OrderAgent is a trading name. Where these documents say “we”, “us” or “our”, they mean the operator of the OrderAgent service.
This policy explains what personal data OrderAgent handles, whose it is, where it is kept, who else sees it, and what you can ask us to do about it. It is written against the Personal Data Protection Act 2010 (Act 709) of Malaysia.
It covers two different groups of people, and almost every question about privacy here is really a question about which of the two you are.
Which relationship you are in
OrderAgent is used by shops — distributors, mills, wholesalers — to take orders from their own customers over WhatsApp. That produces two distinct relationships, with two different answers.
If you run a shop that uses OrderAgent, we hold data about you and your business, and we are the data user for it. This policy is our agreement with you about that data.
If you are a customer of a shop that uses OrderAgent, your data reaches us because you messaged that shop. The shop decides what to do with it; we hold and process it on the shop's instructions. In the language of the Personal Data Protection Act 2010, the shop is the data user and we are the data processor.
What we hold
From a shop
- The owner's WhatsApp number, which is the login — there is no password.
- The shop's name, country, currency, time zone and trading settings.
- Bank account details and a payment QR image, because the bot sends them to customers as payment instructions.
- The product catalogue: names, aliases, prices, units, stock.
- Additional staff phone numbers, where the shop has added any.
- An append-only audit log of decisions that move money or change access — payment approvals, rejections, plan changes, suspensions, logins.
From a shop's customers
- The WhatsApp phone number, and the profile name WhatsApp supplies.
- The content of messages sent to and from the shop's number, including images and documents.
- Orders, order lines, quantities, prices and totals.
- Delivery addresses, stored so a returning customer is never asked twice.
- Payment records, and the receipt image or PDF sent as proof of payment.
- Invoices issued for those orders.
- Whether the customer has opted out of messages.
We do not ask for, and have no use for, identity documents, dates of birth, government identifiers or card numbers. A customer who sends one anyway has sent it into a WhatsApp conversation, where it is stored as part of that conversation — tell us and we will remove it.
Where it comes from
Almost all of it arrives through the WhatsApp Business Platform, because a customer sent a message to the shop's number. The rest is typed into the dashboard by the shop, or given to us during onboarding.
We do not buy data, scrape it, or obtain contact lists from anywhere else. There is no way for a phone number to enter OrderAgent except by messaging a shop that uses it, or by a shop entering it.
Why we hold it
| What | Why |
|---|---|
| Phone number and profile name | To recognise a returning customer and address them by name |
| Message history | The order was made in it, and it is how a dispute about what was said gets settled |
| Orders, prices, totals | The record of the trade |
| Delivery address | So the shop can deliver, and so nobody is asked for it twice |
| Receipts and payment records | Proof of payment, and the duplicate-receipt checks depend on holding the earlier ones |
| Invoices | Financial records the shop is required to keep |
| Opt-out flag | So that STOP keeps working, permanently |
| Audit log | So a money decision can always be attributed afterwards |
We do not use any of it to build advertising profiles, and we do not sell it. There is no advertising in this product and no third party is paid for access to it.
Consent, and how to withdraw it
A customer's consent is given by messaging the shop's WhatsApp number for the purpose of ordering. That consent covers handling the conversation, the order, the payment and the delivery.
It is withdrawn by sending STOP to the shop's number. Nothing further is
sent to that number — not even a message explaining that nothing further will be
sent, because that would still be a message to somebody who asked for none.
START reinstates. Only an explicit START counts: tapping a button in an
older message does not re-consent on a customer's behalf.
Automated processing, and its limits
OrderAgent uses a language model in exactly two places:
- Reading an incoming message — deciding whether it is an order, a question, a payment claim or an acknowledgement, and which catalogue products it names.
- Reading an uploaded receipt — extracting the amount, date, reference and recipient from the image or PDF.
To do that, the message text or the receipt image is sent to Google's Gemini API along with the shop context needed to interpret it. It is not used to make a decision about a person, to score them, or to decide whether to serve them.
Two limits are worth stating plainly, because they are design decisions rather than promises:
- The model never supplies a value that reaches a customer. Prices, stock figures, totals, deadlines and amounts owed are read from the shop's own records. The model classifies and extracts; the code decides and writes.
- The model never approves money. A payment is marked paid by a person at the shop, every time, without exception. Automated receipt checking can only flag a receipt for review — it cannot settle an order.
No decision with a legal or similarly significant effect on anyone is made solely by automated means.
Who else processes it
We use a small number of providers to run the service. Each one only receives what its job needs.
Meta Platforms, Inc.WhatsApp Business Platform
GlobalCarries every message in both directions. Meta necessarily sees message content, phone numbers and profile names — this is the platform your customers are already using.
Google LLCGemini API
GlobalClassifies what an incoming message is asking for, and reads the amount, date and reference from an uploaded payment receipt. It receives the message text or the receipt image and the shop context needed to interpret it.
SupabaseManaged Postgres and object storage
Tokyo, Japan (ap-northeast-1)Stores the database and the receipt and invoice files. Receipt and invoice storage is private and is never reachable by an ordinary URL.
Vercel Inc.Application hosting
Tokyo, Japan (hnd1)Runs the service itself. Compute is placed in the same region as the database.
We do not add a provider to this list quietly — a change here is a change to this policy, and the effective date at the top of the page moves with it.
Where it is stored, and leaving the country
The database and the stored files are hosted in Tokyo, Japan. The service's compute runs in the same region.
That means personal data collected in Malaysia is transferred outside Malaysia and stored there. Message delivery through Meta and the model calls to Google are likewise not confined to any one country.
We say so rather than burying it, because under the Personal Data Protection Act 2010 a cross-border transfer is something you are entitled to know about before you agree to it. Using OrderAgent means accepting that your data — and the data of the customers who message you — is processed in and transferred to jurisdictions outside Malaysia.
Keeping shops apart
Every record in the system belongs to exactly one shop, and every query is filtered by which shop it is. The shop is taken from a verified session and never from anything in the address bar, so there is no URL to edit to see another shop's data.
Records that have no shop of their own — an order line, a payment — are only ever reached through the order they belong to, never directly by their own id.
Security
- Receipt images and invoice PDFs are stored in private storage and are never reachable by an ordinary URL. The dashboard mints a short-lived signed link per view, and refuses to sign a path outside the viewing shop's own folder.
- Traffic is encrypted in transit. Our database and storage providers encrypt data at rest.
- There are no passwords to steal. A shop signs in by asking the bot for a link that is sent to the owner's own WhatsApp number, expires in fifteen minutes and can be used once.
- Money decisions are restricted to the owner. Staff accounts can move an order through packing and delivery but cannot mark anything paid.
- Access we take for support is recorded in a log the code can only append to — there is no path in the software that edits or deletes an entry.
No system is impossible to breach, and we will not claim certifications we do not hold. If a breach affects your data we will tell you what happened, what was reached, and when.
How long we keep it
- Financial records — orders, payments and invoices — are kept for 7 years. They are the shop's tax records, and the shop is required to be able to produce them.
- Conversations, addresses and receipt images are kept while the shop's account is open, because they are what the order history and the duplicate checks are built on.
- Login links expire after fifteen minutes and are single-use.
- A closed account's data is deleted within 30 days of closure, apart from the financial records above.
Your rights
Under the Personal Data Protection Act 2010 you may ask to:
- access the personal data we hold about you;
- correct it where it is wrong or out of date;
- withdraw consent to further processing;
- limit processing for direct marketing — which for a customer is what
STOPdoes immediately, without asking anyone.
Write to us and we will respond within 21 working days. If you are a shop's customer, ask the shop first: they hold the relationship with you, and we act on their instruction. Where a request reaches us directly we verify it with the shop before acting, for the reason given at the top of this page.
Deletion has its own page, because the answer is longer than "yes": see data deletion.
Children
OrderAgent is a tool for businesses and is not directed at children. We do not knowingly hold data about anyone under 18. If a shop's customer is under 18 and their data is here, tell us and we will remove it.
Changes to this policy
When this policy changes materially, the effective date at the top of the page moves and shops are told through the product. Continuing to use OrderAgent after that date means the new version applies.
We do not silently rewrite an old version — a change to what we do with data is worth announcing, and a policy that changes without notice is not a policy.
Questions about this page
Write to hello@orderagent.io. If you are a customer of a shop that uses OrderAgent, that shop is the first place to ask — they hold the relationship with you, and we act on their instructions.

