Legal
Privacy Policy
Last updated 7 October 2026.
This policy explains how AVROQ (Pty) Ltd (registration number 2026/735641/07), trading as Qelo (“we”, “us”), handles personal information processed through Qelo Connect at this domain. We are based in South Africa and follow the Protection of Personal Information Act, 2013 (POPIA).
Who is responsible for what
For the people who sign in to Qelo Connect, we decide how their account details are used, so we are the responsible party. For the contacts a business uploads and messages, the business is the responsible party and we act as its operator: we process that information only on the business’s instructions, to deliver the service described in our Terms of Service.
What we collect
- Account details — the name, email address and password (stored only as a salted hash) of each person who signs in, and the business workspace they belong to.
- Contacts a business uploads — the names and WhatsApp numbers of the business’s own customers, any tags or notes the business adds, and a record of whether and how each of them agreed to receive messages. This data belongs to the business that uploaded it; we process it only to deliver the messages that business sends.
- WhatsApp Business Account details — when a business administrator connects a WhatsApp Business Account through Meta’s Embedded Signup, we store the business name, WhatsApp Business Account ID, phone number ID and displayed phone number, together with an access token that Meta issues for the assets the administrator explicitly shared.
- Shopify store data — when a business connects its Shopify store, we read (never write) its customers’ names, phone numbers, tags, whether they have ordered and whether they agreed to SMS marketing, plus a short list of its published products. Customers arrive as contacts the business has not yet asked; Shopify’s SMS consent is not treated as agreement to WhatsApp messages. We store the access token Shopify issues, encrypted. When a customer asks the store to erase them, or the store removes Qelo Connect, we delete what came from Shopify as Shopify requires.
- Billing details — when a business pays for a plan by card: the email address of the person who paid, the references Paystack gives the customer and the subscription, the card’s brand and last four digits, and the payments made (dates, amounts and whether they succeeded). The card number is entered on Paystack’s payment page and held by Paystack; it never reaches us and we do not store it.
- Messages — the messages a business sends through Qelo Connect, replies its customers send back, and delivery statuses.
- Webhook events — notifications Meta delivers about connected accounts (message statuses, incoming replies, template review outcomes, account updates).
- Technical data — IP addresses used briefly to limit repeated sign-in attempts, and error reports when something breaks.
How we use it
Only to provide the service: connecting WhatsApp Business Accounts, sending the messages a business initiates, managing its message templates and contact lists, showing delivery status and replies, and keeping the service secure. We do not sell personal information and we do not use it for advertising. The one exception to “only” is the AI model described below.
AI drafting and the assistant
Writing a template with “Describe it” and chatting with the assistant on the dashboard both send what you type to Meta’s Muse Spark model through the Meta Model API. That includes your description of the message, any photo you attach, the drafts the model writes, your first name, and the workspace details the assistant looks up to answer you: your business name and WhatsApp number, your template and promotion names, and your contact tag names with how many contacts carry each.
We use Muse Spark’s contributor tier. On that tier Meta may use these prompts and replies to train and improve its AI models. Qelo does not send your customers’ names or phone numbers to the model, though anything you type yourself is sent as you wrote it. Nothing reaches the model unless you use one of these two features, so if you would rather your content not be used this way, write your templates by hand and don’t use the assistant.
Service providers
We use these providers to run the service, each only for the purpose listed. We do not share personal information with anyone else.
- Meta Platforms — delivers WhatsApp messages and operates the WhatsApp Business Platform.
- Vercel — hosts the application.
- Neon — hosts the database.
- Resend — sends account emails (confirmations, password resets, invitations, notifications).
- Upstash — stores short-lived counters that limit repeated requests.
- Sentry — receives error reports so we can fix faults.
- Paystack — processes card payments for paid plans and holds the card. We send it the payer’s email address and the workspace’s ID and plan; the card details are entered on Paystack’s own page.
- Meta (Muse Spark, through the Meta Model API) — generates message drafts and assistant replies, as described under “AI drafting and the assistant” above.
Some of these providers store or process data outside South Africa. We use providers that are bound by data-protection terms offering protection comparable to POPIA, as section 72 of POPIA requires.
Storage and security
Access tokens are encrypted at rest and passwords are stored only as salted hashes. Each business has its own workspace, and every request is checked against the signed-in user’s membership of that workspace — one business cannot see another’s numbers, contacts or messages.
How long we keep it
We keep account and workspace data for as long as the workspace is open. Raw webhook events are deleted 30 days after they are processed and passed on; payment notifications from Paystack after 180 days. Records of payments are kept for as long as tax and accounting law requires. When a workspace is closed or a deletion is requested, we delete the data within 30 days, except where the law requires us to keep a record for longer. A record that someone asked a business to stop messaging them is kept while the business’s workspace exists, so they are not messaged again by mistake.
Your rights
You may ask for access to, correction of, or deletion of your personal information, and object to its processing — see the data deletion page, or email our Information Officer at support@qelo.co.za. If you are a customer of a business that uses Qelo Connect, contact that business first; we will help it respond. You may also complain to the Information Regulator of South Africa (inforegulator.org.za).