Privacy policy
Effective 1 August 2026 · Applies to the Waslio Shopify app and waslioconnect.com
Waslio ("the app", "we") is a delivery-dispatch application for Shopify stores, operated by Waslio ("the developer"). This policy explains what data the app receives, why, and what happens to it. When a merchant installs Waslio, the app processes data on the merchant's behalf to provide delivery dispatch and tracking.
Information the app collects
When installed on a Shopify store, Waslio accesses:
- Store information — store domain, store contact email, and the permissions granted at install (read/write orders, fulfillments).
- Order information — order numbers, delivery addresses, order tags, payment status, and delivery-slot attributes, for orders the merchant dispatches (or has auto-dispatch evaluate).
- Customer information within orders — the recipient's name, shipping address, coordinates and phone number. This is collected solely to arrange the delivery.
- Courier account credentials — API keys the merchant enters for their own courier accounts (noon Send, Careem Express, Quiqup, and others). These are encrypted with AES-256-GCM before storage and are never logged or shared.
- Delivery events — courier status updates, rider name/phone and rider location during an active delivery, and optional customer delivery ratings.
- Support messages — messages a merchant sends through the in-app support chat, with their reply-to email.
How information is used
- To create delivery tasks with the couriers the merchant has connected — the recipient's name, address, coordinates and phone number are transmitted to the selected courier so the rider can complete the delivery.
- To show live delivery status to the merchant and, via an unguessable tracking link, to the order's recipient.
- To update the order's fulfillment status in Shopify and optionally tag orders and trigger Shopify's customer notification emails.
- To produce the merchant's own delivery analytics.
- To remember a confirmed map pin for an address so future deliveries to the same address are accurate ("pin memory").
We do not sell or rent any data, use customer data for advertising, or contact a store's customers for any purpose other than displaying their delivery tracking page.
Sharing
- Couriers — delivery details are shared with the courier the merchant (or the merchant's routing rules) selected for that order. Each courier processes that data under its own privacy policy.
- Infrastructure — the app is hosted on DigitalOcean (EU region) with its database on Neon (EU region). Both act as data processors.
- No other third parties receive personal data.
Retention & deletion
- Delivery records are retained while the app is installed so merchants keep their history and analytics.
- On receipt of Shopify's
customers/redactwebhook, the customer's personal fields in delivery records for that customer are erased. - On
shop/redact(48 hours after uninstall), all of the store's data — settings, encrypted courier credentials, deliveries, analytics — is deleted. - On
customers/data_request, we provide the merchant the delivery data held for that customer.
Security
All traffic is encrypted in transit (TLS). Courier credentials and map-provider keys are encrypted at rest with AES-256-GCM. Tracking pages use random, unguessable tokens and never display the full delivery address or payment details.
Your rights
Merchants and their customers may request access, correction or deletion of personal data by emailing the address below. If you are a store's customer, we may direct your request to the store (the data controller) as required.
Contact
Data controller for app operations: Waslio.
Privacy contact: m.h.elsawy@gmail.com
We will update this page when our practices change; material changes are noted in the changelog.