Privacy Policy
Last updated: April 2026
1. Introduction
GetNextOrder Ltd operates Next-Order, an AI-powered CRM and messaging platform for e-commerce businesses. This Privacy Policy explains how we collect, use, and protect your information when you use our platform.
2. Information We Collect
- Business owner information: name, email address, phone number
- Customer data: name, phone number, platform ID (WhatsApp/Instagram)
- Messages: WhatsApp and Instagram conversations for order processing
- Order data: items, delivery address, order history, payment details
- Usage data: AI message counts, platform activity, login history
3. How We Use Information
- Provide AI-powered automated responses to customer messages
- Process and manage customer orders
- Send order status notifications (confirmation, delivery)
- Improve platform performance and service quality
- Billing and account management
4. WhatsApp & Instagram Data
We process messages through Meta's Graph API and 360dialog to provide automated business responses. Messages are stored securely and are only accessible by the respective business account. We do not access or read messages outside of automated processing.
5. Data Storage & Security
- Data stored on Supabase infrastructure (EU/US servers)
- Row Level Security (RLS) enforced — each business sees only their own data
- Data encrypted at rest and in transit
- HMAC signature verification on all webhook communications
- We never sell or share your data with third parties
6. Data Retention
- Messages retained for 12 months
- Order data retained for 3 years
- Account data retained while the account is active
7. Your Rights
- Access your data at any time through your dashboard
- Request complete data deletion
- Export your data in a portable format
To exercise any of these rights, contact us at support@getnextorder.com
8. Account Security
GetNextOrder Ltd administrators do not have access to business account passwords or credentials. When a new business account is created, login credentials are sent directly to the registered email address. Password resets are handled via email verification sent directly to the account holder. Administrators cannot log into business accounts or access private customer conversations.
