WhatsApp & Meta compliance

Ordro is an ordering tool for small businesses built on the WhatsApp Business Platform. This page sets out exactly what we send, what we store, and how anyone can stop it.

How a business connects a number

A merchant connects their own WhatsApp Business Account through Meta's Embedded Signup. Ordro never asks for a WhatsApp password and never logs in as the merchant. The access token we receive is encrypted at rest with AES-256-GCM and is used only to send and receive that merchant's messages. Disconnecting from Shop settings deletes the token immediately.

What Ordro sends, and nothing else

  • A greeting when a customer first messages the shop, at most once in a window the merchant sets.
  • An order confirmation when that customer places an order.
  • One message per order status change: confirmed, being prepared, on its way, ready, completed, cancelled.
  • A request for a location pin after a delivery order that arrived without one.
  • An optional follow-up after an order, if the merchant switches it on.
  • A six-digit code when someone asks to see their own order history.

Every one of these follows something the customer did. Ordro sends no marketing, no broadcasts and no bulk messages, and gives merchants no way to send them.

The 24-hour window

Messages are sent inside the customer service window opened by the customer's own message or order. When that window has closed, WhatsApp only permits an approved template; Ordro records that the update could not be delivered and shows the merchant plainly, rather than sending anything outside the rules.

Opting out

A customer can reply STOP to any Ordro message to stop automated messages from that shop, or tap “Talk to a person”, which stops them for several hours and alerts the merchant. Neither affects their ability to place an order or talk to the shop directly.

What we store, and for how long

  • Phone number in E.164 form, plus a name if the customer gives one.
  • Orders, their contents and their status history, kept while the shop has an account.
  • A log of messages Ordro sent or received, kept for 12 months.
  • Delivery addresses and location pins the customer chose to share.

We do not store message content from conversations the merchant has directly with a customer in their own WhatsApp app. Ordro is not an inbox.

Who can see what

A merchant sees only their own shop's customers and orders. The existence of a customer's orders at any other shop is never exposed to a merchant, including as a count. A customer can see their own history across shops after verifying their phone with a code.

Security

Access tokens, Stripe keys and linked-device credentials are encrypted at rest with AES-256-GCM. Every inbound webhook is verified against the Meta app secret with a timing-safe comparison before it is processed, and each business account is routed to its own webhook URL so one merchant's messages can never reach another.

Contact