Skip to content
CodScale
Back to home

Privacy policy

Last updated: September 15, 2026

CodScale is an operations platform for cash-on-delivery merchants. This policy explains what data we collect, why, who we share it with, and the choices you have. It applies to codscale.co, the CodScale dashboard, storefront funnels hosted by CodScale, and related APIs.

1. Who we are

CodScale ("we", "us") operates the CodScale platform. For data you upload about your business and your customers, you — the merchant organization — are the data controller and CodScale acts as your processor. For your own account data and website visits, CodScale is the controller.

Contact for privacy matters: support@codscale.co.

2. Data we collect

We collect the following categories of data:

  • Account data: name, email, phone number, password hash, role, organization, language, and login activity (IP address, device, time).
  • Business data you upload or connect: products, prices, stock, stores, businesses, team members, wallets, expenses, salaries, documents, and media.
  • Order and customer data: names, phone numbers, addresses, states and cities, order contents, confirmation outcomes, parcel status, payments, and follow-up notes for the end customers of your stores.
  • Communication data: WhatsApp, Messenger, Instagram, TikTok, SMS, and email messages exchanged through connected channels, including AI confirmation conversations.
  • Integration data: tokens and identifiers for connected platforms (Shopify, Lightfunnels, YouCan, WooCommerce, Google Sheets, Meta, TikTok, carriers) and the data they return.
  • Storefront funnel data: sessions, page views, form interactions, orders, and the pixel or server-side events you configure for your own pages.
  • Usage and technical data: pages visited, features used, browser, device, approximate location, and diagnostic logs.

3. How we use data

  • Run the platform: orders, leads, confirmation, parcels, shipping, finance, and team access.
  • Operate AI features you enable, such as WhatsApp confirmation, follow-up, marketing content, and the AI assistant. Prompts include only the business context needed for the task.
  • Send order lifecycle events (Lead, Purchase, OrderConfirmed, OrderDelivered) to Meta or TikTok when you configure tracking for a store or funnel. Customer identifiers are hashed before they leave our servers.
  • Create and track parcels with the carriers you connect.
  • Send notifications you opt into (email, SMS, WhatsApp templates, in-app).
  • Secure accounts, prevent fraud and abuse, and debug incidents.
  • Improve the product using aggregated, de-identified usage metrics.
  • Comply with legal obligations and enforce our terms.

4. AI processing

AI features use third-party model providers. We send only the data required for the specific task (for example the order details needed to confirm a lead). We do not use your data to train our own models, and our providers are contractually restricted from training on it. AI outputs are suggestions; you remain responsible for messages and content sent under your brand.

5. Who we share data with

We share data only as needed to deliver the service:

  • Carriers and delivery providers you select, to create and deliver parcels.
  • Sales channels you connect (Shopify, Lightfunnels, YouCan, WooCommerce, Google Sheets).
  • Advertising platforms you connect (Meta, TikTok), limited to the events and hashed identifiers you configure.
  • Messaging providers (WhatsApp Business, Meta, TikTok, SMS, email) to send and receive messages.
  • AI model providers, as described above.
  • Infrastructure, hosting, storage, and monitoring vendors bound by data-processing agreements.
  • Authorities when required by law, or to protect the rights and safety of CodScale, merchants, or the public.
  • A successor in the event of a merger or acquisition, under the same protections.

We do not sell personal data.

6. Your customers' data

You decide what customer data enters CodScale and how it is used. You are responsible for having a lawful basis to collect it, to contact customers by phone or WhatsApp, and to send advertising events. We process it only on your instructions and delete or export it on request when your organization is closed.

7. Retention

Account and business data are kept while your organization is active. Order, parcel, and finance records are kept for the period required by accounting and tax rules. Login activity and technical logs are kept for up to 12 months. Storefront session analytics are aggregated after 90 days. When an organization is deleted, personal data is erased or anonymized within 60 days, except where retention is legally required.

8. Security

Data is encrypted in transit and at rest. Access is scoped by organization, business, and store, and gated by permissions. Integration tokens are stored encrypted. We log administrative access and review it. No system is perfectly secure; report suspected issues to support@codscale.co.

9. Cookies and tracking

codscale.co and the dashboard use strictly necessary cookies and local storage for authentication, language, and theme. Storefront funnels load only the pixels their merchant configures; that merchant is responsible for the notices required on their pages.

10. Your rights

Depending on your country you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Account holders can update most data in the dashboard. For everything else, or if you are a customer of a CodScale merchant, email support@codscale.co and we will help or forward your request to the responsible merchant.

11. International transfers

CodScale is operated from Algeria and uses infrastructure providers that may process data in other countries. Where required, we rely on contractual safeguards for those transfers.

12. Children

CodScale is a business tool and is not directed at children under 16. We do not knowingly collect their data as account holders.

13. Changes

We may update this policy as the platform evolves. Material changes are announced in the dashboard or by email before they take effect. The date at the top shows the current version.