Banowi is operated by Banowi, registered at 866 D Central Park Housing Scheme, Lahore, Pakistan. Questions about this policy or about data we hold can be sent to hello@banowi.com.
Who this policy is for
Banowi is a business-to-business platform. Our customers are merchants who run online stores. Those merchants use Banowi to talk to their customers on WhatsApp.
For data about a merchant's own account, we are the controller. For the conversations a merchant has with their customers, the merchant is the controller and we act as their processor, handling that data only to provide the service they have asked us for.
What we collect
From merchants: name, email address, password hash, and the organisation and store they belong to.
From Meta, when a merchant connects their WhatsApp Business Account: an access token, the WhatsApp Business Account and phone number identifiers, the display number and verified name, and the public profile name and picture of the person who authorised the connection, so the merchant can see whose access the connection depends on.
From the merchant's customers, through WhatsApp: the phone number that messaged the business, message content, and any media sent — most often a payment receipt.
From Shopify, when a merchant connects a store: products, inventory, orders and customer records, so answers can be grounded in real data.
What we do with it
We deliver incoming messages to the merchant's inbox, generate and send replies on the merchant's own WhatsApp business number, match payment receipts to open orders, and produce the analytics a merchant sees about their own conversations.
We do not sell merchant or customer data. We do not use it for advertising, and we do not use it to build products for anyone other than the merchant it belongs to.
Who else processes it
We use a small number of service providers, each acting on our instructions and under contract:
- Railway Corporation (Singapore, United States) — application hosting, PostgreSQL and Redis.
- Cloudflare, Inc. (United States) — object storage for media received through WhatsApp.
- Vercel Inc. (United States) — hosting for the merchant dashboard.
- OpenAI, L.L.C. (United States) — language classification, voice-note transcription and reply generation. Message text and voice notes are sent; access tokens and credentials never are.
Because these providers operate outside Pakistan, providing the service involves transferring data internationally.
How it is protected
WhatsApp access tokens are encrypted at rest with AES-256-GCM before they are stored, and are decrypted only in memory for the duration of a request. Every query is scoped to a single merchant, so one merchant's data is never returned to another. Access to production systems is limited to people who need it to operate the service.
How long we keep it
Conversations, customers and orders are retained for as long as the merchant's account is active, because they are the merchant's working record. A merchant can disconnect their WhatsApp Business Account at any time from the dashboard, which immediately deletes the stored access token and ends our access to their account at Meta.
On request to the contact address above, we will delete a merchant's account and the data held for it. Where a merchant's own customer asks us directly, we will pass the request to the merchant, who is the controller of that data.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete personal data we hold about you, and to object to or restrict how it is used. Write to the contact address above and we will respond.
Changes
If this policy changes materially, we will update the date at the top of this page and notify merchants through the dashboard before the change takes effect.