Privacy Policy

Last updated: September 2026

Who this policy is for

Nonito is a marketing automation platform sold to businesses. Two different groups of people appear in this policy, and we treat them differently.

  • Our customers are the businesses that use Nonito: retailers, restaurants and other merchants. We hold their account and billing information, and we decide how that information is used.
  • Their customers are the shoppers who buy from those businesses. We hold information about shoppers only because a merchant asked us to, and only so that we can carry out what that merchant has set up.

For shopper information, the merchant decides and Nonito acts on their instructions. In data protection terms the merchant is the controller and Nonito is the processor. We do not use shopper information for our own purposes, we do not combine it across merchants, and we never sell it.

If you are a shopper and you want your information removed, please contact the store you bought from. They can instruct us to erase it, and we will.

1. Information We Collect

From our customers. Information you provide when you use Nonito:

  • Account details and registration information
  • Campaign data and content
  • Payment and billing information
  • Usage statistics and analytics data

About shoppers, on a merchant's behalf. When a merchant connects a store to Nonito, or uploads a contact list, we receive information about their customers. Depending on what the merchant has connected, this may include:

  • Name
  • Email address
  • Phone number
  • Delivery city and province
  • Order history, including order value, items and status
  • Messages we have sent on the merchant's behalf, and any replies

For merchants using Shopify, this information reaches us through the Shopify Admin API and Shopify webhooks, with the merchant's permission, granted when they install our app. For merchants using other platforms or point of sale systems, it reaches us through the connection they set up.

2. How We Use Your Information

Nonito uses information from our customers to:

  • Provide, improve, and personalise our services
  • Send transactional messages and updates
  • Process payments and maintain billing records
  • Analyse service usage and optimise performance
  • Fulfil legal obligations and enforce our terms

Shopper information is used only to carry out what the merchant has configured: grouping their customers into audiences, and sending the messages the merchant has set up. It is not used to train models, it is not shared with other merchants, and it is not used for any purpose the merchant has not asked for.

Marketing choices. Where a shopper has unsubscribed from a merchant's marketing, we record that and stop sending them marketing messages on that merchant's behalf. Messages about their own orders, such as confirmations, delivery updates, cancellations and refunds, continue. For merchants using Shopify, we receive the shopper's marketing preference from Shopify and apply it automatically.

3. How Long We Keep It

We keep personal information only for as long as it is needed for the purposes described above.

  • Customer account information is kept while the account is open, and for a period afterwards to meet legal and accounting obligations.
  • Shopper order records are kept while the merchant's account is open. These are the merchant's own business records and we hold them on the merchant's behalf.
  • Message history is kept for 24 months.
  • Raw activity events are kept for 30 days.

When a merchant closes their account or disconnects our app, we delete the shopper information we held for them. For merchants using Shopify this happens within 48 hours of uninstalling, in line with Shopify's requirements. For other merchants it happens within 90 days, so that an accidental disconnection can be reversed.

4. Sharing of Information

We do not sell personal information. We share it only in these situations:

  • To deliver messages. To send a WhatsApp message, SMS or email on a merchant's behalf, the recipient's phone number or email address is passed to the relevant messaging provider. We use specialist providers for WhatsApp, for SMS and for email.
  • To run the service. Our database and applications are hosted by cloud infrastructure providers, who store information on our behalf under contract.
  • When legally required. Where we are compelled by law or by a valid request from a public authority.
  • In a business transfer. In the case of a merger, acquisition or asset sale, subject to this policy continuing to apply.

A current list of the providers we use is available to merchants on request.

5. Data Security

We prioritise data security and use industry standard measures to protect information, including:

  • Encryption of data in transit and at rest
  • Encrypted backups, held to the same standard as live data
  • Isolation at the database level, so one merchant cannot access another merchant's information
  • Access controls and authentication measures, limiting staff access to those who need it to operate and support the service
  • Regular security audits and updates

No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

6. Your Rights

If you are a Nonito customer, depending on your location you may have rights to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your data
  • Object to certain data processing
  • Export your data

Please contact us at abdelgalil@nonito.io to exercise these rights.

If you are a shopper and you want to see or delete the information we hold about you, please contact the store you bought from. They are responsible for your information and can instruct us directly. If you would rather contact us, we will pass your request to the merchant concerned.

When a merchant asks us to erase a shopper, we remove that person's identifying details from our systems. The merchant's own sales records are kept, with the person removed from them, so that their accounting remains intact.

7. Updates to Privacy Policy

Nonito may update this Privacy Policy. Changes will be effective immediately upon posting on our website. We will notify you of significant changes via email or through our platform.

8. Contact Information

If you have questions about this Privacy Policy or your data, please contact us at abdelgalil@nonito.io.

CHAT WITH US • CHAT WITH US •