Privacy policy

Last updated on September 16, 2026

Who we are and what this policy covers

Quiqorder is operated by QO DIGITAL INNOVATIONS LIMITED. We provide business-management, customer communication, and storefront tools. This policy covers our websites, dashboard, connected channels including Gmail and WhatsApp, email campaigns, automation, orders, payments, and support services. Connected features may be available in our review or staging environment before their general release.

For customer conversations and orders, the business you contact determines why your data is processed and Quiqorder processes it on that business’s behalf. Quiqorder remains responsible for data used to operate, secure, and administer our own service.

Information we collect

  • Business account data, including names, business details, email addresses, settings, team access, and support communications.
  • Channel connection data, including WhatsApp Business Account and phone-number identifiers, Instagram account identifiers, authorization credentials, webhook configuration, and connection status.
  • Customer conversation data, including messages, attachments, profile or channel identifiers, message status, and automation history.
  • Commerce data, including catalog items, carts, delivery details, orders, receipts, payment status, and transaction references. Payment card details are handled by the payment provider and are not stored by Quiqorder.
  • Connected email data, including the mailbox email address, encrypted authorization tokens, and transmission status. Campaign and transactional email data includes merchant-authored content, selected customer recipients, sending status, and unsubscribe preferences.
  • Storefront and operational data, including domains, published content, inventory, business policies, and fulfillment configuration.
  • Technical and security data, including IP address, browser and device details, webhook events, authentication events, diagnostics, and audit records.

How and why we use information

  • Connect and operate authorized WhatsApp and Instagram business channels.
  • Receive and send messages, automate replies, display products, manage carts, create orders, collect delivery information, and provide receipts and fulfillment updates.
  • Authenticate users, maintain account preferences, provide support, prevent fraud, and protect the service.
  • Process payments through our payment providers and maintain legally required transaction records.
  • Monitor reliability and improve the product using appropriately limited operational data.
  • Meet legal, regulatory, contractual, and platform-policy obligations.

Quiqorder enables businesses to communicate with customers only after explicit customer opt-in.

Users can opt out of messages at any time.

Quiqorder does not support unsolicited or bulk spam messaging.

Google and Gmail access

Gmail access begins only when a merchant chooses to connect a mailbox and grants permission through Google OAuth. We do not ask for or store your Google password. The openid and email permissions identify the connected mailbox. Encrypted access and refresh tokens let the service maintain the connection without asking you to sign in for every request.

  • gmail.send: sends merchant-approved outbound transactional emails, order notifications, recovery messages, and marketing campaigns to selected customer recipients. Recipient addresses, email subject, and message content are transmitted to Google for delivery. Outbound emails include recipient-specific unsubscribe links, and eligibility is checked before sending.

Google user data and Limited Use

Quiqorder’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements.

Affirmative Limited Use Compliance Statement: The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically, Google Workspace user data—including raw, aggregated, or derived data—is never used, transferred, or sold to create, train, fine-tune, or improve foundational or generalized artificial intelligence (AI) or machine learning (ML) models.

We use Gmail access strictly and exclusively for user-directed, user-approved outbound email dispatch (via the gmail.send scope). We do not read inboxes, download email content, or inspect customer mailboxes. Gmail credentials, message payloads, and headers are never transmitted to or processed by any third-party AI or machine learning service providers. Any AI-assisted drafting or copy generation in Quiqorder operates strictly on the merchant’s own commerce data (such as product titles, order totals, and checkout links), never on Google Workspace user data.

Google data is processed only by the isolated infrastructure providers needed to operate these user-facing features, and outgoing messages are shared with Google and the recipients selected by the merchant. We do not sell Google user data, nor do we transfer it for advertising or credit scoring. These specific restrictions take precedence over our general sharing provisions for Google data.

Our personnel do not access your mailbox. We request only send permissions, not mailbox reading access. Connecting Gmail does not give staff or automated systems permission to read your mailbox.

Meta, WhatsApp, and Instagram permissions

We request only the permissions required for the features a business chooses to connect. WhatsApp business messaging permission is used to receive and send customer messages. WhatsApp business management permission is used for Embedded Signup, WhatsApp Business Account and phone-number setup, webhook subscription, phone registration, message-template management, and disconnection. Meta credentials are restricted to authorized services and are removed from the business account when the channel is disconnected.

Sharing and service providers

We do not sell personal data. We disclose data only as needed to provide the service, follow instructions from the connected business, comply with law, or protect users and the platform.

  • Meta for WhatsApp and Instagram messaging, account connection, and webhook delivery.
  • Cloud hosting, database, object-storage, security, monitoring, and communications providers.
  • Payment and fulfillment providers selected by the business or customer.
  • Professional advisers, authorities, or counterparties when legally required or during a properly safeguarded business transaction.

We require service providers to process data only for the contracted purpose and to apply appropriate confidentiality and security controls.

Security

We use access controls, encrypted transport, encryption for sensitive stored credentials and deletion jobs, scoped tenant storage, webhook signature verification, authentication safeguards, audit logging, and restricted operational access. No security measure eliminates every risk, so we also monitor and respond to suspected incidents.

Retention and deletion

We keep data only for an operational, contractual, security, or legal purpose. For stored customer conversations and the existing privacy-cleanup system, current technical defaults hard-delete message content after seven days, transient provider webhook events after 30 days, completed provider-cleanup jobs after 30 days, and deletion-request records and privacy-preserving tombstones after 400 days. Conversation summaries may remain while an account or customer relationship is active, without the expired message content.

For Gmail, the connected mailbox address and encrypted authorization tokens remain in the connection record until it is disconnected or the business account is deleted. We do not store an inbox archive on our servers.

Merchant-authored email campaign and dispatch records, recipient references, send outcomes, and unsubscribe records are stored separately from the mailbox connection. They do not currently have an automatic time-based deletion schedule, and disconnecting Gmail does not erase them. Contact hr@tryquiqorder.com to request deletion of these records or other email-related data. We verify the request and identify any information that must be retained for legal or security purposes. An unsubscribe changes the customer’s marketing preference for that business rather than deleting all customer or campaign data.

A verified customer deletion removes the matched conversation, messages, attachments, carts, checkouts, automation state, and unpaid order data. Completed paid-order records may be anonymized rather than erased when limited transaction information must be retained for accounting, fraud prevention, disputes, or law. Backups age out under protected backup-retention schedules and are not restored for ordinary product use after a deletion.

Disconnect a connected channel

A business administrator can open Dashboard → Settings → Channels and choose Disconnect on the relevant connection. For WhatsApp or Instagram, disconnecting stops future channel processing, cancels pending channel automation, removes locally stored channel credentials, and requests removal of Quiqorder’s provider subscription. It does not delete the business’s Quiqorder account, catalog, completed orders, or all historical business data.

For Gmail, Disconnect removes the saved mailbox connection and its encrypted credentials, preventing new requests through that connection. Requests already in progress may finish. It does not automatically revoke the permission in your Google Account, cancel campaign records, or delete emails in Gmail. You can separately revoke access in your Google Account’s third-party connections settings. Cancel any pending campaigns you no longer want to send before reconnecting.

Delete business or customer data

A business administrator can permanently delete the Quiqorder business account from Dashboard → Settings → Security → Delete account and confirm the account password. This removes the tenant account, connected credentials, customer conversations, catalog and tenant files, while queuing provider cleanup and retaining only legally necessary or privacy-preserving deletion evidence. For the separate email campaign records described above, also request deletion through hr@tryquiqorder.com.

A WhatsApp or Instagram customer can use our Data Deletion page, identify the published business storefront and channel, and verify the request using a one-time code delivered in the original conversation. The page provides an opaque confirmation code for tracking. Requests can also be sent to our support address if the self-service path is unavailable.

Your choices and rights

Depending on where you live, you may request access, correction, portability, restriction, objection, or deletion. We verify identity before disclosing or deleting data. Use the Data Deletion page or contact hr@tryquiqorder.com. You may also complain to your local data-protection authority.

Changes and contact

We may update this policy when our service or obligations change and will publish the revised date. Privacy and deletion questions can be sent to hr@tryquiqorder.com.

Ready to find your next sales opportunity?

Bring your orders, customers, and follow-ups into one connected workspace.

A few things you might want to know.

QuiqOrder brings together customers, products, orders, and payments so you can spot revenue opportunities and manage follow-ups. Start with unpaid orders, unfinished sales, and customers who may be ready to buy again.