Legal Document

Privacy Policy

How CODOS collects, uses, and protects your information.

Last updated: March 11, 2026Effective: March 11, 2026Applies to: codos.ma & all CODOS services

Summary (Plain English)

We protect your data

We never sell your personal data to third parties or use it for advertising.

WhatsApp is for orders only

WhatsApp data is used exclusively for order confirmation and customer support — never for marketing without consent.

You are in control

You can access, export, or delete your data at any time. We comply with GDPR and Moroccan Law 09-08.

1. Introduction

Welcome to CODOS (EGROW) ("CODOS", "we", "our", or "us"). We are a Software-as-a-Service (SaaS) platform designed to help Moroccan e-commerce merchants automate Cash-On-Delivery (COD) order management, including WhatsApp-based order confirmations, courier integrations, and business analytics.

This Privacy Policy explains how we collect, use, disclose, store, and protect information about you when you use our platform at https://codos.ma, including all related subdomains, APIs, and services (collectively, the "Service").

By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.

This policy covers two types of data subjects

Merchants — businesses and individuals who create a CODOS account to manage their orders.

End Customers — customers of our merchants whose order data is processed through the CODOS platform on behalf of the merchant.

2. Who We Are

CODOS (EGROW) is the data controller for merchant account data and a data processor for end-customer data processed on behalf of merchants.

Data Controller Information

CompanyCODOS (EGROW)
Websitehttps://codos.ma
Privacy Contactprivacy@codos.ma
JurisdictionMorocco
Regulatory FrameworkMoroccan Law 09-08, GDPR (where applicable)
WhatsApp Business APIMeta Platforms, Inc. (Partner)

3. Information We Collect

3.1 Information You Provide Directly (Merchant Data)

  • Account registration: full name, business name, email address, phone number, password (stored as bcrypt hash)
  • Business profile: store name, logo, store URL, platform type (Shopify, YouCan, WooCommerce)
  • Payment and subscription information (processed by our payment provider — we do not store full card numbers)
  • Team member information: names, email addresses, and assigned roles
  • Support communications: messages, attachments, and inquiry details sent to our support team
  • Survey responses and feedback submitted voluntarily

3.2 Information Collected Automatically

  • Device and browser information: IP address, browser type, operating system, device identifiers
  • Usage data: pages visited, features used, actions taken, session duration, click paths
  • Log data: server logs, error reports, API request logs with timestamps
  • Authentication events: login timestamps, IP addresses, user agents (for security monitoring)
  • Performance data: response times, error rates (used for service improvement only)

3.3 Order and Customer Data (Processed on Behalf of Merchants)

When merchants use CODOS to manage their orders, the following end-customer data is processed on the merchant's behalf:

  • Customer name and phone number (required for WhatsApp confirmation)
  • Delivery address: city, region, and full address
  • Order details: product names, quantities, prices, order reference numbers
  • Order status history and delivery tracking information
  • WhatsApp message exchange records (sent and received messages related to order confirmation)
  • Call log records when call center agents interact with customers
  • Risk assessment scores derived from order and behavioral patterns

3.4 Integration Data

  • Shopify / YouCan / WooCommerce: store access tokens (encrypted at rest), product catalog, order data
  • WhatsApp Business API: phone number ID, business account ID, access tokens (encrypted), message delivery status
  • Courier APIs: API credentials (encrypted), shipping manifests, tracking data

We do NOT collect

We do not collect biometric data, government ID numbers, financial account numbers, or any special categories of personal data under GDPR Article 9.

4. How We Use Your Information

We use the information we collect for the following purposes, each grounded in a lawful basis:

PurposeLawful Basis
Providing and maintaining the ServiceContract performance
Sending WhatsApp order confirmation messages to end customersLegitimate interests of the merchant / Contract
Pushing confirmed orders to courier providersContract performance
Generating analytics, reports, and business insightsContract performance / Legitimate interests
Fraud detection and risk scoringLegitimate interests (protecting merchants from financial loss)
Account authentication and security (2FA, session management)Contract / Legal obligation
Sending transactional emails (order reports, system alerts)Contract performance
Responding to support requestsContract performance / Legitimate interests
Compliance with legal obligationsLegal obligation
Improving and developing the ServiceLegitimate interests
Detecting and preventing abuse and security incidentsLegitimate interests / Legal obligation

We will NEVER use your data for

Selling personal data to third parties · Advertising or remarketing · Profiling for non-operational purposes · Any purpose not stated in this policy

5. WhatsApp Business API & Meta Platform

WhatsApp Business API — Meta Platform Compliance

CODOS uses the WhatsApp Business API provided by Meta Platforms, Inc. This section describes our specific obligations and practices under Meta's Platform Policies and Terms of Service.

5.1 Permitted Uses of WhatsApp / Meta Data

CODOS uses the WhatsApp Business API exclusively for the following permitted purposes:

  • Sending transactional order confirmation messages to end customers on behalf of merchants
  • Receiving and processing customer replies to order confirmation messages
  • Sending order status updates (e.g., "Your order has been shipped")
  • Providing customer support related to specific orders
  • Enabling merchants to manually respond to customer inquiries within the WhatsApp interface

5.2 Prohibited Uses — Strict Compliance

CODOS strictly prohibits and technically prevents the following uses of WhatsApp Business API data:

  • Using WhatsApp data for advertising, marketing, or promotional purposes without explicit customer opt-in
  • Sharing WhatsApp conversation data with third parties for profiling or targeting
  • Storing or using WhatsApp phone numbers for purposes unrelated to the originating order
  • Re-using customer phone numbers obtained via WhatsApp to contact customers outside of WhatsApp
  • Scraping or bulk-exporting customer phone numbers from WhatsApp conversations
  • Using WhatsApp data to train AI or machine learning models without explicit consent
  • Any use that violates Meta's Platform Policies, Terms of Service, or Community Standards

5.3 Data Processed via WhatsApp Business API

  • Customer phone numbers (used solely to send order confirmation messages)
  • Message content of confirmations sent and replies received
  • Message delivery status (sent, delivered, read)
  • WhatsApp Business Account metadata (phone number ID, business account ID)
  • Webhook events received from Meta (message status updates, incoming messages)

5.4 Meta as a Data Processor

When CODOS sends messages via the WhatsApp Business API, Meta Platforms, Inc. acts as a sub-processor and processes message data according to Meta's own Privacy Policy and Data Processing Terms. CODOS has entered into the required Data Processing Addendum with Meta.

Meta's Privacy Policy is available at: https://www.facebook.com/privacy/policy/

5.5 Customer Opt-Out from WhatsApp Messages

End customers who no longer wish to receive WhatsApp order confirmation messages may opt out by replying "STOP" to any message. Upon receiving this reply, CODOS will:

  • Immediately flag the customer's number as opted-out in our system
  • Stop sending automated WhatsApp messages to that number
  • Notify the merchant of the opt-out status
  • Retain the opt-out record to prevent future messages (legitimate interest to honor the opt-out)

5.6 Message Templates

All message templates used with the WhatsApp Business API are pre-approved by Meta before use. CODOS ensures all templates comply with Meta's Message Template Guidelines and do not contain misleading, promotional, or prohibited content.

6. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

6.1 Service Providers (Sub-Processors)

ProviderPurposeData Shared
Meta Platforms, Inc.WhatsApp Business API message deliveryPhone numbers, message content
Shopify / YouCan / WooCommerceOrder data synchronization (merchant-configured)Order data, product data
Courier Partners (Amana, Kargo, SendIt, etc.)Shipment creation and trackingCustomer name, address, phone, order reference
Resend / Email providerTransactional emails and reportsMerchant email address
PostgreSQL Database (self-hosted)Data storageAll platform data (encrypted at rest)
OpenAI (optional AI features)Risk analysis and intent detectionAnonymized order patterns only

6.2 Merchant-to-Customer Data Flows

Merchants who use CODOS are themselves data controllers for their customers' data. CODOS acts as a data processor on behalf of the merchant. Merchants are responsible for ensuring they have a lawful basis to process their customers' data through CODOS, including obtaining any necessary consents.

6.3 Legal Disclosures

We may disclose personal data if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to:

  • Comply with applicable law or legal process
  • Protect the rights, property, or safety of CODOS, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our Terms of Service

6.4 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of CODOS's assets, personal data may be transferred as part of that transaction. We will notify affected users via email or prominent notice on our website prior to any such transfer.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, and in accordance with applicable law.

Data TypeRetention Period
Merchant account dataDuration of active account + 30 days after account deletion request
Order data and customer recordsDuration of merchant subscription + 90 days
WhatsApp message logs12 months from message date
Authentication logs (login, IP, 2FA)12 months
Audit logs24 months
Support communications3 years from ticket closure
Billing and payment records7 years (legal / tax obligation)
Anonymized analytics dataIndefinitely (no personal identifiers)
Opt-out records (WhatsApp STOP)Indefinitely (to honor the opt-out)
Backup copiesUp to 30 days after deletion request

When data is no longer needed, we securely delete or irreversibly anonymize it. Deletion requests are processed within 30 days.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users regardless of location.

👁️

Right of Access

Request a copy of all personal data we hold about you.

✏️

Right to Rectification

Correct inaccurate or incomplete personal data.

🗑️

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

⏸️

Right to Restriction

Request that we limit how we process your data.

📦

Right to Portability

Receive your data in a structured, machine-readable format.

🚫

Right to Object

Object to processing based on legitimate interests.

🤖

Right Against Automated Decisions

Not be subject to solely automated decisions with significant effects.

↩️

Right to Withdraw Consent

Withdraw consent at any time where processing is consent-based.

How to Exercise Your Rights

To exercise any of these rights, submit a request to privacy@codos.ma. Merchants may also access most rights directly from the dashboard under Settings → Account → Export / Delete.

We will respond within 30 days. We may ask you to verify your identity before processing the request. If you are dissatisfied with our response, you have the right to lodge a complaint with the Moroccan Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) or your local data protection authority.

9. Data Security

We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration.

Technical Measures

  • All data transmitted over HTTPS with TLS 1.2+ encryption
  • Data at rest encrypted using AES-256-GCM
  • Sensitive fields (API keys, TOTP secrets, tokens) individually encrypted in the database
  • Passwords stored as bcrypt hashes (never stored in plaintext)
  • Refresh tokens stored as SHA-256 hashes with expiration and revocation support
  • Two-factor authentication (TOTP) available for all merchant accounts
  • IP-based rate limiting on all authentication endpoints
  • Suspicious login detection with email alerts for new locations
  • Session management with per-device revocation capability
  • Automated daily encrypted database backups to secure cloud storage
  • Admin portal access restricted to allowlisted IP addresses in production

Organizational Measures

  • Principle of least privilege — employees access only data required for their role
  • All team members with data access are bound by confidentiality obligations
  • Security incident response procedure with 72-hour GDPR notification timeline
  • Regular security dependency audits

Security incident notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

10. Cookies & Tracking Technologies

CODOS uses a minimal set of cookies and local storage entries to operate the Service. We do not use advertising cookies or third-party tracking pixels.

NameTypePurposeDuration
tokenlocalStorageStores JWT access token for authenticationSession (15 minutes)
refresh_tokenlocalStorageStores refresh token for silent re-authentication30 days
rthttpOnly CookieSecure refresh token for admin portal30 days
NEXT_LOCALECookieRemembers user language preference1 year
suspended_reasonCookieTemporary flag for suspended account notice24 hours

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking scripts on our platform.

11. Children's Privacy

CODOS is a business-to-business (B2B) service intended exclusively for adults operating e-commerce businesses. We do not knowingly collect personal data from individuals under the age of 18.

If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@codos.ma and we will promptly delete that information.

12. International Data Transfers

CODOS is based in Morocco. Our primary data storage infrastructure is located in Morocco and the European Union (EU-based cloud regions where applicable).

When we engage sub-processors located outside Morocco (such as Meta Platforms, Inc., headquartered in the United States), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with each sub-processor
  • Adequacy decisions where recognized by the European Commission
  • Binding Corporate Rules where applicable

By using CODOS, you acknowledge that your data may be processed in countries outside Morocco or your home country. We ensure all such transfers comply with Moroccan Law 09-08 and, where applicable, GDPR Chapter V requirements.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last updated" date at the top of this page
  • For material changes: send an email notification to all active merchant accounts at least 14 days before the changes take effect
  • For significant changes affecting your rights: display a prominent notice within the CODOS dashboard
  • Maintain an accessible version history of prior policy versions upon request

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should delete your account before the effective date.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy & Data Protection

Response Time

Within 30 days (GDPR) / 48 hours (urgent)

Company

CODOS (EGROW)

Address

Morocco

Regulatory Authorities

Morocco

CNDP — Commission Nationale de Contrôle de la Protection des Données Personnelles

www.cndp.ma

EU (where applicable)

Your local Data Protection Authority (DPA)

edpb.europa.eu

For WhatsApp / Meta platform-related privacy inquiries specifically regarding the use of the WhatsApp Business API, you may also contact Meta directly through their Data Subject Request Portal.

This Privacy Policy was last updated on March 11, 2026 and is effective as of March 11, 2026.

© 2026 CODOS (EGROW). All rights reserved.