Skip to main content

Privacy Policy

Privacy Policy for EightyFive Development covering WhatWali, CodShield, SellableHQ, Kountli, and our website. UK GDPR compliant.

Last Updated: July 28, 2026

1. Introduction

EightyFive Development ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit eightyfive.cloud, use our Shopify Applications (WhatWali, CodShield, SellableHQ, and Kountli when available), use our Shopify Themes, or engage our agency services.

We operate under the Data Protection Act 2018 and the UK GDPR. For Shopify Apps, the merchant is typically the controller of customer personal data and we act as a processor to provide the Service. Merchants remain responsible for providing appropriate notices to their customers.

App-specific privacy pages also publish product detail where available: CodShield Privacy · SellableHQ Privacy. This page is the master policy for EightyFive Development and covers all Apps.

2. Information We Collect

A. Information You Provide Directly

  • Identity & Contact: Name, email, telephone, billing or company address.
  • Support: Messages and attachments you send about WhatWali, CodShield, SellableHQ, Kountli, themes, or custom work (email and, where offered, WhatsApp support).
  • Payments: Subscription and invoice data via Shopify Billing or other processors. We do not store full payment card numbers.
  • Website forms: Contact, newsletter, and related submissions on eightyfive.cloud.

B. Common Shopify App Data (All Apps)

  • Store: Shop name, myshopify.com domain, shop ID, plan, locale, currency.
  • Auth: OAuth access tokens / offline tokens required to operate the App; Shopify staff session fields (e.g. name, email, user ID) where provided by Shopify.
  • Billing: Plan, trial, subscription/charge IDs via Shopify Billing.
  • Usage: Feature usage, limits, and operational logs needed to run and secure the Service.

C. WhatWali

WhatWali automates WhatsApp messaging for Shopify. We process the following on your behalf:

  • Merchant WhatsApp connection: Linked-device / QR connection metadata and technical session credentials needed to keep your WhatsApp number connected (including related connection services we operate).
  • Customer & order data: Phone numbers, names where available, order/checkout/draft IDs, product/variant details for stock alerts, and related Shopify Admin data within granted scopes (orders, checkouts, customers, drafts, fulfillments, inventory, products).
  • Messaging: Outbound automation message content and recipient numbers (e.g. order confirmations, cart recovery, cancellations, fulfillments, back-in-stock, bank-deposit instructions, auto-replies); poll/list reply records where used.
  • Inbox: Live chat UI may keep conversation history in the merchant browser (IndexedDB). Server-side message logs for automations are retained for a short operational window (typically purged on a rolling short-day schedule).
  • Settings: Templates, tags, delays, journeys, and related configuration.

D. CodShield

CodShield confirms COD after checkout and scores orders in an approval queue. We process:

  • Customer phones used for post-order WhatsApp COD confirmation (YES/NO).
  • Delivery / address details from orders (including notes, city, province, and shipping address fields needed for risk and messaging).
  • Order values, risk scores, verification/approval status, payment-method and related workflow markers.
  • Courier RTO history imported by the merchant via CSV, and merchant phone blacklist entries used in scoring.
  • Deposit proof files uploaded to the merchant’s Shopify Files (file IDs/references stored by the App).
  • WhatsApp connection metadata for the merchant’s linked number (QR / Linked devices). Messages are sent from the merchant’s own WhatsApp number, not a shared CodShield platform number. Merchants are responsible for WhatsApp Business terms for their number.
  • Checkout COD tier inputs (allow / confirm / deposit / hide COD, phone validation, fee labels) configured by the merchant.
  • Optional OTP challenges (hashed codes + phone) only if that feature is enabled.

E. SellableHQ

SellableHQ is Channel ATS for Shopify wholesale + DTC. It processes merchant store / inventory data to compute and publish available-to-sell:

  • Shop domain and offline access token (hosted/encrypted at rest by our infrastructure).
  • Products, variants, SKUs, titles, images, tags, vendors, collections.
  • Locations and roles (e.g. shared, online, wholesale).
  • Inventory quantities and states including on hand, committed, available, reserved (wholesale protection), safety_stock (online cushion), quality control, damaged, incoming, and app ledger history (holds, rules, movements, mismatches, publish jobs, audit events).
  • Order IDs and B2B vs DTC channel signals — SellableHQ does not retain customer personal information for ATS operations beyond what Shopify may send in mandatory compliance webhooks.
  • Alert destinations you configure (email and/or Slack webhook URL) and Pro ATS API keys for read-only ERP/BI access.
  • Billing plan status via Shopify Billing; a billing ledger entry (shop domain + trial-used flag) may survive uninstall so a free trial cannot be reused.

F. Kountli (when available)

Store analytics and reporting data (orders, visits, and related metrics) as needed to provide dashboards and reports when the product is available to your store.

3. How We Use Information

  • Provide the Services: Operate WhatWali messaging, CodShield COD workflows, SellableHQ Channel ATS publishing, themes, and the website.
  • WhatWali: Send automations, recover carts, stock alerts, Flow actions, and inbox support.
  • CodShield: Send COD confirmation and deposit instructions from your WhatsApp number; score risk; enforce checkout tiers; support approve/cancel.
  • SellableHQ: Compute policies, holds, cushions, QC, reconcile mismatches, publish Online/wholesale ATS on Shopify, and send alerts.
  • Billing & support: Process subscriptions and resolve tickets.
  • Security & improvement: Prevent abuse, debug, and improve product quality.
  • Legal: Meet tax, accounting, and regulatory duties.

We do not sell personal data or merchant customer data.

4. Legal Bases (UK GDPR)

  • Contract: To provide the App/Theme/service you installed or purchased.
  • Legitimate interests: Product improvement, security, and fraud/abuse prevention (balanced against your rights).
  • Legal obligation: Tax and regulatory requirements.
  • Consent: Where required (e.g. certain marketing emails), which you may withdraw.

5. Sharing & Subprocessors

  • Shopify: Admin API, Billing, Files (CodShield deposit proofs), inventory state writes (SellableHQ), and mandatory GDPR compliance webhooks.
  • WhatsApp / Meta: For WhatWali and CodShield, message content and metadata are transmitted via WhatsApp from the merchant-linked number (Linked devices / WhatsApp Web–style connection—not a shared EightyFive business number). You must comply with WhatsApp’s terms for your number.
  • Hosting & databases: Application hosting and PostgreSQL (and related services such as Redis where used) on infrastructure we operate or procure (including cloud VPS / Coolify deployments under *.eightyfive.cloud).
  • Email providers (e.g. Resend) for transactional and alert email.
  • Slack: Only if you configure a Slack webhook in SellableHQ (or similar).
  • Your systems: SellableHQ Pro ATS API disclosures to ERP/BI tools you authorize.
  • Legal authorities: When required by law or to protect our rights.

6. International Transfers

We are based in the United Kingdom. Hosting or subprocessors may process data outside the UK/EEA. Where we transfer personal data internationally, we use appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

7. Retention, Uninstall & Shopify GDPR Webhooks

We retain data only as long as needed to provide the Services and meet legal duties. Shopify Apps honour mandatory compliance webhooks:

  • customers/data_request — We prepare or acknowledge exports of personal data we hold for the requested customer (CodShield stores temporary export snapshots in shop settings for merchant retrieval, capped at recent exports).
  • customers/redact — We delete or anonymise customer PII we store (e.g. WhatWali message logs / stock alerts / poll records by phone or order; CodShield order PII, verification attempts, blacklist/phone history, and Shopify Files proofs when a store session is available). SellableHQ acknowledges customer redact as it does not retain customer PII tables for ATS.
  • shop/redact — We delete shop installation data after uninstall (typically when Shopify sends shop/redact, often around 48 hours after uninstall for CodShield-style flows).

App-specific uninstall behaviour:

  • WhatWali: WhatsApp connection is disconnected and session material purged promptly on uninstall; remaining store/customer PII is removed on shop/redact. Limited usage metrics may be retained for abuse prevention.
  • CodShield: OAuth sessions and WhatsApp connection are removed promptly on uninstall; shop data is deleted on shop/redact.
  • SellableHQ: Before deleting app data on uninstall / shop/redact, wholesale reserved and DTC safety_stock holds are released back to available so stock is not stranded. If release fails, data is retained until Shopify retries succeed. A billing/trial ledger entry for the shop domain may survive.

8. Your Rights

Under UK GDPR you may have rights of access, correction, erasure, objection, restriction, and portability. Contact support@eightyfive.cloud (or cs@eightyfive.cloud for product support). We aim to respond within one month. Merchants should also use Shopify’s compliance tools for customer requests relating to store data.

9. Cookies

  • Essential: Sessions and security for the website and admin tooling.
  • Analytics: Optional analytics to understand site usage.

You can refuse non-essential cookies in your browser; some features may not work without essential cookies.

10. Third-Party Links

Our Services may link to Shopify, WhatsApp, App Store listings, and other third parties. Their privacy practices are governed by their own policies.

11. Changes

We may update this Policy by posting a revised version and changing the “Last Updated” date. Material App-specific changes may also be reflected on CodShield and SellableHQ privacy pages.

12. Contact

EightyFive Development
London, United Kingdom

  • General / privacy: support@eightyfive.cloud
  • Product support (WhatWali, CodShield, etc.): cs@eightyfive.cloud