Legal
Privacy Policy
Last updated: 8 August 2026
This policy explains what Vendesso collects, why, and what we do with it. It covers two groups of people: the businesses who use Vendesso to answer their customers, and those businesses' customers, whose messages Vendesso reads in order to reply.
1. Who we are
Vendesso is operated by Vendesso Ltd, based in Nigeria.
For anything in this policy — including any request about your own data — contact support@vendesso.com. That address reaches the person responsible for data protection here, and it is monitored.
2. Our role
For a business's own account information we are the data controller. For the messages that business's customers send, we act as a data processor on that business's behalf — we handle those messages to provide the reply service, under that business's instructions. The business remains responsible for how it deals with its own customers.
3. What we collect
From businesses using Vendesso:
- Business name, location, and contact details you give during setup
- Your WhatsApp Business account identifiers and the access token that lets us reply on your line
- Your catalogue — groups, products, versions, prices, stock counts and photos
- Your delivery zones and fees, and your bargaining limits
- The payment details you choose to give your customers (for example a bank account, or credentials for your own payment provider)
- Billing records for your subscription
From customers messaging a business that uses Vendesso:
- The phone number the message came from
- The content of messages sent to that business's line
- Conversation state needed to stay coherent — the item being discussed, the open order, an agreed price
- Delivery zone and address, where the customer provides them to complete an order
4. Why we use it
- To read an incoming message and resolve the reply from the business's own catalogue
- To keep a conversation coherent across several messages
- To build and hold an order until the business fulfils it
- To tell the business when a conversation needs a person
- To report to the business what customers asked for — including things not in stock
- To investigate disputes about what was said, quoted or agreed, and to find and fix cases where the assistant answers badly
- To bill for the subscription, and to keep the service secure and working
We do not sell personal data, and we do not use your conversations to train or build products we sell to anyone else.
5. Legal bases
Under the Nigeria Data Protection Act 2023 we rely on: performance of a contract (running the service you signed up for), legitimate interests (securing the service, preventing abuse, and establishing or defending legal claims — which is why messages are retained for a limited period), legal obligation (records we are required to keep), and consent where it applies and where you may withdraw it.
6. Who we share it with
- Meta Platforms — messages travel over the WhatsApp Business Platform; Meta's own terms and privacy policy apply to that transport
- Your payment provider — if you connect one, so payments can be confirmed. We never receive the money itself
- Hosting and infrastructure providers — who store data on our instructions
- Authorities — where we are legally required to disclose
We do not share data with advertisers or data brokers.
When an authority asks. We comply with lawful requests — and we check that they are lawful first. Every request is reviewed for a genuine legal basis before anything is disclosed; we contest requests that are unlawful or that ask for more than their purpose needs; we disclose the minimum identified rather than an export; and we record every request and what we did about it. Where the data belongs to a business's customers we are the processor, not the controller — so we tell that business, and where appropriate point the authority to her, unless we are legally prohibited from doing so.
7. Storage and transfers
Data is stored on servers operated by our infrastructure providers, which may be located outside Nigeria. Where data leaves Nigeria we rely on the transfer safeguards permitted under the Nigeria Data Protection Act 2023.
8. How long we keep it
- Catalogue and account data — while your account is open, and after cancellation so you can return, until you ask us to delete it
- Conversation state — the working memory that keeps a single conversation coherent. Short-lived; cleared automatically after a period of inactivity
- Messages — the messages sent to a business's line and the replies we sent back are kept for 90 days, then deleted automatically. See below for why
- Price history — a record of the prices, bargaining limits and stock a business sets, kept for as long as the account exists
- Orders — kept as business records for as long as the business needs them
- Billing records — as long as tax and company law requires
Why we keep messages at all. The assistant answers on a business's behalf, so when someone disputes what was quoted, agreed or ordered, the record is the only way to establish what actually happened — for the business as much as against it. It also lets us find and fix the cases where the assistant answers badly. It is not used for advertising, is never sold, and is not used to build products for anyone else.
Access is limited to our own staff, and only where there is a reason to look. Businesses cannot read other businesses' conversations, and we do not offer message history as a feature — a business already has her own copy in WhatsApp.
9. Security
Access tokens and payment provider credentials are held for backend use only, and are never displayed in the product or written to logs. Specifically:
- Encrypted where we must be able to read it back — your WhatsApp access token and our staff's two-factor secrets are encrypted at rest, with a key held outside the database
- Hashed where we don't need the original — staff passwords, sign-in links and session identifiers are stored only as one-way hashes, so a copy of our database grants nobody a login
- Transport — the site, the vendor portal and our connection to the messaging platform all run over HTTPS
- Staff access — limited to those who need it, protected by a password plus an authenticator app, and every administrative change is recorded
Our staff console deliberately cannot show a business's bargaining limits or its payment credentials, and shows customers' phone numbers only in part. Support access is not the same as ownership of your data.
No system is perfectly secure. Where the law requires it, we will notify you and the Nigeria Data Protection Commission of a breach.
10. Cookies
We use no advertising or analytics cookies, and no third-party trackers. The public site sets nothing at all.
Signing in to the vendor portal or the staff console sets one cookie holding your session identifier. It's necessary for the service to work — without it there's no way to stay signed in — so it isn't something we ask consent for. It's marked HttpOnly and SameSite=Lax, is served only over HTTPS, and expires when you sign out, after 30 minutes of inactivity, or after 14 days at the latest.
11. Automated replies
Vendesso answers customers automatically — that's the product. Replies are resolved from the business's own catalogue by fixed rules written by hand. No language model or generative AI is involved and nothing is ever invented — the assistant cannot produce a price, a product or a delivery fee that the business did not set. It does not learn from your conversations, and no profile is built about anyone. Where a business enables bargaining, offers are accepted or declined against limits that business set in advance.
These are decisions about a price, not about a person: we don't profile customers, score them, or treat one differently from another. A customer can ask to speak to a human at any point and the assistant will hand over.
12. Your rights
You may request access to your data, correction of it, deletion of it, restriction of how we use it, a portable copy, or object to a particular use. You may also withdraw consent where consent is what we relied on. Write to support@vendesso.com and we will respond within the timeframe the law sets. Exercising these rights is free, and we won't treat you differently for it.
If you're a customer of a business that uses Vendesso, that business decides what happens to your messages — we handle them on its instructions. Ask that business directly. If you ask us, we'll pass your request on and tell you we've done so.
You may also complain to the Nigeria Data Protection Commission, and you don't have to come to us first.
13. Deleting your data
If you are a business using Vendesso, email support@vendesso.com from the address on your account with the word delete and the WhatsApp number your shop answers on. You can also ask on your Vendesso control line. We do not require a reason, and there is no charge.
Within 30 days of confirming it is you, we delete:
- your catalogue — every collection, product, version, price, floor price and photo
- your account and settings, including delivery zones and payment details
- the connection to your WhatsApp Business Account: we unsubscribe our app from it, so your customers' messages stop reaching us, and we destroy the access token you granted us
- the conversations we handled for you, and the record of what the assistant replied
What we keep, and why. Records of completed orders and payments are kept for as long as tax and record-keeping law requires, and then deleted. We cannot delete these on request — not because we want them, but because a business is required to be able to evidence its own sales. Nothing in that set is used for any other purpose while we hold it.
You can also cut us off yourself, immediately. In Meta Business Settings, remove Vendesso from your WhatsApp Business Account. We stop receiving your messages the moment you do, without waiting for us. Deleting what we already hold still needs the request above.
If you are a customer of a business that uses Vendesso, that business decides what happens to your messages — we only handle them on its instructions. Ask that business directly. If you ask us instead, we record your request, evidence its date, and pass it to that business; we will tell you we have done so. We do not delete a business's records on the instruction of someone who is not that business.
14. Children
Vendesso is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, write to support@vendesso.com and we'll delete it.
15. Changes
We will update this page when the service changes and move the date at the top. If a change materially affects how we handle your data, we'll tell you directly rather than relying on you to notice.
Questions about this policy: support@vendesso.com · Vendesso Ltd