C
CODOS
Legal Document

Privacy Policy

How CODOS collects, uses, and protects your information.

Last updated: April 1, 2026Effective: April 1, 2026Applies to: codos.ma & all CODOS services

Summary (Plain English)

We protect your data

We never sell your personal data to third parties or use it for advertising.

WhatsApp is for orders only

WhatsApp data is used exclusively for order confirmation and customer support — never for marketing without consent.

You are in control

You can access, export, or delete your data at any time. We honor applicable privacy laws, including GDPR where it applies and US state privacy laws where they apply.

1. Introduction

Welcome to CODOS LLC ("CODOS", "we", "our", or "us"). We are a Software-as-a-Service (SaaS) platform that helps businesses streamline their online operations and grow their sales — including automation for Cash-on-Delivery (COD) workflows, WhatsApp-based order confirmations, courier integrations, and business analytics.

This Privacy Policy explains how we collect, use, disclose, store, and protect information about you when you use our platform at https://codos.ma, including all related subdomains, APIs, and services (collectively, the "Service").

By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.

This policy covers two types of data subjects

Merchants — businesses and individuals who create a CODOS account to manage their orders.

End Customers — customers of our merchants whose order data is processed through the CODOS platform on behalf of the merchant.

2. Who We Are

CODOS LLC is the data controller for merchant account data and a data processor for end-customer data processed on behalf of merchants.

Data Controller Information

CompanyCODOS LLC
Websitehttps://codos.ma
Privacy Contactprivacy@codos.ma
JurisdictionWyoming, USA
Regulatory FrameworkGDPR (where applicable), US state privacy laws (where applicable)
WhatsApp Business APIMeta Platforms, Inc. (Partner)

3. Information We Collect

3.1 Information You Provide Directly (Merchant Data)

  • Account registration: full name, business name, email address, phone number, password (stored as bcrypt hash)
  • Business profile: store name, logo, store URL, platform type (Shopify, YouCan, WooCommerce)
  • Payment and subscription information: billing is handled by PCI-DSS compliant payment partners (e.g. Paddle and/or Stripe); we receive subscription status and limited billing identifiers — we do not store full card numbers
  • Team member information: names, email addresses, and assigned roles
  • Support communications: messages, attachments, and inquiry details sent to our support team
  • Survey responses and feedback submitted voluntarily

3.2 Information Collected Automatically

  • Device and browser information: IP address, browser type, operating system, device identifiers
  • Usage data: pages visited, features used, actions taken, session duration, click paths
  • Log data: server logs, error reports, API request logs with timestamps
  • Authentication events: login timestamps, IP addresses, user agents (for security monitoring)
  • Performance data: response times, error rates (used for service improvement only)

3.3 Order and Customer Data (Processed on Behalf of Merchants)

When merchants use CODOS to manage their orders, the following end-customer data is processed on the merchant's behalf:

  • Customer name and phone number (required for WhatsApp confirmation)
  • Delivery address: city, region, and full address
  • Order details: product names, quantities, prices, order reference numbers
  • Order status history and delivery tracking information
  • WhatsApp message exchange records (sent and received messages related to order confirmation)
  • Call log records when call center agents interact with customers
  • Risk assessment scores derived from order and behavioral patterns

3.4 Integration Data

  • Shopify / YouCan / WooCommerce: store access tokens (encrypted at rest), product catalog, order data
  • WhatsApp Business API: phone number ID, business account ID, access tokens (encrypted), message delivery status
  • Courier APIs: API credentials (encrypted), shipping manifests, tracking data

We do NOT collect

We do not collect biometric data, government ID numbers, financial account numbers, or any special categories of personal data under GDPR Article 9.

4. How We Use Your Information

We use the information we collect for the following purposes, each grounded in a lawful basis:

PurposeLawful Basis
Providing and maintaining the ServiceContract performance
Processing subscriptions and payments (via PCI-DSS payment partners)Contract performance / Legitimate interests
Sending WhatsApp order confirmation messages to end customersLegitimate interests of the merchant / Contract
Pushing confirmed orders to courier providersContract performance
Generating analytics, reports, and business insightsContract performance / Legitimate interests
Fraud detection and risk scoringLegitimate interests (protecting merchants from financial loss)
Account authentication and security (2FA, session management)Contract / Legal obligation
Sending transactional emails (order reports, system alerts)Contract performance
Responding to support requestsContract performance / Legitimate interests
Compliance with legal obligationsLegal obligation
Improving and developing the ServiceLegitimate interests
Detecting and preventing abuse and security incidentsLegitimate interests / Legal obligation

Payments. CODOS LLC uses Paddle.com as our Merchant of Record and reseller. All subscription purchases are processed by Paddle, who handles billing, tax collection, and payment disputes on our behalf. When you subscribe, your purchase contract is with Paddle. Paddle’s Buyer Terms of Service (paddle.com/legal/checkout-buyer-terms) and Privacy Policy apply to all purchases. CODOS LLC does not store your full card number. Refer to the Paddle Privacy Policy and Stripe Privacy Policy when those providers process your checkout. You may update payment methods or access invoices through your billing settings or the applicable customer portal when enabled.

We will NEVER use your data for

Selling personal data to third parties · Advertising or remarketing · Profiling for non-operational purposes · Any purpose not stated in this policy

5. WhatsApp Business API & Meta Platform

WhatsApp Business API — Meta Platform Compliance

CODOS uses the WhatsApp Business API provided by Meta Platforms, Inc. This section describes our specific obligations and practices under Meta's Platform Policies and Terms of Service.

5.1 Permitted Uses of WhatsApp / Meta Data

CODOS uses the WhatsApp Business API exclusively for the following permitted purposes:

  • Sending transactional order confirmation messages to end customers on behalf of merchants
  • Receiving and processing customer replies to order confirmation messages
  • Sending order status updates (e.g., "Your order has been shipped")
  • Providing customer support related to specific orders
  • Enabling merchants to manually respond to customer inquiries within the WhatsApp interface

5.2 Prohibited Uses — Strict Compliance

CODOS strictly prohibits and technically prevents the following uses of WhatsApp Business API data:

  • Using WhatsApp data for advertising, marketing, or promotional purposes without explicit customer opt-in
  • Sharing WhatsApp conversation data with third parties for profiling or targeting
  • Storing or using WhatsApp phone numbers for purposes unrelated to the originating order
  • Re-using customer phone numbers obtained via WhatsApp to contact customers outside of WhatsApp
  • Scraping or bulk-exporting customer phone numbers from WhatsApp conversations
  • Using WhatsApp data to train AI or machine learning models without explicit consent
  • Any use that violates Meta's Platform Policies, Terms of Service, or Community Standards

5.3 Data Processed via WhatsApp Business API

  • Customer phone numbers (used solely to send order confirmation messages)
  • Message content of confirmations sent and replies received
  • Message delivery status (sent, delivered, read)
  • WhatsApp Business Account metadata (phone number ID, business account ID)
  • Webhook events received from Meta (message status updates, incoming messages)

5.4 Meta as a Data Processor

When CODOS sends messages via the WhatsApp Business API, Meta Platforms, Inc. acts as a sub-processor and processes message data according to Meta's own Privacy Policy and Data Processing Terms. CODOS has entered into the required Data Processing Addendum with Meta.

Meta's Privacy Policy is available at: https://www.facebook.com/privacy/policy/

5.5 Customer Opt-Out from WhatsApp Messages

End customers who no longer wish to receive WhatsApp order confirmation messages may opt out by replying "STOP" to any message. Upon receiving this reply, CODOS will:

  • Immediately flag the customer's number as opted-out in our system
  • Stop sending automated WhatsApp messages to that number
  • Notify the merchant of the opt-out status
  • Retain the opt-out record to prevent future messages (legitimate interest to honor the opt-out)

5.6 Message Templates

All message templates used with the WhatsApp Business API are pre-approved by Meta before use. CODOS ensures all templates comply with Meta's Message Template Guidelines and do not contain misleading, promotional, or prohibited content.

6. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

6.1 Service Providers (Sub-Processors)

ProviderPurposeData Shared
Paddle Ltd (and affiliates)Payment processing, subscriptions, invoicing (where Paddle checkout is used)Billing contact, subscription IDs, payment status (card data handled only by Paddle)
Stripe, Inc.Payment processing, subscriptions, invoicing (where Stripe checkout is used)Billing contact, subscription IDs, payment status (card data handled only by Stripe)
Meta Platforms, Inc.WhatsApp Business API message deliveryPhone numbers, message content
Shopify / YouCan / WooCommerceOrder data synchronization (merchant-configured)Order data, product data
Courier partners (merchant-configured)Shipment creation and trackingCustomer name, address, phone, order reference
Resend / Email providerTransactional emails and reportsMerchant email address
PostgreSQL Database (self-hosted)Data storageAll platform data (encrypted at rest)
OpenAI (optional AI features)Risk analysis and intent detectionAnonymized order patterns only

6.2 Merchant-to-Customer Data Flows

Merchants who use CODOS are themselves data controllers for their customers' data. CODOS acts as a data processor on behalf of the merchant. Merchants are responsible for ensuring they have a lawful basis to process their customers' data through CODOS, including obtaining any necessary consents.

6.3 Legal Disclosures

We may disclose personal data if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to:

  • Comply with applicable law or legal process
  • Protect the rights, property, or safety of CODOS, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our Terms of Service

6.4 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of CODOS's assets, personal data may be transferred as part of that transaction. We will notify affected users via email or prominent notice on our website prior to any such transfer.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, and in accordance with applicable law.

Data TypeRetention Period
Merchant account dataDuration of active account + 30 days after account deletion request
Order data and customer recordsDuration of merchant subscription + 90 days
WhatsApp message logs12 months from message date
Authentication logs (login, IP, 2FA)12 months
Audit logs24 months
Support communications3 years from ticket closure
Billing and payment records7 years (legal / tax obligation)
Anonymized analytics dataIndefinitely (no personal identifiers)
Opt-out records (WhatsApp STOP)Indefinitely (to honor the opt-out)
Backup copiesUp to 30 days after deletion request

When data is no longer needed, we securely delete or irreversibly anonymize it. Deletion requests are processed within 30 days.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users regardless of location.

👁️

Right of Access

Request a copy of all personal data we hold about you.

✏️

Right to Rectification

Correct inaccurate or incomplete personal data.

🗑️

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

⏸️

Right to Restriction

Request that we limit how we process your data.

📦

Right to Portability

Receive your data in a structured, machine-readable format.

🚫

Right to Object

Object to processing based on legitimate interests.

🤖

Right Against Automated Decisions

Not be subject to solely automated decisions with significant effects.

↩️

Right to Withdraw Consent

Withdraw consent at any time where processing is consent-based.

How to Exercise Your Rights

To exercise any of these rights, submit a request to privacy@codos.ma. Merchants may also access most rights directly from the dashboard under Settings → Account → Export / Delete.

We will respond within 30 days. We may ask you to verify your identity before processing the request. If you are dissatisfied with our response, you may lodge a complaint with your local data protection authority (for example, in the EEA) or, for US residents, with the Federal Trade Commission (FTC), where applicable.

9. Data Security

We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration.

Technical Measures

  • All data transmitted over HTTPS with TLS 1.2+ encryption
  • Data at rest encrypted using AES-256-GCM
  • Sensitive fields (API keys, TOTP secrets, tokens) individually encrypted in the database
  • Passwords stored as bcrypt hashes (never stored in plaintext)
  • Refresh tokens stored as SHA-256 hashes with expiration and revocation support
  • Two-factor authentication (TOTP) available for all merchant accounts
  • IP-based rate limiting on all authentication endpoints
  • Suspicious login detection with email alerts for new locations
  • Session management with per-device revocation capability
  • Automated daily encrypted database backups to secure cloud storage
  • Admin portal access restricted to allowlisted IP addresses in production

Organizational Measures

  • Principle of least privilege — employees access only data required for their role
  • All team members with data access are bound by confidentiality obligations
  • Security incident response procedure with 72-hour GDPR notification timeline
  • Regular security dependency audits

Security incident notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

10. Cookies & Tracking Technologies

CODOS uses a minimal set of cookies and local storage entries to operate the Service. We do not use advertising cookies or third-party tracking pixels.

NameTypePurposeDuration
tokenlocalStorageStores JWT access token for authenticationSession (15 minutes)
refresh_tokenlocalStorageStores refresh token for silent re-authentication30 days
rthttpOnly CookieSecure refresh token for admin portal30 days
NEXT_LOCALECookieRemembers user language preference1 year
suspended_reasonCookieTemporary flag for suspended account notice24 hours

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking scripts on our platform.

11. Children's Privacy

CODOS is a business-to-business (B2B) service intended exclusively for adults operating e-commerce businesses. We do not knowingly collect personal data from individuals under the age of 18.

If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@codos.ma and we will promptly delete that information.

12. International Data Transfers

CODOS LLC is organized in the United States (Wyoming). Our service infrastructure and subprocessors may be located in the United States, the European Union, and other regions where we or our providers operate.

When we engage sub-processors in countries that do not have an adequacy decision (for example, Meta Platforms, Inc. in the United States), we use appropriate safeguards where required by law, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with each sub-processor
  • Adequacy decisions where recognized by the European Commission
  • Binding Corporate Rules where applicable

By using CODOS, you acknowledge that your data may be processed in countries other than your country of residence. Where GDPR applies, we implement measures consistent with GDPR Chapter V for international transfers.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last updated" date at the top of this page
  • For material changes: send an email notification to all active merchant accounts at least 14 days before the changes take effect
  • For significant changes affecting your rights: display a prominent notice within the CODOS dashboard
  • Maintain an accessible version history of prior policy versions upon request

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should delete your account before the effective date.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy & Data Protection

Response Time

Within 30 days (GDPR) / 48 hours (urgent)

Company

CODOS LLC

Address

30 N Gould St Ste N, Sheridan, WY 82801, USA

Regulatory Authorities

United States

Federal Trade Commission — consumer protection and privacy complaints

ftc.gov

EU (where applicable)

Your local Data Protection Authority (DPA)

edpb.europa.eu

For WhatsApp / Meta platform-related privacy inquiries specifically regarding the use of the WhatsApp Business API, you may also contact Meta directly through their Data Subject Request Portal.

This Privacy Policy was last updated on April 1, 2026 and is effective as of April 1, 2026.

© 2026 CODOS LLC. All rights reserved.