Verifo Privacy Policy
Effective 27 September 2026
Verifo is a Shopify app operated by Marketing Misr, a company registered in Egypt ("Verifo", "we", "us"). It helps Shopify merchants send WhatsApp messages to their customers — Cash on Delivery confirmations, abandoned-cart reminders, shipping updates and marketing campaigns — and protect their store from fraudulent orders. This policy explains what data Verifo handles, why, who we share it with, and how long we keep it.
For the personal data of a merchant's customers, the merchant is the controller and Verifo processes that data on the merchant's behalf and on their instructions. Customers should contact the store they bought from about their data; merchants can contact us using the details at the end of this policy.
1. Data about merchants
- Store details from Shopify: store domain, store name, and the access token Shopify issues when the app is installed.
- Your Verifo settings, message templates, and plan and billing history (charges themselves are processed by Shopify).
- Your WhatsApp Business connection: account and phone number IDs, the display phone number, and an access token, which is stored encrypted.
- Questions you ask the in-app AI assistant. These are sent, with a summary of your store's Verifo setup (for example which features are on and your plan), to our AI provider to generate an answer. Verifo does not store these conversations; they are kept only in your browser tab while it is open.
- Your IP address, used once to pre-select your country in some settings. Only the country is used; the IP address is not stored.
2. Data about merchants' customers
To run the features a merchant turns on, Verifo processes:
- Contact details: first name, phone number and, for fraud protection, email address.
- Order and checkout details: order number and total, payment method name, products (title, price, image), abandoned-checkout links, and shipment tracking details.
- WhatsApp messages: which messages were sent and their delivery status, button replies (such as Confirm or Cancel), and marketing opt-in and opt-out records. A free-text reply to an order message is added to that order's notes in Shopify.
- Storefront pop-up sign-ups: phone number and first name, which are also saved as a tagged customer in the merchant's Shopify admin.
- Fraud protection: phone numbers, emails and IP addresses that a merchant blocks or restricts from Cash on Delivery, and the IP address of orders when VPN/proxy detection is enabled. At checkout, the buyer's email, phone and country are checked against the merchant's blocklist; they are not stored as a result of that check.
On the storefront, content protection (if enabled) stores only an on/off flag in the visitor's browser session. The storefront pop-up may look up the visitor's country from their IP address to show a phone number example; the IP address is not stored.
3. How we use data
Only to provide Verifo's features to the merchant: sending the WhatsApp messages the merchant has enabled, applying their fraud and Cash on Delivery settings, showing results in the app, billing through Shopify, providing support, and keeping the service secure. We do not sell personal data, and we do not use customers' data for advertising.
4. Service providers
We share data only with the providers needed to run Verifo:
- Shopify — the platform the app runs on, and app billing.
- Meta (WhatsApp Business Platform) — delivers WhatsApp messages from the merchant's own WhatsApp Business number.
- Fly.io — application hosting, in Frankfurt, Germany.
- Neon — database hosting, in Frankfurt, Germany.
- Anthropic — powers the in-app AI assistant for merchants (receives merchant questions and setup summaries only).
- IPQualityScore — checks order IP addresses for VPNs and proxies, only for merchants who enable that feature.
- ipwho.is — looks up a country from an IP address, as described above.
Some of these providers may process data outside your country, including in the United States.
5. How long we keep data
- We keep data while the app is installed, so the merchant's settings and history keep working.
- When a merchant uninstalls Verifo, its access to the store ends immediately and its WhatsApp connection is deactivated. About 48 hours later, when Shopify sends the store deletion request, we erase all of that store's data.
- When Shopify sends a customer data deletion request, we delete or anonymize that customer's phone number and name across Verifo. Entries a merchant added to their fraud blocklist or Cash on Delivery restrictions are kept as fraud-prevention records until the merchant removes them or uninstalls the app.
- Our database provider keeps a rolling backup history for up to 7 days, so deleted data can remain in backups for up to 7 days before it is gone for good.
6. Security
All traffic to Verifo uses encrypted HTTPS connections. WhatsApp access tokens are encrypted at rest with AES-256-GCM. Requests from Shopify and Meta are verified by their signatures before they are processed, and the app uses Shopify's session tokens to authenticate merchants.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the use of your personal data. Merchants can request this from us directly. Customers of a store should contact that store; merchants can pass on requests through Shopify, which forwards them to us.
8. Marketing messages
Merchants are responsible for having their customers' consent before sending marketing messages. Verifo only sends campaigns to customers who opted in or messaged the store, and any customer can stop marketing messages at any time by replying STOP or tapping "Stop promotions".
9. Children
Verifo is a business tool for merchants and is not directed at children.
10. Changes to this policy
We may update this policy as Verifo changes. The effective date at the top shows when it was last updated.
11. Contact us
Marketing Misr, Egypt
Email: support@verifo.app
WhatsApp: +44 7853 890080