Reco — Privacy Policy
Last updated: September 24, 2026
Reco ("the App") helps Shopify merchants add a WhatsApp chat button to their storefront and send WhatsApp messages such as abandoned-cart reminders, order confirmations, and shipping updates through the WhatsApp Business Platform (Meta). This policy explains what data the App processes and why.
Information we collect
When a merchant installs the App we access and store:
- Store information — store name, domain, and the settings the merchant configures in the App.
- Order and checkout information — order id, order total, checkout status, and fulfillment status, used solely to trigger the messages the merchant has configured.
- Customer contact information — customer name and phone number, used solely to deliver WhatsApp messages on the merchant's behalf, and only where the customer has consented (checkout text-marketing consent or an explicit WhatsApp subscription on the storefront).
- WhatsApp connection data — the merchant's WhatsApp Business Account id, phone number id, and access token issued by Meta during Embedded Signup.
- Message records — messages sent through the App and delivery/read receipts returned by Meta, plus customer replies to power the merchant's inbox.
How we use information
- To deliver the messaging features the merchant configures.
- To show the merchant analytics about their own messages.
- To comply with legal obligations.
We do not sell personal data or use it for our own advertising. We share it only with the processors needed to run the features the merchant turns on:
- Shopify — store, order, checkout and product data the App reads to run automations.
- Meta (WhatsApp Business Platform) — customer phone numbers and message content, to send and receive WhatsApp messages.
- Fly.io — hosting and database for the App.
- Resend — delivery of the App's emails to the merchant (the store's contact email address): setup, account and service alerts. Never used to email the store's customers.
- Anthropic — when the merchant enables the AI chatbot, incoming customer messages and the store's product and FAQ information are sent to generate replies.
- Groq — when the AI chatbot is enabled, customer voice notes are sent for transcription.
- PostHog — product analytics and session replay of the App's admin screens used by the merchant. Screens showing customer data (inbox, message logs, subscribers, chats) are never recorded.
- Klaviyo, Zapier and other integrations — only when the merchant connects them; subscriber and event data are sent to the service the merchant chose.
Consent and opt-out
Marketing messages are only sent to customers who opted in. Customers can opt out at any time by replying STOP to any message; the App honors the opt-out immediately.
Data retention and deletion
Data is retained while the merchant uses the App. When a store owner deletes a customer, or uninstalls the App, we permanently delete the related personal data in response to Shopify's GDPR webhooks (customers/redact, shop/redact). Customers may also request deletion through the merchant they purchased from.
Security
Data is stored on encrypted infrastructure, access tokens are kept server-side only, and all traffic uses TLS.
For support and troubleshooting, authorized Reco staff can view a merchant's app (including conversations) in a strictly read-only mode. Each access is time-limited, individually logged, and cannot change any data.
Contact
Questions or data requests: contact@getrecoverly.net