Legal

Privacy Policy

Last updated: June 10, 2026

This privacy policy describes how Ordylo ("Ordylo", "we", "our service") collects, uses and protects the personal information of merchants who use our platform and of their end customers.

Ordylo is a B2B SaaS OMS (Order Management System) for e-commerce merchants in Morocco and the Maghreb, with a Cash on Delivery (COD) focus. Our service integrates Instagram Messaging and WhatsApp Business to centralize customer conversations, as well as e-commerce platforms (Shopify, YouCan, WooCommerce, etc.) to sync orders and catalog.

This policy complies with the General Data Protection Regulation (GDPR), Moroccan Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and the requirements of the Meta platform for applications using the Instagram and WhatsApp Business APIs.

1. What data we collect

1.1 Merchant account data

At sign-up and during use, we collect:

  • Account credentials: email, password (hashed via bcrypt, never stored in clear text), first and last name
  • Brand information: business name, logo, phone, address, city, country
  • Declared product categories
  • Activity logs (logins, actions performed) for security and audit purposes

1.2 Data from Instagram (via Meta Graph API)

When the merchant connects their Instagram Business account to Ordylo, we access the following data through the Meta Graph API, solely for the purposes described in section 2:

  • Technical identifiers: Instagram User ID, associated Facebook Page ID, OAuth access tokens (encrypted at rest via AES-256-CBC)
  • Published media: photos, reels and stories posted by the merchant on their account (URLs, captions, timestamps). Downloaded to our servers for indexing and matching against the catalog
  • Direct messages (DMs): content, sender technical identifiers, timestamp. Received via Meta webhook to enable replies through the Ordylo unified inbox
  • Minimal public profile of the correspondent (Instagram username, display name, avatar) to identify the customer in the inbox

1.3 Data from WhatsApp Business (via WhatsApp Cloud API)

If the merchant connects a WhatsApp Business number:

  • Technical identifiers: Phone Number ID, WABA ID, Business Manager ID, access tokens (encrypted)
  • Sent and received messages: content, customer phone number, timestamp
  • Message templates approved by Meta for transactional notifications

1.4 Data from connected e-commerce platforms

When a merchant connects their store (Shopify, YouCan, WooCommerce, Salla):

  • Product catalog: names, descriptions, prices, stock, photos, variants
  • Orders: order number, contents, amount, status, payment method
  • Customer data tied to orders: first and last name, phone, delivery address, email (where applicable)

1.5 Cookies and technical data

The Ordylo application (app.ordylo.com) uses only strictly necessary cookies (JWT session, UI preferences). No advertising cookies, no third-party tracking for marketing purposes.

2. What this data is used for

We use the collected data solely for the following purposes, in line with the commitments made to Meta and with the GDPR:

  • Centralizing conversations: displaying Instagram and WhatsApp messages in a unified inbox so the merchant can reply
  • AI-assisted replies: the Ordylo AI agent (when the merchant enables it) generates suggestions or automatic replies to customers using the content of received messages, the product catalog, and the merchant's Instagram media. Processing is carried out by our LLM providers (see section 5)
  • Product matching: automatically associating Instagram media (posts, stories) with catalog products to identify which product a customer is referring to in a DM
  • Order management: tracking the merchant's COD orders from creation to delivery, computing delivery rates, managing carriers
  • Transactional notifications: sending customers (via WhatsApp or email) notifications about their order status (confirmed, shipped, delivered)
  • Authentication and security: securing merchant accounts, detecting suspicious access attempts
  • Service improvement: aggregated and anonymized usage analytics to improve Ordylo

We NEVER use the collected data for targeted advertising, retargeting, resale to third parties, or to train proprietary artificial intelligence models.

3. Legal basis for processing

In accordance with Article 6 of the GDPR, our processing relies on the following legal bases:

  • Performance of a contract (Art. 6.1.b): for the services requested by the merchant (order management, inbox, AI assistant)
  • Consent (Art. 6.1.a): for the Instagram and WhatsApp connection, obtained through the Meta OAuth flow which clearly presents the requested permissions to the merchant. The merchant can revoke this consent at any time from their Meta Business dashboard
  • Legitimate interest (Art. 6.1.f): for platform security, fraud detection, and aggregated usage statistics
  • Legal obligation (Art. 6.1.c): for retaining certain accounting and tax records under Moroccan law

4. How long we keep the data

  • Active merchant account: as long as the account remains active
  • Instagram and WhatsApp messages: kept while the merchant account is active, deleted within 30 days after account deactivation or revocation of the Meta connection
  • Downloaded Instagram media: deleted within 30 days after account deactivation
  • Order data: 10 years for accounting and tax reasons (Moroccan and EU law), then automatic deletion
  • Technical logs: 90 days, then automatic deletion
  • Data after a deletion request: see section 7

5. Who we share data with

Ordylo never sells your data. We share certain data with technical sub-processors strictly necessary for the operation of the service, governed by data processing agreements (DPAs):

  • Neon (hosted PostgreSQL, US/EU): primary database
  • DigitalOcean (Amsterdam): Ordylo application servers
  • Cloudflare: DDoS protection, CDN, landing site hosting
  • Meta Platforms Ireland Ltd.: Instagram and WhatsApp Business APIs (messages transit through their servers to be received and sent)
  • AI providers: for generating automatic replies and analyzing media, when the merchant enables the AI agent. We use GDPR-compliant providers (with signed DPAs) that commit to not using the data to train their models
  • Resend: sending transactional emails (verification, invitations, notifications)
  • Moroccan and international carriers: the data strictly necessary for delivery (name, phone, address) is transmitted to the carrier chosen by the merchant for each order

We do not transfer any data to countries lacking an adequate level of protection without standard contractual clauses or other appropriate safeguards.

5.1 Shared anti-fraud signal between merchants

To prevent cash-on-delivery fraud (fake orders, scams, serial refusals), Ordylo lets merchants flag risky phone numbers. These reports feed a list shared between merchants, but only as hashed numbers (an irreversible cryptographic fingerprint): no merchant can view, browse or download this list, nor discover a number they do not already hold. A merchant is only warned when a number they already have (a customer contacting them or placing an order) has been flagged by several distinct merchants; they remain the sole decision-maker. This processing relies on the legitimate interest of fraud prevention (Art. 6.1.f GDPR). Anyone may dispute a flag by writing to privacy@ordylo.com or via our online dispute form; it will be reviewed and removed if unjustified.

6. Data security

We implement appropriate technical and organizational measures to protect the data:

  • TLS 1.2+ encryption for all communication between your browser and our servers
  • AES-256-CBC encryption at rest for OAuth access tokens (Meta, e-commerce platforms)
  • Passwords hashed via bcrypt (cost factor 12)
  • JWT authentication with rotation, sessions limited to 7 days, automatic logout after 30 minutes of inactivity
  • Strict multi-tenant isolation: each merchant has a tenant_id identifier systematically checked on every request. No cross-tenant leakage is possible by design, with the sole exception of the shared anti-fraud signal (section 5.1), which shares only hashed numbers — never customer data in clear text
  • Daily encrypted backups
  • Audit logs kept for 90 days

7. Your rights

In accordance with the GDPR and Moroccan Law No. 09-08, you have the following rights regarding your personal data:

  • Right of access: obtain a copy of the data we hold about you
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): request deletion of your data (subject to legal retention obligations)
  • Right to restriction of processing
  • Right to portability: retrieve your data in a structured, commonly used, machine-readable format
  • Right to object to processing based on legitimate interest
  • Right to withdraw your consent at any time (Meta connections can be revoked from your Business Manager)
  • Right to lodge a complaint with the CNDP (National Commission for the Control of Personal Data Protection) in Morocco, or with your national supervisory authority in the EU (e.g. the CNIL in France)

To exercise these rights, contact us at privacy@ordylo.com. We respond within 30 days.

8. Data deletion — Meta procedure

In accordance with Meta platform requirements, you can request deletion of the data associated with your Instagram or WhatsApp connection via Ordylo in two ways:

Option 1 — From your Ordylo dashboard (recommended)

  1. Log in at https://app.ordylo.com
  2. Go to Settings → Communications
  3. Click Disconnect Instagram or Disconnect WhatsApp
  4. All data associated with that connection (OAuth token, downloaded media, messages, technical identifiers) is deleted within 30 days

Option 2 — From your Meta account (App Removal)

  1. Go to facebook.com/settings → Business Integrations
  2. Find Ordylo in the list of connected apps
  3. Click Remove
  4. Meta will notify us automatically via the User Data Deletion Callback. Your data will be deleted from our systems within 30 days

Option 3 — Direct request by email

Send an email to privacy@ordylo.com with your Instagram User ID or WhatsApp Phone Number ID. We will process your request within 30 days and confirm by email.

Meta callback URL: if you are a Meta developer consulting this page to configure your application, our Data Deletion Callback endpoint is https://app.ordylo.com/api/communications/instagram/data-deletion. It accepts POST requests signed by Meta and returns a confirmation URL plus a tracking code in accordance with the specification.

9. Changes to this policy

We may update this privacy policy to reflect changes to our service, legal requirements or best practices. The last-updated date appears at the top of this page.

Any significant change will be notified to you by email at the address associated with your merchant account, at least 30 days before it takes effect. Continuing to use Ordylo after that date constitutes acceptance of the new version.

10. Contact us

For any question about this privacy policy or the processing of your data: