Skip to content
OrderAgentOrderAgent

Privacy policy

What personal data OrderAgent holds, who it belongs to, where it is stored, who it is shared with, and how to get it corrected or removed.

In effect from 26 August 2026

OrderAgent is a trading name. Where these documents say “we”, “us” or “our”, they mean the operator of the OrderAgent service.

This policy explains what personal data OrderAgent handles, whose it is, where it is kept, who else sees it, and what you can ask us to do about it. It is written against the Personal Data Protection Act 2010 (Act 709) of Malaysia.

It covers two different groups of people, and almost every question about privacy here is really a question about which of the two you are.

Which relationship you are in

OrderAgent is used by shops — distributors, mills, wholesalers — to take orders from their own customers over WhatsApp. That produces two distinct relationships, with two different answers.

If you run a shop that uses OrderAgent, we hold data about you and your business, and we are the data user for it. This policy is our agreement with you about that data.

If you are a customer of a shop that uses OrderAgent, your data reaches us because you messaged that shop. The shop decides what to do with it; we hold and process it on the shop's instructions. In the language of the Personal Data Protection Act 2010, the shop is the data user and we are the data processor.

What we hold

From a shop

  • The owner's WhatsApp number, which is the login — there is no password.
  • The shop's name, country, currency, time zone and trading settings.
  • Bank account details and a payment QR image, because the bot sends them to customers as payment instructions.
  • The product catalogue: names, aliases, prices, units, stock.
  • Additional staff phone numbers, where the shop has added any.
  • An append-only audit log of decisions that move money or change access — payment approvals, rejections, plan changes, suspensions, logins.

From a shop's customers

  • The WhatsApp phone number, and the profile name WhatsApp supplies.
  • The content of messages sent to and from the shop's number, including images and documents.
  • Orders, order lines, quantities, prices and totals.
  • Delivery addresses, stored so a returning customer is never asked twice.
  • Payment records, and the receipt image or PDF sent as proof of payment.
  • Invoices issued for those orders.
  • Whether the customer has opted out of messages.

We do not ask for, and have no use for, identity documents, dates of birth, government identifiers or card numbers. A customer who sends one anyway has sent it into a WhatsApp conversation, where it is stored as part of that conversation — tell us and we will remove it.

Where it comes from

Almost all of it arrives through the WhatsApp Business Platform, because a customer sent a message to the shop's number. The rest is typed into the dashboard by the shop, or given to us during onboarding.

We do not buy data, scrape it, or obtain contact lists from anywhere else. There is no way for a phone number to enter OrderAgent except by messaging a shop that uses it, or by a shop entering it.

Why we hold it

WhatWhy
Phone number and profile nameTo recognise a returning customer and address them by name
Message historyThe order was made in it, and it is how a dispute about what was said gets settled
Orders, prices, totalsThe record of the trade
Delivery addressSo the shop can deliver, and so nobody is asked for it twice
Receipts and payment recordsProof of payment, and the duplicate-receipt checks depend on holding the earlier ones
InvoicesFinancial records the shop is required to keep
Opt-out flagSo that STOP keeps working, permanently
Audit logSo a money decision can always be attributed afterwards

We do not use any of it to build advertising profiles, and we do not sell it. There is no advertising in this product and no third party is paid for access to it.

A customer's consent is given by messaging the shop's WhatsApp number for the purpose of ordering. That consent covers handling the conversation, the order, the payment and the delivery.

It is withdrawn by sending STOP to the shop's number. Nothing further is sent to that number — not even a message explaining that nothing further will be sent, because that would still be a message to somebody who asked for none. START reinstates. Only an explicit START counts: tapping a button in an older message does not re-consent on a customer's behalf.

Automated processing, and its limits

OrderAgent uses a language model in exactly two places:

  1. Reading an incoming message — deciding whether it is an order, a question, a payment claim or an acknowledgement, and which catalogue products it names.
  2. Reading an uploaded receipt — extracting the amount, date, reference and recipient from the image or PDF.

To do that, the message text or the receipt image is sent to Google's Gemini API along with the shop context needed to interpret it. It is not used to make a decision about a person, to score them, or to decide whether to serve them.

Two limits are worth stating plainly, because they are design decisions rather than promises:

  • The model never supplies a value that reaches a customer. Prices, stock figures, totals, deadlines and amounts owed are read from the shop's own records. The model classifies and extracts; the code decides and writes.
  • The model never approves money. A payment is marked paid by a person at the shop, every time, without exception. Automated receipt checking can only flag a receipt for review — it cannot settle an order.

No decision with a legal or similarly significant effect on anyone is made solely by automated means.

Who else processes it

We use a small number of providers to run the service. Each one only receives what its job needs.

Meta Platforms, Inc.WhatsApp Business Platform

Global

Carries every message in both directions. Meta necessarily sees message content, phone numbers and profile names — this is the platform your customers are already using.

Google LLCGemini API

Global

Classifies what an incoming message is asking for, and reads the amount, date and reference from an uploaded payment receipt. It receives the message text or the receipt image and the shop context needed to interpret it.

SupabaseManaged Postgres and object storage

Tokyo, Japan (ap-northeast-1)

Stores the database and the receipt and invoice files. Receipt and invoice storage is private and is never reachable by an ordinary URL.

Vercel Inc.Application hosting

Tokyo, Japan (hnd1)

Runs the service itself. Compute is placed in the same region as the database.

We do not add a provider to this list quietly — a change here is a change to this policy, and the effective date at the top of the page moves with it.

Where it is stored, and leaving the country

The database and the stored files are hosted in Tokyo, Japan. The service's compute runs in the same region.

That means personal data collected in Malaysia is transferred outside Malaysia and stored there. Message delivery through Meta and the model calls to Google are likewise not confined to any one country.

We say so rather than burying it, because under the Personal Data Protection Act 2010 a cross-border transfer is something you are entitled to know about before you agree to it. Using OrderAgent means accepting that your data — and the data of the customers who message you — is processed in and transferred to jurisdictions outside Malaysia.

Keeping shops apart

Every record in the system belongs to exactly one shop, and every query is filtered by which shop it is. The shop is taken from a verified session and never from anything in the address bar, so there is no URL to edit to see another shop's data.

Records that have no shop of their own — an order line, a payment — are only ever reached through the order they belong to, never directly by their own id.

Security

  • Receipt images and invoice PDFs are stored in private storage and are never reachable by an ordinary URL. The dashboard mints a short-lived signed link per view, and refuses to sign a path outside the viewing shop's own folder.
  • Traffic is encrypted in transit. Our database and storage providers encrypt data at rest.
  • There are no passwords to steal. A shop signs in by asking the bot for a link that is sent to the owner's own WhatsApp number, expires in fifteen minutes and can be used once.
  • Money decisions are restricted to the owner. Staff accounts can move an order through packing and delivery but cannot mark anything paid.
  • Access we take for support is recorded in a log the code can only append to — there is no path in the software that edits or deletes an entry.

No system is impossible to breach, and we will not claim certifications we do not hold. If a breach affects your data we will tell you what happened, what was reached, and when.

How long we keep it

  • Financial records — orders, payments and invoices — are kept for 7 years. They are the shop's tax records, and the shop is required to be able to produce them.
  • Conversations, addresses and receipt images are kept while the shop's account is open, because they are what the order history and the duplicate checks are built on.
  • Login links expire after fifteen minutes and are single-use.
  • A closed account's data is deleted within 30 days of closure, apart from the financial records above.

Your rights

Under the Personal Data Protection Act 2010 you may ask to:

  • access the personal data we hold about you;
  • correct it where it is wrong or out of date;
  • withdraw consent to further processing;
  • limit processing for direct marketing — which for a customer is what STOP does immediately, without asking anyone.

Write to us and we will respond within 21 working days. If you are a shop's customer, ask the shop first: they hold the relationship with you, and we act on their instruction. Where a request reaches us directly we verify it with the shop before acting, for the reason given at the top of this page.

Deletion has its own page, because the answer is longer than "yes": see data deletion.

Children

OrderAgent is a tool for businesses and is not directed at children. We do not knowingly hold data about anyone under 18. If a shop's customer is under 18 and their data is here, tell us and we will remove it.

Changes to this policy

When this policy changes materially, the effective date at the top of the page moves and shops are told through the product. Continuing to use OrderAgent after that date means the new version applies.

We do not silently rewrite an old version — a change to what we do with data is worth announcing, and a policy that changes without notice is not a policy.