Who we are
WEĦDA, also written “wehda”, is a service of Wehda LLC, a Wyoming limited liability company, 30 N Gould St, STE R, Sheridan, WY 82801, USA (“we”, “us”). Wehda LLC is established in, and run from, the United States only. WEĦDA helps independent stores promote each other. After a buyer orders from one store, the buyer can receive a gift: a coupon for their next order at that store, a coupon for a partner store, or both.
Each store is responsible for its own customers’ information. WEĦDA handles buyers’ order information for the stores, as their service provider (under the GDPR and the UK GDPR, their processor), under the terms each store accepts. One part of WEĦDA works across stores: when a buyer uses a coupon from one store’s gift at another store, we check the coupon, record that order with the gift and credit the store that gave it, and we keep the accounting that shares exposure between stores. Where the GDPR or the UK GDPR applies, the stores involved and we are joint controllers of that part, as The part shared between stores explains. Wehda LLC alone is responsible for information about stores and their staff, for invitation requests and for this website.
WEĦDA is in a private pilot. Only stores we invite can use it.
What this notice covers
- this website, wehda.one, and its invitation request form;
- the WEĦDA app for Shopify;
- the wehda for WooCommerce plugin for WordPress;
- the merchant console, where stores manage WEĦDA;
- the gifts, coupons and wallet passes buyers receive, and the pages that help them save a pass on a phone.
Each store has its own privacy policy for its own customers. This notice covers only what WEĦDA does, for stores, buyers and visitors wherever they are, including the European Union and the United Kingdom. The terms for stores are in our terms of service and data processing terms.
This website and invitation requests
Our pages set no cookies of their own and use no analytics or tracking. They load their fonts, images, film and scripts only from wehda.one. Cloudflare hosts the website. Like any web host, it receives your IP address and browser details when you visit, and it may set a security cookie of its own.
Other companies may collect information about your activity over time and across websites when you use WEĦDA, but only those this notice names, under their own policies: for example Cloudflare, which carries all traffic to this website and our servers, and Apple or Google if you save a pass. A store’s own pages, where WEĦDA’s gift appears, may use their own tools, under the store’s privacy policy. We treat every browser the same, whether or not it sends a Do Not Track or Global Privacy Control signal: we don’t sell or share personal information, so there is nothing for the signal to switch off.
If you request an invitation, we store:
- your email address;
- your store’s web address, or that you don’t have an online store;
- when you sent the request, and which version of the notice beside the form you saw.
We use your email address only to contact you about availability and invitations, as the form says. If your store joins the pilot, we use the email address you accept our terms from to run the pilot with you, including notices about the service and our terms. We never sell either address or share it for anyone else’s purposes. We don’t check that the address or the store is yours, and we don’t send a confirmation email.
The form may suggest a store address from your email’s domain. Your browser works this out itself; nothing is sent until you submit. When you submit, the form service uses your IP address for a moment to limit repeated attempts, and doesn’t store it. Invitation requests are stored with Cloudflare.
Stores that use WEĦDA
For each store that uses WEĦDA, we hold:
- the store’s name, web address and currency;
- for a Shopify store: its myshopify.com address, and the access Shopify grants the app, which lets WEĦDA create and end discount codes, read the store’s orders and fulfilments, and route save links through the store’s address;
- for a WooCommerce store: the site’s address and public key, its logo, which we fetch from the address the plugin reports, and the profile the plugin sends: whether prices include tax, the WordPress, WooCommerce and plugin versions, the site’s REST API address, whether WP-Cron is disabled, and the coupon limits you set;
- the choices you make in the console: the stores you promote, the stores you let promote yours, your offer, your gift settings and your preferences;
- records of where each store’s offers appeared, of sales made with WEĦDA coupons and their amounts, and the accounting our system uses to balance what each store gives and receives.
WEĦDA’s service doesn’t store the names or email addresses of a store’s owner or staff, even where Shopify’s notifications include them. When someone opens the console from WordPress, or unlocks a gift by hand, we record their WordPress or Shopify user number, never their name, as a record of who did it. We also keep the email address you gave us when you joined the pilot, our emails with you, and a record of your store’s acceptance of our terms.
The console for Shopify stores opens inside Shopify’s admin and uses Shopify’s sign-in. When you open the console from WordPress, we set one cookie that keeps you signed in. It ends after 30 minutes without use, and after 12 hours at most.
For your own privacy policy
You can adapt this paragraph: “We use WEĦDA, a service of Wehda LLC, to offer you a gift after you order: a coupon for your next order with us, a partner store’s coupon, or both. WEĦDA receives facts about your order, such as its number, dates, status, amounts, currency, discount codes and refunds. [For a WooCommerce store: It doesn’t receive your name, email address, postal address or what you bought.] [For a Shopify store: Our order notifications to WEĦDA also carry what you bought and can carry your contact details, which WEĦDA doesn’t keep.] If you use a partner store’s coupon, that store sees that your order came through our gift, and we see that the coupon was used. WEĦDA’s privacy notice: https://wehda.one/privacy.”
If the GDPR or the UK GDPR applies to your store, also say that you, the partner store and Wehda LLC are joint controllers of the part shared between stores, and point to that section of this notice.
Buyers
When a buyer orders from a store that uses WEĦDA, we receive facts about that order:
- its order ID at the store, when it was placed and paid, its status, and whether it needs shipping;
- its currency and amounts: total, subtotal, discounts, tax, and any refunds with their amounts and times;
- the discount codes used on it (from a WooCommerce store, only WEĦDA’s own codes);
- for a Shopify order, also the amounts and status of its payments, its fulfilments, and how many of its items were fulfilled, which show when the order is complete.
A WooCommerce store’s plugin sends these facts only for orders that concern WEĦDA: orders whose page asks WEĦDA for a gift, and orders that use a WEĦDA coupon. Shopify sends us a notification each time any order at the store changes, with the whole order as Shopify provides it, which can include what the buyer bought and their contact details. We read only the facts above. We keep them for orders that received a gift or used a WEĦDA coupon; for an order that received no gift, we keep only its ID, when we decided and why.
When a buyer uses a WEĦDA coupon, the store where it is used sends us the same facts about that order.
We use these facts to decide whether an order earns a gift, when a coupon becomes usable, whether a refund or cancellation changes it, and which store to credit when a coupon is used.
What stores see: the store where a buyer uses a partner coupon sees in its console that the order came through the other store’s gift, with the order’s amount and time. The store that gave the gift sees that its partner coupon was used and at which store, but not the order, its amount or anything about the buyer. Every store in the pilot sees the other stores’ names and web addresses in the console’s list of stores. Buyers see a store’s name and offer on gifts and wallet passes.
With each gift we keep its reference number, its coupons (their codes, terms and expiry), the partner store it names, its state and when that changed, and the reasons for our decisions, such as why an order received no coupon. The buyer’s browser also tells us its time zone, so that dates show in local time. We keep that time zone with the coupon.
To show a gift, the order page sends us proof that the order is real. On WooCommerce, this is a short-lived token that the store’s site signs. On Shopify, it is Shopify’s checkout token, of which we keep only a keyed fingerprint.
When a buyer’s browser or phone contacts our servers, we see its IP address and browser details, as any website does. We use the browser details for a moment to show the right wallet button. Our application doesn’t store IP addresses or browser details.
Wallet passes and saving to a phone
A buyer can save a gift to Apple Wallet or Google Wallet. A pass shows the coupon: the stores’ names, the offer, its code and a link to use it, when it expires, and the gift’s reference number. It doesn’t show the buyer’s name, email address or order details.
Apple Wallet
When a pass is added to Apple Wallet, the device registers with our server so that we can update the pass, for example when a coupon becomes ready to use. We store, encrypted, the device identifier and the push token Apple provides. When a pass changes, we send Apple’s push service only a signal to fetch it; the pass itself comes from our server. When the pass is removed, the device tells us, and we delete that registration.
Google Wallet
To save a pass to Google Wallet, we create the pass with Google, and Google keeps it in the buyer’s Google Wallet. Google can show notifications about the pass; we send at most three in any 24 hours. Google tells us whether a pass has been saved, but not by whom. Google’s own privacy policy applies to Google accounts.
Saving on another device
If a buyer opens the gift on a computer, the page can show a QR code for saving the pass on a phone. The page draws the code itself, so no separate QR service sees the link. The link lets anyone who has it save that pass, and nothing else. We don’t record when it is scanned. It stops working when all the gift’s coupons have ended, when the gift is erased, or when the store’s connection to WEĦDA changes, for example when it leaves or reconnects.
Save links pass through the store’s own domain. On Shopify, they pass through Shopify. On WooCommerce, they pass through the store’s website, so its host, and any content network, cache, firewall or security plugin in front of it, can see and record them, for example in access logs.
What we never collect
- From WooCommerce stores, WEĦDA never receives buyers’ email addresses, names, postal addresses, phone numbers or customer IDs, their order keys, the items they bought, their cookies or passwords, or their payment details. These stay on the store’s site.
- From Shopify stores, we don’t store buyers’ names, email addresses, postal addresses, phone numbers or payment details, even when Shopify’s notifications include them.
- We never store payment card details.
- We don’t build profiles of buyers. We connect two orders only through a WEĦDA coupon: when a buyer uses a coupon from one store’s gift at another store, we record that order with the gift, to check the coupon and credit the store that gave it. We don’t use that link for anything else, and we don’t follow buyers across stores or websites in any other way.
- Whether a gift includes a partner’s coupon depends on the store’s settings and the order. Which partner it names depends on the stores’ choices and our exchange rules, not on information about the buyer.
- We don’t sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising.
How we use information
- to run WEĦDA: to show gifts, create and end coupons, update passes and credit sales;
- to share exposure fairly between stores;
- to keep WEĦDA secure and working, and to find and fix problems;
- to carry out privacy requests;
- to contact stores in the pilot, and people who requested an invitation, about WEĦDA;
- to meet our legal duties, and to establish or defend legal claims.
We don’t use it for anything else.
WEĦDA decides automatically whether an order earns a gift, when its coupons become usable and which partner a gift names. None of these decisions has a legal or similarly significant effect on anyone, and WEĦDA makes no decision about anyone that does.
Why we may use information
Some laws, such as the GDPR and the UK GDPR, ask us to say on what basis we use information:
- Buyers’ order information we handle for a store: the store decides on what basis, and its privacy policy says so.
- The part shared between stores: our and the stores’ legitimate interests in honouring coupons across stores, crediting the store that sent a buyer, sharing exposure fairly and stopping fraud.
- Information about a store and the people who manage it: to run our agreement with the store, because we need it for that; and for the people who manage a store, our legitimate interests in running that agreement with them and in knowing who did what in the console.
- Invitation requests: to answer the request you sent us, because you asked us to.
- Our emails with you: to answer you and run the pilot, as above. We keep a store’s acceptance of our terms because of our legitimate interest in showing what was agreed.
- Security, logs and database copies: our legitimate interests in keeping WEĦDA and this website secure and working, stopping fraud and being able to recover from a failure.
- Privacy requests and other legal duties: to meet our legal duties.
- Legal claims: our legitimate interest in establishing or defending them.
An invitation request needs an email address, and a store can’t use WEĦDA without the facts about its orders. Otherwise, no law or contract requires you to give us information.
The part shared between stores
When a buyer uses a coupon from one store’s gift at another store, the store that gave the gift, the store where the coupon is used, and Wehda LLC decide together how that order is checked and credited, and we keep the accounting that shares exposure between stores. Where the GDPR or the UK GDPR applies, we are joint controllers of this part. Our data processing terms with the stores set out who does what:
- each store tells its own buyers, in its privacy policy, that it uses WEĦDA and what partner stores see, and this notice describes this part;
- a buyer asks the store they bought from about their information, and that store uses its platform’s privacy tools, which reach us and which we act on;
- we keep this part secure, deal with any breach in it and tell the stores involved;
- you can still use your rights with any of us, including by writing to Wehda LLC at [email protected]. We’ll help, or tell you how to ask the store.
Who else handles information, and where
Our service providers handle information for us:
- Google Cloud runs our servers and database, in its us-east1 region in the United States. Google’s Artifact Registry stores our server software, which holds no personal information.
- Cloudflare runs our domain’s DNS and carries all traffic to our servers through Cloudflare Tunnel. It decrypts that traffic to route it, and can keep logs of some of it under its own policies. Cloudflare also hosts this website and the plugin’s update files, and runs the invitation request form and stores its requests.
- Apple’s iCloud Mail hosts our mailbox, [email protected], and carries the email we send and receive.
Others handle information for their own services, under their own terms:
- Apple provides Apple Wallet and the push service that tells a device a pass has changed, when a buyer saves a pass to Apple Wallet.
- Google provides Google Wallet, when a buyer saves a pass to Google Wallet.
- Shopify sends us order and privacy information for Shopify stores, and shows the WEĦDA app in the store’s admin and checkout.
- For a WooCommerce store, the store’s own website host carries the plugin’s requests and its save links.
We hold information in the United States. Our operator also handles it on our own computers in the United States, for example to answer email and to run and check the pilot. Our providers may process it in the United States and in other countries where they operate.
If you are in the European Union or the United Kingdom, information about you comes to us in the United States, where the law may protect it differently. When you send us information yourself, for example an invitation request, you send it to us there. When a store established in the European Union or the United Kingdom sends us its buyers’ information, the transfer is covered by the European Commission’s Standard Contractual Clauses, and for the United Kingdom by the UK’s International Data Transfer Addendum to them, which form part of our data processing terms with the store. You can ask us for a copy.
We may also disclose information when the law requires it, for example to answer a valid court order, or when needed to protect WEĦDA’s security or someone’s safety.
How long we keep information
- Invitation requests: 12 months after you make the request, or sooner if you ask us to delete yours. After we delete one, Cloudflare’s recovery copies of that database can keep it for up to 30 days.
- Our emails with you: while your store uses WEĦDA or we hold your invitation request, and for up to 12 months after. A store’s written acceptance of our terms: while the terms apply to the store, and for 6 years after, to show what was agreed.
- Store information: while the store uses WEĦDA. When it leaves, we erase it as described below.
- Order information: for an order that received a gift (the gift, its coupons and rewards, its save links and wallet registrations, and our records of the order), while the gift can still be used, and then until 12 months after its last coupon ended, whether it was used, expired, withdrawn or ended in another way. For an order that received no gift, 12 months after we last processed it. We then erase it in the same way as a privacy request does, unless a privacy request erases it sooner.
- Records of the notifications and requests we receive: except a data request’s export, described under Your choices and rights, they name no order, and go 12 months after we receive them. Our requests to a WooCommerce store’s site, with its answers, go 12 months after the site answered, except those we still need for a coupon or for an order’s facts, and those the site never answered, which we keep while the store uses WEĦDA. Once the order they concern is erased, we delete them, except those we still need to end one of its coupons, which go with that coupon’s records.
- When a store leaves: Shopify asks us to erase a store’s data 48 hours after it uninstalls the app, and we do. A WooCommerce store’s data is erased once it has stayed disconnected for our waiting period, which is 48 hours unless we set a longer one, and never longer than 30 days. If a site stops without telling us, its store counts as connected, and isn’t erased, until the store tells us or we record that it has left. If a store reinstalls or reconnects before its data is erased, nothing is erased.
- After an erasure, besides the records of notifications and requests above, we keep only: for each erased order, a coded marker, made with a secret key we hold for its store, so that we don’t process the order again, which we delete with the key when we erase the store’s data after it leaves; what we need to make the erased gift’s coupons stop working and to send passes already saved their final update, such as each coupon’s code and the store it is for, and the pass’s serial number, access key and identifier, which we delete 30 days after the erasure or, if one of those coupons, or the discount on the store that it belongs to, can still be used then, a few days after none can; and our exchange accounting, described next. What else remains of an erased order in our database is anonymous: it can’t reasonably be linked to anyone, we keep it only in that form, and we don’t try to identify anyone from it.
- Our exchange accounting (where offers appeared and which sales were credited, with the stores involved and each sale’s amount and time, but no order number, code or buyer detail): while the pilot runs, and deleted within 30 days after it ends; after a store leaves, under a number that no longer names it. A store’s console lists a sale made at it only until we erase that order’s information.
- Our list of admitted stores and our operator’s history of changes to it: while the pilot runs, and deleted within 90 days after it ends, except the records of stores’ acceptance of our terms described above.
- Apple Wallet registrations: until the pass is removed from the device, or the gift is erased. After the gift is erased, we keep the device’s coded identifier and encrypted push token only to send the pass its final update, and delete them once the device has picked up that update, or Apple tells us its push token is no longer valid, and otherwise 30 days after the erasure.
- Our application logs: kept on our server in a few files of fixed size, where the oldest entries are overwritten as new ones arrive. They hold no buyer’s contact details, and we design them to leave out codes, save links, tokens and device identifiers.
- Database copies: before we update the service, we make an encrypted copy of its database and keep it on our server in Google Cloud. We delete each copy within 30 days of making it, and any copy on our operator’s own computer within 30 days too. Until then, data erased from the live database can remain in them.
- Other parties’ records: Cloudflare, Apple, Google and Shopify keep their own records under their own policies, and a WooCommerce store’s host keeps its own logs. Our erasure doesn’t reach those. A pass already saved on a phone can’t be recalled; after erasure we update it so that it no longer works, where the wallet allows.
Your choices and rights
Buyers
Ask the store you bought from. The store can export or erase your information with its platform’s privacy tools, which reach WEĦDA:
- On Shopify, the store’s customer data requests and erasure requests reach us through Shopify. For a data request, we prepare an export that the store downloads from its console. We keep that export, with the Shopify customer number the request names, until the store’s data or that customer’s orders are erased, and never longer than 12 months after we made it. For an erasure request, we erase the orders Shopify names. Shopify can hold an erasure request for up to six months before sending it to us.
- On WooCommerce, WordPress’s Export Personal Data and Erase Personal Data tools reach us through the plugin. The plugin sends us only the numbers of the orders involved, never your email address. For an export, we send back what we hold and keep no copy of it.
An erasure removes the gift from those orders and makes their unused coupons stop working at every store that still uses WEĦDA. You can also remove a pass from your wallet at any time.
Stores
- You can see and change your settings in the console at any time.
- You can leave at any time by uninstalling the Shopify app or disconnecting the plugin. We then erase your store’s data as described above.
Everyone
You can ask us what we hold about you, and ask us to correct or delete it. Email [email protected] or write to us at the address below, and tell us what your request is about, for example the email address you used to request an invitation, or your store’s web address. We may ask you to confirm the request from that email address, or from your store’s admin, before we act. We hold buyers’ information for the stores and can’t find it by a buyer’s name or email address, so if you bought from a store, please ask the store; if you write to us, we’ll tell you how. Depending on where you live, the law may give you further rights.
In the European Union and the United Kingdom
If you are in the European Union or the United Kingdom, you can also ask us to limit how we use your information, or for a copy of the information you gave us in a common format. You can complain to a data protection authority, for example where you live or work; in the United Kingdom, this is the Information Commissioner’s Office. For buyers’ order information we handle for a store, ask the store first; we’ll help it answer.
Your right to object
Where we use your information because of our legitimate interests, you can object at any time, on grounds relating to your situation. Email [email protected]. We’ll then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need the information to establish or defend legal claims.
Security
- Connections to WEĦDA over the internet use HTTPS.
- Web traffic reaches our servers only through Cloudflare Tunnel. The servers publish no web ports, and the database can’t be reached from outside. Only our operator can administer the servers, through Google’s identity-aware access.
- Everything the WooCommerce plugin sends our server is signed with a key that never leaves the store’s site, and the plugin carries out only work our server signs. That work is limited to creating, lowering, ending and looking up WEĦDA coupons within the store’s limits, and reading the store’s profile and the facts of orders that concern WEĦDA. Our server holds no WooCommerce API key or password, and no key that could sign for the site.
- Save links and other access links carry long random tokens, and our application keeps them out of its logs.
- Plugin updates are signed, and the plugin checks the signature before installing one.
No system is perfectly secure.
Children
WEĦDA is a service for businesses. It isn’t meant for children under 13, and stores may not use it on a store, or part of a store, directed to children under 13. We don’t knowingly collect personal information from children under 13, and the information we hold about buyers doesn’t include their name or age. If we learn that we have, we’ll delete it. If you think we hold such information, email [email protected].
Changes to this notice
We’ll update this notice when WEĦDA or the pilot changes, and publish each version on this page with a new date. Each version takes effect on the date shown at the top of this page. If a change affects stores using WEĦDA, we’ll email them at least 30 days before it takes effect, as our terms of service describe for changes to them.
Contact
WEĦDA is a service of Wehda LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA. For any question, request or complaint about your information, email [email protected].
- If you bought from a store that uses WEĦDA, contact that store. It can reach us through its privacy tools, as described above.
- If your store takes part in the pilot, you can also reply to the email we invited you with.
- If you requested an invitation, you can also reply to any email we send you.
- By post, for any request about your information: Wehda LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA.
