Privacy Policy
Effective date: July 9, 2026
This Privacy Policy explains how ESPLENDORCO S.A. DE C.V. ("Esplendorco", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with our services available at esplendorco.com. Esplendorco is a WhatsApp Business Platform Tech Provider (a Meta-approved solution provider). We give merchant businesses a shared team inbox plus AI-assisted automation to handle WhatsApp conversations for cash-on-delivery (COD) e-commerce, primarily in Latin America (El Salvador, Honduras, Guatemala, and Costa Rica). We integrate with Shopify as a Shopify app to read the order and customer data needed to service COD orders, and we onboard each merchant's own WhatsApp Business Account (WABA) and phone number through Meta's Cloud API, Embedded Signup, and WhatsApp Coexistence.
Esplendorco is based in El Salvador, and El Salvador's data protection law is the primary legal framework governing us where we act as a data controller. This Policy should be read together with our Terms of Service and, for merchants, our Data Processing Addendum (DPA), which is available on request at contacto@esplendorco.com.
1. Who We Are and Our Data Protection Roles
Esplendorco plays two distinct roles depending on the data involved, and this distinction determines who is responsible for the data and how the relevant individual exercises their rights.
- Data controller. Esplendorco is the data controller for merchant account data: the information about the businesses that sign up for our service, including their account, billing, and administrator details. We are also the controller for the provisioning and administration of WhatsApp assets (such as WABA and phone number identifiers, display names, and access tokens) to the extent we process them to operate and secure our own service. For this data, we decide how and why it is processed.
- Data processor. Esplendorco is a data processor acting on behalf of each merchant (who is the controller) for end-customer conversation data and Shopify order data: the personal data of the merchant's own customers who message them on WhatsApp or who place COD orders. For this data, the merchant decides how and why it is processed, and we act only on the merchant's documented instructions under a written DPA, which is available on request at contacto@esplendorco.com.
Where Esplendorco acts as a processor, this Policy describes our practices for transparency, but the merchant's own privacy notice governs the relationship with its end-customers, and requests from those end-customers should be directed to the merchant. See "Your Rights" and "Shopify Protected Customer Data" below.
Contact: ESPLENDORCO S.A. DE C.V., Final 4a Calle Poniente, Local 2-16, Condominio Cuscatlan, Distrito de San Salvador, San Salvador, El Salvador. You can reach us at contacto@esplendorco.com. Our data protection contact is also contacto@esplendorco.com. Esplendorco does not currently target or monitor individuals in the European Union, and it is therefore not required to appoint a representative under Article 27 of the GDPR. If we begin offering services to individuals in the European Union, we will appoint such a representative and update this Policy accordingly; in the meantime, data protection questions can be sent to contacto@esplendorco.com.
2. Data We Collect
We collect and process the following categories of personal data.
2.1 Merchant account data (we are the controller)
- Business name and, where applicable, legal entity details.
- Administrator and user names.
- Email addresses and phone numbers.
- Billing details, including subscription and payment information.
2.2 WhatsApp assets (we are the controller for account provisioning)
- WhatsApp Business Account (WABA) IDs.
- Phone number IDs and display names.
- Access tokens, which are encrypted at rest.
2.3 End-customer data (we are a processor on behalf of merchants)
- Customer phone numbers.
- WhatsApp profile names.
- Message content and media exchanged with the merchant.
- Timestamps and message metadata.
2.4 Shopify data (we are a processor on behalf of merchants)
- Order details and order status.
- Customer names.
- Shipping addresses.
- Other order information needed to fulfil and confirm COD orders.
2.5 AI-generated content
- Suggested and automated replies produced by third-party large language model (LLM) providers based on conversation and order context. See "Automated Replies and AI Processing" below.
We do not intentionally collect special categories of personal data (such as data revealing health, race, religion, or political opinions). Where a merchant or an end-customer includes such data in message content, it is processed by us solely as a processor on the merchant's behalf and under the DPA.
3. Purposes of Processing
We process personal data for the following purposes.
- To create, provision, and administer merchant accounts, including onboarding WABAs and phone numbers through Meta's Cloud API, Embedded Signup, and WhatsApp Coexistence.
- To provide the shared team inbox and to send, receive, and route WhatsApp messages between merchants and their end-customers.
- To integrate with Shopify and read order and customer data needed to fulfil and confirm COD orders.
- To generate AI-assisted suggested or automated replies, where the merchant has enabled this feature.
- To vet phone numbers at onboarding and to detect, prevent, and respond to abuse, spam, fraud, and violations of applicable messaging policies.
- To bill merchants, manage subscriptions, and provide customer support.
- To maintain the security, integrity, and reliability of our service.
- To comply with legal obligations and with the platform policies referenced in this Policy.
4. Legal Bases for Processing (GDPR and UK GDPR)
Where the GDPR or the UK GDPR applies and we act as controller, we rely on the following legal bases. These provisions remain relevant because merchants based in the European Union, the United Kingdom, or the United States may install our Shopify app, even though El Salvador's data protection law is the primary framework governing Esplendorco as controller.
- Performance of a contract (Article 6(1)(b)): to provide the service to merchants, administer accounts, provision WhatsApp assets, and process billing.
- Legitimate interests (Article 6(1)(f)): to secure our service, prevent abuse and spam, vet phone numbers, and improve reliability, balanced against the rights and freedoms of the individuals concerned. You may object to processing based on legitimate interests as described in "Your Rights".
- Legal obligation (Article 6(1)(c)): to comply with applicable laws, respond to lawful requests, and meet platform compliance requirements.
- Consent (Article 6(1)(a)): where we specifically ask for it. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
Where Esplendorco acts as a processor for end-customer conversation data and Shopify data, the merchant, as controller, is responsible for establishing the legal basis for processing, including obtaining verifiable prior opt-in consent from end-customers before messaging them on WhatsApp. We process such data only under the merchant's instructions and the DPA, which is available on request at contacto@esplendorco.com.
5. Sub-Processors
We use the following sub-processors to deliver our service. A current and maintained list is available on request at contacto@esplendorco.com.
- Meta Platforms Ireland Limited / Meta Platforms, Inc. — WhatsApp Cloud API messaging.
- Shopify Inc. — e-commerce data integration.
- Vercel Inc. — application hosting.
- Supabase — managed PostgreSQL database and authentication.
- Backblaze B2 — media and file storage.
- AI / LLM providers used to generate automated replies, configurable per merchant: Anthropic, OpenAI, Google, xAI, and OpenRouter. Merchants may disable AI automation.
We impose contractual data protection obligations on our sub-processors consistent with our own commitments and with applicable law. Where required, we notify merchants of intended additions or replacements of sub-processors so that they may object in accordance with the DPA.
6. International Data Transfers
Some of our sub-processors and infrastructure are located outside the country in which you or the relevant data subjects are based, including outside the European Economic Area (EEA) and the United Kingdom, and outside the Latin American countries in which merchants operate. Where we transfer personal data internationally, we rely on an adequacy decision where one exists, or on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with any supplementary measures required. For transfers governed by applicable Latin American data protection laws, we rely on the transfer mechanisms those laws permit, such as the data subject's consent, contractual clauses, or equivalent safeguards. Because several of our sub-processors are located in the United States and elsewhere, we transfer personal data internationally under appropriate safeguards such as Standard Contractual Clauses and the sub-processors' own data protection commitments, and, where applicable under Salvadoran and other applicable law, on the basis of contract performance or the data subject's consent. Details of the transfer mechanism applicable to a specific transfer are available on request at contacto@esplendorco.com.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, to comply with our legal obligations, and to resolve disputes and enforce agreements.
- Merchant account and billing data: retained for the duration of the account plus 24 months.
- WhatsApp assets and access tokens: retained while the merchant's account and connection are active, and deleted within 30 days of disconnection.
- End-customer conversation data and media: retained on behalf of the merchant for 24 months, or as otherwise instructed by the merchant under the DPA.
- Shopify order data: retained on behalf of the merchant for 24 months, or as otherwise instructed by the merchant.
- AI-generated content and related logs: retained for 12 months.
Where Esplendorco acts as a processor, retention periods for end-customer and Shopify data are ultimately determined by the merchant as controller. When retention periods expire or upon a valid deletion request, we delete or anonymize the data.
8. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:
- Encryption at rest for sensitive credentials, including WhatsApp access tokens, and encryption in transit for data exchanged with our service and sub-processors.
- Access controls, including role-based access, authentication, and the principle of least privilege for staff and systems.
- Logging, monitoring, and measures to detect and respond to security incidents.
- Contractual security obligations imposed on our sub-processors.
No method of transmission or storage is completely secure, but we work to maintain safeguards appropriate to the risk. Where required by applicable law, we will notify the relevant supervisory authority and affected individuals or merchants of a personal data breach.
9. Your Rights
Depending on where you are located and applicable law, you may have the following rights regarding your personal data:
- Access to the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data in certain circumstances.
- Data portability, to receive your data in a structured, commonly used, machine-readable format.
- Objection to processing based on legitimate interests, including profiling.
- Restriction of processing in certain circumstances.
- Withdrawal of consent at any time, where we rely on consent, without affecting the lawfulness of processing carried out before withdrawal.
- Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. We do not use automated decision-making of this kind; AI-generated replies are a drafting aid used under human or merchant control.
How to exercise your rights. The correct route depends on our role:
- For merchant account data, where Esplendorco is the controller, contact us directly at contacto@esplendorco.com and we will respond in accordance with applicable law.
- For end-customer conversation data and Shopify data, where Esplendorco is a processor, the merchant is the controller. If you are an end-customer, please direct your request to the merchant you were messaging or ordering from. If a request reaches us directly, we will forward it to the relevant merchant and assist that merchant in responding, as required by our DPA and applicable law.
We do not charge a fee to handle most requests and will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request. You also have the right to lodge a complaint with a supervisory authority, such as your local data protection authority in the EEA, the UK, or your country of residence in Latin America.
10. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you the right to know what personal information we collect and how we use it, to request access to and deletion of your personal information, to correct inaccurate personal information, to limit the use and disclosure of any sensitive personal information, and to be free from discrimination for exercising your rights.
The categories of personal information we collect, the sources of that information, the business purposes for which we use it, and the categories of recipients to whom we disclose it are described in "Data We Collect", "Purposes of Processing", and "Sub-Processors" above.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. Because we do not sell or share personal information as those terms are defined under the CPRA, no "Do Not Sell or Share My Personal Information" opt-out is required for us to honor; we do not engage in such activity. We also do not use or disclose sensitive personal information for purposes that would trigger a right to limit under the CPRA. To exercise your California rights, contact us at contacto@esplendorco.com; you may use an authorized agent to submit a request on your behalf, subject to verification. Where Esplendorco acts as a service provider or processor on behalf of a merchant, we handle personal information only as permitted by our contract with that merchant, and consumer requests regarding that information should be directed to the merchant.
11. Children
Our service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. We do not knowingly collect personal information from children under 13 in the United States as defined by the Children's Online Privacy Protection Act (COPPA). If you believe a child under the applicable age has provided us with personal data, please contact us at contacto@esplendorco.com and we will take appropriate steps to delete it.
12. Shopify Protected Customer Data
When we access data through the Shopify platform, we comply with the Shopify API License and Terms of Use and with Shopify's Protected Customer Data Requirements. We access, use, and retain Shopify customer data only to provide and improve the specific COD-order functionality merchants request, and we apply the data minimization, security, and processing controls required by those requirements.
We support the mandatory Shopify compliance webhooks and respond to them as follows:
- customers/data_request: when a merchant's customer requests their data, we make available the personal data we hold on behalf of that merchant so the merchant can respond.
- customers/redact: when a merchant's customer requests deletion, we delete or redact that customer's personal data that we hold on behalf of the merchant, subject to legal retention requirements.
- shop/redact: when a merchant uninstalls the app or requests shop deletion, we delete or redact the shop's data that we hold on behalf of that merchant after the applicable Shopify waiting period.
For Shopify customer data, the merchant is the controller and Esplendorco is a processor. End-customer requests should be directed to the merchant, and we assist the merchant in fulfilling them.
13. Meta Platform Data Use and Limited Use of WhatsApp / Meta Data
Our use of information received from Meta platforms, including the WhatsApp Cloud API, complies with the Meta Platform Terms and Developer Policies, the WhatsApp Business Messaging Policy, and the WhatsApp Business and Commerce Policies. We use WhatsApp and Meta data only to provide and improve the messaging and COD-servicing functionality that merchants and their customers expect, and we do not use it for purposes that these policies prohibit, including selling it, using it for advertising, or building unrelated profiles. Merchants are responsible for obtaining verifiable prior opt-in consent from end-customers before messaging them, for honoring opt-out and STOP requests, and for using the correct message template categories and customer service window rules.
14. Automated Replies and AI Processing
Where a merchant enables AI automation, message content and relevant order context may be processed by third-party AI / LLM sub-processors (Anthropic, OpenAI, Google, xAI, or OpenRouter, configurable per merchant) to generate suggested or automated replies. This processing occurs on behalf of the merchant as controller. Merchants can disable AI automation at any time, in which case message content is not sent to these AI providers for reply generation. We select AI providers that offer appropriate confidentiality and data protection commitments, and we do not permit them to use merchant or end-customer data to train their own models except as necessary to provide the service and as permitted by the applicable provider terms.
15. Contact and Data Protection Officer
If you have questions or concerns about this Policy or our data practices, or wish to exercise your rights, you can contact us at:
- General, legal, and data protection contact: contacto@esplendorco.com
- Postal: ESPLENDORCO S.A. DE C.V., Final 4a Calle Poniente, Local 2-16, Condominio Cuscatlan, Distrito de San Salvador, San Salvador, El Salvador
- EU representative (GDPR Article 27): Esplendorco does not currently target or monitor individuals in the European Union and is therefore not required to appoint an Article 27 representative. If we begin offering services to individuals in the European Union, we will appoint one and update this Policy; in the meantime, data protection questions can be sent to contacto@esplendorco.com.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and notify affected merchants by email or through the service before the changes take effect, where required by applicable law. We encourage you to review this Policy periodically. Your continued use of the service after an update takes effect constitutes acceptance of the revised Policy.
17. Governing Law
This Privacy Policy is governed by the laws of El Salvador, without prejudice to any mandatory data protection rights you may have under the GDPR, the UK GDPR, the CCPA/CPRA, or applicable Latin American data protection laws. Any dispute arising out of or in connection with this Policy shall be submitted to the competent courts of San Salvador, El Salvador.