Privacy Policy
Last updated 2026-09-05
Dafatir is a trading brand of Tal3a E-Commerce Company, the registered company that operates every product named here and the data controller for the information this policy covers. Dafatir builds software that shops use to run their business: a point of sale for the counter, accounting books for the office, and Hiwar, an inbox for the WhatsApp and Instagram messages customers send a shop. This policy explains what personal information we handle, why we handle it, and what you can ask us to do about it. It covers this website and every Dafatir product. Questions go to admin@dafatir.app.
Who is responsible for which information
Tal3a E-Commerce Company, trading as Dafatir, stands in two different relationships to the information it holds, and your rights depend on which one applies to you.
- Merchants, their staff, and people who ask us to call them. Dafatir decides what is collected and why, so Tal3a E-Commerce Company is the controller of that information and this policy governs it directly.
- A merchant's own customers. When a shop uses Dafatir to serve its customers — a sale at the till, an invoice, a WhatsApp conversation — the shop decides what is recorded and why. The shop is the controller and Dafatir is its processor, acting on the shop's instructions. If you are a customer of a shop that uses Dafatir, ask that shop to change or delete your information; you can also write to us and we will pass the request on.
What information we handle
Some of this is given to us directly, some is produced as the products are used, and some arrives from Meta on a merchant's behalf.
- Merchant and staff accounts: name, phone number, email address, the role assigned to each person, and the credential used to sign in. Passwords are stored only as a one-way hash, never as text anyone at Dafatir can read.
- People who ask us to call: shop name, contact name, phone number, language, and which products they were interested in.
- A merchant's business records: products, prices, stock, sales, shifts, receipts, invoices, payments, expenses, and the ledger entries raised from them.
- A merchant's customers, where the merchant records them: name, phone number, address, purchase and invoice history, and loyalty balance.
- Where a merchant connects their ad account: the campaigns, ad sets and ads on it, the audiences, budgets and schedules they set, and what each one spent and produced — reach, clicks, conversions, and the conversations an ad started.
- Technical records needed to run and secure the service: IP address, browser or device type, timestamps, and error diagnostics.
WhatsApp, and what we receive from Meta
Hiwar connects a merchant's own WhatsApp Business Account to Dafatir through Meta's WhatsApp Business Platform. The merchant authorises that connection themselves in Meta's sign-up flow and can end it at any time, from WhatsApp or from Dafatir. While it is connected, we receive the following on that merchant's behalf.
- The WhatsApp phone number of anyone who messages the merchant, and the profile name WhatsApp shows for them.
- The content of messages sent to and from the merchant's number — text, photos, documents, voice notes, and shared locations — with their delivery and read status. We keep our own copy of media because the links Meta provides expire within minutes.
- Where a merchant chooses it while connecting, up to 180 days of their earlier conversations and the contacts from their WhatsApp Business app. Meta permits this import once, it runs only on the merchant's explicit consent, and every imported item is marked as imported so it can be deleted on its own.
- Where the merchant turns on calling, the metadata of calls placed through WhatsApp — who called whom, when, and for how long — and, only if the merchant also turns on recording, the recordings themselves.
- Details of the merchant's WhatsApp Business Account: display name, quality rating, messaging limits, and what Meta charged for each conversation, which we show the merchant so they can check our invoice against it.
We use all of this for one purpose: to deliver the merchant's conversations into their inbox, let their staff reply, keep the history they are paying us to keep, and pass Meta's charges through at cost. Meta processes the same messages under its own terms, and the merchant's own agreement with Meta governs that.
Instagram, and what we receive from Meta
Hiwar can also connect a merchant's own Instagram professional account to Dafatir through Meta's Instagram API. The merchant authorises that connection themselves with Instagram's own sign-in, granting only the two permissions the inbox needs — the account's identity and its direct messages — and can end it at any time, from Instagram's own settings under Apps and websites or from Dafatir. While it is connected, we receive the following on that merchant's behalf.
- The Instagram-scoped id and username of anyone who sends the merchant a direct message. Instagram does not give us their phone number, email, or anything from their profile beyond that.
- The direct messages exchanged between the merchant's account and their customers — text, media, reactions, and the buttons a customer taps — from the moment of connection onwards, and the replies the merchant's staff send from the inbox.
- The id and username of the merchant's own Instagram professional account, so the shop can see which account it linked and so each incoming message is routed to the right shop.
- The access token Meta issues for that connection. It is encrypted at rest with AES-256-GCM, renewed before it expires, and deleted the moment the merchant disconnects.
We do not read comments, publish posts, fetch insights, or follow anyone on the merchant's behalf; the connection carries direct messages and nothing else. Nothing we hold about a customer's Instagram account is used for advertising.
What we never do with it
These limits apply to everything above, and to WhatsApp and Instagram data in particular.
- We do not use it for our own advertising, and we do not build advertising audiences from one merchant's data for anyone else. Where a merchant asks us to run their campaigns, we work inside that merchant's own ad account, on their instruction, and only with their own data.
- We do not sell it, rent it, or hand it to data brokers.
- We do not use it to train machine-learning or AI models, and neither does our AI provider. Where a merchant turns Hiwar's AI features on, the text of the messages in their conversations is sent to Anthropic for analysis on that merchant's behalf — never their customer's name, phone number, or media — and Anthropic is contractually bound not to retain that text after processing it and not to train its models on it.
- We do not mix one merchant's information with another's. Every record belongs to exactly one merchant, and every query is confined to that merchant.
- Our staff do not read a merchant's conversations except where a named person needs to for support the merchant asked for, a security investigation, or a legal obligation — and every such access is recorded.
Why we handle it
We handle personal information only for the purposes below: to perform the contract we have with the merchant, for our legitimate interest in running and securing the service, on the consent you give where we ask for it, and to meet obligations the law places on us.
- To run the point of sale, the books, and the inbox the merchant subscribed to, and to keep them in step across the merchant's devices — including while a till is offline.
- To send and receive messages and calls on the merchant's number and keep one shared inbox in sync across their staff.
- To invoice the subscription, and to pass Meta's conversation and call charges through at cost.
- To create and manage advertising campaigns inside a merchant's own ad account where the merchant asks us to, and to report back what those campaigns spent and produced.
- To answer support requests and investigate faults a merchant reports.
- To keep the service secure, detect abuse, and prevent fraud.
- To meet legal, tax, and VAT obligations, including keeping the records the law requires us to keep.
- To call back people who asked us to, and to tell merchants about changes to the service they use.
Who else touches it
We do not sell personal information. We rely on a small number of service providers, each of which handles information only to do a job for us and is bound to protect it.
- Meta Platforms — carries WhatsApp messages and calls to and from the merchant's number, and Instagram direct messages to and from the merchant's Instagram account.
- Amazon Web Services — the servers and databases the service runs on, in Frankfurt, Germany.
- Cloudflare — stored media and encrypted backups, and protection in front of our websites.
- Anthropic — analyses the text of conversations where a merchant turns Hiwar's AI features on. Customer names, phone numbers and media are never sent, and Anthropic may not retain the text or train on it.
- Sentry — error diagnostics. Message content, credentials, and personal identifiers are stripped before a report leaves our systems.
- Statsig — feature flags and product measurement, on technical and usage signals rather than on message content.
- Banks and payment providers in Palestine and Jordan that collect subscription payments, and, where a text message carries a sign-in code, the operator that delivers it.
- Authorities, where a valid legal order compels disclosure. We tell the affected merchant unless the law forbids it.
If Dafatir is ever sold or merged, information moves with the business, and we will say so on this page before it does.
Where it is kept
Dafatir runs on servers in Frankfurt, Germany, and stored media and encrypted backups are held in the European Union. Merchants and their customers are mostly in Palestine, Jordan, and neighbouring countries, so information crosses a border to reach us. We use providers that commit to European data-protection standards for it.
How long we keep it
We keep information for as long as it is needed for the purpose it was collected for, and no longer.
- Conversations, contacts, and media: for as long as the merchant's subscription is active. Deleted on request, or after the account closes.
- Imported WhatsApp history: the same, and separately deletable — a merchant can delete what was imported without touching conversations that have happened since.
- Call recordings: 90 days by default. A merchant can shorten that, or not record at all.
- Sales, invoices, and ledger entries: kept for the statutory accounting and VAT period, which can run to ten years. These are kept even after an account closes, because the law requires it.
- Files we generate for an export or a report: 90 days, then deleted.
- Enquiries from people who asked us to call: deleted on request, and reviewed periodically.
When a retention period ends, the information is deleted or irreversibly anonymised. Security and audit logs are kept for a limited period so that a past incident can still be investigated.
How we protect it
Protecting a merchant's books and their customers' conversations is the basis of the product, not a feature of it.
- Traffic between a merchant device and our servers travels over HTTPS. Stored media sits in private object storage reachable only through the product, never by a public link.
- WhatsApp and Instagram access tokens, and the PIN Meta issues for a number, are encrypted with AES-256-GCM. They are never displayed in the product, never returned by our API, and never written to a log.
- Every record belongs to exactly one merchant, and every query the products run is confined to that merchant; the database carries row-level rules drawn on the same boundary. Within a merchant, what each member of staff can see follows the role they were given.
- Changes are written to an audit log, so who did what, and when, is answerable after the fact.
- Message content and credentials are stripped from diagnostics before they leave our systems.
No service can promise perfect security. If a breach affects a merchant's information, we will tell that merchant without undue delay, and explain what happened and what we did about it.
Your rights
Depending on where you live, you can ask us to do the following with information we hold about you.
- Get a copy of the information we hold about you.
- Correct anything that is wrong or out of date.
- Delete it, apart from records we are legally required to keep.
- Receive it in a portable, machine-readable form, or have it sent to another provider.
- Object to a particular use, or withdraw a consent you gave — without affecting what was done before you withdrew it.
- Complain to your local data-protection authority.
Write to admin@dafatir.app and we will answer within 30 days. We may need to confirm who you are before we act, so that we do not hand someone's information to the wrong person. If your request concerns a shop that uses Dafatir, we forward it to that shop and act on their instruction.
How to delete your data
You can have information deleted at any time. Which route applies depends on whose information it is.
- If you are a merchant: disconnect WhatsApp or Instagram in Hiwar under Settings, which stops us receiving anything further on that number or account. To delete stored conversations, media, contacts, or your whole account, email admin@dafatir.app from the address on the account, or ask your Dafatir representative. We delete within 30 days and confirm when it is done.
- If you are a customer of a shop that uses Dafatir: ask the shop, which controls its own records. You can also email admin@dafatir.app, and we will forward the request to that shop and act on their instruction.
Deleting a chat in the WhatsApp Business app or in Instagram does not delete the merchant's copy in Dafatir, and deleting it in Dafatir does not remove it from WhatsApp or Instagram on anyone's phone. Records the law requires us to keep — accounting and VAT entries in particular — are separated and deleted when their statutory period ends.
Children
Dafatir is software for businesses and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child's information has reached us, write to admin@dafatir.app and we will delete it.
Changes to this policy
When this policy changes, we post the new version on this page and change the date at the top. If a change materially affects how we handle personal information, we tell merchants directly before it takes effect.
Contact us
Dafatir provides the products described here and is responsible for the information this policy covers. For any privacy question, a request about your rights, or a deletion request, write to us at:
The registered company behind this service
- Legal name
- Tal3a E-Commerce Company
- Registered address
- رام الله - بيتونيارام الله، رام الله والبيرةPalestine
- Phone
- +970592026002
- admin@dafatir.app