The Qadam Technology / Privacy policy
Privacy policy
How Qadam handles business, customer, and connected-channel information.
Last updated: 7 October 2026 · Draft pending operational review
Who this policy covers
The Qadam Technology (“Qadam”, “we”, “us”) provides business management software for store owners and their authorized staff. This policy describes information processed through our website, web and mobile applications, and supported Meta business integrations. When a store uses Qadam to manage its customers, the store decides why customer information is used; Qadam processes that information to provide the store’s service. Please contact the store directly about its own sales, marketing, or customer records.
Information we process
- Account and business information: names, email addresses, contact numbers, business profiles, staff roles, and account identifiers.
- Commerce information: products, variants, inventory, customer contact and delivery details, order drafts, orders, and payment or fulfillment status. Do not send card passwords or full payment card details in messages.
- Meta integration information: authorized business, Page, Instagram, WhatsApp account and phone-number identifiers, permission and connection status, access credentials, sender identifiers, message identifiers, timestamps, and delivery events, depending on the connected channel and permissions granted.
- Customer messages: message content received through enabled integrations is processed to understand enquiries and extract order intent. The current WhatsApp processing design avoids keeping raw inbound message text and webhook payloads in the conversation and draft database tables; structured order details, metadata, and outgoing message records may remain.
- Technical information: application errors, security and access logs, browser or device information, and hosting request data needed to operate and protect the service.
How we use information
We use information to provide account access, operate business workspaces, maintain catalogs and inventory, manage orders, process customer requests, send authorized service messages, support users, diagnose failures, and prevent abuse. We process information under the store’s instructions where applicable. Depending on the activity and applicable law, processing may rely on providing a requested service, consent for optional connections, legal obligations, or legitimate interests in operating and securing the service.
WhatsApp, Instagram and Facebook
Stores choose which eligible Meta business accounts to connect and authorize the permissions needed for the enabled features. We use the information received through those permissions to support the connected business’s messaging and order workflows. We do not ask for personal WhatsApp, Facebook, or Instagram passwords. Connecting a channel does not give us unrestricted access to a person’s private accounts. Disconnecting or revoking permissions stops future authorized access, but does not automatically remove previously created business records. See our data deletion instructions. Meta independently processes information under its own privacy policy and WhatsApp privacy policy.
AI-assisted processing
When AI features are enabled, customer message text is sent to the configured AI service provider, currently OpenAI, to extract structured information such as product choices, quantities, and order intent. Extracted details may contain personal information. Qadam uses these results within the business workflow and validates catalog information; AI results can be incorrect and may need owner review. Provider handling and retention are governed by the applicable provider agreement and configuration. This policy does not promise zero provider retention or that all processing happens on your device.
Retention and security
We retain account, commerce, and integration information for as long as needed to provide the service and meet applicable accounting, legal, security, and dispute-resolution requirements. Actual retention depends on the record type, the store’s instructions, and applicable obligations; no universal deletion period is stated here. Raw inbound WhatsApp text is processed transiently by the current application design, but this does not mean structured records, provider copies, logs, or backups are immediately erased. We use access controls and business-scoped authorization to restrict access. No system can guarantee absolute security. Revoking a connection and deleting stored data are separate actions.
Your choices and data deletion
You may request access, correction, deletion, or other rights available under applicable law. Store customers should first contact the store they interacted with so the relevant records can be located. Account holders can revoke connected app permissions through Meta and request removal of Qadam-held data using our data deletion instructions. We may need to verify identity or account authority before acting. Some records may need to be retained to meet legal obligations; we will explain applicable limits when handling the request.
Contact and policy updates
We may update this policy as the service changes. The effective date at the top of this page identifies the latest version. Material changes will be communicated as required.