Data Processing
Status: engineering draft, not legal advice. To be reviewed by an Israeli lawyer before release.
1. Roles
- The merchant (store owner) is the controller of customer data. Kavimia Order Messaging is software running on the merchant's own site; the plugin author does not receive customer data.
- Meta Platforms is a processor/independent service the merchant contracts with directly (own WhatsApp Business account).
- Freemius (optional, only after opt-in) receives licensing/site data, see section 5.
2. Data sent to Meta (WhatsApp Cloud API)
| When | Data | Purpose |
|---|---|---|
| A configured order status event fires (processing/completed/cancelled) and, where consent is required, the customer ticked the consent box | Customer phone number (normalised), template name and language, first name, order number, order total | Deliver the order notification |
| Merchant presses "Save and test connection" / template actions | Phone Number ID, WABA ID, access token (Authorization header) | Verify credentials, create/read message templates |
| Nothing is sent when the master switch is off, for orders without consent (when consent is enabled), or when Meta is not configured. |
3. Data stored locally (merchant's database)
- Options: settings (access token stored in the options table; never displayed back or included in diagnostics).
- Order meta: consent flag (
yes/no) and per-event send markers. - Log table
{prefix}kavimia_om_whatsapp_log: order ID, event, masked phone, SHA-256 phone hash, template name, status, error code, provider message id, timestamp. No full phone number, no message text, no token. - Retention: log rows are deleted automatically after 180 days (filter
kavimia_om_whatsapp_log_retention_days, 0 keeps forever). - Uninstall: data removed only if the merchant ticked "Delete all Kavimia Order Messaging data" before uninstalling.
4. WordPress privacy tools (implemented in 0.1.4)
- Suggested privacy-policy text (Settings > Privacy).
- Personal data exporter: consent and log entries per order for an email address.
- Personal data eraser: deletes log rows and the consent flag for that email's orders. The per-event send markers are kept on purpose (operational idempotency state, no personal data; removing them could cause duplicate notifications).
- Note: the order itself and its billing phone are handled by WooCommerce's own exporter/eraser.
5. Freemius (optional)
- Before opt-in: only the licensing/update checks strictly needed by the SDK.
- After "Allow & Continue": site URL, plugin/WP/PHP versions, admin name and email; with license activation: license key. Skipping keeps all free features working.
Service providers
- Meta - message delivery / WhatsApp Cloud API
- Freemius - merchant of record, licensing, checkout and subscription management
- Cloudflare - website hosting/CDN, DNS and security (the Kavimia website is delivered through Cloudflare and may process technical request information such as IP addresses and request metadata for delivery and security purposes)
The exact legal role of each provider may vary by service and context.