Who we are
Toward Technology Private Limited ("we," "us,") operates Waktaa, an omni-channel messaging service for shops. This policy covers:
- This marketing website (pages such as features, pricing, and contact)
- The Waktaa tenant dashboard and APIs where you connect WhatsApp, Instagram, Messenger, Shopify, and store chat, manage buyer conversations, and send order updates
We process personal information in line with the Constitution of Nepal (Article 28 — right to privacy), the Privacy Act 2075 (2018), and other applicable Nepali law. Read this together with our Terms of Use and the acceptable-use rules on Trust.
Controller & processor
2.1 Your role as controller
If you use Waktaa for your shop, you are the data controller (or equivalent responsible party under the Privacy Act 2075) for your buyers' and customers' personal information—including names, phone numbers, order details, and message content.
2.2 Our role as processor
Toward Technology Private Limited acts strictly as a data processor on your instructions. We process that information only to provide the Waktaa features you configure: unified inbox, routing, order notifications, optional AI Assist, billing, security, and compliance tooling.
2.3 Your obligations
You are responsible for having a lawful basis to message buyers, providing your own notices to buyers where required, honouring opt-out and rights requests from your customers, and instructing us when a buyer's request affects data we store for you. Waktaa is an inbox and reply product; we do not run your marketing lists or a STOP / unsubscribe screen for buyers. Email privacy@waktaa.com when a buyer asks you to access or delete data we store. We do not decide who you may message or what you may say.
2.4 Our processor commitments
We implement appropriate technical and organizational measures, process data only for the purposes in this Policy, and use sub-processors (hosting, Meta, Shopify, payments, AI inference) only as needed to deliver the service and as described in Sections 5 and 8.
2.5 Data Processing Agreement
Our standard Data Processing Agreement Cover Page (Common Paper DPA Standard Terms Version 1.1, incorporated by reference) is published at waktaa.com/dpa. It applies to Customer Personal Data processed in the Waktaa service as described there. For a countersigned copy, email privacy@waktaa.com with the subject DPA countersign.
This website
3.1 What we collect
- Contact requests: If you use our contact form, your email client sends us the details you enter (name, contact method, channel, notes) after you confirm consent on the form. We do not store those fields in a server-side database on this site—the form opens a
mailto:link. - Enterprise or pricing inquiries: If you email us from pricing or contact flows, we use those details to respond and, where relevant, prepare a written quote.
- Technical logs: Our hosting provider (for example Cloudflare) may log IP address, browser type, requested URL, and timestamps for security and reliability.
3.2 Cookies, analytics, and online identifiers
Under Section 2 of the Privacy Act 2075, online identifiers—including IP addresses, cookie identifiers, device and browser metadata, and generalized location inferred from IP—may be personal information when they relate to an identifiable individual.
Strictly necessary technologies. We use cookies or similar technologies needed for security, load balancing, and basic site operation (including services such as Cloudflare).
Google Analytics. We use Google Analytics on this marketing website to understand aggregate traffic—not inside the Waktaa dashboard. How we load it depends on where you are:
- EEA, UK, and Switzerland (and when we cannot determine your country): We show a cookie banner on first visit. We load optional Google Analytics cookies only after you choose Accept cookies. Your choice is stored in your browser (typically until you clear site data). You may choose Reject to decline optional analytics cookies.
- Other regions: We may load Google Analytics without showing the banner, based on our legitimate interest in measuring aggregate site use and on the disclosure in this Policy. You may still block or delete cookies through your browser settings or Google's opt-out tools where available.
Google Analytics may collect IP address (we configure anonymization where supported), browser and device type, pages visited, referral source, session duration, and generalized country or city location inferred from IP. We do not use Google Analytics to read message content inside the Waktaa product dashboard. See Google's Privacy Policy.
What we do not collect on this site. We do not collect live GPS or precise real-time geolocation from your device on this marketing site.
Third-party processing. Google and other analytics or CDN providers may process data under their own terms and may store or process data outside Nepal.
Your choices. You may block or delete cookies through your browser settings. Where required by law or when we cannot determine your country, we present a cookie consent banner with Accept cookies and Reject before loading optional analytics cookies. In other regions, browser controls and Google's opt-out tools remain available.
Product analytics. Usage metrics inside the Waktaa dashboard (message counts, AI pool usage, delivery status) are separate from website analytics and are described in Section 4.
The dashboard
4.1 Account and organization data
- Name, email, organization name, and authentication identifiers (including OAuth tokens from sign-in providers you choose)
- Team membership (named operator seats linked to Google or Apple sign-in), roles, and audit events related to compliance (for example AUP acceptance timestamps)
- Billing contact details and subscription status when you pay through our billing and payment flows
4.2 Messaging and order data
- Buyer identifiers, conversation threads, message bodies, attachments metadata, and delivery status from connected channels
- Instagram post and reel comments ingested into your inbox when you connect Instagram with comment permissions
- Product catalog entries (names, prices, SKUs, and related metadata) you maintain in the Products hub, and Shopify catalog data you authorize us to sync (names, prices, images, variants)
- Store-chat messages from the widget on your Shopify theme, plus the name and/or email you choose to request before a shopper's first message
- Order references you link for templates (for example "order packed" notifications)
- Channel connection configuration (WhatsApp Cloud, Meta tokens, and Shopify store credentials)
4.3 Automated and AI-assisted processing
In line with the Privacy Act 2075, we process message content and related context only for purposes disclosed in this Policy—principally: displaying conversations in your unified inbox; routing and assignment; order-notification workflows you trigger; generating suggested or automated replies when you enable AI Assist; and safety, abuse prevention, and usage metering.
When AI Assist is enabled, we may transmit relevant message text, limited conversation history, optional knowledge-base excerpts you upload, and category prompts you configure to a cloud inference provider solely to produce inbox assistance for your organization.
We do not sell message content. To our knowledge, we do not use your buyers' private communications to train public, general-purpose third-party models, and we require inference providers to process data for API delivery unless separate written consent applies for any other use.
Depending on your settings, AI output may be held in a confirmation queue for operator review before sending. You may disable AI Assist at the organization or category level, or use Starter if you only need one channel.
You may upload knowledge-base files (for example shop FAQs or product notes) within plan limits shown in Billing. We store file content to provide AI Assist context and delete it when you remove the file or your account, subject to backup and legal retention limits.
We store usage aggregates (for example how many AI-initiated outbound messages your team sent in a billing period) to enforce plan limits. These counters do not need to include full message bodies.
4.4 Shop Insights and operational metrics
Organization owners and admins may view Shop Insights—aggregated message volume, plan usage, and similar operational metrics for their organization. These charts do not expose buyer message bodies to other tenants and are not sold for advertising.
4.5 Staff push notifications
When enabled, operators may opt in to alerts when a customer messages a connected channel, an AI reply awaits confirmation, or a send fails. You may disable notifications in the dashboard or through the device or browser settings.
- Web: we store a push subscription endpoint and related browser identifiers using industry-standard Web Push (VAPID).
- Android and iOS apps: we store a device push token (Firebase Cloud Messaging / Apple Push Notification service) so we can deliver the same alerts to the phone you signed in on. Tokens are tied to your operator account and are removed from our systems when you turn off alerts in the app, sign out, or we delete the account.
4.6 Why we process it
- Provide and secure the inbox, automations, and billing you request
- Enforce subscription limits (seat count, AI Assist pools)
- Enforce acceptable use, rate limits, and abuse prevention to protect all customers
- Support you during pilot and production use
- Meet legal obligations and respond to lawful requests
4.7 Legal bases (Nepal)
We process personal information only where permitted under the Privacy Act 2075 and related applicable law, including where:
- Consent — you have given informed consent (for example contact-form consent or AUP acceptance)
- Contract — processing is necessary to provide the Waktaa service you request
- Legal obligation — we must retain or disclose records under applicable law
- Other bases — where specifically permitted by Nepali law (for example vital interests or public interest as provided by statute)
We collect only the personal information reasonably necessary for the purposes described in this Policy.
Retention
We keep information only as long as needed for the purposes above, including while your account is active and for a reasonable period afterward for backups, billing records, usage metering aggregates, and legal compliance. You may request deletion subject to limits (for example we may retain logs required for security or law).
6.1 If your subscription ends or payment lapses
When a subscription ends or a payment lapses, sending and automation freeze, but we do not delete your data right away:
- Grace period (first 60 days). We keep your conversation history and media so you can restore the account by renewing. Renew within this window and your inbox history comes back.
- Days 61–90. Data stays retained so you can still request an export from privacy@waktaa.com or settle a late payment. Sending remains frozen.
- Day 90. If you have not renewed, we may permanently delete stored messages and media from our live systems. Once performed, deletion cannot be undone, so request an export before day 90 if you need a copy.
Backups. Residual copies may remain in routine backups until the backup rotation completes (typically within 30 days). We do not restore deleted tenant data from backups into production.
Billing records. Invoices, payment references, and subscription records may be kept longer than message content where we need them for tax and accounting obligations.
Security
We use technical and organizational measures appropriate to a messaging platform (access controls, encryption in transit, tenant isolation, monitoring). No method of transmission or storage is completely secure; you should protect dashboard credentials and connected channel tokens.
Hosting
8.1 Current hosting (as of this policy date)
Waktaa product data—including account records, conversation history, order data, uploaded knowledge-base files, and application logs—is stored and processed on secure cloud infrastructure. As of the "Last updated" date above, primary product data is hosted at Virginia, United States. This marketing website may be served through Cloudflare (global edge network; may process outside Nepal).
Connected channels (Meta, Shopify, payment gateways, AI inference) may also process data in their own regions under their terms, in addition to the locations we control.
8.2 Nepal, cross-border, and future hosting
We may store or process Personal Information inside Nepal, outside Nepal, or across both, depending on operational needs, performance, cost, and applicable law—including requirements under the Data Center and Cloud Service Directives 2081 (2025) for private-sector cloud use. We are not locked to a single country: we may migrate primary hosting to a Nepal-based data centre or another qualified region if law, security, or service quality requires it.
8.3 Safeguards
We select infrastructure providers with appropriate security practices and contractual confidentiality obligations. Data is encrypted in transit (TLS). Access is limited by authentication, tenant isolation, and role-based controls.
8.4 Legal basis and your instruction
Where Nepali law requires consent or notice for cross-border processing, we rely on your informed acceptance of this Policy, your use of the service, and performance of our contract with you. By connecting channels and storing buyer conversations in Waktaa, you instruct us to transfer and store Personal Information in the hosting locations described in this Section for the purposes in this Policy.
8.5 Changes to hosting location
If we change primary product hosting region, we will update this Policy (including Section 8.1 and the "Last updated" date). Where permitted by applicable Nepali law, your continued use of the service after the update is posted constitutes your agreement to the revised hosting disclosure.
Your rights
Article 28 of the Constitution of Nepal protects privacy. As a Waktaa account holder, you may exercise rights under the Privacy Act 2075, including:
- Right of access (Section 9) — request confirmation of whether we hold your personal information and obtain a readable copy, subject to verification and legal exceptions
- Right of correction (Section 11) — request correction of inaccurate or incomplete account or billing information we control
- Right of erasure (Section 11) — request deletion of your Waktaa account data and connected integrations, including channel tokens, inbox messages, and uploaded knowledge-base files, subject to retention we must maintain for security, billing, or legal obligation
- Withdraw consent — where processing is based on consent, to the extent permitted by law and technical feasibility
9.1 How to exercise your rights
To delete your Waktaa account and associated data, email privacy@waktaa.com from your account email with the subject Data deletion request. For access or correction, use the subject Privacy rights request. Include your name and organization name. We aim to acknowledge requests within 15 days and complete verified deletion within 30 days. You can also start this from Settings in the Waktaa app or dashboard.
9.2 Platform-specific deletion
For Meta-connected data, you may remove Waktaa in Facebook Settings to trigger our automated deletion flow. Step-by-step instructions are available on our data deletion page in the dashboard. For Shopify, store chat, or other channels, disconnect in Channels and email us with your deletion request.
9.3 Buyers of your shop
Individuals who messaged your business should contact you first as data controller. We will assist you as processor where technically feasible and legally permitted.
9.4 Complaints
Contact us first at privacy@waktaa.com. You may also pursue remedies before competent courts or administrative bodies in Nepal as provided by applicable law.
General support (non-privacy): hello@waktaa.com. We may need to verify your identity before fulfilling a rights request.
Rights outside Nepal
Shopify requires public apps to honour the same access, correction, and deletion rights for personal data regardless of where a person lives. We apply the request path in Section 9 to every verified requester—not only people in Nepal.
If European Union, United Kingdom, or Swiss law applies to you (or to a shopper whose data you stored in Waktaa), you may also have GDPR rights to access, rectify, erase, restrict, object, and data portability, and to complain to a supervisory authority. Email privacy@waktaa.com with the subject Privacy rights request.
If California or another US state privacy law applies, use the California notice, the privacy rights request form, and—if you want to opt out of sale or share— Do Not Sell or Share. We do not sell personal information. Optional analytics cookies on this marketing site can be declined with Reject on the cookie banner or via the opt-out form. Shopper requests about inbox data should go to the merchant first; we assist as processor.
To exercise applicable US state privacy rights for information we hold as controller, prefer the request form or email privacy@waktaa.com with the subject Privacy rights request. We will verify your identity and respond as described in Section 9.
10.1 Operator address and email
The registered operator of Waktaa is Toward Technology Private Limited, Biratnagar, Koshi, Nepal. Privacy and legal notices may be sent to that address or to privacy@waktaa.com.
This marketing website does not operate a newsletter or other commercial mailing list. Email we send in connection with this site is limited to replies to contact requests and service or transactional messages about your account.
California notice (CCPA / CPRA)
This section is for California residents and others who wish to use the same controls. It supplements the rest of this Policy.
11.1 Categories of personal information
In the last 12 months we have collected the categories below as a controller (this website and your Waktaa account). "Shared" means share for cross-context behavioural advertising under CPRA. An asterisk (*) means optional Google Analytics on waktaa.com may be treated as a share by some interpretations; we do not sell personal information, and you can opt out.
Controller — website and Waktaa account
Identifiers
Collected · YesSold · NoShared · No*Name, email, phone, account ID, IP address, device or browser IDs
Business purposeProvide the site and service, security, support, billing identity, analytics if you accept cookies
Customer records / commercial information
Collected · YesSold · NoShared · NoPlan, billing status, organization name, invoice-related details via payment partners
Business purposeOperate your Waktaa account and process payments through Paddle, Shopify, or Apple
Internet or electronic network activity
Collected · Yes (marketing site)Sold · NoShared · No*Pages viewed on waktaa.com, referral URL, session duration (Google Analytics when enabled)
Business purposeMeasure aggregate site traffic; not used inside the Waktaa dashboard product
Geolocation data (coarse)
Collected · Yes (limited)Sold · NoShared · No*Country or city inferred from IP
Business purposeSecurity, consent region for cookies, approximate analytics
Professional or employment-related information
Collected · YesSold · NoShared · NoShop or brand name you provide when contacting us or creating an organization
Business purposeRespond to inquiries and set up your workspace
Inferences
Collected · NoSold · NoShared · NoWe do not build marketing profiles or credit scores about you
Business purposeN/A
Sensitive personal information (as defined by CPRA)
Collected · Limited / not intentionalSold · NoShared · NoNot intentionally collected for marketing; account login uses Google or Apple where you choose
Business purposeAuthenticate you when you use those sign-in providers
When you use Waktaa for your shop, we also process shopper data as a processor on your instructions (see the DPA). Those categories include:
Processor — shopper data for your shop
Identifiers (shoppers)
Collected · On your instructionSold · NoShared · No (except channel platforms you connect)Buyer name, phone, email, channel user IDs in connected conversations
Business purposeProvide inbox, routing, notifications, and optional AI Assist for your shop
Commercial / transaction (shoppers)
Collected · On your instructionSold · NoShared · No (except platforms you connect)Order updates, COD details, catalog SKUs you attach in chat
Business purposeOperate messaging and order-comms features you configure
Contents of communications
Collected · On your instructionSold · NoShared · No (except platforms you connect)Message text and media in connected channels
Business purposeDisplay and send messages in Waktaa
11.2 Sale / share
We do not sell personal information. We do not share personal information for cross-context behavioural advertising as we understand that term. If you want to record an opt-out and disable optional analytics cookies, use Do Not Sell or Share My Personal Information.
11.3 Your California rights
Subject to verification and legal exceptions, you may request to:
- Know / access the personal information we hold about you
- Delete personal information
- Correct inaccurate personal information
- Opt out of sale or share
- Limit use of sensitive personal information (where applicable)
- Not be discriminated against for exercising these rights
Submit a request with the privacy rights request form. We verify by confirming control of the email you provide (and account email for Waktaa users). We aim to acknowledge requests within 15 days and complete verified deletion within 30 days.
11.4 Sources and disclosure
Sources include: you (forms, account), your devices (logs, cookies you allow), and sign-in providers (Google or Apple) when you use them. We disclose personal information to service providers / subprocessors listed in this Policy and the DPA (for example hosting, Meta, Shopify, Paddle, Cloudflare, Google) only for the business purposes described there—not for monetary sale.
Children
Waktaa is a business tool, not directed at children. We do not knowingly collect personal data from children under 16, and we do not knowingly collect personal data from children under 13 (the COPPA age). If you believe we have, contact us and we will delete it where appropriate.
Updates
We may update this policy. We will post changes here with a new "Last updated" date. Material changes to the service may also be communicated in the dashboard or by email where appropriate.