Privacy Policy
Last updated: 2026-08-23
Wakeel is a platform that runs an AI sales and customer service agent for online stores. This page explains what we collect, why, who processes it, and how to delete it. It describes what the system actually does, not a template.
Who controls the data
There are two kinds of user: the **merchant** who opens an account with us, and the **merchant's customer** who talks to the agent. For merchant account data we are the controller. For their customers' conversations and orders, the merchant is the controller and we are a processor acting on their behalf — the agent answers on behalf of their store, and they decide what is stored and when it is deleted.
What we collect
- •Merchant account: name, email, store name, language, currency, time zone.
- •Store content the merchant enters: products, prices, policies, knowledge base, business hours, shipping rates.
- •Customer conversations: message text, the channel (WhatsApp or website chat), the customer's identifier on that channel (their WhatsApp number, for example), and timestamps.
- •Customer memory: facts the customer states about themselves during a conversation — their name, sizes, preferences, delivery address. We do **not** store the contents of their questions as facts about them.
- •Orders, tickets and bookings the agent records, plus subscription and billing data.
Why we collect it
Conversations, memory and catalogue are what let the agent answer correctly: know your prices, recognise a returning customer, and record an order without asking them to repeat themselves. Account and billing data run the subscription. We do not sell any data, and we do not use your store's conversations to train models.
Who processes data with us
- •OpenAI — to generate the agent's replies. Message text and store context are sent to their API. Business accounts there are not used for training.
- •Meta (WhatsApp Cloud API) — to receive and send WhatsApp messages.
- •Stripe — for card payments. Card details never touch our servers.
- •Neon — database hosting · Railway — application hosting · Hostinger — email.
How we protect it
- •Store isolation is enforced by the database itself (Row-Level Security), not only in application code. One store cannot read another store's rows even if a query is written wrong.
- •Channel tokens (WhatsApp and others) are encrypted at rest with AES-256-GCM.
- •Passwords are stored as bcrypt hashes, never in plain text.
- •WhatsApp webhooks are verified by HMAC signature; anything with an invalid signature is rejected.
- •Traffic to the site and API is over HTTPS; the database connection uses TLS.
How long we keep it
We keep store data and conversations for as long as the account is active. When a subscription lapses the account drops to a limited plan and **the data stays intact** — nothing is deleted automatically. Deletion happens when you ask for it; see the data deletion page.
Your rights
You can request a copy of your data, its correction, or its deletion. A merchant's customer who wants their data removed can contact the store directly or contact us. Email hello@wakeelhq.com; we respond within 30 business days at the latest.
Changes to this policy
If we change anything material we update the "last updated" date above and notify merchants by email. Continuing to use the service after a change means accepting it.