Privacy Policy

Last updated 10 August 2026

What we collect, how long we keep it, and what you can ask us to do with it.

This document is published in English only. The English version is the one that applies.

Who is responsible for what

Nasara Core is the data controller for the Omoja platform: merchant accounts, storefront content, billing records and site analytics.

Each business is the data controller for its own orders and customer conversations. That covers the contact details a buyer gives at checkout, which we hold on that business’s behalf, and the chat itself. Once a buyer presses the WhatsApp button, the conversation belongs to the buyer and the business. It happens on WhatsApp, not on Omoja, and we have no access to it and keep no copy of it.

What we collect from merchants

If you run a store on Omoja, we hold:

  • Your account details: email address, password in hashed form, and when you verified your email.
  • Your store details: name, web address, description, logo, currency, country and city, the WhatsApp number you publish, any social usernames you add, and any payment notes you write.
  • Your catalogue: products, variants, prices, stock and photographs.
  • Billing records: your plan, what you have paid for and until when, and the reference our payment processor gives us. We never see or store your card number.
  • Security records: sign-in sessions, and an audit trail of significant account actions.

What we collect from buyers

You do not need an account to browse a store, and browsing asks nothing of you.

Placing an order does. Before the WhatsApp hand-off we ask for your name and a phone number, and optionally an email address. This is so the seller knows who the order is from and can reach you if the chat never opens or you get cut off part way through — which happens often enough that orders were being lost to it. Giving a number you can be reached on is the point of the field.

These details are stored on the draft order, which the seller of that store can see in their dashboard. They are not shared with any other store, and they are not used to market anything to you by us.

The draft order also holds the items, quantities and prices, so the seller can look it up by reference and see what actually sold. It is deleted automatically thirty days after it is created, and your details go with it. What you and the seller then say to each other happens on WhatsApp, not on Omoja, and we keep no copy of it.

Your name and number are also saved in your own browser, so you do not have to type them again at the same store. Clearing your browser data removes that copy.

Analytics, and why there is no cookie banner

We count page views, cart additions and confirmed sales, so a business can see what is working. This is deliberately built so that it does not identify anybody.

We do not set analytics cookies and we do not track you from one site to another. Instead, a visit is tagged with a one way hash computed from ordinary request details combined with a secret value that changes every day. The previous day’s secret is discarded, which means yesterday’s visits cannot be linked to today’s even by us. There is no profile to build, and nothing to opt out of.

A business sees totals and trends. It never sees a list of visitors, because no such list exists.

How long we keep things

We delete on a schedule rather than on request alone:

  • Individual analytics events: 90 days, after which only daily totals remain.
  • Draft orders, including the buyer contact details on them: 30 days from creation, then deleted automatically.
  • Sign-in sessions: 30 days, or until you sign out.
  • Account and store data: for as long as your store exists, then removed when you close it.
  • Billing records: kept longer where tax and accounting law requires it, even after a store closes.

Who else sees your data

We do not sell personal data, and we do not share it for advertising. We use a small number of providers to run the service, and each one only receives what it needs:

  • Paystack, to take subscription payments and to tell us that a payment succeeded.
  • Our hosting and database providers, which store the data described above.
  • Our email provider, to send verification, password reset and billing notices.

We may also disclose data

Where we are legally required to, where it is necessary to investigate fraud or a breach of the Acceptable Use Policy, or to establish or defend a legal claim.

Where your data is held

Omoja is hosted in the European Union. Data may be processed in other countries by the providers listed above, under contractual protections for international transfers.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict how we use it, or object to a use. Two of these are self-serve and immediate:

  • Export: download everything in your store as a single file from your dashboard settings, at any time, without asking us.
  • Deletion: close your store from your dashboard settings. This removes your account and your store data and cannot be undone.
  • Anything else: email info@ussdly.com and we will answer within 30 days.

Buyers asking about a specific order

If you bought from a business on Omoja and want your order details corrected or removed, contact that business directly. They hold the conversation and the sale. If they do not respond and you believe your rights are being ignored, write to us and we will help you reach them.

Children

Omoja is not intended for children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.

Complaints and changes

If you are unhappy with how we handle your data, tell us first, and you also have the right to complain to your local data protection authority.

We will post any change to this policy here, with a new date at the top, and email merchants about anything significant.