Threadesk ("Threadesk", "we", "our", or "us") provides a browser extension, web application, and related services that help merchants organize customer and commerce activity originating from WhatsApp conversations.
This Privacy Policy explains how information is collected, used, processed, disclosed, protected, and retained when you use:
- The Threadesk browser extension.
- The Threadesk seller dashboard.
- Threadesk websites and support services.
- AI-assisted Capture and review features.
- Subscription, billing, notification, and related account services.
By using Threadesk, you acknowledge the practices described in this Privacy Policy.
1. Our Approach to Privacy
Threadesk is designed around user control, data minimization, and human review.
Threadesk does not:
- Continuously monitor all of your WhatsApp conversations.
- Automatically scan your entire WhatsApp inbox.
- Send WhatsApp messages on your behalf.
- Automatically reply to customers.
- Send bulk WhatsApp messages.
- Operate as a WhatsApp chatbot.
- Sell personal information.
- Use WhatsApp conversation data for advertising.
- Build advertising profiles from WhatsApp activity.
WhatsApp conversation processing occurs as part of user-initiated Threadesk functionality.
When Capture is used, Threadesk may temporarily process and retain the conversation source data necessary to perform the requested Capture operation. This may include message content, message and media metadata, and supported media.
Threadesk does not use this temporary Capture data to create a permanent general-purpose archive of your WhatsApp conversations.
Business records proposed by AI are presented for review. Approval is the point at which proposed information may become a durable Threadesk business record.
2. Data Roles and Responsibilities
Merchant Customer Data
Merchants using Threadesk generally determine why customer information is processed, which WhatsApp conversations are submitted to Capture, which AI-generated proposals are approved, and which customer and commerce records are maintained.
Accordingly, where applicable under data protection law, the merchant acts as the Data Controller or equivalent business responsible for customer information, and Threadesk acts as a Data Processor or service provider processing that information on the merchant's behalf.
Merchants are responsible for ensuring that they have an appropriate legal basis or other authority to process their customers' personal information through Threadesk.
Threadesk Account and Service Data
For information that Threadesk processes for its own account administration, authentication, security, billing, service operation, fraud prevention, legal compliance, and platform reliability purposes, Threadesk may act as a Data Controller or equivalent responsible entity.
The applicable role may vary depending on the information involved and applicable law.
3. Information We Collect and Process
Merchant Account Information
We may collect or process:
- Name.
- Email address.
- Phone number.
- Business name.
- Country.
- Preferred currency.
- Language preferences.
- Time zone.
- Account settings.
- Subscription status.
- Plan and capability information.
- Account and user identifiers.
Authentication and Device Information
Threadesk processes information necessary to authenticate users and paired extension devices.
This may include:
- Login information.
- Google Sign-In information where Google authentication is used.
- Access and refresh tokens.
- Session identifiers.
- Extension device identifiers.
- Account identifiers.
- Authentication and security events.
The browser extension may store paired-device authentication material, extension preferences, and limited UI or session state in extension storage.
Access credentials are used only to authenticate and secure access to Threadesk services.
4. WhatsApp and Capture Data
Threadesk's browser extension operates alongside WhatsApp Web.
When you use Capture, Threadesk may process information from the selected or active WhatsApp conversation that is necessary to provide the requested feature.
Depending on the conversation and Capture request, this may include:
- Message text.
- Message identifiers.
- Message timestamps.
- Sender and conversation metadata.
- Customer or participant information.
- Conversation relationship information.
- Images.
- PDFs.
- Voice notes and audio.
- Supported documents.
- Supported video or other media.
- Media type, size, integrity, and processing metadata.
- Quoted or related conversation context required to interpret selected messages.
The extension initially holds hydrated Capture information in a bounded local transport buffer.
Information required for Capture may then be securely transmitted to Threadesk services for planning, eligibility checks, media processing, AI analysis, review creation, recovery, and related Capture operations.
Once locally buffered Capture information has been successfully synchronized as required, the extension removes that local transport source rather than using browser storage as a permanent WhatsApp conversation database.
5. WhatsApp Identity Information
Threadesk must associate Capture activity with the WhatsApp identity that is currently connected to WhatsApp Web.
To support this, the extension derives an identity value from the active WhatsApp session and provides a hashed identity to Threadesk.
Threadesk uses this information to:
- Verify that the connected WhatsApp identity belongs to an authorized Threadesk account.
- Keep identity-specific Capture and review activity separated.
- Prevent information from one connected WhatsApp identity from appearing in another identity's sidecar session.
- Deliver appropriate real-time update notifications to the connected extension.
The live WhatsApp identity is not used for advertising or unrelated tracking.
6. AI-Assisted Processing
Threadesk uses AI-assisted processing to identify business information from user-initiated Capture operations.
Depending on the material selected for Capture, AI processing may involve:
- Message text.
- Relevant conversation context.
- Images.
- Payment evidence.
- Documents.
- Voice notes or audio.
- Other supported media.
- Existing customer or order context necessary to interpret a proposed business action.
Threadesk limits AI processing to information needed to provide the requested functionality and applicable operational safeguards.
AI systems may generate proposed:
- Orders.
- Payment information.
- Delivery updates.
- Customer inquiries.
- Customer notes.
- Other supported business information.
AI output is not automatically treated as verified business data.
Threadesk presents AI-generated proposals for human review where required.
A merchant may review, edit where supported, approve, or reject proposed information.
Approval of AI-detected payment evidence does not itself mean that the merchant has verified that payment. Payment evidence may remain pending merchant verification until the seller separately confirms or rejects it.
7. Temporary Capture Storage and Retention
Unlike a permanent WhatsApp chat archive, Capture source data is retained only for the operational purposes required to provide the Capture workflow.
Threadesk may temporarily retain protected:
- Source message text.
- Message metadata.
- Media metadata.
- Uploaded media bytes.
- Capture planning information.
- Processing and recovery information.
- AI job information.
- Source-to-result evidence references.
Temporary source information may need to remain available while Capture work is:
- Queued.
- Being processed.
- Awaiting retry.
- Recovering from a processing interruption.
- Awaiting lifecycle finalization.
- Subject to technical cleanup or retention processing.
Capture source information expires under Threadesk's configured retention and cleanup policies.
Threadesk does not retain temporary Capture source material indefinitely merely to create a historical copy of a user's WhatsApp conversations.
Where a Capture run fails or is cancelled, certain source information may temporarily remain available to support a safe retry or recovery until it expires or is removed through the applicable cleanup process.
8. Business Records Stored in Threadesk
When business information is approved, entered manually, or otherwise intentionally created through Threadesk, we may retain structured records such as:
- Customer names and contact information.
- Customer notes.
- Orders and line items.
- Prices, adjustments, totals, and currencies.
- Payment records.
- Payment evidence or payment proof.
- Payment status and verification information.
- Delivery and fulfilment details.
- Addresses provided for fulfilment.
- Customer inquiries.
- Reminders.
- Tags.
- Lead or customer status information.
- Receipts.
- Timeline activities.
- Record timestamps.
- Audit and source-correlation information.
These structured records are maintained as Threadesk business data and are distinct from temporary Capture source information.
Rejected Capture proposals do not create the corresponding business record.
9. Seller Payment Information
Threadesk supports seller-side payment records associated with customer orders.
Seller payment information may include:
- Amount.
- Currency.
- Transaction date.
- Payment method.
- Payment reference.
- Sender information.
- Payment evidence.
- Uploaded payment proof.
- Verification status.
- Related order and customer information.
AI-detected payment evidence may be stored as pending verification after approval of the Capture proposal.
The merchant remains responsible for confirming whether payment evidence represents a valid payment.
Threadesk's seller order-payment records are separate from payments that merchants make to Threadesk for their own Threadesk subscription.
10. Subscription and Billing Information
Threadesk may process billing and subscription information necessary to sell and manage Threadesk plans, subscriptions, and credit purchases.
This may include:
- Billing name.
- Country and currency.
- Subscription status.
- Transaction identifiers.
- Checkout information.
- Invoice information.
- Payment-provider customer identifiers.
- Saved-payment-method references where supported.
- Entitlement and credit information.
- Billing audit and reconciliation records.
Payment processing may be handled by third-party payment providers, including providers such as Paystack and Flutterwave where available.
Threadesk does not require or intend to store complete payment card numbers through its own application database when payment processing is performed by an external payment provider.
11. Usage, Diagnostic, and Security Information
We may process operational information necessary to maintain and secure Threadesk, including:
- Browser type.
- Extension version.
- Operating system.
- Device and session identifiers.
- Error information.
- Diagnostic logs.
- API and processing status.
- Feature usage information.
- Capture processing status.
- Security events.
- Authentication events.
- Service performance information.
We use this information to diagnose problems, prevent abuse, protect accounts, maintain reliability, and understand whether Threadesk features are functioning correctly.
Threadesk does not use this information to build advertising profiles or track a user's unrelated browsing activity.
12. How We Use Information
We use information to:
- Provide the Threadesk browser extension and web application.
- Authenticate users and paired devices.
- Authorize connected WhatsApp identities.
- Provide user-initiated Capture functionality.
- Determine Capture eligibility and processing requirements.
- Process supported message and media content.
- Provide AI-assisted business extraction.
- Create and manage review items.
- Apply merchant-approved business actions.
- Maintain customer records.
- Maintain orders and fulfilment information.
- Maintain payment records and verification state.
- Generate and manage receipts.
- Maintain customer notes, inquiries, reminders, and timelines.
- Manage subscriptions, plans, entitlements, and credits.
- Provide real-time application updates.
- Send operational communications and notifications.
- Provide customer support.
- Maintain account and platform security.
- Diagnose errors and service failures.
- Prevent fraud and abuse.
- Meet legal and regulatory obligations.
- Improve the reliability and performance of Threadesk.
We do not use WhatsApp conversation data for unrelated advertising or marketing profiling.
13. Third-Party Service Providers
Threadesk uses service providers where necessary to operate the service.
AI and Media Processing Providers
Selected message and media content may be provided to configured AI or transcription providers when required to perform a user-requested Capture operation.
Such providers receive only information necessary for the processing service being requested.
Cloud and Storage Providers
Threadesk uses hosting, database, networking, file-storage, and related infrastructure providers to operate the platform and securely store applicable service information.
Payment Providers
Threadesk may use payment providers such as Paystack and Flutterwave to process subscription and other Threadesk billing transactions.
Email and Communication Providers
Threadesk may use service providers such as Brevo or equivalent providers for operational email and service notifications.
General
We may change service providers as our infrastructure evolves.
Service providers are permitted to process information only as necessary to provide their contracted services, subject to applicable contractual and legal requirements.
14. Data Sharing
Threadesk does not:
- Sell personal information.
- Rent customer information.
- Share customer conversation data for advertising.
- Use captured communications to build advertising profiles.
- Transfer user information for creditworthiness or lending decisions.
Information may be disclosed:
- To service providers required to operate Threadesk.
- When instructed or authorized by the merchant.
- To comply with applicable law, legal process, or regulatory requirements.
- To investigate fraud, abuse, security incidents, or threats.
- To protect Threadesk, its users, or other persons.
- In connection with a merger, acquisition, financing, restructuring, or sale of all or part of the business, subject to applicable legal requirements.
15. Chrome Extension Limited Use
Threadesk uses information accessed through its browser extension only to provide and support the extension's disclosed purpose: helping merchants turn selected WhatsApp conversation context into reviewed and organized business records and manage those records alongside WhatsApp Web.
Extension data is also used where necessary for related operational purposes such as authentication, security, fraud prevention, service reliability, diagnostics, and feature functionality.
Threadesk does not use browser-extension data:
- For targeted advertising.
- To create advertising profiles.
- To track unrelated browsing activity.
- For purposes unrelated to Threadesk's disclosed functionality.
- To determine creditworthiness or eligibility for lending.
- For sale as personal information.
Threadesk limits the collection, use, and transfer of extension user data to what is necessary to provide and operate its disclosed functionality.
16. Data Retention
Different categories of information have different retention requirements.
Temporary Capture Data
Capture source data is subject to a limited operational retention period and cleanup process.
It is removed when it expires under Threadesk's applicable Capture retention policy and is not maintained as an indefinite WhatsApp chat archive.
Business Records
Approved or manually created customer, order, payment, fulfilment, receipt, note, reminder, and timeline information may remain available while the merchant's account remains active or until removed in accordance with available product functionality and applicable retention requirements.
Account and Operational Records
Account, authentication, security, billing, credit, audit, fraud-prevention, and compliance records may be retained for as long as reasonably necessary for the applicable purpose.
Some records may need to be retained after account or record deletion where required for:
- Financial reporting.
- Tax requirements.
- Fraud prevention.
- Dispute resolution.
- Security investigations.
- Legal obligations.
- Audit requirements.
When account deletion is requested, Threadesk may apply a deletion or recovery period before permanent removal of eligible data.
17. Security
Threadesk uses technical and organizational safeguards designed to protect personal information.
Measures may include:
- Encryption in transit.
- Protection of sensitive queued processing payloads.
- Secure authentication.
- Access controls.
- Session and token management.
- Account and identity authorization.
- Data isolation between accounts and connected identities.
- Audit logging.
- Integrity validation for uploaded files.
- Controlled file-storage access.
- Rate limiting and abuse prevention.
- Retention and cleanup controls.
- Secure infrastructure practices.
No system can guarantee absolute security. We continually work to reduce security and privacy risks.
18. International Data Transfers
Threadesk may serve users in multiple countries.
Depending on the merchant's location and the service providers involved, information may be processed in countries other than the country in which it was originally collected.
Where required by applicable law, Threadesk uses appropriate measures to support lawful international data transfers.
19. Your Rights
Depending on your location and applicable law, you may have rights relating to your personal information, including rights to:
- Request access.
- Request correction.
- Request deletion.
- Request restriction of processing.
- Object to certain processing.
- Request portability.
- Withdraw consent where processing relies on consent.
- Lodge a complaint with an applicable supervisory authority.
Certain rights may be subject to legal exceptions and verification requirements.
For customer information processed on behalf of a merchant, customers should normally contact the merchant that controls the relevant Threadesk account. Threadesk will assist merchants with applicable data-subject requests where required.
20. GDPR
Where the European Union General Data Protection Regulation or related European data-protection law applies, Threadesk may process information on legal bases including:
- Performance of a contract.
- Legitimate interests.
- Compliance with legal obligations.
- Consent where required.
Where Threadesk processes customer personal information on behalf of a merchant, the merchant is responsible for establishing the appropriate lawful basis for that customer processing and Threadesk processes the information in accordance with the merchant's instructions and applicable law.
21. Nigeria Data Protection Act
Where the Nigeria Data Protection Act 2023 and related Nigerian data-protection requirements apply, Threadesk processes personal information in accordance with applicable obligations for data controllers and data processors.
Merchants remain responsible for ensuring that their use of customer information through Threadesk complies with applicable Nigerian data-protection requirements.
22. Sensitive Information
Threadesk is not designed for the intentional collection of health information or other highly sensitive categories of personal information unless such processing is specifically supported and legally permitted.
Merchants should avoid submitting unnecessary sensitive personal information through Capture and should ensure that any sensitive information they process through Threadesk is lawful and necessary for their business purpose.
23. Children's Privacy
Threadesk is intended for merchants and business users.
Threadesk is not directed to children under 18, and users must meet the eligibility requirements set out in our Terms of Service.
If we become aware that personal information has been collected from a child in circumstances where it should not have been collected, we will take appropriate steps in accordance with applicable law.
24. Changes to This Privacy Policy
Threadesk may update this Privacy Policy as the service, legal requirements, or data practices change.
When changes are material, we may provide notice through the Threadesk application, website, or email.
The effective and last-updated dates shown at the beginning of this policy identify the current version.
25. Contact Us
Questions, privacy requests, and data-protection enquiries may be submitted through Threadesk's published support or privacy contact channels.