Recupera — Privacy Policy

Last updated: August 13, 2026

Who we are

Recupera is a Shopify app that helps merchants recover abandoned checkouts by sending WhatsApp messages through the merchant's own WhatsApp Business account (official Meta Cloud API). Contact: jotamoraga12@gmail.com.

Data we process

For each store that installs Recupera we process: store domain and name, Shopify access token, and abandoned checkout data — cart value, currency, line items (title and quantity), the checkout recovery link, and the customer's phone number, first name and last name when the checkout provides them.

Marketing consent decides whether we message a customer, not whether their checkout is recorded: an abandoned checkout without consent is stored like any other, and no message is ever sent for it.

We also store the WhatsApp Business credentials the merchant connects (token, account IDs), a log of the messages sent (delivery status, timestamps), an access log of every time a personal field is decrypted (which field and why — never the value), and irreversible hashes of phone numbers, used for the suppression list, for matching the number WhatsApp reports against the one typed at checkout, and for limiting how often the same person can be messaged.

Why we process it

One purpose only: sending abandoned-checkout recovery messages on behalf of the merchant, and measuring the revenue those messages recover. We do not sell data, we do not use it for advertising, and we do not contact customers for any other reason. The merchant is the data controller; Recupera acts as a processor.

Consent and opt-out

Recupera only messages customers who accepted SMS/text marketing at checkout. If a customer replies asking to stop (e.g. "stop", "baja", "unsubscribe"), their number goes on a suppression list — stored as an irreversible hash — and is never messaged again from that WhatsApp number, including from any other store the same merchant connects it to. Replying "ALTA" lifts the suppression. Every marketing message carries both notices in its footer.

Security

Phone numbers, names and access tokens are encrypted at rest (AES-256-GCM). Where a number is only ever compared, never read back — the suppression list, the frequency limit — it is stored as an irreversible keyed hash instead. The identifier WhatsApp returns for each message encodes the recipient's number inside it, so it too is stored only as a hash. All traffic uses TLS. Data is hosted on Railway (PostgreSQL, US region). Messages are delivered by Meta's WhatsApp Cloud API through the merchant's own Meta account — Meta's terms apply to message transport.

Retention and deletion

Personal data is kept for 90 days from the checkout. After that a daily sweep erases the phone number, the name and last name, the phone hash and the recovery link. The row itself survives carrying only non-identifying data — amount, currency, status, dates — so the merchant keeps their sales history. Access logs and data-request records are deleted after 365 days.

Recupera also implements Shopify's mandatory privacy webhooks: customer data requests are answered within 30 days; a customer redaction request erases those same personal fields right away, without waiting for the 90 days; and when a store uninstalls, all of its data is permanently deleted after Shopify's 48-hour redaction window.

One deliberate exception: a suppression outlives the data it came from, along with the hash pairing that makes it work across the two formats a phone number can take. Deleting it would start sending messages again to someone who asked us to stop. It holds no phone number — only irreversible hashes.


Recupera — Política de privacidad

Última actualización: 13 de agosto de 2026

Quiénes somos

Recupera es una app de Shopify que ayuda a los comerciantes a recuperar checkouts abandonados enviando mensajes de WhatsApp desde la cuenta de WhatsApp Business del propio comerciante (API oficial de Meta). Contacto: jotamoraga12@gmail.com.

Qué datos procesamos

Por cada tienda que instala Recupera procesamos: dominio y nombre de la tienda, token de acceso de Shopify y los datos del checkout abandonado — valor del carrito, moneda, productos (título y cantidad), el link de recuperación del checkout y el teléfono, el nombre y el apellido del cliente cuando el checkout los trae.

El consentimiento de marketing decide si le escribimos a un cliente, no si su checkout queda registrado: un carrito abandonado sin consentimiento se guarda igual que cualquier otro, y por él nunca sale ningún mensaje.

También guardamos las credenciales de WhatsApp Business que el comerciante conecta (token, IDs de cuenta), un registro de los mensajes enviados (estado de entrega, fechas), una bitácora de cada vez que se descifra un campo personal (qué campo y para qué — nunca el valor) y huellas irreversibles de los teléfonos, que usamos para la lista de bajas, para hacer coincidir el número que reporta WhatsApp con el que se escribió en el checkout y para limitar con qué frecuencia se le puede escribir a la misma persona.

Para qué los usamos

Un solo propósito: enviar mensajes de recuperación de checkouts abandonados en nombre del comerciante y medir las ventas que esos mensajes recuperan. No vendemos datos, no los usamos para publicidad y no contactamos a los clientes por ningún otro motivo. El comerciante es el responsable del tratamiento; Recupera actúa como encargado.

Consentimiento y baja

Recupera solo escribe a clientes que aceptaron marketing por SMS/mensajes en el checkout. Si un cliente responde pidiendo no recibir más (por ejemplo "baja", "stop"), su número entra a una lista de supresión —guardada como huella irreversible— y no vuelve a recibir mensajes desde ese número de WhatsApp, incluidas las demás tiendas en las que el mismo comerciante lo tenga conectado. Responder "ALTA" levanta la baja. Los dos avisos van al pie de cada mensaje de marketing.

Seguridad

Teléfonos, nombres y tokens se cifran en reposo (AES-256-GCM). Donde un número solo se compara y nunca se vuelve a leer —la lista de bajas, el límite de frecuencia— se guarda como huella irreversible con clave en lugar de cifrado. El identificador que devuelve WhatsApp por cada mensaje lleva adentro el número del destinatario, así que también se guarda solo como huella. Todo el tráfico va por TLS. Los datos se alojan en Railway (PostgreSQL, región EE.UU.). Los mensajes los entrega la API de WhatsApp Cloud de Meta a través de la cuenta del propio comerciante.

Retención y eliminación

Los datos personales se conservan 90 días desde el checkout. Cumplido el plazo, una purga diaria borra el teléfono, el nombre y el apellido, la huella del número y el link de recuperación. La fila sobrevive con datos que no identifican a nadie —monto, moneda, estado, fechas— para que el comerciante conserve su histórico de ventas. La bitácora de accesos y las solicitudes de datos se borran a los 365 días.

Recupera implementa además los webhooks de privacidad obligatorios de Shopify: las solicitudes de datos se responden dentro de 30 días; una solicitud de eliminación borra esos mismos campos personales de inmediato, sin esperar los 90 días; y al desinstalar la app, todos los datos de la tienda se borran definitivamente tras la ventana de 48 horas de Shopify.

Una excepción deliberada: la baja sobrevive a los datos de los que salió, junto con la equivalencia de huellas que la hace funcionar entre las dos formas que puede tomar un mismo número. Borrarla haría que esa persona volviera a recibir los mensajes que pidió no recibir. No contiene ningún teléfono, solo huellas irreversibles.