may update this Privacy Policy from time to time.

Any updates will be published on this page with a revised “Last updated” date.

Continued use of the App after updates means you accept the updated Privacy Policy.

20. Contact Us

If you have any questions about this Privacy Policy or how your information is handled, please contact:

DevFlow Pty Ltd
Email: info@devflowltd.com

Learn how we helped 100 top brands gain success.

Let's have a chat