01
Who we are
Shazi (“Shazi”, “we”, “us”) is a software service operating from Kenya at shazi.app. We are reachable at hello@shazi.app.
We wear two different hats, and which one we are wearing changes who is answerable for your data:
- When you chat with a business on WhatsApp, that business decides what to do with your details. It is the data controller. Shazi only runs the software on its behalf, which makes us the data processor. We act on that business’s instructions and do not use your chats for our own purposes.
- When a business owner signs up for a Shazi account, we are the data controller for that account holder’s own details.
If you want a business to delete what it holds about you, contact that business first. If you cannot reach them, write to us and we will help.
02
What we collect
When you message a business running on Shazi
- Your WhatsApp phone number — this is how the business knows who is ordering and how it replies to you.
- Your WhatsApp profile name, as WhatsApp supplies it, so staff can greet you properly.
- The messages you send to that business number, including the menu choices and buttons you tap, so the conversation can continue where it left off.
- Order and booking details — what you ordered, how many, the price, and where relevant a pickup or delivery address and preferred date, so the business can actually fulfil the job.
- Timestamps and message identifiers, which we use to keep the conversation in order and to avoid processing the same message twice.
When you hold a Shazi dashboard account
- Your name and email address.
- A scrambled version of your password. We never store the password itself and cannot read it.
- Your business details — trading name, currency, services and prices, and the identifiers Meta issues for your WhatsApp number.
Technical information
- Ordinary server logs generated when you use the dashboard, such as the request made and the time it happened. These help us keep the service running and spot abuse.
03
What we never collect
It is worth being explicit about the things people worry about most.
- We cannot read your other WhatsApp chats. We only ever see messages sent directly to a business number running on Shazi. Your private conversations are invisible to us.
- We do not store card or bank details. Shazi does not process card payments.
- We do not track you around the web and we do not run advertising trackers on this site.
- We do not sell, rent or trade personal data. Not to advertisers, not to data brokers, not to anyone.
- We do not collect your precise device location. If an address is recorded, it is because you typed it into the chat.
04
How we use it
We use personal data for these purposes and no others:
- To carry your conversation with a business — understanding what you asked for and replying with the right answer.
- To create and manage your orders and bookings, and to send you updates about them, such as a confirmation or a note that a rider is on the way.
- To show the business owner their own orders, customers and takings in the dashboard.
- To keep the service secure and reliable — verifying that incoming messages genuinely came from WhatsApp, preventing duplicates, and investigating faults.
- To meet legal and tax obligations where a business is required to keep records of what it sold.
We do not use your chats to build advertising profiles, and we do not use the contents of customer conversations to train artificial intelligence models.
05
Our legal basis
We handle personal data under the Data Protection Act, 2019 of Kenya. The grounds we rely on are:
- Performance of a contract — when you place an order or booking, we need your details to deliver it.
- Consent — you start the conversation by messaging the business, and you can stop at any time by saying so or by blocking the number.
- Legitimate interests — keeping the platform secure, preventing fraud and abuse, and fixing faults.
- Legal obligation — where the law requires records to be retained.
06
WhatsApp and Meta
Shazi is built on the WhatsApp Business Platform, which is operated by Meta. Every message between you and a business travels through Meta’s systems before it reaches us, and Meta handles that traffic under its own privacy policy and terms — we cannot change them on your behalf.
Two consequences worth knowing. First, WhatsApp’s standard end-to-end encryption protects a message in transit, but a message you send to a business is readable by that business once it arrives — that is the point of sending it. Second, Meta applies a 24-hour window for ordinary replies; outside it, a business may only reach you using message templates that Meta has approved in advance.
Shazi is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.
07
Where your data is stored
Our application and database run on a private server in a data centre in Germany, in the European Union. Data therefore leaves Kenya.
Section 48 of the Data Protection Act, 2019 permits such a transfer where there are appropriate safeguards or where the transfer is necessary to perform a contract with you. Germany is subject to the European Union’s General Data Protection Regulation, which provides protection comparable to Kenyan law. Data in transit is encrypted using HTTPS, and access to the server is restricted to named administrators using cryptographic keys.
09
How long we keep it
We do not keep personal data longer than it is useful for the purpose it was collected.
- Orders and bookings are kept while the business needs them for its records, and for as long as tax law requires.
- Conversation state — the working cart and where you had reached in a chat — is short-lived and cleared once the conversation ends.
- Dashboard accounts are kept while the account is open and removed after it is closed.
- Message identifiers, which carry no message content, are kept briefly so the same message is never processed twice.
When a business closes its Shazi account, its customer records are deleted along with it.
10
How we protect it
- All traffic to Shazi runs over HTTPS with certificates issued by a recognised authority.
- Every incoming webhook from Meta is cryptographically verified before we act on it, so forged messages are rejected.
- Passwords are stored only as one-way hashes and cannot be recovered, by us or anyone else.
- Each business’s data is isolated so it cannot be reached from another account.
- Server access is limited to named administrators using cryptographic keys rather than passwords.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, as the Act requires.
11
Your rights
Under the Data Protection Act, 2019 you have the right to be told how your data is used, to get a copy of it, to have mistakes corrected, to have it deleted, to object to how it is being used, and to withdraw consent at any time.
To exercise any of these, email hello@shazi.app from the address on your account, or send a WhatsApp message to the business number you dealt with. We respond within 30 days. We may ask you to confirm your identity first, so that nobody else can request your data.
To stop receiving messages from a business, reply STOP to it, or block the number in WhatsApp.
If you are unhappy with how we have handled a request, you may complain to the Office of the Data Protection Commissioner of Kenya at odpc.go.ke.
12
Children
Shazi is built for business, not for children. We do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, tell us and we will delete it.
13
Changes to this policy
We update this page when the service changes. The date at the top always shows the current version. If a change materially affects your rights, we will give notice through the dashboard or by email before it takes effect.
14
Contact us
Questions about this policy, or about the data we hold, go to hello@shazi.app. A real person reads that inbox.