HomiFlow

Privacy Policy

Last updated: 28 July 2026 النسخة العربية

HomiFlow is an order management platform for merchants in Algeria who sell cash on delivery. Their customers reach them on WhatsApp, Messenger and Instagram, and orders are confirmed by conversation rather than by checkout. This policy explains what data we collect, why, how we protect it, and what rights you have over it. The product interface is in Arabic; this English text is the same policy, provided for reviewers and partners.

1. Who we are

HomiFlow is operated by Oussama Ramdani, Place Andalous, Ghardaia 47000, Algeria. For anything in this policy, write to support@homiflow.online or message +213 660 87 55 11.

Our customer is the merchant. For the data belonging to the merchant's own customers we act as a processor: the merchant decides what happens to it, and we act on their instructions.

2. What we collect

  • Account data:name, email address and role of each person using the merchant's HomiFlow account.
  • Store data (from Shopify, if connected): products, inventory, locations and orders, through the permissions granted at connection time.
  • End-customer data: name, phone number, wilaya/commune and address — needed to confirm an order and deliver it.
  • Meta platform data (if the merchant connects a channel): see section 3.
  • Advertising data (optional):performance figures for the merchant's own ad account on Meta or TikTok, if connected.

3. Meta platform data

A merchant may connect their own Facebook Pages, Instagram professional account and WhatsApp Business account. Nothing is accessed until they authorize it through Meta's own consent dialog, and the merchant chooses which Pages and accounts to include.

Once connected, and only for the accounts they selected, we access:

  • Page and account details: the name and identifier of the Page, Instagram account or WhatsApp phone number, used to label the connection and route incoming messages to the right merchant.
  • Conversations:messages people send to the merchant on Messenger, Instagram Direct and WhatsApp, with their attachments, together with the sender's platform-scoped identifier and public display name, so the merchant can read and answer them in one inbox.
  • Comments:comments on the merchant's own posts and ads, so the merchant can reply publicly or move the conversation to a private message.
  • Access tokens:issued by Meta at connection time, stored encrypted, and used only to perform the actions above on the merchant's behalf.
  • Ad insights:spend and results for the merchant's own campaigns, shown next to the orders those campaigns produced, since in cash on delivery an order only counts once it is delivered and paid.

What we commit to:

  • We use this data only to provide the merchant with the features they connected it for.
  • We do not sell it, rent it, or share it with data brokers, and we do not use it to build advertising profiles or to target advertising.
  • We reply to people who messaged the merchant first. We do not message anyone otherwise, except through WhatsApp message templates the merchant has had approved by Meta.
  • A merchant can disconnect at any time; disconnecting deletes the token and ends our access immediately.
  • We keep this data no longer than the merchant's account is active, and delete it on request — see Data Deletion.

4. How we use data

  • Managing orders, stock, confirmation calls and delivery.
  • Bringing messages and comments from the connected channels into one inbox.
  • Sending order updates to the customer on the channel they wrote from.
  • Passing orders to delivery companies so the parcel reaches the customer.
  • Syncing stock and orders with the merchant's Shopify store.
  • Reporting and analytics that help the merchant run their business.
  • Contacting the merchant about their account and subscription.

We do not use merchant or customer data for advertising, and we do not sell it.

5. Service providers

We share the minimum necessary with providers that run parts of the service:

  • Delivery companies (ZR Express, Ecotrack, Yalidine, Maystro, Noest and others the merchant chooses): customer name, phone, address and order details, to deliver the parcel.
  • Hosting and database (Vercel, Neon): running and storing the platform.
  • Email (Resend): account and invitation emails.
  • Payments (Chargily): subscription payments.
  • Shopify: syncing and billing where the merchant subscribes through Shopify.
  • AI providers (Anthropic; fal.ai for image and video generation): where a merchant turns on an AI feature, the relevant text — which may include a customer message the AI is drafting a reply to — is sent to the provider to produce that reply or asset. These providers act on our instruction and do not use the content to train their models.

All of them are bound to protect the data and to use it only to provide their service to us.

6. Your rights

You can ask for access to your data or its deletion, at any time, free of charge, at support@homiflow.online. We respect privacy rights including those under the GDPR. Deletion is described step by step on the Data Deletion page.

For end-customer data coming from Shopify we support the official webhooks: customers/data_request (we provide what is stored about the customer), customers/redact (we redact that customer's personal data) and shop/redact(after uninstall, we delete the connection and redact the store's personal data).

7. Retention

We keep data while the account is active. Disconnecting a channel deletes its connection and token immediately. Closing the account, or asking us to delete stored data, results in deletion within 30 days, except records we are legally required to keep, such as invoices and audit-log entries — which contain no message content.

8. Security

Traffic is encrypted in transit (HTTPS), secrets such as access tokens are encrypted at rest, every incoming platform notification is verified before it is trusted (HMAC), and each merchant's data is isolated from every other merchant's. No system is 100% secure, and we keep working on it.

9. Children

HomiFlow is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.

10. Changes

We may update this policy. Any significant change will be communicated, and the date at the top will be updated.