At Groply (operated at https://groply.shop), we believe privacy is a fundamental right. This Privacy Policy details the exact types of personal and commercial data we collect, why we process it, how we safeguard it, and the full rights you possess regarding your information under Cameroon cybersecurity legislation and international data privacy benchmarks.
01. Overview & Scope
This Privacy Policy applies to all merchants, shoppers, visitors, and partners interacting with the Groply platform, including our central marketplace, digital QR storefronts, Merchant Dashboard, and WhatsApp AI Business Assistant integrations.
02. Data Controller vs. Data Processor Roles
- Groply as Data Controller: We act as a Data Controller for our registered merchant and shopper user accounts, subscription billing history, platform telemetry, and security audit logs.
- Groply as Data Processor: When an end-customer communicates with a merchant's WhatsApp AI Agent or places an order on a merchant's digital storefront, the merchant is the Data Controller of their customer relationships, and Groply acts strictly as the technical Data Processor executing conversational intelligence, order slip generation, and catalog synchronization on the merchant's behalf.
03. Information We Collect
We only collect information strictly necessary to provide our digital storefront, discovery, and automated sales services:
A. Information Provided by Merchants
- Account Credentials: Full name, business/store name, email address, password hash, and WhatsApp Business phone number.
- Store Profile & Catalog: Product names, descriptions, pricing in FCFA, high-resolution product photography, stock quantities, city/location, delivery fees, and business operating hours.
- Billing & Subscription Records: Selected subscription tier (e.g. Starter Storefront, AI Closer Bundle), MoMo transaction reference numbers, invoice timestamps, and payment confirmation logs.
B. Information Provided by Shoppers & Customers
- Order & Checkout Data: Customer name, delivery address/city (e.g. Douala, YaoundΓ©), contact phone number, and items in cart.
- WhatsApp Chat Logs: Inbound inquiries and conversational messages exchanged with the merchant's WhatsApp AI sales agent.
- Guest Preferences: Saved favorite products (wishlist) and local shopping carts saved client-side in the browser.
C. Automated Device & Telemetry Data
- Anonymized storefront visit counts, geographic region (city level), browser type, and server error diagnostics used strictly for platform reliability.
04. Identity Verification Documents, Fortified Storage & Law Enforcement Disclosure
To verify merchant legitimacy, prevent scams, and protect buyers across Cameroon in accordance with Law No. 2010/012 on Cybersecurity and Cybercrime and Law No. 2010/013 on Electronic Commerce, merchants seeking verified status must submit identity verification proofs:
- Categories of ID Data Collected: High-resolution photographs of valid government-issued or institutional identity documents (National ID Card / CNI, Passport, Driver's License, Valid Student/School ID, Taxpayer ID) and a selfie photograph holding that document.
- Purpose & Legal Basis: Identity verification is conducted strictly to authenticate the store owner, safeguard consumer payments, prevent fraudulent impersonation, and uphold marketplace trust.
- Fortified Encrypted Storage: All ID documents and verification selfies are stored in a dedicated, fortified, government-grade encrypted object storage environment with strict access-control policies. They are never accessible via public URLs, never indexed by web crawlers or search engines, and never displayed on public storefronts.
- Access Governance: Verification files can only be accessed by authorized Groply compliance officers via temporary, cryptographically signed, short-lived URLs.
- Disclosure to Law Enforcement (Anti-Scam Protocol): In cases of reported fraud, customer scams, or illegal transactions, Groply will furnish merchant identity records, photographs, and connection logs directly to the National Gendarmerie (SED) and Police Judiciaire (DGSN) to assist in law enforcement investigations and buyer protection.
- Consent & Audit Logs: Merchants give explicit legal consent prior to uploading verification files. Groply records the consent timestamp, IP address, and legal agreement version to maintain an immutable compliance record.
05. WhatsApp AI Processing & Voice Notes Privacy
Our conversational commerce engine integrates state-of-the-art Large Language Models (Google Gemini) to interpret customer intents, transcribe incoming voice notes, and answer questions in French, English, and Cameroonian Pidgin.
π‘οΈ Strict AI Privacy Protections
We never sell your conversational data or customer phone numbers to advertisers. Customer WhatsApp messages and audio notes sent to our AI agent are processed ephemerally solely to formulate helpful sales responses and generate order slips. Message data is never utilized to train public foundational AI models.
06. How We Use Information
We utilize the collected information exclusively for legitimate commercial purposes:
- To operate, host, and display merchant digital QR storefronts and public marketplace catalogs.
- To automate 24/7 WhatsApp customer inquiries, provide real-time stock checks, and format structured orders.
- To facilitate peer-to-peer and merchant Mobile Money (MTN MoMo & Orange Money) transaction reference verification.
- To provide merchants with transparent sales analytics, traffic metrics, and inventory alerts in their Merchant Dashboard.
- To detect, prevent, and mitigate fraudulent behavior, counterfeit merchandise, and security violations.
07. Third-Party Sub-processors & Infrastructure
Groply partners only with industry-leading, high-security infrastructure providers:
- Meta Platforms (WhatsApp Cloud API): Official delivery and webhook transmission of WhatsApp business messages.
- Google Cloud (Gemini AI & Vertex API): Secure natural language inference, multilingual understanding, and voice note transcription.
- Supabase & PostgreSQL: Secure, encrypted cloud database storage, authentication, and role-based access control.
- Hostinger VPS Cloud Infrastructure: High-speed European/Global cloud hosting with automated TLS/SSL certificate encryption and isolated execution environments.
08. Security & Cloud Storage Architecture
Groply implements rigorous technical and organizational safeguards:
- End-to-End Encryption in Transit: All web traffic across
groply.shop is strictly enforced over HTTPS (TLS 1.3) via automated reverse proxy certificates.
- Token Protection: WhatsApp Access Tokens, database passwords, and cryptographic secrets are stored encrypted with restricted server-side access.
- Automated Backups & Rollbacks: Automated daily database snapshots and Hostinger VPS pre-deploy snapshots ensure instant recovery against data loss.
09. Data Retention & Automatic Purging
- Active Merchant Data: Retained for the entire duration of the merchant's active subscription.
- Account Deletion: Upon merchant request for account termination, all personal data, catalog items, and API linkages are permanently erased from active production databases within thirty (30) days.
- Chat Session Pruning: WhatsApp conversation logs older than ninety (90) days may be pruned automatically to optimize system storage.
10. Cookies & Local Browser Storage
Groply respects your digital footprint:
- Essential Session Cookies: We use secure cookies (e.g.
sb_access_token) strictly for maintaining your authenticated merchant or shopper login session.
- Client-Side Local Storage: We utilize browser
localStorage (e.g. groply_cart, groply_recently_viewed) to preserve your shopping cart and saved favorites offline without tracking your browsing habits across external websites.
- Zero Third-Party Advertising Trackers: We do not install third-party tracking pixels, ad cookies, or behavioral surveillance scripts.
11. Your Privacy Rights & Data Controls
Regardless of your geographic location, Groply affords you full control over your data:
- Right to Access: You may request a complete export of the personal data we store regarding your account.
- Right to Rectification: You can update, correct, or refine your business information, catalog prices, and contact numbers at any time in your dashboard.
- Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and associated records by emailing contact@groply.shop.
- Right to Restrict Processing: You can unlink your WhatsApp number or pause AI automated responses at any time with a single toggle in your Merchant Dashboard.
12. Age Restrictions (18+)
Groply is exclusively designed for business operators and consumers aged 18 and older. We do not knowingly solicit or collect personal information from individuals under eighteen (18) years of age. If we discover that a minor has registered without parental consent, we will promptly delete the account.