SnopDesk AI ("SnopDesk", "we", "us") operates a multi-tenant software-as-a-service platform that helps e-commerce merchants manage a shared WhatsApp customer-support inbox, confirm orders, and use AI-assisted replies, at app.snopdesk.com and related services (the "Service"). This Privacy Policy explains what personal data we process, why, and what choices you have. It applies to merchants who create a SnopDesk workspace ("merchants", "you") and, where relevant, to the end customers merchants communicate with through the Service.
1. Introduction and scope
This policy covers the SnopDesk web application, its APIs, and the official and legacy WhatsApp connection methods described in §9. It does not cover third-party websites or services we link to, including Meta's own platforms, which are governed by their own privacy notices.
2. Identity and contact details
The Service is operated by SnopDesk AI. For privacy inquiries or data-subject requests, contact contact@snopdesk.com.
Legal facts requiring confirmation before publication: the precise registered legal entity name, registered business address, and whether a Data Protection Officer or EU/UK representative is required, are not yet confirmed in this document — see docs/legal-review-required.md. This policy uses "SnopDesk AI" as the operating name pending that confirmation.
3. Our roles as controller and processor
SnopDesk's role depends on the data involved — we are not always only one or the other:
- Controller: for merchant account data, billing and subscription data, workspace security/audit logs, and our own marketing or support communications with you.
- Processor: for data about your end customers and their orders and messages, which you (the merchant) instruct us to process on your behalf through the Service. You are generally the controller of that end-customer data.
- Independent processing: in limited cases — security monitoring, fraud and abuse prevention, and compliance with legal obligations — we may determine the means and purposes of processing ourselves, acting as an independent controller for that narrow purpose.
- Meta / WhatsApp: Meta Platforms, Inc. processes data under its own terms as a separate, independent party — see §9. SnopDesk is not Meta and does not control Meta's processing.
See the Data Processing Agreement for the contractual terms that apply where SnopDesk acts as your processor.
4. Categories of information we collect
Merchant account data: name, email address, hashed password or authentication identifiers, workspace membership and role, workspace settings, subscription and invoice metadata, support communications, and audit/security events.
Merchant-customer data: name, phone number, order details, items, totals, shipping information, delivery status, and customer support communications your workspace collects while serving your customers.
WhatsApp data: contact identifiers, message content, timestamps, conversation history, media and media metadata, interactive replies, delivery/read/failure statuses, and voice notes and their transcriptions where voice features are enabled for your workspace.
Meta integration data (official connections only): Meta business/user authorization identifiers, WhatsApp Business Account (WABA) ID, business phone-number ID, display number and verified business name, granted permission scopes, message-template metadata, webhook event data, encrypted authorization tokens, token expiration, and connection/quality status. See §9.
AI-related data: prompts sent to AI providers, relevant conversation context, knowledge-base excerpts, product/catalog information, generated draft or sent replies, classifications, and voice transcriptions, where these features are enabled. See §10.
Technical data: IP address, browser and device information, application logs, the cookies described in §13, authentication events, webhook events, and abuse/security signals.
Payment data: Stripe customer, subscription, and invoice identifiers and billing status. We do not store full payment card numbers — Stripe processes and stores card details directly. See §12.
5. Sources of information
- Directly from you, when you create an account, configure a workspace, or contact support.
- From your end customers, when they message your WhatsApp number.
- From Meta, through Embedded Signup and webhook events, once you connect an official WhatsApp line.
- From store platforms (Shopify, YouCan) and delivery carriers you connect, per the permissions you grant them.
- From Stripe, for billing and subscription status.
- Automatically, through your use of the Service (technical data, per §4 and §13).
6. Purposes of processing
- Provide, secure, and improve the Service.
- Receive and send WhatsApp messages on your behalf through your connected line.
- Import orders and send order confirmations and support replies.
- Run AI-assisted drafting, routing, and human-handoff workflows you configure.
- Process billing, prevent fraud and abuse, and comply with legal obligations.
- Send service, security, and product notices.
7. Legal bases (where applicable)
Where EU/UK/EEA data-protection law applies to our processing, we rely on the following bases, depending on the activity:
- Contract — to deliver the Service you signed up for.
- Legitimate interests — security, fraud prevention, and product improvement.
- Consent — where required (for example, optional features that request it).
- Legal obligation — tax, accounting, and regulatory requirements.
Where your end customers are concerned, you as the merchant are responsible for establishing a lawful basis for messaging them — see §8.
8. Merchant and customer responsibilities
As the operator of your workspace, you are responsible for: having a lawful basis and, where required, consent or opt-in before messaging a customer; configuring AI and automation features appropriately for your business; reviewing automated replies where your configuration requires it; and complying with WhatsApp's and Meta's own policies (see §9) and applicable law in your markets. SnopDesk provides the tools; you decide how your workspace uses them.
9. Official WhatsApp Business Platform and Meta
SnopDesk offers an official integration with Meta's WhatsApp Business Platform (Cloud API), and continues to support a legacy, unofficial QR-based connection method for some existing workspaces during migration. This section covers the official integration specifically.
When you complete Meta's Embedded Signup flow, you authorize SnopDesk to access only the WhatsApp Business Account and phone number(s) you select — never a WABA you have not authorized. That authorization lets SnopDesk receive your customers' messages, send replies you or your AI configuration approve, manage the message templates and other assets you permit, and display delivery/read status, all through Meta's official APIs and webhooks.
Your Meta access token is encrypted using authenticated encryption before it is stored, is never exposed to the browser, and is scoped to your workspace — it is not accessible from, or shared with, any other workspace. Every inbound Meta webhook is verified using Meta's signature scheme before we process it.
Meta and WhatsApp process data you send and receive through the platform under their own terms and privacy notices, independently of SnopDesk — see the WhatsApp Business Terms and Meta Privacy Policy. SnopDesk is an independent software provider that connects to the WhatsApp Business Platform — we are not WhatsApp or Meta, and we do not claim ownership of your WhatsApp Business Account or phone number. Disconnecting SnopDesk does not necessarily delete data Meta or WhatsApp independently retain — see §22.
10. AI processing
SnopDesk uses AI to analyze customer messages, draft or (where you enable it) automatically send replies, retrieve relevant knowledge-base and catalog information, and support human handoff. Automated sending is gated by confidence, knowledge-coverage, and risk checks configured per workspace; when those checks are not met, SnopDesk drafts a reply for human review or escalates to a human agent instead of sending automatically. You are responsible for configuring and supervising these features appropriately for your business, and generated replies can be inaccurate — human review is recommended for sensitive or high-stakes communications.
Where a workspace enables voice-note handling, inbound voice notes are transcribed to text so they can be processed the same way as text messages.
Message content and relevant context are sent only to the AI providers configured for your workspace (see §14) when needed to generate a response. Our default policy is not to use customer message content to train public foundation models; we are not in a position to make representations about how each third-party AI provider itself may use data under its own terms, beyond what that provider discloses in its own policies. We do not claim "zero retention" by any AI provider unless that is contractually confirmed — see docs/legal-review-required.md.
11. Store and logistics integrations
When you connect Shopify, YouCan, or a delivery carrier you configure, we receive the order, customer, and shipping fields needed to confirm orders and message customers, according to the permissions you grant those platforms. These are independent third-party services with their own terms — connecting them is your decision, and you can disconnect them at any time from your workspace settings.
12. Payments
Subscription billing is processed by Stripe. We store Stripe-issued customer, subscription, and invoice identifiers and billing status to manage your subscription — we do not store full payment card numbers. Stripe's processing of your payment details is governed by Stripe's own privacy policy.
15. International transfers
We and our providers may process data in Morocco, the European Union, the United States, and other countries where our infrastructure and service providers operate. Where a transfer requires a safeguard under applicable law (such as Standard Contractual Clauses), we use appropriate mechanisms for that transfer — see the Data Processing Agreement for detail on transfer mechanisms that apply where SnopDesk acts as your processor.
16. Retention
We retain personal data for as long as your workspace is active and as needed for the purposes described in this policy, using purpose-based retention rather than a single fixed period across all data types:
| Category | Retention approach |
|---|---|
| Merchant account & workspace configuration | While your account/workspace is active, plus a limited period after closure for legal, accounting, and dispute-defense purposes. |
| Conversation/message data (official WhatsApp connections) | While the connection is active, to support the inbox, order confirmation, and AI features. |
| Order data | While your workspace is active and as needed for accounting/tax obligations. |
| Meta authorization tokens | Deleted or disabled promptly when a connection is validly disconnected or deauthorized (see §22), subject to technical processing time. |
| Webhook idempotency receipts | Short-lived, kept only long enough to detect duplicate deliveries. |
| Billing/tax records | As required by applicable accounting and tax law. |
| Security/audit logs | As needed for security investigation and abuse prevention. |
| Backups | Backup copies may persist for a limited operational period after deletion from primary systems. |
Note for internal follow-up: SnopDesk does not yet publish a formal, numerically specified retention schedule for every category above. We recommend adopting one — see docs/legal-review-required.md. Deletion from backups is not instantaneous; backup copies are retired on their normal operational cycle rather than deleted on demand.
17. Security
We use encryption in transit (TLS), authenticated encryption for stored Meta access tokens, workspace data isolation, role-based access control, webhook signature verification, and redacted/structured logging that avoids storing full message bodies in aggregate logs. No method of transmission or storage is 100% secure.
18. Automated decision-making
SnopDesk offers optional AI-assisted and, if you enable it, automated order-confirmation features. These are configured per workspace by you, the merchant, and are gated by confidence, knowledge, and risk checks that route uncertain or high-risk cases to a human instead of sending or confirming automatically. We do not believe this constitutes solely automated decision-making that produces legal or similarly significant effects on your customers within the meaning of applicable law, since the feature is merchant-configured commercial order processing rather than an automated decision about an individual's legal status or rights — but you remain responsible for reviewing whether your specific configuration is appropriate for your customers and your legal obligations.
19. Your privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or port your data, object to certain processing, withdraw consent, and lodge a complaint with a competent supervisory authority. We respond within the period required by applicable law rather than a fixed universal timeframe.
To exercise rights related to your own SnopDesk merchant account, email contact@snopdesk.com. We may need to verify your identity before acting on a request.
20. Merchant end-customer requests
If you are a merchant, you are generally the controller for your end customers' data (§3), so you are responsible for handling their data-subject requests. SnopDesk assists you where we are contractually and legally required to, as your processor — see the Data Processing Agreement.
21. Children
The Service is not directed to children under 16. We do not knowingly collect their data.
22. Official WhatsApp Business Platform (Meta Cloud API)
This section explains how to disconnect the official WhatsApp integration and how data-deletion requests are handled — Meta requires this URL fragment (#data-deletion) to be directly reachable as part of App Review.
Disconnecting your WhatsApp connection: from your workspace's WhatsApp settings, you can disconnect the official connection at any time. Disconnecting immediately deletes the stored, encrypted access token and the connection's Meta-issued identifiers from our systems.
Requesting SnopDesk account or workspace deletion: email contact@snopdesk.com. We process account-deletion requests subject to §16 (Retention) — including legal, security, fraud-prevention, and accounting retention obligations that may require us to retain limited records even after a deletion request.
Meta's deauthorization and data-deletion callbacks: if you remove SnopDesk's access from your Meta Business settings, Meta notifies us through a cryptographically signed request. We verify that signature before acting on it, then disconnect the affected connection and delete its stored Meta credentials — this never affects another workspace, even one that happens to share the same WhatsApp Business Account (for example, an agency managing several clients' numbers). The same applies if you submit a data-deletion request to Meta directly: we verify Meta's signed request, delete the applicable Meta-derived credentials, and return a confirmation code and status page URL as Meta requires. You can check that status at https://app.snopdesk.com/whatsapp-data-deletion/{confirmation_code}.
Deleting or disabling your SnopDesk-side credentials does not, by itself, delete data Meta or WhatsApp independently retain under their own policies — for that, contact Meta directly through your Meta Business settings.
23. Region-specific disclosures
SnopDesk serves merchants in multiple regions, including Morocco and other Arabic-, French-, and Spanish-speaking markets, as well as English-speaking markets more broadly. Where EU/UK/EEA law applies to our processing of your data, §7 and §19 describe the applicable legal bases and rights. Where Moroccan data-protection law (Law 09-08 and CNDP requirements) applies, we intend to meet its requirements; the specific compliance steps (such as any required CNDP filings) are tracked in docs/legal-review-required.md pending confirmation. If California or other US state privacy law applies to you, additional disclosures may be required — also tracked in that document pending a determination of applicability.
24. Changes
We may update this policy. We will post the new date at the top and, for material changes, provide notice in the Service or by email.
25. Contact
Questions about this policy or your data: contact@snopdesk.com.