1. Who we are and what this policy covers
2sra3 (“2sra3”, “we”, “us”) is a WhatsApp ordering system for online stores, service providers and other businesses. A business (a “merchant”) connects its WhatsApp number to 2sra3; our software then answers the merchant’s customers, shows them an online store page, takes their orders and keeps them updated in WhatsApp. Merchants and their team manage everything in the 2sra3 mobile app (Android, package com.sra3.merchant) and in the merchant web app at app.2sra3.com.
This policy covers three groups of people:
- Merchants and their team members (owners, admins, staff) who create a 2sra3 account.
- Customers of a merchant, who message a merchant on WhatsApp or order from the merchant’s store page. They do not need an app, an account or a password.
- Visitors of 2sra3.com and of store pages.
Our role. For the merchant and team-member account data, and for running and securing the service, 2sra3 decides how the data is used (we are the “controller”). For the data a merchant’s customers send to that merchant (their orders, contact details, addresses and messages), the merchant decides why and how it is used and 2sra3 processes it on the merchant’s behalf (we are the “processor”). If you are a customer and want to see, correct or delete data a store holds about you, ask the store first; you can also ask us (section 12) and we will help.
Contact: see section 14. 2sra3 is an independent service. It is not affiliated with, endorsed by or sponsored by WhatsApp or Meta.
2. The data we collect
2.1 Merchant and team-member accounts
- Full name, email address and, if you give one, phone number.
- Your password, which we keep only as a one-way (bcrypt) hash. We cannot read it.
- Your role and which merchant workspace(s) you belong to; invitations you send or accept; your sign-in sessions.
- Email verification and password-reset codes (short-lived).
- Your app language and notification preferences.
2.2 The business workspace
- Business name, business type, contact phone number, logo, working hours, welcome and automatic messages, and settings.
- Catalog: categories, products or services, descriptions, prices, options, and the photos you upload. Optionally a guide or price-list file that is sent to new customers.
- Payment methods you offer your customers (for example the title and the transfer details you choose to show), and delivery or branch settings.
- Team members and, if you use the delivery feature, delivery agents (name and WhatsApp number).
- Optional webhooks you configure (a web address of your own that receives order events).
- If you use the optional catalog import, the PDF or photo of your menu or price list that you upload, and the catalog extracted from it.
2.3 Subscription records
- Your plan, trial and renewal dates, and when you ask to subscribe or renew: the payment transfer reference you type and the photo of the transfer receipt you attach, plus our review decision. We do not take card payments in the app and we never see your card or bank login.
2.4 A merchant’s customers
Collected when a customer messages a merchant’s WhatsApp number or uses the merchant’s store page:
- WhatsApp number or WhatsApp identifier of the customer (for some accounts WhatsApp shows a privacy identifier instead of a number), and the name they give.
- A contact phone number the customer chooses to give (one tap can copy their WhatsApp number).
- Delivery address or pickup choice, an optional map location pin, and the address text they type.
- Their orders: items, quantities, notes, totals, status, the payment method they choose, and any rating they give.
- Text replies and comments they send about an order; these are saved on the order so the merchant can read them. Images they send (for example a payment-transfer receipt) are saved with the order. Images sent in chat that the flow does not need are held only for a short staging period (section 8).
- Voice messages, stickers and similar non-text messages are not transcribed or analysed; the bot treats them as a message that it cannot read.
- When a customer registers on the store page: the same name, phone number and address details, and a sign-in token that stays in that browser (local storage) so they do not have to register again. Registering can optionally verify that the customer owns their WhatsApp number through a short code exchanged in WhatsApp.
2.5 The connected WhatsApp number
To act as the merchant’s assistant, 2sra3 keeps a linked-device session for the merchant’s WhatsApp number. After the merchant scans a QR code, the session credentials are stored in our database so the connection can continue without scanning again. Our systems receive one-to-one messages that reach the number (not group chats, broadcasts or status updates). They also see one-to-one messages the merchant sends from the phone, only to coordinate automatic replies. Messages that are not part of an order flow are not kept as a message archive; we keep a short-lived marker that a message was already handled (about 48 hours) so nothing is processed twice.
2.6 Device and usage data
- Push notification token and device type (Android or iOS) when you allow notifications in the mobile app. Notifications are delivered through Google Firebase Cloud Messaging (and Apple’s service on iOS).
- Technical logs of our servers: request times, error details and IP addresses as received by our cloud services. We use them to keep the service running and secure.
- Usage counters per merchant and month (for example how many messages were handled), for plan limits and billing.
2.7 What we do not collect
- The mobile app does not contain third-party analytics, advertising or crash-reporting SDKs.
- The Android app does not request access to your device location, contacts, microphone or camera. Photos and files are chosen through the system picker and only the ones you select are uploaded.
- We do not sell personal data and we do not use it to build advertising profiles.
3. Why we use data and our legal bases
Where data protection law (such as the GDPR) requires a legal basis, these are ours:
- Provide the service you asked for (create and secure your account, run your store and bot, take and track orders, send WhatsApp, push and email updates, support you). Basis: performing our contract with you. For customers’ data, we do this as the merchant’s processor under the merchant’s instructions; the merchant’s basis is usually performing the order the customer placed.
- Subscriptions (review a transfer receipt, activate, renew, remind you before expiry) and keep the records we need. Basis: contract and our legal and accounting obligations.
- Security, abuse and fraud prevention, reliability and support (rate limits, logs, diagnosing faults). Basis: our legitimate interest in running a safe and dependable service.
- Service emails and notifications (verification codes, password resets, new-order and subscription alerts). Basis: contract. Push notifications also need the permission you give in your device settings, which you can withdraw at any time.
- Optional catalog import (analysing a menu or price list you upload). Basis: contract, and only when you choose to use it.
- Ads on store pages (section 7). Basis: legitimate interests, or consent where the law requires consent for the cookies or identifiers Google uses.
- Legal obligations and legal claims. Basis: legal obligation or legitimate interest.
We do not make decisions about people that have legal or similarly significant effects by purely automated means. The ordering bot follows rules the merchant configures; the optional catalog import only drafts a catalog that the merchant reviews.
4. WhatsApp
2sra3 connects to WhatsApp by linking a device to the merchant’s own number (the same way WhatsApp Web works). WhatsApp has its own privacy policy and terms, which apply to your use of WhatsApp. Messages travel through WhatsApp’s servers, and WhatsApp and Meta handle that data under their own policies, not ours. A merchant should only connect a number they own and should tell their customers that an automated assistant answers on that number. We are not responsible for how WhatsApp or Meta treat your data.
6. Browser and device storage
We do not use advertising or analytics trackers of our own. The merchant web app and the mobile app keep your sign-in session in the browser’s local storage or in the device’s secure storage so you stay signed in. A store page keeps the customer’s sign-in token for that store in the browser’s local storage. Clearing your browser data or signing out removes them. Google’s ad script, where it runs (section 7), may use its own cookies or identifiers.
7. Ads (Google AdSense)
The public store pages on merchant.2sra3.com can show one Google AdSense banner at the very end of the store’s home page. It does not appear on cart, checkout, registration or order screens, or inside the merchant app or dashboard. This website (2sra3.com) also loads Google’s AdSense script. Google decides which ads to show and may use cookies, device identifiers and your IP address to show and measure ads, including personalised ads where allowed. We do not give Google the names, phone numbers, addresses or orders of customers. See how Google uses information from sites that use its services and manage ad personalisation at adssettings.google.com. Most ad blockers and browser privacy settings stop it, and 2sra3 keeps working normally when the ad is blocked.
8. How long we keep data
- Account and workspace data (accounts, business profile, catalog and photos, orders, customer records, comments, receipts): kept while the account and workspace are active, and permanently deleted when the account or workspace is deleted (see how to delete your account).
- Conversation state (where a customer is in the ordering flow): automatically removed after about 48 hours without activity.
- “Message already handled” markers: about 48 hours.
- Images staged from chat before they are needed: automatically deleted after 7 days. An image that becomes part of an order (for example a payment receipt) stays with the order.
- Monthly usage counters: about 400 days.
- Server logs: about 30 days.
- Backups: our database keeps point-in-time backups for up to 35 days. Deleted data leaves backups as they age out; backups are not used for anything else.
- Records we must keep for legal, tax, security or fraud-prevention reasons are kept only as long as needed.
- WhatsApp connection credentials are removed when the workspace is deleted. A merchant can also unlink 2sra3 at any time from WhatsApp on their phone (Settings → Linked devices).
Data already delivered to a merchant (for example on an order) is under that merchant’s control and their own retention choices.
9. Security
All traffic between your device and 2sra3 uses HTTPS. Data is stored in AWS services that encrypt data at rest, and file storage is private and reachable only through short-lived signed links. Access between customers’ workspaces is separated by merchant, passwords are stored only as bcrypt hashes, and sign-in sessions expire. No system is perfectly secure; if we learn of a breach that affects you we will tell you and the authorities as the law requires. To protect your account, use a strong, unique password and sign out of shared devices.
10. Where data is processed (international transfers)
Our main servers are in the United States (AWS US East, N. Virginia). If you use 2sra3 from another country, your data is transferred to, and processed in, the United States and in the countries where our service providers (section 5.2) operate. Where the law requires safeguards for such transfers, we rely on the contractual protections our providers offer, such as the standard contractual clauses in their data processing terms.
11. Children
2sra3 is a business tool and is not directed to children. Merchant accounts are for adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us (section 14) and we will delete it.
12. Your choices and rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, withdraw consent you gave, and complain to your data protection authority. In practice:
- Merchants and team members can edit their profile, business details and catalog in the app, and can delete the account and its data themselves: Settings → Profile → Delete account in the mobile app or at app.2sra3.com. Full instructions: how to delete your account.
- Customers of a store can ask the store to correct or delete their data, or ask us using section 14. We will verify that the request comes from the owner of the number or the email before we act.
- Notifications: turn push notifications off in your device settings or in Settings → Notifications in the app.
- Ads: see section 7.
We answer requests within 30 days. We may ask you to prove who you are so we do not give your data to someone else.
13. Changes to this policy
If we change what we collect or how we use it, we will update this page and its “Last updated” date, and for important changes we will also tell merchants in the app or by email. The current version is always at https://2sra3.com/en/privacy/.
14. Contact us
For any privacy question or request, including customers of a store and people who cannot sign in:
- Email: [email protected]
- WhatsApp support: +34 675 786 406
When you write, include the email address or WhatsApp number your request is about, so we can find it.