Privacy Policy

Effective date: July 9, 2026

This Privacy Policy explains how ESPLENDORCO S.A. DE C.V. ("Esplendorco", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with our services available at esplendorco.com. Esplendorco is a WhatsApp Business Platform Tech Provider (a Meta-approved solution provider). We give merchant businesses a shared team inbox plus AI-assisted automation to handle WhatsApp conversations for cash-on-delivery (COD) e-commerce, primarily in Latin America (El Salvador, Honduras, Guatemala, and Costa Rica). We integrate with Shopify as a Shopify app to read the order and customer data needed to service COD orders, and we onboard each merchant's own WhatsApp Business Account (WABA) and phone number through Meta's Cloud API, Embedded Signup, and WhatsApp Coexistence.

Esplendorco is based in El Salvador, and El Salvador's data protection law is the primary legal framework governing us where we act as a data controller. This Policy should be read together with our Terms of Service and, for merchants, our Data Processing Addendum (DPA), which is available on request at contacto@esplendorco.com.

1. Who We Are and Our Data Protection Roles

Esplendorco plays two distinct roles depending on the data involved, and this distinction determines who is responsible for the data and how the relevant individual exercises their rights.

Where Esplendorco acts as a processor, this Policy describes our practices for transparency, but the merchant's own privacy notice governs the relationship with its end-customers, and requests from those end-customers should be directed to the merchant. See "Your Rights" and "Shopify Protected Customer Data" below.

Contact: ESPLENDORCO S.A. DE C.V., Final 4a Calle Poniente, Local 2-16, Condominio Cuscatlan, Distrito de San Salvador, San Salvador, El Salvador. You can reach us at contacto@esplendorco.com. Our data protection contact is also contacto@esplendorco.com. Esplendorco does not currently target or monitor individuals in the European Union, and it is therefore not required to appoint a representative under Article 27 of the GDPR. If we begin offering services to individuals in the European Union, we will appoint such a representative and update this Policy accordingly; in the meantime, data protection questions can be sent to contacto@esplendorco.com.

2. Data We Collect

We collect and process the following categories of personal data.

2.1 Merchant account data (we are the controller)

2.2 WhatsApp assets (we are the controller for account provisioning)

2.3 End-customer data (we are a processor on behalf of merchants)

2.4 Shopify data (we are a processor on behalf of merchants)

2.5 AI-generated content

We do not intentionally collect special categories of personal data (such as data revealing health, race, religion, or political opinions). Where a merchant or an end-customer includes such data in message content, it is processed by us solely as a processor on the merchant's behalf and under the DPA.

3. Purposes of Processing

We process personal data for the following purposes.

4. Legal Bases for Processing (GDPR and UK GDPR)

Where the GDPR or the UK GDPR applies and we act as controller, we rely on the following legal bases. These provisions remain relevant because merchants based in the European Union, the United Kingdom, or the United States may install our Shopify app, even though El Salvador's data protection law is the primary framework governing Esplendorco as controller.

Where Esplendorco acts as a processor for end-customer conversation data and Shopify data, the merchant, as controller, is responsible for establishing the legal basis for processing, including obtaining verifiable prior opt-in consent from end-customers before messaging them on WhatsApp. We process such data only under the merchant's instructions and the DPA, which is available on request at contacto@esplendorco.com.

5. Sub-Processors

We use the following sub-processors to deliver our service. A current and maintained list is available on request at contacto@esplendorco.com.

We impose contractual data protection obligations on our sub-processors consistent with our own commitments and with applicable law. Where required, we notify merchants of intended additions or replacements of sub-processors so that they may object in accordance with the DPA.

6. International Data Transfers

Some of our sub-processors and infrastructure are located outside the country in which you or the relevant data subjects are based, including outside the European Economic Area (EEA) and the United Kingdom, and outside the Latin American countries in which merchants operate. Where we transfer personal data internationally, we rely on an adequacy decision where one exists, or on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with any supplementary measures required. For transfers governed by applicable Latin American data protection laws, we rely on the transfer mechanisms those laws permit, such as the data subject's consent, contractual clauses, or equivalent safeguards. Because several of our sub-processors are located in the United States and elsewhere, we transfer personal data internationally under appropriate safeguards such as Standard Contractual Clauses and the sub-processors' own data protection commitments, and, where applicable under Salvadoran and other applicable law, on the basis of contract performance or the data subject's consent. Details of the transfer mechanism applicable to a specific transfer are available on request at contacto@esplendorco.com.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, to comply with our legal obligations, and to resolve disputes and enforce agreements.

Where Esplendorco acts as a processor, retention periods for end-customer and Shopify data are ultimately determined by the merchant as controller. When retention periods expire or upon a valid deletion request, we delete or anonymize the data.

8. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

No method of transmission or storage is completely secure, but we work to maintain safeguards appropriate to the risk. Where required by applicable law, we will notify the relevant supervisory authority and affected individuals or merchants of a personal data breach.

9. Your Rights

Depending on where you are located and applicable law, you may have the following rights regarding your personal data:

How to exercise your rights. The correct route depends on our role:

We do not charge a fee to handle most requests and will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request. You also have the right to lodge a complaint with a supervisory authority, such as your local data protection authority in the EEA, the UK, or your country of residence in Latin America.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you the right to know what personal information we collect and how we use it, to request access to and deletion of your personal information, to correct inaccurate personal information, to limit the use and disclosure of any sensitive personal information, and to be free from discrimination for exercising your rights.

The categories of personal information we collect, the sources of that information, the business purposes for which we use it, and the categories of recipients to whom we disclose it are described in "Data We Collect", "Purposes of Processing", and "Sub-Processors" above.

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. Because we do not sell or share personal information as those terms are defined under the CPRA, no "Do Not Sell or Share My Personal Information" opt-out is required for us to honor; we do not engage in such activity. We also do not use or disclose sensitive personal information for purposes that would trigger a right to limit under the CPRA. To exercise your California rights, contact us at contacto@esplendorco.com; you may use an authorized agent to submit a request on your behalf, subject to verification. Where Esplendorco acts as a service provider or processor on behalf of a merchant, we handle personal information only as permitted by our contract with that merchant, and consumer requests regarding that information should be directed to the merchant.

11. Children

Our service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. We do not knowingly collect personal information from children under 13 in the United States as defined by the Children's Online Privacy Protection Act (COPPA). If you believe a child under the applicable age has provided us with personal data, please contact us at contacto@esplendorco.com and we will take appropriate steps to delete it.

12. Shopify Protected Customer Data

When we access data through the Shopify platform, we comply with the Shopify API License and Terms of Use and with Shopify's Protected Customer Data Requirements. We access, use, and retain Shopify customer data only to provide and improve the specific COD-order functionality merchants request, and we apply the data minimization, security, and processing controls required by those requirements.

We support the mandatory Shopify compliance webhooks and respond to them as follows:

For Shopify customer data, the merchant is the controller and Esplendorco is a processor. End-customer requests should be directed to the merchant, and we assist the merchant in fulfilling them.

13. Meta Platform Data Use and Limited Use of WhatsApp / Meta Data

Our use of information received from Meta platforms, including the WhatsApp Cloud API, complies with the Meta Platform Terms and Developer Policies, the WhatsApp Business Messaging Policy, and the WhatsApp Business and Commerce Policies. We use WhatsApp and Meta data only to provide and improve the messaging and COD-servicing functionality that merchants and their customers expect, and we do not use it for purposes that these policies prohibit, including selling it, using it for advertising, or building unrelated profiles. Merchants are responsible for obtaining verifiable prior opt-in consent from end-customers before messaging them, for honoring opt-out and STOP requests, and for using the correct message template categories and customer service window rules.

14. Automated Replies and AI Processing

Where a merchant enables AI automation, message content and relevant order context may be processed by third-party AI / LLM sub-processors (Anthropic, OpenAI, Google, xAI, or OpenRouter, configurable per merchant) to generate suggested or automated replies. This processing occurs on behalf of the merchant as controller. Merchants can disable AI automation at any time, in which case message content is not sent to these AI providers for reply generation. We select AI providers that offer appropriate confidentiality and data protection commitments, and we do not permit them to use merchant or end-customer data to train their own models except as necessary to provide the service and as permitted by the applicable provider terms.

15. Contact and Data Protection Officer

If you have questions or concerns about this Policy or our data practices, or wish to exercise your rights, you can contact us at:

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and notify affected merchants by email or through the service before the changes take effect, where required by applicable law. We encourage you to review this Policy periodically. Your continued use of the service after an update takes effect constitutes acceptance of the revised Policy.

17. Governing Law

This Privacy Policy is governed by the laws of El Salvador, without prejudice to any mandatory data protection rights you may have under the GDPR, the UK GDPR, the CCPA/CPRA, or applicable Latin American data protection laws. Any dispute arising out of or in connection with this Policy shall be submitted to the competent courts of San Salvador, El Salvador.