Privacy Policy
AiBayya is a WhatsApp sales assistant operated by Difae Research. Running it means handling two different sets of people's data: the merchant who signs up, and the shoppers who message that merchant's WhatsApp number. This page states exactly what is collected in each case, which third parties it passes through, where it is stored, how long it is kept, and how to have it deleted. It describes the service as it actually works today, not an aspiration.
Last updated
Who is responsible for what
The distinction below decides who you contact, so it comes first.
- For merchant account data, we are the controller. Difae Research decides what is collected when a store signs up and how it is used, and answers directly to the merchant for it.
- For shopper conversation data, the merchant is the controller and we are the processor. The conversations belong to the store the shopper chose to message. We store and process them on that store's instructions, and we do not decide what happens to them independently.
In practice: if you are a shopper who messaged a store, the store owns that conversation and is the right first contact. We will still act on a request sent to us, and will pass it to the merchant where they are the controller.
What we collect from merchants
- Store identity: the store domain, display name, currency, and the platform it runs on.
- Account credentials for the connections you authorise: the store access token, WooCommerce keys, POS token, and your WhatsApp phone number ID and access token.
- Contact details for the account owner, including the email address used to sign in to the merchant portal and, if you set one, the phone number for owner alerts.
- Usage and billing records: conversation counts against your plan, model token counts, and payment records.
- Operator audit records: when a member of our team views or changes an account, that action is logged.
We do not collect payment card numbers. Where a plan is paid through a store platform's billing system, that platform holds the card details and we only see the resulting subscription and charge records.
What we collect about shoppers
Only what arrives because a shopper chose to message a store on WhatsApp, or placed an order with it. There is no tracking pixel, no advertising identifier, and no purchase of data from anyone.
- The WhatsApp number the customer messages from, and the profile name WhatsApp presents with it.
- The full content of the conversation in both directions, stored message by message, including messages the assistant sends.
- Cart contents and order records tied to that number: items, quantities, prices, order numbers, and status.
- A marketing opt-out flag, set when the customer replies STOP.
- Timestamps, and for assistant replies the model used and its token counts, which is how usage is metered.
Conversations are stored in full because the assistant needs the recent history to answer coherently, and because the merchant needs to be able to read what was said in their name. Recent messages from a conversation are replayed as context to generate the next reply.
We never sell personal data, and we never use one merchant's data to serve another. Data is isolated per store at the database level, and inbound messages are routed strictly by the WhatsApp phone number ID that received them.
Why we process it
- To perform the contract. Answering a shopper, building a cart, creating an order, and sending an order update are the service itself.
- Legitimate interests. Keeping the service secure, preventing abuse, metering usage against a plan, and diagnosing faults.
- Consent, for marketing messages only. Broadcasts and promotional templates go only to people who can lawfully receive them, and every recipient can stop them by replying STOP, which is honoured permanently and immediately.
- Legal obligation. Retaining billing and tax records for the period the law requires.
Order confirmations, shipping notices, and cash-on-delivery confirmations are transactional messages about a purchase the person made. They are not marketing and are not gated on marketing consent, which is also how Meta categorises them.
Who else processes it
Four categories of third party, and no others. Each one is necessary for the service to function.
| Processor | What it receives | Why | Where |
|---|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Phone numbers, profile names, and the content of every WhatsApp message in both directions. | Meta operates WhatsApp. It is the carrier: a message cannot reach a customer without passing through it. | Global infrastructure, governed by Meta's own terms. |
| OpenAI | Message text from the conversation, plus product and order details needed to answer, sent as prompt context. | Generates the assistant's replies. OpenAI states that data submitted through its API is not used to train its models. | United States. |
| Your store platform (Shopify, WooCommerce, or your POS) | Product, inventory, cart, and order data, read and written using credentials the merchant granted. | The assistant quotes real prices, real stock, and creates real orders. It is the merchant's own store, connected on the merchant's instruction. | Wherever that platform hosts the merchant's store. |
| Hetzner Online GmbH | Everything above, at rest in the application database. | Hosts the servers the service runs on. | Helsinki, Finland (European Union). |
We may also disclose data where the law compels it, or to establish or defend a legal claim. If the business is ever sold or merged, data moves with it and merchants are told before that happens.
Where it is stored, and transfers
The application database and servers are in Helsinki, Finland, inside the European Union. Two of the processors above operate outside it: message delivery necessarily reaches Meta's global infrastructure, and reply generation sends conversation text to OpenAI in the United States. Both transfers are necessary to deliver the service a merchant has asked for, and both are covered by the respective provider's data-processing terms and standard contractual clauses.
How long it is kept
- Conversations and orders are kept for as long as the merchant's account is active, because they are the merchant's own record of their customers. There is no automatic expiry today.
- Uninstalling or disconnecting deactivates the account, it does not erase it. This is deliberate: merchants reinstall, and losing their order history to a mis-click would be worse. Data is erased when someone asks, following the deletion process.
- Billing and tax records are kept for the statutory period even after deletion of everything else, because we are required to keep them.
- Credentials are erased immediately when a connection is removed or an account is deleted.
Your rights
Wherever you live, we will act on a request to access, correct, export, or delete your data, and to object to or restrict processing. If you are in the EU or UK you have these rights under the GDPR, including the right to complain to your local supervisory authority.
The deletion page sets out exactly how to make the request, what happens to each category of data, and how long it takes. Requests are free, and we do not require an account to make one.
Security
- All traffic runs over HTTPS, with strict transport security enforced.
- Inbound WhatsApp webhooks are rejected unless they carry a valid Meta signature, and store webhooks are rejected unless they carry a valid platform signature. An unsigned or forged request never reaches the message handler.
- The database is bound to the local machine only and is not reachable from the internet. The application runs as an unprivileged user.
- Access to production data is limited to the operators who need it, and operator actions on an account are recorded in an audit log.
Stated plainly: credentials are held in the database without an additional layer of application-level encryption at rest, protected by the controls above. We would rather say that than imply a safeguard we have not built. No service can promise perfect security, and if a breach affects your data we will tell you and the relevant authority within the time the law allows.
Children
The service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If a shopper's message reaches us and we learn they are under 16, we delete the conversation on request from them or their guardian.
Changes
When this policy changes materially, the date below moves and active merchants are notified by email before the change takes effect. Superseded versions are available on request.
Contact
AiBayya is operated by Difae Research, a sole proprietorship registered with the Federal Board of Revenue in Pakistan.
Privacy questions, access requests, and deletion requests: privacy@difaeresearch.com. We answer within 30 days, and usually far sooner.
Effective 2026-08-23.