Privacy policy

Last updated: Sep 29, 2026

This policy explains which data Wakeel collects, why we use it, who receives it, and how you can control it.

Who we are

Wakeel is software for online sellers who sell with cash on delivery, first in Algeria. Sellers use it to build store pages, receive and confirm orders, answer messages and ship parcels.

Wakeel is a product of ISR Services, powered by Scalemind LLC.

Scalemind LLC operates the service and is responsible for the data in this policy. In this policy, “we” and “us” mean Scalemind LLC.

For any question about your data, write to contact@scalemindapps.com.

Sellers and buyers

Sellers use Wakeel to run their online store. Buyers order from the store of a seller. Buyers do not have a Wakeel account.

For the account data of sellers, we decide how the data is used.

Sellers collect buyer data with Wakeel, or import it into Wakeel. We process this buyer data for the seller and on the instructions of the seller.

Each seller must tell its buyers how it uses their data, including calls and messages.

Data we collect

Seller account

  • Your name, email address and profile photo, from Sign in with Google.
  • Your phone number. We verify it with a code that we send on WhatsApp.
  • Your answers during onboarding, for example the platform that you used before.
  • The email addresses of the team members that you invite.

Store data

  • Your products, photos, videos, store pages and settings, the knowledge texts of your AI agents, and your chats with the assistant.
  • The API keys of your delivery carriers. We store them encrypted.
  • Billing data: your plan, credits, invoices and payments. Your card data stays with Stripe and SlickPay. We do not store it.

Buyer data that we process for sellers

  • Name, phone numbers, email address, wilaya, commune, address and notes.
  • The lines of each order, and the counts of orders, delivered orders and returns.
  • The IP address and the browser user agent of the order.
  • Ad click IDs (fbclid, fbc, fbp, ttclid, ttp), UTM values, the referrer and the landing page.
  • A fake-order risk score and its reasons.
  • Abandoned orders: a buyer types a phone number in an order form, but does not send the form. We keep what the buyer typed as an abandoned order.

Messages and comments

A seller can connect Facebook Pages and Instagram accounts. We then receive the messages and comments that people send to them: the text, the attachments, the name, username and profile photo of the sender, and the ad that brought the person, if there is one. When the AI agent takes an order in a conversation, we also keep the order details that it collects.

AI confirmation calls

A seller can use AI confirmation calls. An AI voice agent then calls the buyer to confirm the order. The call is recorded, transcribed and summarized. We store the recording, the transcript, the summary and the result of the call.

Technical data

The session cookie of your sign-in, the IP address and browser of each session, and server logs.

Data from connected platforms

Sellers can connect Wakeel to Meta, Google and TikTok. Each connection is optional. It gives Wakeel only the access that this section describes.

Meta: Facebook, Instagram and WhatsApp

We use Facebook Login only to connect the Facebook Pages, Instagram accounts and ad accounts of a seller. Nobody signs in to Wakeel with Facebook.

We ask for these permissions:

  • pages_show_list: shows the list of your Pages, so that you can pick the Pages to connect.
  • pages_read_engagement: reads the name, picture and posts of the Pages that you connect.
  • pages_read_user_content: reads the comments and posts that people leave on your Pages.
  • pages_manage_metadata: subscribes your Pages to updates, so that new messages and comments arrive in the Wakeel inbox.
  • pages_manage_engagement: replies to the comments on your Pages, and hides or shows them.
  • pages_messaging: receives and answers the Messenger messages of your Pages.
  • instagram_basic: reads the username, profile photo and posts of your Instagram professional account.
  • instagram_manage_comments: reads, answers and hides the comments on your Instagram posts.
  • instagram_manage_messages: receives and answers your Instagram direct messages.
  • ads_read: reads your ad accounts, your campaigns and their results.
  • ads_management: creates and changes campaigns, ad sets, ads and creatives when you ask. New campaigns start paused.
  • business_management: finds the ad accounts that belong to your Meta business portfolio.

Conversions API: when a seller turns it on, Wakeel sends order events to the Meta pixel of the seller. The phone number, first name, last name, city and country of the buyer are hashed with SHA-256 before Wakeel sends them. Hashing changes each value into a code that does not show the original text. Wakeel also sends the IP address, the browser user agent, fbp and fbc. Each event also carries the event name, the event id, the time, the address of the page, the order id, the order value and currency, and the products with their ids, quantities and prices.

WhatsApp: Wakeel sends phone verification codes and order confirmation messages from its own WhatsApp Business number. We receive the answer of the buyer, “Confirm” or “Cancel”. Wakeel then confirms or cancels the order.

Google

Sign in with Google: we receive your name, email address and profile photo, with the openid, email and profile permissions.

Google Sheets order sync: this is a separate, optional connection. For files, it uses only the drive.file permission. Wakeel can read only the spreadsheet that you pick in the Google Picker. It reads the name of the file, the list of its tabs, and the cells of the tab that you choose. Every 5 minutes, it turns the new rows into orders.

The sync also reads the email address of the Google account, to show which account is connected. We store the access tokens encrypted. When you disconnect Google, we delete the tokens and revoke the access at Google, unless another of your stores still uses the same Google account. The orders that Wakeel already imported stay in your store. We store the id and name of the spreadsheet, the name of the tab, your column choices, the id of the Google account, and short codes of the rows that Wakeel already imported, so that a row is never imported twice. To match the products and places of a row with your store, Wakeel sends these cell texts to an AI model (Jev, through the Vercel AI Gateway). The new orders then follow the rest of this policy, for example the risk score, the carriers and the confirmation calls that you use.

Wakeel's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data to train AI models. We do not sell it. We do not use it for advertising. People read it only with the permission of the seller, for security, or when the law requires it.

TikTok

Events API: when a seller turns it on, Wakeel sends order events to the TikTok pixel of the seller. The phone number of the buyer is hashed with SHA-256 before Wakeel sends it. Wakeel also sends the IP address, the browser user agent, ttclid and ttp. Wakeel uses the access token that the seller gives. Each event also carries the event name, the event id, the time, the address of the page, the order id, the order value and currency, and the products with their ids, quantities and prices.

How we use data

  • To run the service: store pages, orders, order confirmation, delivery and messages.
  • To run the AI features that the seller uses. The next section explains them.
  • To check for fake orders. Wakeel gives each order a risk score. The score alone never cancels or changes an order. The seller decides.
  • To send order events to Meta and TikTok, when the seller turns this on.
  • To bill sellers for plans and credits.
  • To keep the service safe, to give support, and to meet our legal duties.

We do not sell personal data. We do not use data from Meta, Google or TikTok for our own advertising. We do not use it to train AI models.

AI processing

Some features send text to AI model providers through the Vercel AI Gateway. Most features use Anthropic models, and other providers of the gateway are a fallback. The fake-order risk score, the matching of imported orders and the matching of ads use Jev, a model of TypeSafe. For the risk score, Jev receives the name of the buyer, the address, the commune, the wilaya and the note of the order. We use AI for:

  • Replies to messages and comments.
  • The assistant chat of the seller.
  • The fake-order risk score.
  • Matching products and places when a seller imports orders.
  • The summary and the result of each confirmation call.
  • Product texts and store pages.

Higgsfield creates images and videos from the product photos that the seller gives. The seller can also give the photo of the face of a person as a model. Higgsfield then receives that photo too.

ElevenLabs runs the AI confirmation calls. It receives the phone number and name of the buyer, the products, the order total, the city, the store name and the knowledge texts of the agent. It hears the voice of the buyer, records the call, makes the transcript and stores the audio and the transcript. Twilio gives the phone line: it carries the phone number and the voice of the call. When the buyer refuses on the call, Wakeel cancels the order. When the buyer asks for a change, Wakeel can change the quantity or the address, if the seller allows it.

AI can make mistakes. The seller must check the important results. By default, Wakeel asks the seller before the AI spends money on ads or publishes something new, such as a page or a campaign. The seller can turn these questions off in the assistant.

Service providers that receive data

We share data only with the providers that run the service with us:

  • Neon: the database.
  • Cloudflare R2: the storage of files, such as photos and call recordings.
  • Vercel: the hosting of store pages, and the AI Gateway.
  • Trigger.dev: the jobs that run in the background.
  • Anthropic, TypeSafe and other AI model providers, through the Vercel AI Gateway: the AI features.
  • Higgsfield: images and videos.
  • ElevenLabs and Twilio: the AI confirmation calls.
  • Resend: emails.
  • Meta, Google and TikTok: the connections that the seller turns on, and the WhatsApp messages.
  • Stripe and SlickPay: payments.
  • Sentry: the error reports of store pages.
  • The delivery carriers that the seller picks (Yalidine, ZR Express, Maystro). They receive the name, phone number, address, wilaya and commune of the recipient, the cash amount and the product description.

Cookies and browser storage

The Wakeel dashboard uses one session cookie to keep you signed in. It expires after 7 days without use. During the Google sign-in, the dashboard also sets a short security cookie that expires after a few minutes. When you pick a spreadsheet, the dashboard loads the Google Picker from Google. The dashboard keeps your language, theme, active store and some display choices in browser storage. The dashboard has no advertising cookies and no analytics cookies.

Store pages keep the cart and the ad click details in browser storage. A seller can add a Meta or TikTok pixel to a store page. That pixel then sets its own cookies (_fbp, _fbc, _ttp).

International transfers

Wakeel and its service providers can process data outside Algeria.

Security

  • We encrypt the access tokens of connected platforms and the API keys of carriers with AES-256-GCM.
  • Connections to Wakeel use HTTPS.
  • Inside a store, each team member gets access by role.
  • We check the signature of each update that a platform sends to Wakeel (a webhook).
  • We store call recordings as files behind links that nobody can guess.

No system is perfectly secure.

How long we keep data

We keep data while the account of the seller is active.

Phone verification codes expire after 5 minutes. Sign-in sessions expire after 7 days without use.

When a seller disconnects Meta, Wakeel deletes the access tokens and removes its access at Meta, unless another store of the seller still uses the same Facebook account. Wakeel then stops receiving new data. The data that Wakeel already received stays until the seller asks for deletion or deletes the store.

When a seller disconnects Google, we delete the tokens and revoke the access at Google, unless another store of the seller still uses the same Google account. The imported orders stay.

After a verified deletion request, we delete the data within 30 days. We keep only the records that the law makes us keep, for example invoices. See Delete your data.

Your rights

You can ask to access, correct or delete your data. You can object to a use of your data, and you can withdraw your consent.

These rights come from Algerian Law 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, and from the GDPR for people in the European Union.

Write to contact@scalemindapps.com. We answer within 7 days, and we complete the request within 30 days.

Buyers: contact the seller first, because the seller decides how it uses your data. You can also write to us, and we help.

Children

Wakeel is for adults: 18 years or older. Sellers must not use Wakeel to collect the data of children.

Changes to this policy

When this policy changes, we update this page and its date. For important changes, we tell sellers in the app or by email.

Contact

Scalemind LLC, contact@scalemindapps.com