Skip to main content
Legal

Privacy Policy

Effective Date: May 9, 2026

1. Introduction

This Privacy Policy describes how Kovax.ai (“we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our website, dashboard, and connected integrations (the “Service”).

Kovax.ai is a voice and messaging AI platform for Shopify merchants. This policy applies to merchants who connect their stores to Kovax.ai, end-user customers whose data is processed through the Service on behalf of those merchants, and visitors to our marketing website.

2. Information We Collect

We collect three categories of information.

Information merchants provide to us

When a merchant signs up for or uses Kovax.ai, we collect Shopify account details (store URL, merchant name, email, shop ID), WhatsApp Business number registration details (phone number, display name, business profile), and any content submitted through dashboards, support requests, or onboarding forms.

Information collected automatically

When you use the Service, we automatically collect usage logs, referrer URLs, timestamps, and interaction events. We use cookies and similar technologies to keep you signed in, remember preferences, and measure how the Service is used.

Information received from third parties

We receive data from platforms our merchants connect, including Shopify (orders, products, customers, inventory) and Meta (WhatsApp Business API events, message status updates, template approvals, phone number quality ratings). The scope of data received depends on the permissions granted by the merchant during connection.

3. How We Use Your Information

We use the information described above to:

  • Operate, maintain, and provide the features of the Service to connected merchants;
  • Send transactional and operational notifications, including order confirmations, shipping updates, and abandoned-cart reminders on behalf of merchants;
  • Provide customer support, troubleshoot issues, and respond to inquiries;
  • Protect the Service against fraud, abuse, and security incidents, and enforce our terms;
  • Analyze usage to improve product reliability, performance, and develop new features.

4. WhatsApp Business API Data Handling

Kovax.ai integrates with Meta’s WhatsApp Business Cloud API on behalf of connected Shopify merchants. When a merchant connects their WhatsApp Business number, we process the following data received from Meta:

  • Inbound and outbound message content, message status updates (sent / delivered / read / failed), and wamid identifiers;
  • Conversation metadata, including the 24-hour session window state and conversation category;
  • Message template names, contents, approval status, and rejection reasons;
  • Phone number profile metadata, including display name, business profile fields, and quality rating;
  • Recipient opt-in consent records, hashed at storage for privacy.

We retain this data only for the duration necessary to deliver our service to the merchant, plus a 30-day audit window required for compliance with Meta’s policies. End-user customers may request deletion of their data via the merchant they interacted with, or directly by contacting us at [email protected]. Merchants may request a full data export and deletion at any time by initiating offboarding from their Kovax.ai dashboard.

5. How We Share Information

We share information only with third-party service providers that are necessary to operate the Service, and only to the extent required for them to provide their services to us. Current providers include:

  • Meta Platforms (WhatsApp Business Cloud API) — delivery of inbound and outbound messages and template management;
  • Shopify — store data sync (orders, products, customers, inventory);
  • Our cloud hosting provider — compute, storage, and content delivery.

We may also disclose information when required by law, in response to valid legal process, or to protect the rights, property, or safety of our users, the public, or us.

We do not sell user data. We do not share personal information with third parties for their own marketing purposes.

6. Data Retention

We retain personal data for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and are reviewed periodically.

WhatsApp-related data is subject to the specific retention rules described in Section 4 — WhatsApp Business API Data Handling, including the 30-day audit window required by Meta.

When a merchant closes their account or requests deletion, we delete or anonymize personal data within a reasonable period, subject to retention requirements imposed by law or our service providers.

7. Your Rights

Depending on where you live, you may have rights under data protection laws such as the EU/UK GDPR and the California CCPA/CPRA. These rights include:

  • Access — request a copy of the personal data we hold about you;
  • Correction — ask us to correct inaccurate or incomplete data;
  • Deletion — ask us to delete your personal data, subject to legal exceptions;
  • Portability — receive your data in a structured, machine-readable format;
  • Objection & Restriction — object to certain processing or ask us to restrict it;
  • Withdrawal of consent — withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email [email protected] from the address associated with your account. We will verify your identity before responding. End-user customers should contact the merchant they interacted with first; we will assist that merchant in fulfilling the request.

8. Data Security

We use industry-standard safeguards to protect personal data. Traffic between your browser or device and our servers is encrypted in transit using TLS. Data at rest in our databases and object storage is encrypted using AES-256 or equivalent.

Access to production systems is restricted to authorized personnel with role-based permissions, and administrative actions are audit-logged. Secrets and credentials are stored in a managed secrets vault, never in source code.

No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security and encourage you to use strong, unique passwords and protect your account credentials.

9. Cookies

Our marketing website uses a small number of cookies for essential functionality (session, CSRF protection) and aggregate analytics (page views, referrers). Our dashboard uses cookies to keep you signed in and remember interface preferences.

We do not use cookies for cross-site advertising. You can disable cookies in your browser settings; doing so may limit some features of the Service.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, the Service, or applicable law. When we make material changes, we will update the “Effective Date” above and, where appropriate, notify connected merchants by email or through the dashboard.

Your continued use of the Service after an updated policy takes effect constitutes your acceptance of the revised terms.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your data, please contact us at: