Privacy Policy
Last updated September 11, 2026
This Privacy Policy explains what information Oderfy processes, why, and how it is protected, when a merchant connects their Shopify store to Oderfy's AI-assisted order-confirmation service.
1. Who this applies to, and our role
Oderfy is a service that merchants (“you,” “merchant”) connect to their Shopify store so that an AI voice agent can call the merchant's own customers to confirm cash-on-delivery (COD) orders before they ship.
For order and customer data that flows from a merchant's Shopify store into Oderfy, the merchant is the data controller and Oderfy acts as a data processor, processing that data only to provide the service the merchant has configured — not for Oderfy's own independent purposes. Oderfy does not have a direct relationship with the merchant's end customers; those individuals' relationship (including their own consent to be contacted, where required) is with the merchant, governed by the merchant's own store policies.
2. Information we process
Merchant account information: name, email address, and password (stored only as a one-way cryptographic hash — we never store or can recover your actual password), and your subscription plan/billing status.
Shopify store connection information: your store's domain, the access token Shopify issues when you connect your store (encrypted at rest — see Section 8), and the specific permissions (“scopes”) you granted, which are exactly read_orders and read_products — nothing broader.
Shopify order and product data, synced automatically when an order is placed: order and product identifiers, product name/variant, price, and the following customer fields necessary to confirm the order by phone:
- Name
- Phone number
- Email address
- Shipping/billing address
We do not request or process a customer's full historical order data, payment card details, marketing preferences, or any Shopify data category beyond what the read_orders/read_products scopes and the fields above cover.
Call data: the outcome of each confirmation call (for example: confirmed, cancelled, a requested change, no answer, or unclear), and operational metadata about the call (timing, stage reached, retry count). We do not currently store or make available the audio recording of a call as a usable feature — our systems keep only an internal reference/pointer to where a recording might exist on our telephony infrastructure, and no mechanism currently exists to retrieve or play back that audio. If this changes in the future, this policy will be updated before the feature is enabled.
Billing/wallet information: your subscription plan, prepaid wallet balance, and top-up/usage history. Card and payment-method details themselves are handled directly by our payment processor, not stored by Oderfy — see Section 7.
Service and security logs: standard operational logs (timestamps, request outcomes, error codes) used to run and secure the service. We take care not to log full customer PII or credentials in these logs.
Account session data: a security token stored in your browser's local storage to keep you signed in. We do not use third-party advertising or analytics cookies.
3. Why we process this information
- To detect new COD orders from your connected Shopify store.
- To place an AI-assisted phone call to your customer to confirm, modify, or cancel the order before it ships, in Moroccan Darija or another supported language.
- To show you the resulting order and call status in your dashboard.
- To operate, secure, and improve the service (fraud prevention, abuse prevention, debugging).
- To bill your account according to your selected plan and prepaid wallet balance.
- To comply with Shopify's own mandatory data-request, data-erasure, and shop-erasure requirements (Section 9).
We do not sell personal data, and we do not use customer data for advertising, marketing profiling, or any purpose beyond providing the service described above.
4. Automated calling and how outcomes are decided
An AI voice agent conducts the confirmation call. The customer's own spoken response during the call (for example, saying “yes”/“confirmed” or “no”/“cancel,” in Darija, Arabic, French, or English) determines the recorded outcome — it is not a decision the AI reaches unilaterally without the customer's participation. The outcome is then shown to the merchant as information; it does not, by itself, cancel, ship, refund, or otherwise automatically execute any action on the order. The merchant decides what to do next.
5. Subprocessors
We use the following service providers to operate Oderfy:
- Shopify — the platform your store runs on and the source of order/product data.
- Twilio — telephony infrastructure that places and connects the confirmation call.
- Google (Gemini API, and Google Cloud Speech-to-Text where applicable) — AI language understanding, text-to-speech, and speech-to-text used during the call.
- OpenAI — real-time AI voice conversation for the Android-based calling path.
- Our infrastructure hosting provider — runs the servers and database that store the information described in Section 2.
We do not currently use a live payment processor in production for merchant billing (see Section 7).
6. International processing
Our infrastructure and subprocessors may process data in countries other than the one your store or your customers are located in. Each subprocessor operates under its own data-protection commitments; we select subprocessors with established security practices. If you need details about a specific transfer for your own compliance purposes, contact us (Section 13).
7. Payments
Stripe is integrated into our codebase but is not yet an active production payment processor. Wallet top-ups and plan billing, where currently live, are handled through Oderfy's own prepaid wallet ledger. When a live card-payment processor is activated, this policy will be updated to name it before it goes live, and no payment-card data will ever be stored directly by Oderfy.
8. Security measures actually in place today
We take the security of your data seriously. As of this policy's last-updated date, verified measures include:
- Your Shopify access token is encrypted at rest with a dedicated encryption key, never logged, and automatically refreshed before it expires.
- All traffic to our service is encrypted in transit (HTTPS/TLS).
- Access to your data is scoped strictly to your own account at the database and application layer; no merchant can see another merchant's data.
- Elevated or cross-account access to customer data (for support or operational purposes) requires a specific internal permission separate from ordinary account access, and every such access is logged.
- Shopify's own mandatory webhook requests are cryptographically verified before we act on them.
We are actively working on additional measures that are not yet complete, including broader encryption of customer/order data at rest, encrypted and off-site backups, and multi-factor authentication for internal accounts. We will update this section as each is completed rather than claim them in advance.
9. Shopify-mandated privacy requests
As required by Shopify for all apps, we honor Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks: a customer data request is recorded for manual fulfillment, and redaction requests permanently remove identifying fields (name, phone, email, address) from the affected order records while preserving the underlying business/financial record integrity your accounting may require. Redaction of an entire shop's data occurs only after the store has been disconnected.
10. Your rights, and your customers' rights
If you are a merchant, you can request a copy or deletion of your own account data, or disconnect your store at any time (which stops new data from syncing) by contacting us (Section 13).
If you are a customer of a merchant using Oderfy, please contact the merchant directly for requests about your personal data — the merchant is best positioned to identify your data across their own systems, and Shopify's own mandatory data-request/redaction flow (Section 9) is the mechanism through which that request reaches us as the merchant's processor.
11. Retention
We keep personal data only as long as needed for the purposes in Section 3, or as required by law (for example, financial/accounting record-keeping). A specific, numbered retention schedule per data category is being finalized, and this section will be updated with exact periods once that work is complete and enforced. Until then, data is retained at minimum for the duration your store remains connected, and is redacted in response to Shopify's mandatory data-erasure webhooks (Section 9) as already described.
12. Children's privacy
Oderfy is a business-to-business service intended for use by merchants operating a commercial Shopify store, not by children, and is not directed at children.
13. Contact
Questions about this policy, or a request under Section 10, can be sent to oderfy.com@gmail.com.
14. Governing law
We operate the Oderfy service and are in the process of finalizing our registered business entity and jurisdiction. This section will be updated with a specific governing-law and registered-address clause once that process is complete.
15. Changes to this policy
We will update the “Last updated” date above whenever this policy changes, and will not reduce your rights under this policy without clear notice.